Privacy Policy

Effective: March 19, 2026

1. Who We Are

Roof Prospect AI is operated by Roof Prospect Inc. at roofprospect.ai. We are an appointment auction marketplace that connects pre-qualified roofing appointments with licensed roofing contractors. Questions about this policy may be directed to support@roofprospect.ai.

2. Data We Collect

We collect the following categories of information:

  • Account data: Name, email address, mobile phone number, company name, license number
  • Payment data: Billing address, last 4 digits of card (full card data handled by Stripe)
  • Usage data: Pages visited, bids placed, appointments viewed, session activity
  • Communication data: Support messages, contact form submissions, SMS message delivery metadata (timestamps, delivery status — we do not store message content after delivery)
  • Homeowner data (platform side): Name, address, phone, email — used solely to fulfill won appointments and never shared beyond the winning contractor
  • Phone number data: Your mobile phone number is collected during registration and used to deliver transactional SMS messages including two-factor authentication codes, appointment alerts, appointment reminders, auction updates, and security notifications. Phone numbers are also used to facilitate proxy communication between contractors and property owners via temporary masked relay numbers

3. How We Use Your Data

We use your information to:

  • Create and manage your contractor account
  • Process bids, payments, and appointment awards
  • Send transactional emails (bid confirmations, auction alerts, receipts)
  • Send transactional SMS messages (2FA codes, appointment alerts, reminders, auction updates, security notifications)
  • Facilitate proxy phone communication between contractors and property owners via temporary masked numbers
  • Deliver marketing communications (you may opt out at any time)
  • Prevent fraud and enforce our Terms of Service
  • Improve platform performance and user experience
  • Comply with legal obligations

We do not sell your personal data to third parties. Homeowner contact details are shared exclusively with the winning contractor and only after payment is confirmed.

4. Cookies and Tracking

We use essential session cookies to keep you logged in. We may use analytics cookies to understand how the platform is used in aggregate. We do not use third-party advertising cookies. You can disable cookies in your browser settings; however, this may prevent you from logging in or using core features.

Cloudflare provides our CDN, DDoS protection, and Bot protection services. Cloudflare may process your IP address and request metadata as part of these services. See Cloudflare's Privacy Policy.

5. Third-Party Services

We work with the following third parties who may process your data:

  • Stripe — Payment processing. Stripe handles all card data under PCI-DSS compliance. See Stripe's Privacy Policy.
  • Cloudflare — CDN, Workers runtime, D1 database, Turnstile bot protection. See Cloudflare's Privacy Policy.
  • GoHighLevel (GHL) — CRM used by our partner network to book and manage appointments.
  • Twilio — SMS messaging and proxy phone communication. Twilio processes your phone number and message content solely to deliver SMS messages on our behalf and to facilitate masked phone relay between contractors and property owners. Your phone number is not sold to or shared with Twilio for their own marketing purposes. See Twilio's Privacy Policy.

6. Data Retention

We retain account data for as long as your account is active and for up to 3 years after account closure for legal and audit purposes. Transaction records are retained for 7 years as required by financial regulations. Homeowner contact data associated with won appointments is retained for 2 years.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and associated data (subject to legal retention requirements)
  • Opt out of marketing communications at any time
  • Data portability — request a copy of your data in a machine-readable format

To exercise any of these rights, contact us at support@roofprospect.ai. We will respond within 30 days.

8. SMS Messaging & Phone Number Privacy

Your mobile phone number is collected during account registration and is used exclusively for transactional SMS communications and proxy phone relay. We do not sell, rent, or share your phone number with third parties for marketing purposes. Your mobile information — including your phone number, carrier details, and SMS opt-in consent data — will not be shared with or sold to third parties or affiliates for promotional or marketing purposes under any circumstances.

SMS provider: We use Twilio to deliver SMS messages. Your phone number and message content are shared with Twilio solely for the purpose of message delivery. Twilio processes this data under their Privacy Policy and does not use your data for their own marketing.

Proxy communication: When contractors and property owners communicate through the platform, we use temporary masked phone numbers provided by Twilio. Neither party's personal phone number is revealed to the other through the proxy system. Call and message content routed through proxy numbers is not permanently stored by Roof Prospect AI. Proxy numbers are deactivated after the appointment engagement concludes.

SMS opt-out: You may stop receiving SMS messages at any time by replying STOP to any message. You may also disable SMS notifications per category in your account settings. Opting out of SMS does not affect email or in-app notifications. Reply HELP for assistance.

Data retention: SMS delivery metadata (timestamps, delivery status) is retained for 90 days for troubleshooting and compliance. Message content is not stored after successful delivery. Proxy call logs are retained for 30 days.

9. Security

We use industry-standard security measures including TLS encryption in transit, encrypted database storage via Cloudflare D1, bcrypt password hashing, and role-based access controls. No system is 100% secure; in the event of a data breach we will notify affected users as required by law.

10. Children's Privacy

Roof Prospect AI is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us immediately at support@roofprospect.ai.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or in-app notice. The effective date at the top of this page will always reflect the most recent version.

12. Contact

Questions or concerns about this Privacy Policy? Reach us at support@roofprospect.ai.