← Compass

Effective August 7, 2026

Privacy Policy

Compass is a construction project-management service operated by High Performance Structures Inc. dba Open Range Construction, Ltd. for its operating departments, including Open Range Construction, Ltd., High Performance Structures, Nu-Tech, and Design. This policy explains how Compass handles information when staff, owners, subcontractors, suppliers, and invited project participants use the service.

Information Compass processes

Compass processes account and contact information, project records, schedules, messages, files, photos, videos, financial workflow records, activity history, device and security information, and information users intentionally submit to project workspaces. Access is limited by role, organization, project membership, and configured project visibility.

Google and YouTube information

Authorized internal administrators may connect company-managed Google and YouTube accounts. Compass requests only the OAuth scopes displayed on Google's consent screen. For YouTube, Compass uses authorization to identify the selected company channel and upload user-selected project videos with their title, description, audience, and visibility choices.

Compass stores the connected Google account email, YouTube channel ID and title, granted scopes, connection timestamps, and an encrypted OAuth refresh token. Tokens are used server-side and are not exposed to project participants. Compass does not sell Google user data or use it for advertising, credit, or unrelated profiling.

Compass's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Review Google's own practices in the Google Privacy Policy and the Google API Services User Data Policy.

Facebook, Instagram, and X information

Authorized internal administrators may connect company-managed Facebook Pages, professional Instagram accounts, and X accounts. Compass uses those connections only to identify the approved business destination and publish project updates that an authorized staff member has reviewed and approved.

Compass stores the provider account identifier and display name, granted permissions, connection timestamps, and encrypted OAuth access or refresh tokens. It may also store published post identifiers, links, status, and error details for operational and audit history. Passwords are never requested or stored by Compass.

Project photos and post copy are sent to Meta or X only when an authorized user selects those destinations and confirms publication. Public posts use a privacy-safe project title and town or city name only; Compass does not intentionally include client names, street addresses, ZIP codes, coordinates, or photo location metadata.

How information is used

Information is used to provide project collaboration, scheduling, communications, file and media workflows, requested integrations, notifications, security, auditing, support, and service improvement. Compass does not use YouTube API data to create independent advertising profiles or to recreate YouTube's service.

Sharing and visibility

Project information is shared only with authorized organization members, invited project participants, service providers needed to operate Compass, and integrations a permitted administrator enables. YouTube videos may be private, unlisted, or public as shown before publication. An unlisted YouTube link can be viewed and forwarded by anyone who obtains the link, even when Compass distributes it only to authorized users.

Retention, deletion, and revocation

Compass retains project information according to business, contractual, legal, and backup requirements. Google OAuth tokens and connected-channel metadata are retained only while the connection is active or as required for security records. An authorized administrator can disconnect a YouTube channel from the project-video workspace. Compass then removes the stored connection and attempts to revoke the Google token.

A Google user may also revoke Compass directly from Google Account permissions. Users may request deletion or correction through their Compass administrator. Removing a Compass connection does not automatically delete videos already published to a company YouTube channel; a channel manager can remove those videos in YouTube Studio or request assistance.

An authorized administrator may disconnect a Facebook, Instagram, or X account in Compass. Compass then removes the usable stored OAuth credentials while retaining limited connection and publishing history when required for security, audit, contractual, or legal records. A user may also revoke Compass in the applicable Meta or X account settings.

Users may request deletion or correction of Meta or X connection data through their Compass administrator or by emailing the address below. Disconnecting an account does not automatically delete posts already published to Facebook, Instagram, or X; an account manager can remove those posts on the provider or request assistance.

Security

Compass uses authentication, authorization checks, encrypted integration credentials, server-side token handling, activity records, and access controls designed to protect project and integration data. No system can guarantee absolute security, so suspected misuse should be reported promptly.

Contact

Privacy, access, correction, and deletion requests may be sent to martine@openrangeconstruction.com.

High Performance Structures Inc. dba Open Range Construction, Ltd.
660 Chipmunk Dr., Woodland Park, CO 80863