Tier 2 Desk Start a building
Privacy

Privacy

What Tier 2 Desk collects, why, and where it is kept. Last updated 2026-10-01.

Who we are

Tier 2 Desk is a Jestr company (Duke Security, Inc., Delaware, USA). Contact: matan@jestr.ai.

What we collect

  • When you start a building: your name, company, role, business email, optional phone, and the building's address, county, size, type, utility and QEM status. Later on your status page: the Commerce building ID, utility account numbers, operating hours, and the photos and videos you upload.
  • Payments: Stripe processes card payments. We receive the payment status and your billing name and email from Stripe, never your card number.
  • Site analytics: anonymous page and calculator events. The visitor id is a hash of a daily rotating secret, your IP address and browser string, so it can't be linked across days. No cookies, no third-party trackers, no advertising pixels.
  • Business outreach: we may email people who manage Tier 2 buildings, using business contact details from public sources. Every email has an unsubscribe link; once used, we don't email that address again.

Why

To prepare and file your building's Tier 2 compliance, to bill you, and to see which pages help. We share building data only with the people doing your filing: the QEM, your utility (for the data request) and, through the Clean Buildings Portal, the Department of Commerce. We never sell data.

Where and how long

Data is stored on Amazon Web Services (Frankfurt, eu-central-1), encrypted at rest. Uploads are private. We keep building records for the five-year Tier 2 reporting cycle unless you ask us to delete them sooner; abandoned starts without a deposit are deleted after 12 months.

Your choices

Email us to see, correct or delete your data. Your private status link works like a password: don't share it.