Version 2026-10-02 · Effective October 2, 2026
Privacy Policy
Measure IH, LLC ("MeasureIH," "we," "us") provides proposal software for EHS consultancies. This policy describes how we process personal information when you use the Proposal Studio (team users) or a client proposal portal (portal readers).
Information we collect
- Studio users: Google account email, name, workspace membership, and activity within your organization's workspace. We also keep a 90-day authentication log of studio sign-in success and failure (email, method, hashed IP, and browser family only). Raw IP addresses and full user-agent strings are not stored. Platform operators can review these logs for security and access monitoring. Client portal emails are not included.
- Portal readers: Email address (verified before access), mobile phone number when your consultancy listed one on the proposal and you choose text verification, name and email entered at signing, electronic signature, engagement metrics (views, section time, video playback), and technical metadata (IP address, user-agent) recorded in our audit log at acceptance.
- Payment: Billing is processed by Stripe; we do not store full card numbers.
How we use information
- Authenticate users and deliver proposal portals
- Record legally meaningful electronic acceptances with audit trails
- Send transactional emails (portal links, reminders, acceptance confirmations)
- Send transactional SMS one-time sign-in codes when you request them (not marketing or promotional texts)
- Operate billing and workspace features for consultancies
- Detect abuse and review studio access (authentication logs, 90-day retention)
Retention
Proposal records, signatures, and portal audit logs are retained for the life of the consultancy's workspace and as needed for legal, tax, and dispute purposes. Studio authentication logs are retained for 90 days, then deleted via Firestore TTL on the expireAt timestamp. Workspace administrators can download a JSON export of workspace records from Settings → Data, or delete the workspace. File downloads are omitted from that export. PDF and Excel bulk export are not available yet. Customer-content retention after deletion will be stated when counsel finalizes the Customer Data Protection agreement. Portal readers should contact the consultancy that sent the proposal.
Security
Data is stored in Google Cloud Firestore with organization-scoped access rules. Portal clients never access the database directly - all reads and writes go through authenticated server APIs. Studio authentication logs and platform audit events are written only by the server and cannot be read from the client SDK. Signatures and audit records are written once at acceptance and are not modified afterward.
Sub-processors
We use Firebase (Google), Vercel (hosting), Resend (email), ClickSend (transactional SMS for portal sign-in codes; Twilio may be used as a backup provider), Stripe (payments), Sentry (error monitoring - scrubbed; no session replay), and Google Gemini and other optional AI providers (OpenAI, Anthropic, or OpenRouter when configured). SDS text and proposal content you choose to analyze may be sent to those AI providers to generate results. Each processes data under their respective terms. See our Data Processing Addendum.
Your rights
Depending on your location, you may have rights to access, correct, or delete personal information. Studio workspace administrators can download a JSON export or delete the workspace in Settings → Data. Portal readers should contact the consultancy that sent the proposal. You may also contact Measure IH, LLC at legal@measureih.com.
Related: MeasureIH Terms of Service · Data Processing Addendum · Customer Data Protection · Portal & E-Signature Terms