Ghostdog Systems, Inc.
Privacy Policy
RestoreAI Platform
Effective date: 30 July 2026 Version: 2.0 (draft) Last reviewed: 30 July 2026
1. Introduction and Scope
Who we are. Ghostdog Systems, Inc. (“Ghostdog,” “we,” “us”) provides RestoreAI, a software platform that helps property-restoration professionals document jobs and produce insurer-ready scopes, estimates, and reports. Our registered address is 254 Chapman Rd, Newark, DE 19702.
Scope. This Privacy Policy explains how we collect, use, share, retain, and protect personal information through the RestoreAI web and mobile applications, related APIs, and our website (collectively, the “Services”). It applies to property owners/claimants whose information is documented in the Services, our customers’ personnel who use the Services, and website visitors.
Controller / processor roles. For information about our own account holders and website visitors, Ghostdog acts as a data controller. For claim and property information that our business customers document in the Services, Ghostdog generally acts as a processor on the customer’s behalf, and the customer’s own privacy notices may also apply.
2. Information We Collect
We collect the following categories of personal information:
● Account & profile data — name, email address, profile image, role, and authentication identifiers (including OAuth identifiers from Google or Microsoft).
● Claim, property & project data — property owner/claimant names, property addresses, contact details, insurance/claim information, loss descriptions, scope of work, estimates, and related project records.
● Uploaded media — photographs, video, 3D scans, and voice notes captured at job sites, together with any personal information those files may incidentally contain.
● Measurements & field data — moisture readings, equipment logs, and technician documentation (including digitized daily/TIC sheets).
● Billing data — subscription and billing-contact details (card data is handled by our payment processor and not stored by Ghostdog).
● Device & usage data — log data, device identifiers, IP address, and product-analytics events describing how the Services are used.
● Cookies & similar technologies — as described in Section 7.
3. How We Collect Personal Information
● Directly from users who create accounts and enter or upload information into the Services.
● Automatically, through logs, device signals, analytics, and cookies when you use the Services.
● From third parties, including authentication providers (Google/Microsoft) and property/insurance-data enrichment providers used to help complete a claim record.
4. Purposes of Processing
We process personal information to: provide, operate, and secure the Services; authenticate users and manage accounts; analyze uploaded media and field data to generate scopes, estimates, sketches, and compliance-checked reports; communicate service-related information; process billing; enrich claim records with property data; meet legal and contractual obligations; and detect, prevent, and investigate security incidents and misuse.
5. Lawful Bases for Processing (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on the following lawful bases:
● Performance of a contract — to provide the Services to our customers and account holders.
● Legitimate interests — to secure, improve, and operate the Services, provided these interests are not overridden by your rights.
● Consent — for non-essential cookies/analytics and any optional processing, which you may withdraw at any time.
● Legal obligation — to comply with applicable law.
6. Automated and AI-Assisted Processing
RestoreAI uses machine-learning and AI services to analyze uploaded photos, video, voice notes, and field data in order to draft scopes, estimates, sketches, and compliance assessments. This processing supports — and does not solely automate — decisions; outputs are reviewed by users before use. Personal information may be transmitted to AI service providers acting as our subprocessors (Section 8) for this purpose. We do not permit these providers to use your data to train their foundation models where such terms are available, and we do not sell personal information.
7. Cookies and Tracking Technologies
We use strictly necessary cookies to operate and secure the Services, and, subject to your consent where required, analytics cookies (including our product-analytics provider) to understand usage and improve the Services. Where required by law, we present a consent banner allowing you to accept or decline non-essential cookies, and you can change your choice at any time. We do not use cookies to serve third-party advertising.
RestoreAI is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and handle your information when you use our website and services, specifically regarding our use of Google OAuth for authentication.
8. How We Share Information; Subprocessors
We share personal information only as needed to provide the Services and as described here: with subprocessors that host, process, or support the Services under written agreements requiring confidentiality and appropriate security; with our customers (for data documented on their behalf); to comply with law or lawful requests; and in connection with a corporate transaction, subject to this Policy. We do not sell personal information.
Our subprocessors include categories such as cloud infrastructure and storage, AI/model providers, payment processing, transactional email, product analytics, and property/insurance-data enrichment. We maintain a current list of subprocessors and will provide notice of material changes through our website.
9. Your Privacy Rights
9.1 EEA / UK (GDPR)
Subject to applicable law, you have the right to access, correct, delete, and receive a portable copy of your personal information; to restrict or object to certain processing; and to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority.
9.2 United States (including California / CCPA-CPRA)
Subject to applicable state law, you have the right to know what personal information we collect and how it is used; to access, correct, and delete it; to opt out of any “sale” or “sharing” of personal information (we do not sell or share personal information as those terms are defined); and to be free from discrimination for exercising your rights.
9.3 How to exercise your rights
Contact us at privacy@ghostdog.io . We will verify your request and respond within the timeframe required by applicable law. You may also revoke third-party authentication access (e.g., Google/Microsoft) through the provider’s account settings.
10. Data Quality and Your Responsibilities
We take reasonable steps to keep personal information accurate, complete, and current for its intended use. Because much of the information in the Services is entered by users, you are responsible for the accuracy of information you provide or upload, and for keeping it up to date. You may correct or update information through the Services or by contacting us.
11. How We Protect Information (Security)
We implement technical and organizational measures appropriate to the risk, including encryption of data in transit (TLS), role-based access controls and least-privilege access, authentication controls, audit logging, network security controls, vulnerability scanning, and vendor due diligence. No method of transmission or storage is completely secure; we work to protect your information and to respond promptly to any incident. Our security practices are described further in our internal information-security, encryption, and vendor-management policies.
12. Children's Privacy
The Services are intended for business use and are not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.
13. Monitoring, Enforcement, and Complaints
We monitor our compliance with this Policy through our privacy and security governance program. If you have a concern about how we handle personal information, contact us at privacy@ghostdog.io and we will investigate and respond. If you are in the EEA/UK, you also have the right to complain to your supervisory authority; if you are in California or another U.S. state, you may contact the relevant regulator.
14. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a revised effective date and, where required, provide additional notice. Material changes will be communicated as required by applicable law.
15. Contact Us
If you have any questions regarding this Privacy Policy, please contact us at: Email: RestoreAI@ghostdog.io or privacy@ghostdog.io Website: https://restoreai.ghostdog.io
Ghostdog Systems, Inc.
Copyright © 2026 Ghostdog Systems, Inc. - All Rights Reserved.
Registered IICRC Firm · IICRC WRT-Certified Team ·