Privacy Policy
Effective and last updated: September 9, 2026
This Privacy Policy explains how ZECO CM LLC ("ZecoCM," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the TRACE Management System website (tracems.com and app.tracems.com) and application (together, the "Service"). It is written to address the rights of visitors and users in California, elsewhere in the United States, and in Canada.
1. Information we collect
We collect information in the following ways:
- Account and contact information — name, work email, telephone number, business address, employer/organization, job role, and password (stored as a salted hash, never in plain text), when you or your organization create an account, request a demo, or complete an authorized onboarding workflow.
- Usage and log data — IP address, browser and device type, pages visited, timestamps, and similar diagnostic information collected automatically when you use the website or application, authentication and session data, cookies or local browser storage used for security and interface preferences, and similar diagnostic information collected for security and reliability purposes. We do not use third-party advertising trackers on the marketing website.
- Content you or your organization submit — project records, RFIs, submittals, pay applications, change orders, daily reports, schedules, documents, and correspondence entered into the Service by authorized users. This may incidentally include personal information about project personnel (names, contact details, electronic signatures and attestations) supplied by your organization. Uploaded photographs, videos, drawings and field records may include device, time and location metadata when an authorized user chooses to provide it.
- TRACE Intelligence records — questions, prompts, retrieved source references, responses, feedback and audit information created when an authorized user invokes an intelligence feature.
- Transaction and subscription information — selected plan, account capacity, payment-provider customer or subscription identifiers, and related commercial records when paid services are configured. TRACE does not store complete payment-card numbers in the application.
- Communications — messages you send us (support requests, demo requests, general inquiries) and our records of that correspondence.
2. How TRACE (our AI) processes information
TRACE answers questions using project records that the requesting user is already authorized to read. To generate a response, the relevant authorized content may be sent to one or more configured third-party infrastructure or model providers to perform the requested processing. Optional public-research features may also retrieve information from public web sources. Provider, account and source configuration determine which services are used. TRACE only retrieves project content the asking user is already authorized to read; access is never widened by an intelligence request. Contractual and technical controls govern provider processing, subject to the applicable customer agreement and current subprocessor list.
3. How we use information
- To provide, maintain, and secure the Service, including authenticating users and enforcing account and project-level access controls;
- To respond to demo requests, support inquiries, and other communications;
- To send account, security, and service-related notices;
- To monitor, troubleshoot, and improve the Service's reliability and performance;
- To comply with legal obligations and enforce our Terms of Service.
We do not use personal information to serve targeted third-party advertising, and we do not sell personal information.
4. How we share information
We share information only as follows:
- Service providers who process information on our behalf — including hosting and storage, configured model or intelligence providers, email delivery, payment processing, security and customer-selected integrations — to help us operate the Service.
- Within your organization, according to the project authorizations your organization's administrators configure. TRACE platform staff employed by ZECO CM LLC (technicians and administrators) can access customer accounts only in a logged, customer-scoped "System Full Admin" mode that is fully audited; technicians cannot modify customer data directly — proposed fixes are routed to your organization's administrator for approval.
- Legal and safety reasons — to comply with a legal obligation, protect the rights, property, or safety of ZecoCM, our users, or the public, or respond to a lawful request from a public authority.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
We do not sell personal information and we do not share personal information for cross-context behavioral advertising, as those terms are defined under California law.
5. Data retention
We retain information according to its purpose, the customer agreement, configured retention settings, applicable public-records or legal requirements, and the need to protect and audit the Service. Account and contact information is generally retained while the account is active and afterward when reasonably needed for business, legal, security or dispute-resolution purposes. Security logs, support communications, TRACE Intelligence audit records and commercial records may have different retention periods. Backup copies are removed through the applicable backup lifecycle rather than immediately from every backup image. ZecoCM is designed to preserve project records (RFIs, submittals, pay applications, change orders, and related evidence) for the duration of your organization's engagement and, where the record has evidentiary or contractual significance, for the retention period your organization's agreement or applicable public-records law requires — corrections are recorded as superseding history rather than by deleting the prior record, which is a deliberate design choice for construction project accountability. Requests to delete personal information within Customer Data should generally be directed to your organization's administrator, who controls that content; contact us and we will help route the request appropriately.
6. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption of data in transit, hashed password storage, tenant-scoped data isolation enforced at the server (not just hidden in the interface), and audited access for our own platform staff. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you the following rights with respect to your personal information:
| Category (CCPA) | Collected? | Purpose |
|---|---|---|
| Identifiers (name, email, IP address) | Yes | Account creation, communication, security |
| Commercial information (selected plan and, when configured, subscription records) | As applicable | Providing and administering the Service |
| Internet/network activity (log and usage data) | Yes | Security, reliability, diagnostics |
| Professional/employment information (employer, job role) | Yes | Account setup, project authorization |
| Precise location or other sensitive information | When provided by an authorized user or included in Customer Data | Field evidence, project administration, security and legal obligations |
| Electronic signatures and attestations | When a configured workflow requires them | Authorization, approval and evidentiary history |
- Right to know / access what personal information we have collected, used, disclosed, and the purposes for doing so;
- Right to delete personal information we have collected from you, subject to certain exceptions (for example, information we must retain for legal, security, or contractual reasons);
- Right to correct inaccurate personal information;
- Right to opt out of sale or sharing — we do not sell or share personal information as those terms are defined by California law, so there is nothing to opt out of today;
- Right to limit use of sensitive personal information — we do not use sensitive personal information for purposes beyond what CCPA/CPRA permits without limitation;
- Right to non-discrimination for exercising any of these rights.
To exercise these rights, contact us using the details in Section 13. We will verify your request using information reasonably available to us before acting on it, and you may designate an authorized agent to act on your behalf. If we deny a request, you may appeal by replying to our response. We have not disclosed personal information to third parties for those third parties' own direct marketing purposes (California Civil Code § 1798.83, "Shine the Light").
8. Canadian privacy rights (PIPEDA)
For users in Canada, we handle personal information consistent with the ten principles of the Personal Information Protection and Electronic Documents Act (PIPEDA): accountability, identifying purposes, obtaining meaningful consent, limiting collection, limiting use/disclosure/retention, accuracy, appropriate safeguards, openness, individual access, and providing recourse for compliance challenges. You have the right to access the personal information we hold about you, request correction of inaccuracies, and withdraw consent (subject to legal or contractual restrictions), by contacting us using the details in Section 13. If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada. Where we send commercial electronic messages to Canadian contacts, we do so consistent with Canada's Anti-Spam Legislation (CASL), including honoring unsubscribe requests.
9. Other U.S. state privacy rights
Residents of states with comprehensive consumer privacy laws in effect (including Virginia, Colorado, Connecticut, Utah, and others) generally have similar rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of certain processing. You may exercise these rights by contacting us using the details in Section 13; we will honor requests consistent with the law applicable to you.
10. Children's privacy
The Service is a business tool intended for construction industry professionals and is not directed to children. We do not knowingly collect personal information from anyone under 13 (or the relevant minimum age in your jurisdiction). If you believe a child has provided us personal information, contact us and we will delete it.
11. International data transfers
The Service is hosted in the United States. If you access the Service from Canada or another country, your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those of your home jurisdiction.
12. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the revised version here with an updated effective date, and where changes are material, we will provide additional notice (such as email to account administrators).
13. Contact us
Questions, requests, or complaints about this Policy or our handling of personal information can be sent to info@tracems.com. For account or technical assistance, contact support@tracems.com.
ZECO CM LLC — 22765 Savi Ranch Parkway, Unit F, Yorba Linda, CA 92887 — 714-622-7111