Privacy Policy
Your privacy matters. RafterCore is committed to handling your personal information with transparency, care, and respect. This policy explains exactly what we collect, why we collect it, how we use it, and what rights you have.
Table of Contents
- Who We Are
- Information We Collect
- How We Use Your Information
- How We Share Your Information
- Data Storage & Security
- Data Retention
- Your Rights & Choices
- Cookies & Tracking
- Children's Privacy
- Third-Party Services
- California Privacy Rights (CCPA)
- GDPR — EU & UK Rights
- International Users
- Changes to This Policy
- Contact Us
1. Who We Are
RafterCore is operated by RafterCore LLC, a Phoenix, Arizona-based company providing a SaaS platform for roofing contractors and homeowners. References to "RafterCore," "we," "us," or "our" throughout this policy refer to RafterCore LLC.
For privacy inquiries, contact us at: contact@raftercore.com or 1-833-723-8371.
2. Information We Collect
Information you provide directly:
| Category | Examples | Purpose |
|---|---|---|
| Account info | Name, business name, email, password, phone, city, state | Account creation and authentication |
| Business data | Client records, job details, invoices, photos, estimates, team member info | Core platform functionality |
| Payment info | Billing email (card numbers handled entirely by Stripe) | Subscription billing |
| Communications | Support messages, booking requests, client communications | Customer support and platform features |
| Homeowner requests | Name, phone, email, property address and roof details a homeowner submits through a RafterCore storm or inspection form | Connecting the homeowner with a roofing contractor (see section 4) |
| Identification documents | At an in-person inspection, with the homeowner’s written consent, a contractor may photograph a government-issued ID. We store the image and only the last four digits of the document number; we never store the full number. Images are deleted after one year; the consent record is kept. | Verifying who authorized the inspection or contract |
Information from other sources:
To power property reports, storm alerts and prospecting tools, we obtain information about properties and their owners from public records (such as county assessor, parcel and building-permit records and government weather data) and from commercial data providers, including property-data and skip-trace providers such as BatchData, Enformion, Shovels and RentCast. This can include owner names, mailing addresses, phone numbers and email addresses. Contractors who use these tools are responsible for contacting people lawfully, including under the Telephone Consumer Protection Act and Do Not Call rules.
Information collected automatically:
- Usage data — pages visited, features used, session duration, click patterns
- Device data — device type, operating system, browser type, screen resolution
- Log data — IP address, access timestamps, error logs
- Location data — approximate city/region based on IP, used for storm alerts. We do not track precise GPS location without explicit consent.
3. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the RafterCore platform
- Process subscription payments and invoice transactions via Stripe
- Deliver platform features including AI roof analysis, storm alerts, and booking notifications
- Send booking confirmations and service-related notifications
- Provide AI-powered features including roof scanning, supplement letter generation, and prospect building
- Send transactional and account-related emails (password resets, receipts, subscription notices)
- Respond to support requests and communicate with you
- Detect and prevent fraud, abuse, and security incidents
- Analyze usage patterns to improve the platform (using aggregated, anonymized data)
- Comply with legal obligations
We do not use your data to serve third-party advertising, and we do not sell merchant account data. Homeowner requests may be shared with contractors as described in section 4.
4. How We Share Your Information
We share your data only in these circumstances:
Service providers (data processors):
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Email, subscription details |
| Supabase | Database & authentication | All account & business data |
| Anthropic Claude | AI features | Address/property queries, job context |
| Vapi.ai | AI voice calls | Customer phone, name, booking details |
| Vonage | SMS messaging | Phone numbers, message content |
| Maps, geocoding, solar data, calendar and business profile integrations | Addresses; booking details with your consent | |
| Resend | Transactional email | Email addresses, message content |
| Intuit QuickBooks | Accounting sync, when you connect it | Invoices, customer names, amounts |
| Netlify | Website hosting and serverless functions | Request data, IP addresses |
Each provider operates under its own privacy policy and our data processing agreements requiring them to protect your data.
Between merchants and customers: When a homeowner books through your customer portal, their contact information is shared with you as the merchant. This is core to the platform's function.
Homeowner requests and the lead marketplace: When a homeowner submits a request through a RafterCore storm or inspection form, and agrees to it on that form, we may share the request with a roofing contractor who uses RafterCore, including by making it available to contractors in our lead marketplace for a fee. Before a contractor accepts, the listing shows only a first name, last initial, city and state; the contractor who accepts receives the full request. This may be a “sale” of personal information under some state privacy laws. Homeowners can opt out of future sharing at any time by emailing privacy@raftercore.com with “Do not sell or share” in the subject line.
Legal requirements: We may disclose information when required by law, court order, or government authority, or to protect the rights, property, or safety of RafterCore, our users, or the public.
Business transfers: If RafterCore is acquired or merged, your information may be transferred as part of that transaction. We will notify you in advance.
5. Data Storage & Security
Your data is stored in Supabase's cloud infrastructure with the following protections:
- Encryption in transit — All data transmitted between your device and our servers uses TLS 1.3
- Encryption at rest — Database storage is encrypted
- Row-level security — Each merchant can only access their own data
- Access controls — Production system access is restricted to authorized personnel only
- No card storage — Payment card data is handled entirely by Stripe and never stored on RafterCore servers
While we take security seriously and implement industry-standard protections, no system is completely secure. We cannot guarantee absolute security of your data.
6. Data Retention
- Active accounts — Data is retained for as long as your account is active
- After deletion request — Personal data is removed within 30 days
- Financial records — Invoice and payment records may be retained for up to 7 years for accounting and legal compliance
- Backup purge — Encrypted backups are overwritten within 90 days of account deletion
7. Your Rights & Choices
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion via our Delete Account page.
Request an export of your data in a machine-readable format.
Unsubscribe from marketing emails at any time via the unsubscribe link.
Request that we restrict processing of your data in certain circumstances.
To exercise any of these rights, email us at contact@raftercore.com. We will respond within 30 days.
8. Cookies & Tracking
RafterCore uses browser localStorage (not traditional cookies) to store your session data, preferences, and cached business data for offline use. We do not use:
- Third-party advertising cookies
- Cross-site tracking pixels
- Behavioral targeting technologies
- Social media tracking buttons
If we add analytics tools in the future, we will update this policy and notify users accordingly.
9. Children's Privacy
RafterCore is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal data, please contact us at contact@raftercore.com and we will promptly delete it.
10. Third-Party Services
Our platform links to and integrates with third-party services. When you use these integrations, you are also subject to those parties' privacy policies. We recommend reviewing the privacy policies of:
Lawful Basis for Processing (GDPR)
Where GDPR applies, RafterCore processes personal data under one or more of the following lawful bases:
- Contract performance — processing necessary to deliver the services you subscribed to (job management, invoicing, scheduling, customer portal access)
- Legitimate interests — fraud prevention, platform security, abuse detection, product analytics that improve the service
- Legal obligation — retaining financial records and responding to lawful requests from authorities
- Consent — marketing emails, optional notifications, and any processing where we explicitly ask for your permission
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, RafterCore will:
- Notify affected users without undue delay and within 72 hours of becoming aware of the breach (GDPR requirement)
- Notify the relevant supervisory authority where required by applicable law
- Provide a description of the breach, categories of data affected, likely consequences, and measures taken
To report a suspected breach or vulnerability, contact contact@raftercore.com with "Security" in the subject line.
11. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information we collect and how it is used
- The right to delete personal information we hold about you
- The right to opt out of the sale or sharing of personal information. Merchant account data is not sold. Homeowner requests may be shared with contractors for a fee as described in section 4; to opt out, email privacy@raftercore.com with “Do not sell or share” in the subject line
- The right to limit use of sensitive personal information, such as identification document images
- The right to non-discrimination for exercising your CCPA rights
To submit a CCPA request, email contact@raftercore.com with "CCPA Request" in the subject line.
12. International Users
RafterCore is operated in the United States. If you access the platform from outside the US, your data will be transferred to and processed in the US. By using RafterCore, you consent to this transfer. We ensure appropriate safeguards are in place for any international data transfers.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Sending an email to the address associated with your account
- Displaying a prominent notice within the RafterCore platform
The "Last updated" date at the top of this page reflects the most recent revision. Continued use of RafterCore after changes take effect constitutes acceptance of the updated policy.
14. Contact Us
For privacy-related inquiries, data requests, or concerns:
RafterCore / RafterCore LLC
Email: contact@raftercore.com
Phone: 1-833-723-8371
Response time: within 30 days for data requests, within 5 business days for general inquiries.
12. GDPR — EU & UK Resident Rights
If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:
- Right of access — request a copy of all personal data we hold about you (Subject Access Request)
- Right to rectification — correct inaccurate or incomplete personal data
- Right to erasure ("right to be forgotten") — request deletion of your personal data where there is no legitimate reason for us to continue processing it
- Right to restriction — request that we restrict processing of your data in certain circumstances
- Right to data portability — receive your data in a structured, machine-readable format and transmit it to another controller
- Right to object — object to processing based on legitimate interests, including profiling
- Rights related to automated decision-making — not be subject to solely automated decisions that produce legal or similarly significant effects
- Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
International Data Transfers
RafterCore is operated from the United States. If you access our platform from the EU, EEA, or UK, your data will be transferred to and processed in the US. We rely on the following safeguards for international transfers:
- Standard Contractual Clauses (SCCs) — our sub-processors (Supabase, Stripe, Resend, Anthropic) have executed SCCs approved by the European Commission
- UK International Data Transfer Agreement (IDTA) — for transfers to and from the United Kingdom
Data Protection Officer
RafterCore does not currently meet the threshold requiring a formal DPO appointment. Privacy inquiries are handled by our founding team. Contact: contact@raftercore.com — Subject: "GDPR Request".
Supervisory Authority
You have the right to lodge a complaint with your local supervisory authority. EU residents may contact their national data protection authority. UK residents may contact the ICO (ico.org.uk).
To exercise any GDPR right, email contact@raftercore.com with "GDPR Request" in the subject line. We will respond within 30 days.