Privacy Policy
How CleanFile Ops handles business information when we chase COIs, W-9s, and lien waivers for US GCs. Last updated: September 2, 2026.
1. Who this covers
This policy describes CleanFile Ops (vynlith.com). Contact for privacy questions: [email protected].
We serve businesses. We primarily process business contact and document data supplied by our GC clients and their subcontractors in connection with the service.
2. What we collect
- Client intake: company name, contact name, email, phone (if provided), project/state, sub roster, stated insurance/document requirements, billing email
- Subcontractor contacts for chase: names, company names, and email addresses (and phone if the client supplies them) so we can request documents
- Documents and message content: COIs, W-9s, lien waivers, and related email replies or portal exports you or your subs send
- Operational records: register fields we extract, chase status, deficiency notes, and weekly reports we generate for you
- Payment metadata: amount, date, and status processed by Stripe (we do not store full card numbers)
- Site/technical: standard web logs and security telemetry via our host (Cloudflare) when you visit vynlith.com
We do not intentionally collect consumer marketing profiles. Do not send us passwords to Procore, Textura, banking, or other portals — use invites or exports only.
3. Why we collect it
- To deliver the document-chase and reporting service you purchase
- To communicate with you and (on your behalf) with subcontractors about outstanding documents
- To invoice, process payment, and provide support
- To secure the site and prevent abuse
- To meet legal, tax, or dispute-related obligations when required
4. Processors we use
- Zoho — email (ops@ / chase@) for client and chase correspondence
- Stripe — payment processing for invoices and payment links
- Cloudflare — website hosting (Pages) and related CDN/security for vynlith.com
We may also use ordinary productivity tools (for example spreadsheets or e-sign providers you approve) solely to deliver the engagement. We do not sell your data.
5. Sharing
We share information only as needed to run the service:
- With processors listed above under their terms
- With subcontractors when chasing documents you asked us to request (they already know they are on your job)
- With your designated contacts at the GC client
- If required by law, lawful process, or to protect rights and safety
We do not sell personal or business contact data. We do not rent sub lists for marketing.
6. Retention
We keep intake, registers, originals, and reports for the engagement plus a reasonable wind-down period so we can answer follow-ups and provide an export. Default practice: retain while the engagement is active and for a limited time afterward, then delete or return on request after we deliver a final export — unless a longer period is required by law, dispute, or your written SOW.
W-9 / TIN data is treated as sensitive business tax information: access is limited to people delivering your engagement; we avoid broadcasting full TINs on wide-share views.
7. Security
We use reasonable administrative and technical measures appropriate to a small B2B ops service (access-limited mailboxes, paid processor accounts, and no portal-password collection). No method of transmission or storage is perfectly secure.
8. Your choices
Clients may request an export or deletion of engagement files by emailing [email protected]. Subcontractors who receive chase mail from [email protected] may reply to ask what data we hold for that chase or to correct an email address; we will coordinate with the GC client where appropriate, since the client is typically the controller of the sub list.
9. Children
The service is for businesses. We do not knowingly collect information from children.
10. Changes
We may update this policy by posting a new version here with a new date. Material changes affecting active clients will be emailed to the ops contact on file when practical.
11. Contact
Privacy questions: [email protected].