Skip to main content
changeorderkitJob paperwork before work starts.

Policy

Privacy Policy

Last updated: 27 July 2026

Who operates ChangeOrderKit

ChangeOrderKit is operated by Ifeoluwa Adegbite in Nigeria. This policy explains how personal information is handled when you use the website, create an account, save job documents, or interact with a paid pilot or external checkout.

Information we collect

  • Account information: your email address, authentication status, account identifiers, and security-related timestamps.
  • Business and document information: business profile details, customer and project information, original scope, additional work, pricing, schedule impact, payment terms, notes, and other content you choose to save.
  • Browser drafts:unsigned drafts may be stored in your browser's local storage so work is not lost when you refresh.
  • Usage information: aggregate events such as page views, generator use, selected industry and currency, broad price ranges, and button clicks.
  • Client approval records: the exact document snapshot presented, its SHA-256 fingerprint, link status, typed approver name, optional role/title, optional decline reason, consent confirmation, and server-generated event times.
  • Limited decision metadata: when a client approves or declines, we may store the server-observed IP address and a shortened, sanitised browser user-agent string. We do not use this workflow to collect precise location, fingerprinting identifiers, or advertising profiles.
  • Transaction information: if you use an external checkout, the payment provider may return limited status or reference information. ChangeOrderKit does not intend to store full card or bank-account details.

How we use information

We use information to:

  • provide authentication, saved workspaces, calculations, and generated documents;
  • secure accounts, diagnose errors, prevent abuse, and maintain service reliability;
  • understand product usage and improve features and onboarding;
  • operate paid pilots, verify access, and respond to support requests;
  • create a consistent record of what a client reviewed and the decision they made; and
  • comply with applicable legal obligations and enforce the Terms of Use.

Depending on your location, these activities rely on performing our agreement with you, legitimate interests in operating and improving the service, consent where required, and compliance with law.

Client approval links and record sharing

A contractor may create a capability link containing a signed, randomised token and send it to a client. Anyone who possesses a valid unexpired link can view that exact document snapshot without creating an account, so recipients should avoid forwarding it unnecessarily. The reusable raw token and its HMAC signature are not stored in the approval database.

The audit timeline records the first successful open of a pending link. Automated mail-security scanners or link-preview services can cause that event, so it should not be treated by itself as proof that a person read the document.

The contractor receives the approval status, signer name and role where supplied, decline reason where supplied, and event timeline. IP address and user-agent metadata are retained as restricted audit data and are not exposed through the contractor account or shown on the public confirmation page. Typed approval records an acknowledgement; it is not represented as a cryptographic or universally qualified electronic signature.

External early-access and pilot links

The pricing page may link to an external early-access, waitlist, or pilot form. Following that link takes you to a third-party form or service that we do not operate. That provider may collect the contact information you enter under its own privacy terms, which govern the submission.

ChangeOrderKit does not receive or store what you submit on such a form unless that information is later intentionally imported or sent to us by the operator. Following the link is optional and is never required to use the free generator.

Service providers and international processing

ChangeOrderKit uses service providers including Supabase for authentication and database services, Resend for delivery of account and security emails, and Vercel for hosting, analytics, and application delivery. To deliver those emails, Resend processes recipient addresses, message content, and delivery metadata. External payment or checkout providers process information under their own privacy terms. These providers may process information outside your country, subject to their safeguards and applicable law.

ChangeOrderKit does not sell personal information.

Analytics and data minimisation

Analytics events are designed not to include client names, project descriptions, detailed scope, email addresses, phone numbers, or exact document totals. Do not enter sensitive financial, medical, legal, identification, password, or account-security information into document fields.

Vercel Analytics is not loaded on direct tokenised approval routes, and application tracking filters approval page views and events after client-side navigation. The hosting provider may still retain requested paths in protected infrastructure logs; access to those logs is restricted for operational and security purposes.

Retention and deletion

Browser drafts remain until you reset the generator or clear the site's browser storage. Account and saved-document data is retained while your account is active and for as long as reasonably needed to provide the service, resolve disputes, secure the platform, or meet legal obligations.

Approval snapshots and audit events are designed to remain unchanged for recordkeeping. They are retained with the account for as long as reasonably needed to provide the workflow, document decisions, resolve disputes, or satisfy legal obligations. A working document may be edited or deleted without rewriting its earlier approval snapshot.

You may request access, correction, export, or deletion through the support channel from which you received access or any contact method displayed in the product. Some records may be retained where required by law or necessary to protect legal rights.

Security

We use reasonable technical and organisational safeguards, including authenticated accounts, password controls, encrypted connections, and owner-scoped database access. No internet service is completely secure, so you are responsible for protecting your password and signing out on shared devices.

Your rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information, and to withdraw consent. You may also have the right to complain to a relevant data-protection authority.

Children

ChangeOrderKit is intended for business users aged 18 or older and is not directed to children.

Policy changes

This policy may be updated as the product, providers, or legal requirements change. The revised date will be shown at the top of this page. Material changes may also be communicated in the product or by email where appropriate.