This notice explains what information Controls Star (“we”, “us”) collects when you visit controls-star.com or use the Controls Star application and related services, how we use it, whom we share it with, and the rights you have. If you do not agree with it, please discontinue use of the services.
1. What information do we collect?
In short: Account details you give us, the project data you upload, messages you send us, and limited technical data needed to run and secure the service.
- Account information — your name, work email, password (stored only as a salted hash), workspace/organization name, role, plan and billing status.
- Project data — the cost, schedule, hours, discipline, progress and file data (for example Primavera P6 .xer, Excel/CSV or images) you upload or enter, plus project metadata such as project name, client, location and project manager.
- Communications — information you submit through our Contact, Book a Demo and Feedback forms (name, company, job title, email, phone, project types, how you heard about us and your message).
- Billing information — handled by Stripe. Controls Star stores Stripe customer/subscription identifiers and invoice status; we never store full card numbers.
- Automatically collected data — IP address, browser and device type, timestamps and the pages or API actions used. We record this in server logs and security audit logs to keep accounts secure, enforce rate limits and investigate abuse.
- Optional product analytics — only if you allow it in Privacy Choices, our analytics provider (PostHog) collects page views, product actions and interaction patterns. This is off by default and off whenever your browser sends a Global Privacy Control signal.
2. How do we use your information?
In short: To provide and secure the service, bill you, answer you, and — with consent — understand how the product is used.
- Provide the service — computing earned value, schedule health and other metrics, generating findings and recommendations, and delivering exports and reports you request.
- Generate insights — summaries of your project metrics are sent to our AI model provider to produce narrative findings. Your customer data is not used to train those models.
- Operate, secure and improve the service — authentication, fraud and abuse prevention, rate limiting, error monitoring and troubleshooting.
- Billing and account management — processing subscriptions, seats and project slots through Stripe and sending transactional email (receipts, security alerts, password resets, deletion confirmations) through our email provider.
- Respond to you — replying to contact, demo and feedback submissions and scheduling demos you request.
- Comply with law — meeting legal, tax, accounting and security obligations.
- We rely on performance of our contract with you, our legitimate interests (security, service improvement), your consent (optional analytics, marketing communications) and legal obligations as the bases for this processing.
3. Will your information be shared with anyone?
In short: Only with service providers that help us run Controls Star, when the law requires it, or in a business transfer. We do not sell personal information.
- Service providers (processors) acting on our instructions: cloud hosting and object storage for the application and uploaded files; a managed MongoDB database; Stripe for payments; an email delivery provider for transactional and notification email; PostHog for optional analytics; and an AI model provider that receives project-metric summaries to generate insights.
- Within your workspace — project data is visible to the members and owners of your workspace according to the roles you assign.
- Legal requirements — where required to comply with applicable law, regulation, legal process or an enforceable governmental request, or to protect the rights, property or safety of Controls Star, our customers or others.
- Business transfers — in connection with a merger, acquisition, financing or sale of all or part of our business, subject to this notice.
- We do not sell personal information, do not share it for cross-context behavioral advertising, and do not share one customer's project data with another customer.
4. Do we use cookies and other tracking technologies?
In short: Only strictly necessary storage by default; optional analytics cookies load only after you opt in.
- Strictly necessary — your sign-in session, security tokens and your Privacy Choices preference are stored in your browser so the site can function. These cannot be switched off.
- Optional analytics — PostHog cookies and identifiers are set only after you choose "Allow all" in Privacy Choices. You can change your choice at any time from the footer link.
- We do not use third-party advertising cookies, pixels or retargeting tags.
5. How long do we keep your information?
In short: For as long as your account is active or as needed for the purposes above, then deleted or anonymized on the schedules below.
- Account and project data — retained while your account/workspace is active. When you request deletion, we action it within 30 days of your confirmation.
- Uploaded files marked for deletion are held in a 90-day grace period (so accidental deletions can be recovered) and then permanently purged.
- Sign-in attempt records are kept for up to 180 days and security audit logs for up to 400 days to detect and investigate abuse.
- Contact, demo and feedback submissions are kept until we have answered you and no longer need them, or until you ask us to delete them.
- Billing records are kept as long as required by tax and accounting law. Data in backups is isolated from further processing until it expires.
6. How do we keep your information safe?
In short: Encryption, workspace-scoped access and logged administrative access — but no system is 100% secure.
- Data is encrypted in transit (TLS) and at rest. Every database query is scoped to your workspace, and administrative access is limited and logged.
- Passwords are stored as salted hashes; sign-in is protected by rate limiting and brute-force lockouts.
- Despite these safeguards, no transmission over the internet or storage technology can be guaranteed to be completely secure. Use the service from a secure environment and keep your credentials confidential.
7. Do we collect information from minors?
In short: No. Controls Star is a business service for users 18 and over.
- We do not knowingly collect data from or market to anyone under 18. By using the service you represent that you are at least 18. If you believe a minor has provided us personal information, contact us and we will delete it.
8. What are your privacy rights?
In short: You can access, correct, export or delete your personal information and withdraw analytics consent at any time.
- Access, correction and portability — you can review and update your profile in the app and export your project data at any time. You may also request a copy of the personal information we hold about you.
- Deletion — use the "Request account deletion" button below. You will confirm by email link and we will complete the request within 30 days and confirm when done.
- Consent — withdraw analytics consent at any time via Privacy Choices in the footer; unsubscribe from marketing email using the link in the message or by contacting us.
- If you are in the European Economic Area, the United Kingdom or Switzerland you also have the right to object to or restrict certain processing and to lodge a complaint with your local data protection authority. We do not make automated decisions that produce legal or similarly significant effects about you.
9. Controls for Do-Not-Track and Global Privacy Control
In short: We honor Global Privacy Control signals as an opt-out of optional analytics.
- When your browser sends a Global Privacy Control (GPC) signal, optional analytics stay off unless you actively choose "Allow all". Because no uniform standard for Do-Not-Track (DNT) has been adopted, we do not respond to DNT signals separately; our default is already to load no optional tools until you opt in.
10. Do California residents have specific privacy rights?
In short: Yes. California residents may exercise CCPA/CPRA rights using the contact methods below.
- California residents have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and to not be discriminated against for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising, so there is no need to opt out of sale or sharing.
- Under the "Shine the Light" law (Civil Code §1798.83) you may request information about disclosures to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
11. Do we make updates to this notice?
In short: Yes. We will post the revised notice here with a new "Last updated" date.
- If we make material changes, we will also notify account holders by email or by a prominent notice in the app before the change takes effect.
12. How can you contact us about this notice?
In short: Use the Contact page or the request buttons on this page.
- Questions, access or correction requests: send us a message through the Contact page linked below. Deletion requests: use the "Request account deletion" button below so we can verify your identity by email. We respond to privacy requests within 30 days.