← Back to RoundTrips.io

Privacy Policy

Effective Date: February 2026 · Last Updated: February 2026

RoundTrips.io ("the Platform", "we", "our") is a file processing and management platform that integrates with Autodesk Construction Cloud (ACC) via Autodesk Platform Services (APS) APIs. This privacy policy describes what data we collect, how we use it, how we store it, and your rights regarding that data.

1. Data We Collect

1.1 Account Information

When your administrator creates your account or you are invited to the platform, we collect:

DataPurpose
Email addressAccount identification, login, and invite delivery
User IDInternal account reference (generated by Supabase Auth)
Password (hashed)Authentication — stored by Supabase Auth, never accessible in plaintext
Company assignmentMulti-tenant access control
Role (member/admin)Authorization and access level

1.2 Autodesk Account Information

When you connect your Autodesk account via OAuth, we collect:

DataPurpose
Autodesk User IDLink your Autodesk identity to your platform account
Autodesk emailDisplay your connected Autodesk identity
Autodesk display nameDisplay your connected Autodesk identity
OAuth access tokenAccess ACC files on your behalf (encrypted at rest)
OAuth refresh tokenMaintain your connection without re-authenticating (encrypted at rest)

We use the standard 3-legged OAuth 2.0 flow with PKCE (Proof Key for Code Exchange). We never see or store your Autodesk password.

1.3 File and Project Data

DataPurpose
ACC hub, project, and folder namesNavigation and file selection UI
File names and metadataDisplay file lists, track processing status
File contents (temporarily)Processing files through Navisworks conversion pipeline
Processed output filesStored locally until uploaded back to ACC or manually cleared

1.4 Usage and Operational Data

DataPurpose
Task/job recordsTrack file processing requests, status, and history
Admin audit logRecord administrative actions
Server logsDebugging, error tracking, and operational monitoring

1.5 Data We Do NOT Collect

2. How We Use Your Data

We use collected data exclusively for:

  1. Authentication and authorization — verifying your identity and access rights
  2. Platform functionality — browsing ACC projects, downloading files, processing files, uploading results
  3. Multi-tenant isolation — ensuring you only see your company's data
  4. Administration — managing users, companies, and platform settings
  5. Operational maintenance — debugging issues, monitoring system health

3. Data Storage and Security

3.1 Where Data Is Stored

Data TypeStorage LocationSecurity
Account dataSupabase (cloud PostgreSQL)Row-Level Security, encrypted in transit
Autodesk OAuth tokensSupabase databaseFernet encryption at rest, RLS
APS app credentialsSupabase databaseFernet encryption at rest
File cacheLocal server filesystemCompany-scoped directories
PasswordsSupabase AuthBcrypt hashed

3.2 Security Measures

3.3 Data Retention

Data TypeRetention Period
Account dataUntil account is deleted by admin
Autodesk OAuth tokensUntil user disconnects or account deleted
Cached filesUntil manually cleared or cache eviction
Task/job recordsIndefinite (for history/audit)

4. Data Sharing

We do not sell, rent, or share your personal data with third parties. Data is shared only with:

RecipientData SharedPurpose
Autodesk (via APS APIs)OAuth tokens, API requestsAccess your ACC files on your behalf
SupabaseAccount data, application dataDatabase hosting and authentication

Both services have their own privacy policies: Autodesk Privacy · Supabase Privacy

5. Your Rights

6. Children's Privacy

This platform is not intended for use by individuals under the age of 16. We do not knowingly collect data from minors.

7. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via the platform or email. Continued use of the platform after changes constitutes acceptance of the updated policy.

8. Contact

For privacy-related questions or data requests: