Privacy Policy

Effective July 25, 2026

Kraken holds the working record of a construction business — its crews, its customers, and its jobs. This page says plainly what we collect, who touches it, and what you can ask us to do about it.

Who this policy covers

Sora Construction builds and operates Kraken, a construction operations platform used by contractors to run their projects, crews, and back office. This policy explains how we handle personal information across the Kraken web application and the Kraken mobile app for iOS and Android.

It does not cover the separate websites, products, or job sites of the companies that use Kraken.

Two different roles

Most people who use Kraken were given an account by an employer. That distinction matters for your data:

  • For information about our own customers — the companies that sign up, their admins, and anyone who contacts us — we decide how the data is used. We are the controller.
  • For the working data a company puts into Kraken — its employees, customers, jobs, time, documents, and photos — that company decides what is collected and why. We only process it on their instructions, to run the service for them.
  • If your employer gave you your Kraken login and you want your data corrected or deleted, start with them. We will help them act on your request.

What we collect

Depending on how your organization uses Kraken, this can include:

  • Account and profile details — name, work email, phone number, job role, organization, language preference, and your authentication state (including multi-factor enrollment).
  • Work records you or your organization enter — time entries and timesheets, time-off requests, vehicle trips and odometer readings, work orders with notes and photos, daily logs, documents and plans, equipment assignments, and customer, estimate, and invoice records.
  • Location, only where your organization turns it on — for dispatch and vehicle features, Kraken can store a worker's last reported position and a history of those points, so a supervisor can see where crews are during the workday. In the mobile app, a technician is asked for location the first time they build a driving route, and it is read at that moment to work out the order of their stops. The app does not track location in the background.
  • Payment information — handled by our payment processor. Card numbers never reach our servers; we keep identifiers and status so invoices and receipts reconcile.
  • Diagnostics — crash reports and error traces, so we can fix what breaks. Our crash reporting is configured not to attach personal data, and it stays off entirely in builds with no reporting key configured.
  • Product usage — which pages and screens are opened, and which features are used, so we can tell what is working and what is being ignored. See “Cookies and analytics” below for what this does and does not record.
  • Basic technical data — IP address, browser or device type, and timestamps, recorded as part of normal request logging and security auditing.

What we do not do

We do not sell personal information, and we do not share it for cross-context behavioral advertising. Kraken carries no advertising, no ad identifiers, and no advertising or marketing trackers. We do use one product analytics service to see how the platform is used — described under “Cookies and analytics” — and it is not connected to any ad network. We do not use your organization's working data to train machine learning models.

Plan and document text recognition in the takeoff tools runs in your own browser — those files are not sent to an outside recognition service.

Service providers

We use a small number of vendors to run the platform. Each receives only what it needs to do its job:

  • Supabase — database, authentication, and file storage.
  • Sentry — crash and error diagnostics.
  • PostHog — product analytics. Hosted in the United States.
  • Stripe — payment processing, where an organization enables payments.
  • Resend — transactional email such as invitations, notifications, and document delivery.
  • Twilio — text messages, where an organization enables SMS notifications.
  • Mapbox — maps and geocoding for dispatch, routing, and address lookup.
  • Expo — mobile app build and distribution. It does not receive your working data.

Cookies and analytics

Our website and the Kraken applications use a small number of cookies and similar storage. Some are strictly necessary — they keep you signed in and protect forms against cross-site request forgery. Without those, the platform does not work.

We also use PostHog, a product analytics service, to understand how the marketing site and the applications are used. It sets a cookie so that several pages viewed in one visit are counted as one visit rather than several. What it records is deliberately narrow:

  • Which pages and screens were opened, in what order, and when.
  • Approximate location derived from IP address — country and region, not a precise position.
  • Device and browser type, and screen size.
  • For signed-in staff, an identifier tying those events to a Kraken account, so we can tell one person's session from another's.
  • We have turned off automatic event capture, which would otherwise record the text of whatever you clicked. On a job card that text is a customer's name and address, and it has no business leaving the platform. Events are declared explicitly instead.
  • We have turned off session recording. Kraken shows customer names, site addresses, invoice totals, and signatures on screen, and we do not send recordings of that to anyone.

Turning analytics off

If your browser sends a Global Privacy Control or Do Not Track signal, we honour it: analytics does not start and no analytics cookie is set. Both are settings in your browser or an extension, and they apply to every site that respects them, not just ours.

You can also block or clear cookies for this site in your browser settings. Doing so does not affect your ability to use Kraken, though clearing the strictly necessary cookies will sign you out.

We use analytics to improve the product. We do not sell personal information, we do not share it for cross-context behavioral advertising, and there is no advertising or ad tracking anywhere in Kraken.

Connections your organization chooses

An administrator can connect Kraken to outside services — QuickBooks Online, Xero, or Slack among them. Those connections are off until someone with the right permissions turns one on, and each one only exchanges the records that feature needs, such as invoices to an accounting system or a notification to a Slack channel. Once data reaches a connected service, that service's own privacy terms apply.

How we use information

We use personal information to:

  • Provide the service — sign you in, show your work, save what you enter, and send the notifications your organization has configured.
  • Keep the platform secure — authenticate users, enforce per-organization access rules, and investigate abuse or suspicious activity.
  • Support you — answer questions and reproduce problems you report.
  • Improve the product — understand which features break or go unused, using aggregate and diagnostic data.
  • Meet legal and contractual obligations, including tax, payroll, and recordkeeping requirements our customers are subject to.

When we share information

Beyond the service providers listed above, we disclose personal information only when the law requires it, when we must protect the rights or safety of people or the platform, or as part of a merger, acquisition, or sale of assets — in which case we will say so before your information becomes subject to a different policy.

How long we keep it

We keep working data for as long as the organization that owns it maintains its Kraken account, because that data is their business record. When an organization closes its account, we delete or de-identify its data within a reasonable period, except where we must retain records to meet a legal obligation or resolve a dispute. Diagnostic and log data is kept on a shorter cycle.

How we protect it

Traffic to Kraken is encrypted in transit, and our hosting providers encrypt data at rest. Every record is scoped to an organization and enforced in the database itself, so one company's data is not reachable from another's session. Accounts support multi-factor authentication, and permissions are role-based so people see what their job requires. No system is perfectly secure, but we treat that as a floor to keep raising, not a box to tick.

Your choices and rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to certain uses. To exercise any of these, email us at privacy@buildwithsora.com. We will ask for enough information to verify who you are, and we will not treat you differently for asking.

If your account came from an employer, we will route the request to them, since the data belongs to their organization. You can always ask us directly and we will help.

The mobile app specifically

The Kraken mobile app is for the crews and staff of companies already using the platform, and it requires an employer-issued account. It asks for one device permission: location while the app is in use, requested the first time a technician builds a driving route for their day. Declining it means routes are not ordered by drive time; nothing else stops working. The app does not request camera, microphone, or contacts access, and it does not track location in the background. If a future release needs another permission, it will be requested in context, explained at the moment it is asked for, and reflected here and in the store listing before it ships.

Children

Kraken is a workplace tool. It is not directed at children and we do not knowingly collect information from anyone under 16. If you believe a child has provided us information, write to privacy@buildwithsora.com and we will remove it.

Where your data is handled

Kraken is operated from the United States, and information is stored and processed there. If you use the platform from another country, you are sending your information to the United States, where privacy laws differ from those in your home country.

Changes to this policy

We will update this page when our practices change, and we will move the effective date at the top. If a change materially affects how we handle your personal information, we will give notice through the product or by email before it takes effect.

Contact us

Questions, requests, or concerns about privacy: privacy@buildwithsora.com. For help using Kraken, support@buildwithsora.com will reach the right people faster.