Nimbus Takeoff Privacy Policy
Accountable organization: Nimbus Takeoff Inc.
Mailing address: 51 Guided Ct, Etobicoke, ON M9V 5G2, Canada
Privacy Officer: Privacy Officer, Nimbus Takeoff Inc.
Version: 3.0
Effective Date: July 2026
Privacy and support contact: support@nimbustakeoff.com
Privacy Summary
This summary does not replace the complete Policy below.
- What Nimbus receives: Nimbus receives account, company, billing, device, usage, support, and security information, together with documents and other content customers submit to the Services.
- Google sign-in: Optional Google sign-in provides basic identity information through the
openid,email, andprofilescopes. It does not give Nimbus access to Gmail, Google Drive, Google Photos, or Google Workspace content. - Customer Content and AI processing: Nimbus processes Customer Content to provide, secure, maintain, and support the Services and meet legal obligations. Under this version, Nimbus does not use Customer Content for generalized Nimbus model training. Any future generalized training requires a separate, affirmative opt-in before it begins.
- Payments: Stripe processes payment credentials. Nimbus does not intentionally receive or store full card numbers, but it receives Stripe identifiers and payment metadata needed to operate billing and maintain records.
- Cancellation and deletion: An explicitly elected ordinary end-of-term cancellation of paid Pro service, or an unconverted trial naturally reaching its previously identified scheduled terminal end, may enter the prospective six-month retention path in Section 8.1. Early trial cancellation, nonpayment, and other exceptional termination paths do not. A separately confirmed permanent company-deletion request follows a different path.
- No sale or advertising use: Nimbus does not sell personal information or Customer Content and does not use them for third-party advertising.
1. Scope and Accountability
This Privacy Policy (“Policy”) explains how the accountable organization identified above (“Nimbus,” “we,” “us”) collects, uses, discloses, stores, retains, and deletes information when a customer or authorized user uses Nimbus Takeoff websites, applications, support channels, and related services (the “Services”).
Nimbus has designated the Privacy Officer identified above to oversee this Policy and Nimbus's privacy request, complaint, and breach procedures.
Nimbus Takeoff is a business service. A customer organization controls which users may access its company account and the Customer Content those users submit. The organization and its administrators may manage user access and use the company-data controls available on particular product surfaces. Individual users should direct organization-controlled requests to their company administrator first.
The Terms of Service govern Customer Content licenses, account use, billing, and the Services. This Policy describes Nimbus’s privacy practices and forms part of the agreement identified in the Terms.
2. Information Nimbus Collects
2.1 Account, User, and Company Information
Nimbus may collect:
- name, email address, telephone number, job title, and account preferences;
- company name, address, trade, business type, tax or billing details, and company settings;
- user role, permissions, invitation status, account status, acceptance records, and authentication history;
- an email/password credential stored as a one-way password hash for users who set a Nimbus password; and
- basic Google identity information for users who choose Google sign-in, as described in Section 4.
Google-authenticated users may not have a usable Nimbus password unless they separately establish one.
2.2 Customer Content
“Customer Content” includes drawings, specifications, documents, images, pages, project and customer records, measurements, quantities, rates, estimates, bid information, annotations, labels, prompts, feedback, saved estimate snapshots, Project outcome records, portfolio and outcome analytics generated from Customer Content, and other material submitted to the Services or created through the Services from customer inputs.
Processing Customer Content may create derived information such as rendered pages, thumbnails, crops, extracted text, geometry, measurements, detected or classified elements, annotations, labels, embeddings or feature representations, model outputs, portfolio and outcome analytics generated from retained Customer Content, and product-quality records.
Customer Content may contain personal information, confidential business information, intellectual property, or information about third parties. Customer is responsible for having the authority required to submit and license it.
Unless Nimbus expressly enables and authorizes a compliant use in writing, the Services are not intended to receive protected health information, full payment-card or bank-account credentials, government identification numbers, export-controlled information, or other specially regulated or highly sensitive information that the Services do not require.
2.3 Billing and Transaction Information
Stripe processes payment credentials and is the source of truth for subscription and invoice state. Nimbus does not intentionally receive or store full card numbers. Nimbus may receive and retain:
- Stripe customer, subscription, invoice, payment-intent, payment-method, tax, and related identifiers;
- billing names, email addresses, telephone numbers, and addresses;
- card brand, last four digits, card fingerprint, expiry information, and payment-method type;
- subscription status, billing cadence, seat quantity, currency, tax information, invoice and payment status, and transaction timestamps; and
- subscription-change, billing-support, refund, dispute, payment-failure, grace-period, and customer-support records.
Stripe processes payment information under its own privacy terms.
2.4 Usage, Device, Browser, and Security Information
Nimbus may collect account-linked and device-linked information such as:
- IP address, user agent, browser and operating-system information, language, locale, time zone, and device characteristics;
- login, logout, session, token, account-switch, invitation, enrollment, feature-use, page, action, error, performance, and audit events;
- fraud, abuse, rate-limit, email-validation, signup, payment-risk, and security signals;
- a device or browser identifier produced for enrollment-abuse and security controls; and
- diagnostic logs and request metadata needed to operate, secure, debug, maintain, and support the Services.
This information is not necessarily anonymous. Nimbus may associate it with a user, company, session, request, project, or transaction where needed for the purposes in this Policy.
Nimbus may use device, IP, email-validation, payment-risk, and related signals to block, rate-limit, or route an enrollment, trial, login, or payment attempt for additional review or support.
2.5 Support, Communications, and Feedback
Nimbus may collect messages, attachments, support history, product feedback, survey responses, and other information a user sends to Nimbus. In-product assistant or AI interactions may include prompts, Customer Content, generated responses, tool activity, and feedback needed to provide, secure, maintain, troubleshoot, and support the feature. Under this version, Nimbus does not use Customer Content inside those interactions or submissions for generalized model training.
3. How Nimbus Uses Information
Nimbus may use information to:
- create, authenticate, administer, and secure accounts and company workspaces;
- provide document processing, takeoff, estimating, collaboration, billing, support, and Customer-requested AI functions;
- create and present saved estimate snapshots, Project outcome history, and Company-scoped portfolio and outcome analytics from retained Customer Content;
- process enrollment, subscriptions, invoices, taxes, payment actions, cancellations, renewals, authorized refunds, and related support through Stripe;
- communicate service, security, billing, trial, legal, and support information;
- prevent fraud, enrollment abuse, unauthorized access, and other misuse;
- diagnose errors, measure performance, understand account-linked feature use, and maintain the Services;
- enforce agreements, preserve evidence, protect rights and safety, comply with law, and resolve disputes;
- perform customer-requested inference and analysis and the purpose-limited Customer Content processing described in Section 5; and
- perform other uses disclosed when information is collected or authorized by Customer.
Nimbus does not use a trial-warning acknowledgement as payment authorization. The enrollment terms and payment-method authorization govern automatic continuation of a trial subscription.
4. Google Sign-In Information
4.1 Information Accessed
If a user chooses Google sign-in, Nimbus requests only the standard openid, email, and profile scopes. Google’s standard UserInfo response may transiently include additional profile fields, such as a display name or profile-image URL. Nimbus selects and persists only the stable subject identifier, verified email address, and given and family names needed for account creation and access; it does not intentionally retain unselected profile fields after the sign-in exchange.
Nimbus does not request access to Gmail, Google Drive, Google Photos, Google Calendar, contacts, or Google Workspace document content through Google sign-in.
4.2 How Google Information Is Used and Stored
Nimbus uses Google identity information to authenticate the user, create or link the Nimbus account, display account identity, protect the signup and login flow, and support the account. Nimbus stores the stable Google identifier, verified email address, and given and family names needed for those purposes in its account records.
The Google access token used to verify sign-in is processed transiently and is not intentionally retained by Nimbus after the authentication exchange. During signup, a short-lived Nimbus enrollment credential derived from the verified Google exchange may briefly pass through the signup route so the user can complete the ordinary company-enrollment form; Nimbus removes it from the visible browser address after it is read.
Revoking Google access stops Google authentication unless the user authorizes it again, but does not by itself delete the Nimbus account, end a subscription, or delete Customer Content. A user may use the applicable Nimbus account or deletion process separately. Documents or other content that a user independently uploads to Nimbus are Customer Content; they are not Google user data merely because the user authenticates with Google.
4.3 Google Information Restrictions
Nimbus does not sell Google identity information, use it for advertising, include it in Nimbus model-training material, or permit service providers to use it to train their independent models. Nimbus shares it only as necessary to operate and secure the Services, comply with law, or complete a user-requested function under this Policy.
4.4 Google-Powered Address Search and Validation
Where enabled, Nimbus address-entry surfaces use Places Autocomplete and Address Validation. Authenticated Company and Project address validation uses the signed-in Nimbus session. Signup address validation is available only after a signed private-email enrollment admission or a verified Google signup continuation; authority-free public email signup uses manual entry. As a user types in an enabled search surface, the user’s browser sends the address query and a short-lived session token directly to Google and receives a suggestion list shown with the required Google Maps attribution. When the user selects a suggestion, the browser sends the selected suggestion text and the same session token to Nimbus; Nimbus verifies the applicable signed-in or signup authority before sending only those values to Google Address Validation and returning a filtered, normalized candidate for review with the same required attribution. Nimbus does not call Place Details in this flow or request a selected place identifier.
The normalized candidate remains transient until the user chooses Use this address, or chooses manual review or correction and later submits the form. Required Google Maps attribution remains visible while provider-derived candidate fields remain visible during manual correction, until save, reset, cancellation, or abandonment. Only then does Nimbus construct and retain the user-confirmed or user-corrected address in the applicable company or project record. Failed or incomplete validation does not substitute the prediction text. Nimbus does not intentionally persist the raw suggestion list, prediction text as a fallback, session token, raw Address Validation response, response identifier, geocode, verdict or component-validation metadata, provider metadata, or a Google-returned timezone field. Any stored company or project timezone is supplied or derived separately from Google address content.
Nimbus does not use Google Maps Platform content—including Places predictions and Address Validation response content—to train, test, validate, fine-tune, or otherwise improve machine-learning or artificial-intelligence models.
Use of these address features is subject to the then-current Google Maps End User Additional Terms of Service and Google Privacy Policy. Google may receive the typed query or selected suggestion text, session token, IP address, browser or server request information, and the fields needed to return suggestions and validate the address. Blocking or not using the feature leaves manual address entry available.
5. Customer Content and AI Processing
5.1 Purpose-Limited Service Processing
Nimbus processes Customer Content to provide, secure, maintain, and support the Services and meet legal obligations. This includes document rendering, OCR, customer-requested inference and analysis, collaboration, fraud and abuse prevention, troubleshooting, backup, and support. An enabled AI model may process Customer Content to answer a Customer request; that processing is not a license for secondary or generalized model training.
Under this version, Nimbus does not select, retain, or use Customer Content for generalized Nimbus model training. Any future generalized Nimbus training using Customer Content is a separate feature and may begin only after Nimbus publishes updated disclosures and obtains a distinct, affirmative opt-in. Continued use of the Services or acceptance of ordinary service processing is not that opt-in.
Nimbus does not sell Customer Content or use it for third-party advertising.
5.2 AI-Provider Training Boundary
Nimbus configures its AI providers so that Customer Content is not used to train their models. Nimbus limits provider processing to the requested service and related operational needs. Depending on the verified provider terms and account settings, providers may retain or process limited Customer Content or request information for service delivery, short-lived caching, abuse and safety monitoring, security, or legal obligations. Nimbus does not describe that boundary as Customer Content never leaving Nimbus or as universal zero retention.
Google Maps Platform content, including Places predictions and Address Validation response content, is not included in Nimbus training, testing, validation, fine-tuning, or model-improvement material. This exclusion does not reclassify independently uploaded Customer Content merely because that content contains a street address.
5.3 Ownership and Required Customer Authority
Customer retains ownership of Customer Content, including outputs covered by the definition in the Terms, subject to the limited operating license in the Terms. Nimbus owns its software, model parameters, interfaces, documentation, and other Nimbus technology; this does not transfer ownership of Customer Content to Nimbus.
Customer must have all rights, permissions, notices, consents, and lawful authority needed to submit Customer Content and permit the uses in the Terms and this Policy, including where third-party drawings, documents, people, contact details, or confidential information are involved. A customer that cannot grant those permissions must not submit that content to the Services.
6. When Nimbus Discloses Information
6.1 Within a Customer Organization
Nimbus makes account and Customer Content available to authorized users of the same customer organization according to product roles, permissions, collaboration features, and company-administrator controls. Company administrators may manage users and access company-level information.
6.2 Service Providers
Nimbus uses service providers to host, deliver, secure, maintain, and support the Services. Depending on the enabled feature and deployment, these may include:
- Render for application hosting and managed infrastructure;
- Amazon Web Services, including S3, CloudFront, and Textract, for storage, content delivery, and document extraction;
- Stripe for payments, subscriptions, invoices, tax functions, fraud prevention, and billing support;
- Google for optional sign-in and, where a customer separately uses an enabled feature, mapping/place or Gemini-powered processing;
- third-party AI model and inference-infrastructure providers for enabled AI processing;
- Postmark for transactional and authorized service/broadcast communications;
- ZeroBounce, where enabled, which receives the signup email address and client IP for email validation and enrollment-abuse controls;
- Sentry, where enabled, for error and performance diagnostics;
- hosted database, cache, job-processing, and real-time delivery infrastructure used by Nimbus.
Browser-executed software does not become a separate data recipient merely by running locally. Under the reviewed release configuration, Nimbus serves its version-matched PDF.js worker from the Nimbus origin and uses a locally executed FingerprintJS package. Nimbus disables FingerprintJS vendor monitoring and does not send its optional installation-statistics request to openfpcdn. Applicable software licenses and notices are provided through Nimbus's Third-Party Notices surface.
Nimbus limits information sent to a provider to what is reasonably needed for the enabled function. Providers process information under their applicable terms and, where applicable, agreements with Nimbus. Some providers independently process information under their own terms, particularly Stripe and Google when a user interacts directly with their services.
Nimbus configures its AI providers so that Customer Content and Google identity information are not used to train their models, subject to the provider-processing limits described in Section 5.2.
6.3 Legal, Safety, and Business Transfers
Nimbus may disclose information when reasonably necessary to comply with law or legal process; protect customers, users, Nimbus, or others; investigate fraud, abuse, security incidents, or disputes; enforce agreements; or establish, exercise, or defend legal claims.
Nimbus may disclose or transfer information in connection with a financing, merger, acquisition, reorganization, sale of assets, insolvency, or transfer of all or part of the Services, subject to applicable law and appropriate protection of the information.
6.4 No Sale or Third-Party Advertising
Nimbus does not sell or rent personal information or Customer Content and does not disclose them for third-party targeted advertising.
7. Cookies, Browser Storage, and Similar Technology
Nimbus uses cookies, browser storage, session storage, tokens, and similar technology to authenticate users, route requests, preserve settings, support cross-tab behavior, secure enrollment, prevent abuse, and operate features.
Depending on the flow, the browser may store Nimbus access and refresh tokens, a limited user/session representation, authentication and OAuth state, an application-authentication cookie, locale and interface preferences, in-progress assistant or feature state, dismissal state, and device or enrollment-abuse identifiers. Stripe and content-delivery providers may set or use their own cookies or storage when their services are loaded.
Some state remains on the particular browser or device until Nimbus code removes it, it expires, the user clears it, or browser settings remove it. Signing out or deleting an account on one device does not guarantee that every non-sensitive preference or cached browser value is immediately removed from every other device, although expired or invalid credentials no longer authorize server access.
Blocking required cookies or browser storage may prevent authentication, billing, document viewing, or other Services from working correctly.
8. Retention, Cancellation, and Deletion
Nimbus retains information only for as long as reasonably necessary for the purposes described in this Policy, the Terms, the customer relationship, security and dispute needs, and legal or accounting obligations. Different categories follow different rules.
8.1 Six-Month Post-Subscription Retention
When a company administrator explicitly elects ordinary end-of-term cancellation of a live paid Pro subscription and that exact Stripe Subscription reaches terminal end, Nimbus retains the former customer’s operational company data before scheduled finalization. The same rule applies when an unconverted trial naturally reaches the exact scheduled terminal end that Nimbus identified for this path before that end occurred. This rule applies prospectively; Nimbus does not infer a retention window from legacy or ambiguous cancellation state.
The deadline is six UTC calendar months after the exact terminal Stripe Subscription’s ended_at time, and finalization becomes eligible at that deadline. Merely scheduling a future cancellation does not start the clock. Early trial termination, paused or unpaid service, nonpayment, material breach, fraud or security action, administrative termination, and Nimbus-initiated termination do not enter this path. A separately confirmed permanent company-deletion request under Section 8.2 also follows a different path. Retention does not itself grant application access, a complete export right, or restoration of the former Stripe subscription.
An incomplete replacement Stripe Subscription, or a not-started or active Stripe Subscription Schedule, is unresolved billing activity. Nimbus preserves the operational company data and retries the finalization check while that state remains unresolved; it does not by itself cancel finalization. If Nimbus verifies a replacement Stripe Subscription in an active or otherwise resumable state before irreversible finalization, Nimbus cancels finalization and preserves the retained operational company data under the renewed account. If the finalization check verifies that neither unresolved billing activity nor a replacement Subscription prevents finalization, Nimbus finalizes the company at or after the six-calendar-month deadline, subject to the distinctions below and applicable law.
8.2 Customer-Initiated Company Deletion
A confirmed voluntary company-deletion request immediately disables customer access and begins terminal account and billing cleanup. Voluntary company deletion follows the finalization process below instead of the six-month subscription-retention path.
Nimbus may temporarily retain inaccessible operational data during a limited internal incident-response window to investigate a suspected unauthorized deletion and, when Nimbus verifies one, perform the support-only account-recovery process described in the Terms. That temporary window is not a general retention entitlement or a customer right to reverse voluntary deletion.
At finalization, Nimbus removes ordinary operational company information, including ordinary project, customer, and company document copies, subject to technical completion and applicable law.
8.3 Information That May Survive Operational Finalization
Operational finalization does not require Nimbus to delete:
- Protected records: Nimbus may retain the minimum identifying billing, tax, accounting, payment-dispute, fraud-prevention, security, litigation, legal-acceptance, and immutable-audit records reasonably required for their documented purpose and retention period.
- Required temporary or technical copies: limited backups, logs, queued work, or provider copies may remain until overwritten, expired, or deleted through the applicable technical cycle, provided they remain protected and are not restored to ordinary use except for continuity, security, or legal purposes.
Saved estimate snapshots, Project outcome records, and associated estimate ledgers used to generate portfolio or outcome analytics are ordinary operational Project content. Their product immutability or auditability does not, by itself, make them protected records under this Section.
Protected records are access-restricted, excluded from generalized model training, and are not described as anonymous when a required identifier remains.
9. Security
Nimbus uses administrative, technical, and organizational safeguards appropriate to the nature of the Services and information. These include authentication, tenant-scoped access controls, password hashing for email/password users, transport security in deployed environments, and private or signed delivery controls for protected documents.
No system is completely secure. Customers are responsible for controlling user access, protecting their devices and credentials, reviewing company permissions, and promptly reporting suspected unauthorized use. Nimbus investigates known security incidents and provides notices required by applicable law.
10. Privacy Choices and Requests
Subject to the customer organization’s authority, identity verification, applicable law, and legitimate retention needs, a person may ask Nimbus to:
- provide information about Nimbus’s processing of their personal information;
- provide access to or correct personal information Nimbus controls;
- address a concern or challenge compliance with this Policy;
- withdraw consent where consent is the applicable legal basis and withdrawal is legally available; or
- delete personal information that Nimbus is not required or permitted to retain.
Send requests to support@nimbustakeoff.com. Nimbus may need to verify the requester’s identity and authority, and may direct organization-controlled requests to the customer’s company administrator. Nimbus will respond as required by applicable law. Some requests may be limited where information concerns another person, is subject to privilege or legal restriction, is needed for security or dispute purposes, or cannot be separated from required protected records.
Google access can also be reviewed or revoked through the user’s Google account controls. Revocation does not by itself delete the Nimbus account or Customer Content.
11. International Processing
Nimbus and its service providers may process information in Canada, the United States, and other countries where the providers operate. Information processed outside a person’s province, state, or country may be subject to the laws and lawful-access regimes of that jurisdiction.
Nimbus uses contractual and operational safeguards appropriate to the service and information. This Policy does not claim that every privacy law applies to every customer; Nimbus handles requests and obligations according to the law applicable to the particular processing and relationship.
12. Children
The Services are intended for business users who are at least 18 years old. Nimbus does not knowingly offer the Services to children. If Nimbus learns that a child provided personal information contrary to this restriction, Nimbus will take appropriate steps to delete or otherwise address it.
13. Changes to This Policy
Nimbus may update this Policy to reflect changes to the Services, law, security, or business practices. Nimbus will identify the version and effective date and provide notice required by applicable law or the agreement. Where Nimbus requires explicit acceptance of a new version, continued access may be conditioned on that acceptance.
A new version does not silently replace the text attached to a previously recorded acceptance. Before a material change affecting Customer Content governs an existing customer, Nimbus will provide the notice and obtain any affirmative acceptance required by applicable law or the applicable agreement. Before introducing generalized Nimbus model training using Customer Content, Nimbus will publish updated disclosures and obtain a distinct, affirmative opt-in before that use begins; a change notice or continued use alone is not that opt-in.
14. Contact
Questions, requests, and complaints about this Policy may be directed to the Privacy Officer at support@nimbustakeoff.com. The same monitored address also accepts general product and account support.
Privacy Officer, Nimbus Takeoff Inc.<br> 51 Guided Ct<br> Etobicoke, ON M9V 5G2<br> Canada
The applicable affirmative acceptance record confirms that Customer read and understood the presented version of this Policy. Ordinary use of the Services and acknowledgement of a supplemental trial warning do not replace a required Privacy Policy acceptance record.
© 2026 Nimbus Takeoff. All rights reserved.
