Privacy Policy
Last updated: February 19, 20261. Introduction
Roof Report Pro ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. By using Roof Report Pro, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect information that you provide directly to us:
- Account Information: When you create an account, we collect your name, email address, and password.
- Organization Information: If you create or join an organization, we collect organization name and contact details.
- Inspection Data: Photos, property addresses, homeowner contact information, and report content you create using our platform.
- Payment Information: When you subscribe, payment processing is handled by Stripe. We do not store your full credit card details.
- Communications: When you contact us, we may keep a record of that communication.
3. Automatically Collected Information
When you use our platform, we automatically collect certain information:
- Device Information: Browser type, operating system, and device identifiers.
- Usage Information: Pages visited, features used, and time spent on the platform.
- Log Data: IP address, access times, and referring URLs.
- Cookies: We use cookies to maintain sessions and improve user experience.
Cookie types we use:
- Strictly Necessary: Authentication session tokens and device recognition tokens. Required for login and platform functionality. Cannot be disabled without breaking the service.
- Functional: User preferences and settings to improve your experience.
- Analytics: Aggregated, anonymized usage data to help us improve the platform.
You can manage cookies through your browser settings. Disabling strictly necessary cookies will prevent login and use of the platform.
4. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process your transactions and manage your account
- Send transactional emails (report delivery, account updates)
- Respond to your comments, questions, and support requests
- Monitor and analyze usage patterns to improve user experience
- Detect, prevent, and address technical issues and fraud
- Train and improve our AI models using aggregated, anonymized data
5. AI and Photo Processing
Our platform uses artificial intelligence to analyze roof inspection photos. Photos you upload are processed by our AI systems and may be processed by third-party AI providers (such as OpenAI or Anthropic) to generate damage analysis. We use industry-standard security measures to protect this data during processing. We may use aggregated, anonymized photo data to improve our AI models, but your photos are not shared publicly or used for advertising.
6. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
- With Your Consent: When you explicitly authorize sharing.
- Service Providers: With third parties who perform services on our behalf (hosting, payment processing, email delivery, AI processing).
- Report Recipients: When you send a report, the recipient receives the report content.
- Legal Requirements: If required by law or to protect our rights, safety, or property.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
7. Data Security
We implement appropriate technical and organizational measures to protect your information. This includes encryption of data in transit and at rest, secure cloud infrastructure (AWS), access controls, and regular security assessments. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
8. Data Retention and Deletion
We retain your information for as long as your account is active or as needed to provide services. When you delete your account or data, we use a "soft delete" process:
- Anonymization: Your personal information (name, email, contact details, property addresses, homeowner information) is permanently removed or anonymized within 90 days.
- Retained Data:We may retain anonymized, non-identifiable data—primarily inspection photos with all personal information stripped—to train and improve our in-house AI models. This data cannot be traced back to you or your customers.
- AI Training: Anonymized photos help us improve damage detection accuracy and develop better analysis features for all users.
Retention periods by data category:
- Reports, photos, AI analysis, homeowner and property data: Retained while your account is active; deleted 90 days after account deletion.
- Authentication session tokens:30 days (24 hours without the "Remember Me" option).
- Device recognition tokens: 1 year from last use.
- Application logs and error tracking: 90 days.
- Database backups: 7 days of daily backups.
Permanent Deletion: If you prefer that we do not retain any of your data for AI training purposes, you may request permanent deletion of all your data, including photos. To request permanent deletion, contact us at support@roofreportpro.ai with the subject line "Permanent Data Deletion Request." We will process your request within 30 days.
We may retain certain data longer if required for legal, accounting, or regulatory compliance purposes.
9. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate information.
- Deletion: Request deletion of your personal information.
- Data Portability: Request a copy of your data in a portable format (JSON).
- Opt-Out: Opt out of marketing communications at any time.
To exercise these rights, contact us at support@roofreportpro.ai.
10. Third-Party Services
Our platform uses the following sub-processors — third-party services that process data on our behalf:
- Amazon Web Services (S3): Storage for inspection photos, PDF reports, and thumbnails. Hosted in the US.
- DigitalOcean: API server and database hosting. Hosted in the US.
- Vercel: Frontend web application hosting. No server-side customer data processed.
- Stripe: Payment processing and subscription management. Processes billing information.
- OpenAI / Anthropic: AI analysis providers that process inspection photos to generate damage assessments. Both have signed Data Processing Agreements prohibiting training on customer data.
- Resend: Transactional email delivery (report delivery, account notifications).
- Sentry: Error tracking. Captures error context and user IDs; not configured to capture full request bodies or personal information.
- BetterStack: Uptime monitoring and structured application log management. Logs contain request IDs and account IDs, not personal information.
If you connect third-party integrations such as JobNimbus or CompanyCam, those services are connected at your direction and subject to their own privacy policies. We encrypt the credentials you provide and access those services only to fulfill your requested sync.
Each sub-processor is contractually required to protect your data consistent with this Privacy Policy. To request a current sub-processor list or notification of sub-processor changes, contact us at support@roofreportpro.ai.
11. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us so we can delete it.
12. International Data Transfers
Your information may be transferred to and processed in the United States and other countries where our service providers operate. These countries may have different data protection laws than your country of residence. By using our platform, you consent to such transfers.
13. California Resident Rights (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Categories of personal information we collect:
- Identifiers: Name, email address, IP address, device identifiers.
- Commercial information: Subscription plan, billing history, token usage.
- Professional/inspection data: Roof inspection photos, property addresses, homeowner contact information, and AI-generated report content you create using our platform.
- Internet or other network activity: Pages visited, features used, access logs.
We do not sell or share your personal information for cross-context behavioral advertising. We do not engage in profiling that produces legal or similarly significant effects.
Your California rights include:the right to know what personal information we collect and how it is used; the right to delete your personal information; the right to correct inaccurate information; the right to opt out of the sale or sharing of personal information (not applicable — we do not sell); the right to limit use of sensitive personal information; and the right to non-discrimination for exercising your privacy rights.
To exercise your California privacy rights, contact us by: (1) email at support@roofreportpro.ai with subject line "California Privacy Request", or (2) using the support option within your account settings. We will respond within 45 days as required by law.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the platform after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at support@roofreportpro.ai.