Privacy Policy
Last updated: July 6, 2026
1. Who we are
Rooferan (“Rooferan,” “we,” “us”) provides software that helps roofing contractors run their business — leads, estimates, jobs, scheduling, invoicing, and payments. This Privacy Policy explains how we collect, use, share, and protect information when you visit rooferan.com or use the Rooferan application (together, the “Service”). Questions about this policy: support@rooferan.com.
2. Who this policy covers
This policy covers two kinds of people:
- Customers — the roofing companies and their staff who sign up for and use Rooferan.
- Homeowners — our customers’ clients, whose contact and project details a customer enters into Rooferan and who may receive estimates, invoices, and a customer portal link.
For customer-entered data about homeowners, the roofing company is the “controller” and Rooferan acts as a “processor” on its behalf (see our Terms of Service).
3. Information we collect
- Account & organization data: name, email, phone, business name, role, and password (stored only as a secure hash) when a customer creates or is invited to an account.
- Customer business data: the contacts, properties, leads, estimates, jobs, photos, documents, invoices, and notes that customers enter or upload to run their business.
- Payment data: subscription and customer-payment processing is handled by Stripe. We do not store full card numbers; we keep limited billing metadata (e.g. plan, status, last four digits, payment status) returned by Stripe.
- Google account data (Calendar integration): if a customer’s admin connects Google Calendar, we access the data described in Section 4.
- Technical & usage data: IP address, device/browser type, pages viewed, and app interactions, collected via server logs and cookies for security, performance, and product improvement (see Section 9).
4. Google user data & Limited Use
When an administrator connects Google Calendar in Settings → Integrations, Rooferan requests these Google OAuth scopes: calendar.events and calendar.calendarlist.readonly (plus openid and your email address to identify the connected account).
- What we access and why: we read your list of calendars only so you can choose which calendar job events go to; and we create, update, and delete calendar events so your scheduled Rooferan jobs appear on that calendar.
- One-way and minimal: the sync is one-way (Rooferan → Google). We do not read the contents of your existing calendar events. We store only each job’s Google event ID, the target calendar ID, and sync status — never your calendar’s contents.
- Storage & security: Google OAuth tokens are encrypted at rest and are accessible only to Rooferan’s servers; they are never exposed to browsers or other customers.
- Revoking access: you can disconnect at any time in Settings → Integrations, or from your Google Account’s security settings. Disconnecting stops all future sync; events already placed on your calendar remain unless you delete them.
Limited Use. Rooferan’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not transfer or use it except to provide or improve the calendar sync feature, or as required by law.
5. How we use information
To provide, maintain, and secure the Service; process subscriptions and customer payments; send transactional messages (estimates, invoices, receipts, notifications) by email (Resend) and SMS (ClickSend); provide support; and analyze and improve the Service. Where AI features are enabled, customer-provided content may be processed by Anthropic solely to generate the requested output.
6. How we share information
We do not sell personal information. We share it only:
- with service providers that operate the Service under contract — Supabase (database, authentication, file storage), Vercel (hosting), Stripe (payments), Resend (email), ClickSend (SMS), Google (calendar, maps/measurements), and Anthropic (AI features);
- to comply with law, enforce our Terms, or protect rights and safety;
- in a merger, acquisition, or asset sale, subject to this policy.
7. Data retention
We retain account and business data for as long as an account is active and as needed to provide the Service, then delete or de-identify it within a reasonable period, except where longer retention is required by law (e.g. tax/financial records) or to resolve disputes.
8. Security
We protect data with encryption in transit and at rest, tenant isolation (row-level security scoped per organization), encrypted third-party credentials, and access controls. No method of transmission or storage is 100% secure, but we work to protect your information and to notify you of material incidents as required by law.
9. Cookies
We use strictly necessary cookies for authentication and security, and limited analytics/performance cookies. You can control cookies through your browser; some features may not work without necessary cookies.
10. Your rights
Depending on where you live (e.g. under GDPR or the CCPA/CPRA), you may have rights to access, correct, delete, or port your personal information, and to object to or restrict certain processing. Homeowners should direct such requests to the roofing company that entered their data; we will assist that company as its processor. To exercise rights or ask questions, contact support@rooferan.com.
11. International transfers
We may process information in the United States and other countries. Where required, we use appropriate safeguards for cross-border transfers.
12. Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.
13. Changes
We may update this policy; we will post the new version here with an updated “Last updated” date and, for material changes, provide additional notice.
14. Contact
Rooferan — support@rooferan.com.