This Privacy Policy explains how D&S Tech LLC (“D&S Tech,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with the MEPSub platform and the website at mepsub.org (together, the “Service”). MEPSub and the MEPSub logo are trademarks of D&S Tech LLC.
This policy applies to information we process when you visit our website, create or use a MEPSub account or workspace, or otherwise interact with the Service. It does not apply to third-party websites, applications, or services that we do not control, even if they link to or from the Service.
If you use MEPSub as an employee, contractor, or member of an organization that has its own MEPSub workspace (your “Workspace Administrator”), that organization controls the workspace and its data, and its own privacy practices may also apply to you.
Depending on the data, we act in one of two roles:
We do not sell personal information, and we do not use third-party advertising trackers on the Service.
Where we use optional AI features, your prompts and the relevant records are sent to our AI provider solely to generate the requested output (for example, drafting an estimate). We do not permit that content to be used to train third-party foundation models.
We share information only as described here:
We do not sell or rent personal information to third parties.
We use trusted providers to deliver the Service. Categories and representative providers include:
| Purpose | Providers |
|---|---|
| Payments (customer invoice payments) | Stripe, Square (Block), PayPal, Intuit QuickBooks Payments |
| Accounting sync | Intuit QuickBooks Online |
| Calendar & file storage (when connected) | Google, Microsoft, Dropbox |
| SMS & messaging | Telnyx |
| Email delivery | Our transactional mail service |
| Hosting & infrastructure | Our cloud hosting and storage providers |
Providers only receive the data needed for their function and are bound by confidentiality and data-protection obligations. We can provide a current list of sub-processors on request.
The Service uses a single essential cookie to maintain your authenticated session and protect against cross-site request forgery. It is required for the Service to function and cannot be switched off from within the app. We do not use advertising or cross-site tracking cookies. Your browser can block or delete cookies, but the Service may not work correctly if you block the essential cookie.
We retain account and workspace data for as long as your account is active. If your account or workspace is closed, we retain data for a limited period to allow recovery and to meet legal, tax, and accounting obligations, after which it is deleted or anonymized. You or your Workspace Administrator can request export or deletion of Customer Data as described in §10, subject to those obligations.
We use technical and organizational measures designed to protect information, including encryption in transit (HTTPS), hashed passwords, role-based access controls, per-workspace data isolation, and regular backups. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please use a strong, unique password and keep your credentials confidential.
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. Residents of California (CCPA/CPRA) and the EEA/UK (GDPR) have specific rights, including the right not to receive discriminatory treatment for exercising them.
For personal information we hold as a controller, contact us at support@mepsub.org and we will respond as required by applicable law. For Customer Data held within a workspace (where we act as processor), please direct your request to your Workspace Administrator; we will assist them in responding.
We are based in the United States and process data there. If you access the Service from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States, where data-protection laws may differ from those in your country. Where required, we rely on appropriate safeguards for such transfers.
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us and we will delete it.
We may update this policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide additional notice (for example, by email or an in-app notice). Your continued use of the Service after an update means you accept the revised policy.
If you have questions about this policy or our privacy practices, contact: