WHITEGATE MECHANICAL INC.Employee sign in

Project Control

Privacy Policy

How Whitegate Mechanical handles information in Project Control and its integrated Purchasing Tool.

Effective September 21, 2026

1. Who operates the Application

Whitegate Mechanical, Inc. (“Whitegate”, “we” or “us”) operates Whitegate Mechanical | Project Control and its integrated Purchasing Tool (the “Application”). A connected service may identify it as “Whitegate Tool” or “Whitegate Control”. This policy covers the Application’s employee accounts, company records, connected services and AI features.

The Application is an internal business workspace. The public availability of this policy does not make its business records public. This policy is specific to Project Control; other websites and connected providers have their own privacy practices.

2. Information we handle

We process the information needed for the features you use and the permissions granted to you, including:

  • Account information: name, work or approved sign-in email, role, project assignments, access settings, password verification records and session information.
  • Business records: project plans, contacts, budgets, forecasts, tasks, material lists, quotations, purchase orders, deliveries, returns, supplier invoices, credits, approvals, notes and uploaded supporting documents.
  • Connected-service information: account or company identifiers, authorization permissions and tokens, selected imported records, connection status and update timestamps.
  • Work email: the authorized mailbox address, sender and recipient details, subject, dates, message text, message identifiers and labels needed to present recent received and sent mail, plus derived priorities and user-entered notes or drafts.
  • Operational information: access and change history, error information and service request data. Hosting and security services may process IP addresses, browser information and request logs to deliver and protect the service.
  • AI inputs and outputs: questions, selected authorized records and generated answers or document-extraction results when an AI feature is used.

3. Why we use information

We use information to provide employee access; plan and monitor projects; manage purchasing and delivery evidence; support Finance review and reconciliation; show recent work email and follow-ups; answer questions using permitted records; and maintain security, accountability and reliable operation.

Whitegate does not sell Application data or use connected email or accounting data for advertising, data brokerage or credit scoring. We do not use connected-service data to train general-purpose AI models.

4. Personal email connection and owner visibility

Each employee authorizes their own approved Google mailbox. The personal email feature requests read-only Gmail access. It reads recent received and sent messages to show the rolling last seven days and suggest work priorities; spam, trash and drafts are excluded from that review. Message content is displayed as text, and remote email images and attachments are not automatically loaded by this feature.

The connected employee and the company owner can review that employee’s email and priorities. Other employees do not gain mailbox access merely because they belong to Finance, Purchasing or another department. The connection notice explains owner visibility before authorization. Do not connect an account you are not authorized to share for this purpose.

This personal email feature does not send messages, mark them read, change labels, archive or delete them in Google. A separately authorized Purchasing mailbox may support supplier-document intake and explicitly requested outgoing supplier messages; those permissions and actions are separate from personal read-only email review.

5. Google data use

Information obtained through Google APIs is used only to provide the disclosed email, purchasing and assistance features, subject to the Google API Services User Data Policy, including its Limited Use requirements. Transfers are limited to providing authorized features with the required consent, security needs, legal obligations or another use expressly permitted by that policy.

Human access to Google data is limited to the access you authorize through the disclosed feature and the exceptions allowed by Google’s policy, such as necessary security or legal access. Google data is not provided to advertising platforms or data brokers and is not used to develop or improve general-purpose AI models. A materially different use requires an updated disclosure and any required consent before it begins.

6. QuickBooks, Salesforce and purchasing records

When an authorized Finance user connects QuickBooks Online, the Application can access the company identifier and the vendor, customer/project, account, bill and balance information needed by the enabled Finance workflows. Authorized invoice posting sends the approved bill details and applicable supplier, project and account references to QuickBooks. Connection alone does not approve a bill, make a payment or establish that a balance is current.

When Salesforce is connected, the Application imports the opportunity, related customer and owner details, task and organization information needed for its sales views and permitted questions. Access depends on both the connecting Salesforce account and the employee’s Project Control permissions.

Purchasing and Finance use shared purchase, receipt and invoice records with their respective permissions. Information is exchanged with a provider only through a configured and authorized feature. This policy does not imply that an unconnected service is already receiving or supplying data.

7. AI processing

When you use an enabled AI feature, your question and the relevant records your account may access are sent to OpenAI to produce the requested answer or extraction. These may include project and purchasing information, authorized Salesforce records, email excerpts or priorities, and documents submitted through a supported extraction feature. Connection secrets and passwords are not supplied as answer evidence.

Ask Whitegate applies the employee’s permissions before selecting evidence. Its conversation is held in the current page rather than a persistent chat-history table. The company’s OpenAI API settings and the provider’s service data controls govern provider-side handling and retention; this is not a promise of zero retention. Whitegate does not use those inputs or outputs to train a general-purpose model.

8. Who can receive information

Information is available to Whitegate personnel according to their roles and project permissions, with the owner oversight described above. Service providers process information needed to host, secure and operate the Application. These include OpenAI’s Sites hosting service, Cloudflare infrastructure and storage, OpenAI for enabled AI features, and the connected Google, Salesforce or Intuit services for their authorized functions. The company website hosts these public policy pages.

Information may also be shared when necessary to investigate abuse, protect rights or comply with a legal requirement. Any disclosure must respect applicable law and connected-provider restrictions. Provider processing may occur in the United States or other countries; this policy does not promise a particular country of data residency.

9. Retention, disconnecting and deletion

The personal email view covers a rolling seven-day window. Older cached messages are removed during successful mailbox updates; a failed or delayed update can leave a previous cache until the next successful update or disconnection. This display window is not a seven-day deletion rule for independent business notes, approvals, audit records or supporting documents.

Disconnecting a personal mailbox removes its saved connection and cached messages from the Application and stops further imports through that connection. It does not delete the original mailbox or automatically erase independent business records. You can also revoke the Application’s access through your Google account’s third-party connection settings.

An authorized administrator can disconnect company integrations. Disconnection stops future access through that connection but does not undo records already posted to QuickBooks or remove the originals held by a provider. Company, purchasing, invoice and audit records may be retained while needed for ongoing work, reconciliation, security, contractual obligations or applicable legal requirements. Any retained information remains subject to access controls. Provider backups and operational logs follow the relevant provider’s retention arrangements.

For access, correction, deletion or retention questions, contact us using the details below. We will verify the requester’s identity and authority and consider the request under applicable law and provider requirements. Where information must be retained, we will explain the applicable limitation.

10. Security and cookies

The Application uses HTTPS, employee authentication, server-side permissions, password hashing and encrypted connection credentials. Session cookies support sign-in and access controls. These measures reduce risk but cannot guarantee that every interruption or unauthorized access will be prevented. Keep your account credentials private and promptly report a suspected incident.

The Application does not include advertising trackers. Hosting, sign-in and connected provider pages may use their own necessary cookies and operational logging under their respective policies.

11. Your choices and policy updates

You can choose whether to authorize an optional connection, disconnect your mailbox, ask your administrator to review your access, and request access to or correction or deletion of information as applicable. You may also have other rights under the laws that apply to you. Company and contractual recordkeeping requirements can limit deletion of work records. The Application is intended for authorized business personnel and is not directed to children.

We will update the effective date when this policy changes. Material changes will be communicated through the Application or company communications. Before using connected data for a materially different purpose, we will provide the required notice and obtain any required consent.

12. Contact Whitegate

For privacy requests, contact info@whitegatemechanical.com and use “Project Control privacy” in the subject. Employees may also contact the company owner or their administrator. Do not send passwords, authorization tokens or unnecessary sensitive documents in an initial request.

Whitegate Mechanical, Inc.
2003 S Easton Rd, Suite 308, Office 306
Doylestown, PA 18901, United States

Related document: End-User License Agreement.