1. Introduction
HomeRoots is a software service that helps homeowners build a digital record of their home and connect with independent contractors for service, repair, and improvement work. This Privacy Policy explains what personal information HomeRoots collects from you, how we use it, who we share it with, how long we keep it, and the choices you have. It applies to your use of the HomeRoots websites and the HomeRoots mobile apps once released. If you have questions, contact us at `support@gethomeroots.com`.
2. Who we are
"HomeRoots", "we", "us", and "our" refer to HomeRoots LLC, a Washington limited liability company, which operates the Service. HomeRoots is the data controller for personal information you provide to us through the Service. The sub-processors listed in Section 10 act as data processors under our instructions.
3. Information we collect
We collect personal information in three main ways: information you give us, information generated by your use of the Service, and information from third parties.
3.1 Information you give us
- Account information: email address, password stored as a one-way hash by our authentication provider, and the role you choose at signup.
- Profile information: display name, optional phone number, optional profile photo. For contractors: business name, business address, service categories, service area, professional-license information, insurance information, certification information, and credential documents you choose to upload. A contractor's business address is the address of the business itself and is separate from the service area, which describes where the contractor works.
- Home record information: property address, home type, year built, spaces and rooms, items and appliances, exterior details and photos, maintenance tasks, notes, and documents you upload.
- Your Pros: if you save a contractor or business you work with to Your Pros, the name, phone numbers, email addresses and additional contact people you record for them, and the notes and labels you add. You can save a contractor who does not have a HomeRoots account. Your Pros are part of your home record. HomeRoots does not verify these details.
- Service request information: descriptions of work you want done, preferred timing, photos or attachments you upload, and the parts of your home record you choose to share with contractors.
- Messages and attachments: the content of messages you send through in-platform, per-project messaging and any files you attach. See Section 5 for how messaging data is handled.
- Reviews: when a project is complete, you may submit a rating, written feedback, and optional completion photos about the contractor who did the work. See Section 5.2 for how reviews are displayed.
- Payment information: when you pay through HomeRoots Pay, Stripe collects card details directly from your browser. HomeRoots does not see or store full card numbers. We retain a payment-processor token, the last four digits of the card, the brand, and an expiration month and year so you can recognize a saved card. For contractors, Stripe Connect collects business identity information for the connected account; HomeRoots receives the Connect account identifier and capability status.
- Contractor credential documents: insurance certificates, and certification documents if you choose to upload them. HomeRoots no longer collects professional-license documents; a professional license is checked against public licensing records from the details you enter.
- Support correspondence: when you email `support@gethomeroots.com` or submit a support form, we receive the content of your message.
3.2 Information generated by your use of the Service
- Authentication and session data: IP address at sign-in, browser user agent, session timestamps. Our authentication provider sets session cookies.
- Usage activity: pages visited, in-app actions, request, job, quote and credential state changes, message read timestamps, and notification read timestamps.
- Error and reliability telemetry: when something breaks, we record an error correlation ID and contextual data for diagnostics.
- Audit logs: administrative actions taken by HomeRoots staff are recorded with the staff member's identity, the action, the target, the reason entered, and a timestamp. Free-text fields in audit logs are sanitized to redact email-shaped, phone-shaped, and payment-identifier strings before storage.
3.3 Information from third parties
- Stripe: we receive payment-processing status, dispute notifications, and Connect account capability changes from Stripe.
- CPSC recall feeds: we match the make and model information you save against the U.S. Consumer Product Safety Commission's free public recall feed to surface recalls relevant to your home. We do not send your personal information to CPSC.
- AI suggestions: when you use a scan feature on a product label, we send that photo to our AI provider to suggest item details for your review. We do not send the content of documents you store in your home record to the AI provider. See Sections 6 and 10.
- Homeowners, if you are a contractor: a homeowner may save your business's name and contact details in their private Your Pros list, and may share a HomeRoots invitation link with you. HomeRoots does not use a homeowner's saved details to contact you, and those details do not become part of your account or your public profile. If you use an invitation link, we record that your contractor account used it, and once your contractor profile is publicly visible as described in Section 5.2, we may let the members of that homeowner's home know and show them your profile.
We do not purchase marketing lists, advertising profiles, or social-graph data about you from third parties.
4. How we use your information
We use your personal information to:
- Operate the Service: create your account; render your dashboard; deliver messages; route service requests; process payments; remind you of appointments; surface recalls; and display contractor credentials.
- Provide customer support: respond to your support emails; investigate issues you report; help resolve disputes; confirm identity before honoring data-export or deletion requests.
- Maintain safety, prevent fraud, and protect platform integrity: investigate reported safety or harassment concerns; investigate suspected fraud; and run automated checks that flag in-platform messages containing language suggesting payment or contact outside HomeRoots, so they can be routed to authorized staff for review. We enforce the Terms of Service.
- Comply with legal obligations: respond to subpoenas, court orders, and other valid legal process; satisfy tax-record retention obligations; comply with applicable consumer-protection, payments, and privacy laws.
- Maintain security and reliability: detect and investigate intrusions, brute-force attempts, and abuse; diagnose customer-impacting bugs; restore service after an incident.
- Improve the product: we use aggregate, de-identified statistics about how the Service is used. We do not use the content of your messages or your home record to train AI models.
- Communicate about HomeRoots: send transactional emails such as account confirmation, password reset, receipts, job updates, and service messages, and where you have given permission, periodic product-update emails you can unsubscribe from at any time.
We do not sell your personal information. We do not "share" your personal information for cross-context behavioral advertising as those terms are defined under California law.
5. Sharing and disclosure
5.1 With contractors you choose
When you start a project, you may choose to share parts of your home record with the matched contractor(s): selected rooms and spaces and their details, selected items and appliances, selected documents, your home profile, and only if you opt in exterior photos. Contractors receive a point-in-time snapshot of only what you chose to share for that specific project, isolated to that project.
Before you accept anything, a contractor sees an approximate or masked location and your first name and last initial only. Your full name and full street address are revealed to a contractor only when a job is booked, you approve a site visit, or you directly hire that contractor.
If your home record has co-owners, each co-owner has access to the one shared home record and to the project communications on it.
Your Pros are part of your home record and, like the rest of it, are shared with the co-owners of that home. HomeRoots does not share the notes, labels or contact details you save in Your Pros with the contractor they describe or with any other contractor, and does not use them to contact anyone. HomeRoots does not match the details you save against contractor accounts to connect a saved Pro automatically: a saved Pro is connected to a contractor's HomeRoots profile only when a member of your home chooses to connect it. If you connect a saved Pro, your notes, labels and contact details stay private to your home, and connecting does not give that contractor access to your home record or to any project.
Invitation links. If HomeRoots lets you invite a saved Pro who is not connected to a HomeRoots profile, it does so by creating an invitation link for you to share. HomeRoots does not send the invitation: it does not email or text the contractor, and creating a link does not notify the contractor. You decide whether to share the link, with whom and how, and HomeRoots does not know how or with whom you share it. Anyone who has the link can use it until it has been used, it expires, or it is turned off. The invitation does not show your name, your home address, your home record, or anything you saved in Your Pros. HomeRoots keeps the status of each invitation, and a record of which contractor account used it, so that the invitation works, so that a used, expired or turned-off link cannot be used again, and so that your household can be told when that contractor can be connected. When the contractor's HomeRoots profile is publicly visible as described in Section 5.2, we may let the members of your home know, for example with an in-app notification, and show them that profile so that you can decide whether to connect it to your saved Pro. Creating a contractor account or using an invitation link does not connect the contractor to your saved Pro, does not make a contractor's profile publicly visible, and does not give the contractor access to your home record or to any project.
5.2 Contractor profiles, and what is publicly visible
A contractor with an eligible, active HomeRoots account has a contractor profile. A contractor profile may be publicly visible: it may be viewed by anyone, including people who do not have a HomeRoots account and are not signed in; it may be shared by its web address; it may be listed in, and found through, HomeRoots' own public search and browse features; and it may be indexed by search engines and appear in search results. HomeRoots does not guarantee that any profile is indexed or that it appears in any particular search result. There is no separate setting for marketplace listing. When HomeRoots offers public search or browse features, a profile that is otherwise publicly visible may be included in them on the same basis as the rest of its public visibility, and stops being included when that public visibility ends. A contractor profile is publicly viewable only while that contractor's account is active and eligible. Profiles belonging to accounts that are not yet published, suspended, closed, or deleted are not served publicly.
A publicly visible contractor profile may show: the business name; the profile description the contractor writes; the business city and business state; the service categories and trades the contractor selects; the profile photo, portfolio photos, portfolio collections and captions the contractor uploads; the public phone number, public email address and public website address the contractor chooses to publish; when the contractor joined HomeRoots; credential information as described below; and reviews as described below.
Business location. A contractor's business city and business state may appear on that contractor's HomeRoots profile. The street address, suite or unit, and postal code of a contractor's business address are not published as profile fields. A business address is the address of the business itself and is separate from the service area, which describes where the contractor works. HomeRoots does not verify a business address; it is information the contractor provides, and HomeRoots may use it as one signal when reviewing credential or licence information.
Credentials. For a professional license marked "License verified," HomeRoots shows only scoped public-record-check information such as license type, issuing state, review date, optional expiration date, and a masked last four characters of the license number. HomeRoots does not show the full license number, license owner name, or license document. For insurance, a publicly visible profile shows only that insurance information is on file; the carrier, policy type, and coverage amounts are shown only to signed-in homeowners. For certifications, a profile may show the certification title, issuer, and expiration date. Credential documents themselves are never published on a publicly visible profile: an uploaded insurance or certification document can be opened only by signed-in users the document is shown to, through short-lived, access-controlled links, and the Service displays the notices described in the Terms of Service with those documents.
Reviews. When a homeowner completes a project and submits a review, that review may appear on the contractor's profile, including where that profile is publicly visible. A published review may show the rating, the written feedback the reviewer submitted, and the date it was submitted. A review is shown under a shortened reviewer label rather than the reviewer's full name. Except for information a reviewer chooses to include in their written feedback, HomeRoots does not add the reviewer's full name, email address, phone number, home address, account identifier, or project details to a published review. Written feedback is published as the reviewer wrote it; HomeRoots does not scan, edit or remove personal information from it, so please do not include personal information you do not want published. Photos attached to a review are not published on a publicly visible profile.
What is not published. A publicly visible contractor profile does not show the contractor's legal name, private phone number, private email address, street address, suite or unit, postal code, payment or payout details, tax information, or internal account, billing, or capacity state. Apart from the reviews described above, HomeRoots does not put a homeowner's personal information, home record, or project information on a contractor's profile.
5.3 With HomeRoots personnel
Members of our team in privileged support, trust-and-safety, and platform-operations roles may view per-project message contents and attachments inside HomeRoots' internal tooling. Other authorized staff may see only the per-project communication index and cannot read message bodies or open attachments.
This access is permitted only to respond to a support request, investigate a reported safety, harassment, or fraud concern, resolve a dispute or complaint, comply with a legal obligation, or operate, maintain, secure, or improve the Service. The staff member must enter a reason at view time, and every such access writes a record to our internal audit log.
5.4 With sub-processors
We use third-party services to operate the Service. See Section 10 for the full list with privacy-policy links. Sub-processors process your information only under our instructions and only as needed to provide the contracted service.
5.5 In legal and safety contexts
We may disclose your information when we believe in good faith that doing so is necessary to comply with a subpoena, court order, search warrant, or other valid legal process; enforce our Terms of Service; protect the rights, property, or safety of HomeRoots, our users, or the public; or investigate, prevent, or take action regarding suspected illegal activity, fraud, or violations of our terms. Where the law permits, we will attempt to notify you before disclosing your information in response to compelled legal process.
5.6 In a business transition
If HomeRoots is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, or sale of assets, your personal information may be transferred as part of that transaction. We will give notice before your information becomes subject to a materially different privacy policy.
6. AI and automated processing
HomeRoots uses AI, currently Claude provided by Anthropic, to help with specific assistive homeowner-facing tasks: classifying and enhancing project descriptions you type, suggesting service categories, and suggesting item details from a photo of a product label you scan.
Data we send to the AI provider is limited to the content needed for the specific task, such as a project description you typed or a photo of a product label you scanned. We do not send the content of messages between you and a contractor, the contents of documents you store in your home record, contractor credential documents, or payment data to the AI provider.
The AI provider acts as a processor. It processes the content we send under its commercial data-handling terms and states that it does not use API content to train its general-purpose models. HomeRoots does not rely on the AI provider as long-term storage for your records.
AI is assistive, not autonomous. Suggestions are shown to you for review; you can edit, reject, or replace them before they are saved. AI does not accept quotes on your behalf, does not move money, does not share your data with contractors, and does not resolve disputes.
HomeRoots does not use AI to make decisions that produce legal effects on you or similarly significant effects. Where automated logic is involved, such as matching nearby contractors to your request, it operates on objective criteria such as service area and the service category you request, and does not use protected-class information.
7. Retention
We keep your personal information only as long as we need it for the purposes described in this policy. Some windows are tied to legal obligations. Default retention windows:
- Payment records and tax-related transaction history: 7 years after the transaction.
- Per-project messages and attachments between homeowners and contractors: 1 year after the related service request, project, or dispute reaches a final state, after which the thread is archived for an additional period as required by applicable law or active disputes.
- Contractor credential documents: 3 years after the contractor's account becomes inactive, unless a longer retention period is required by an active claim, dispute, chargeback, or legal hold.
- Profile information: retained while your account is active. After account deletion, retained for 90 days for recovery purposes, then deleted, except records subject to legal hold.
- Reviews you submit about a contractor: retained for as long as that contractor's account exists, so the review remains useful to other homeowners. If you delete your HomeRoots account, the review may be retained, and its reviewer label is no longer derived from your HomeRoots profile name. The rating and the written feedback you submitted are kept as you wrote them.
- Home record information: retained while your account is active and deleted on the same schedule as your profile.
- Invitation links: a link that has not been used stops working 14 days after it is created. Once a link has been used, we keep the record of which contractor account used it for up to 90 days so that your household can be told when that contractor's profile is publicly visible; the invitation ends sooner if a member of your home connects that saved Pro, turns the link off, or deletes the saved Pro. We delete the record of an ended invitation within 30 days after it ends, and deleting a saved Pro or its home deletes its invitation records with it.
- Audit logs of administrative access: 7 years.
- Security and access logs: 90 days for routine logs; longer if needed for an active security investigation.
- Error and reliability telemetry: per Sentry's retention defaults.
- AI provider request content: subject to the AI provider's published retention; HomeRoots does not request extended retention, and we retain the result only if you save it to your record.
When records are subject to multiple categories, the longest applicable retention window applies. Records subject to active legal hold are retained until the hold is released. After the retention window ends, we delete or de-identify the records. De-identified, aggregate statistics may be retained indefinitely.
8. Your rights and choices
Depending on where you live, you may have rights under applicable privacy law. These rights generally include the right to know or access the personal information we hold about you; the right to correct inaccurate information; the right to delete your personal information, subject to exceptions; the right to receive your information in a portable format; the right to opt out of "sale" or "sharing"; the right to non-discrimination for exercising a privacy right; and, in some states, the right to appeal a declined request.
How to exercise your rights. You can delete your account yourself from within the Service at Settings > Legal & privacy > Danger zone. You can request a copy of your data in-app from Settings > Legal & privacy. You may also exercise any of these rights by emailing `support@gethomeroots.com` with the subject line "Privacy Request" and telling us which right you want to exercise and the email address associated with your account. We will follow up with confirmation questions before honoring a request, acknowledge it within 5 business days, and complete it within 30 days of acknowledgement, unless we need a reasonable extension permitted by applicable law.
Limits on deletion. We may decline or delay a deletion request when we are required by law to keep the records; when the records are needed to resolve an active dispute, complete an in-flight service request, or fulfill a contract; or when the records are needed for fraud prevention, security incident response, or compliance with legal process.
Authorized agents. If you authorize someone else to make a privacy request on your behalf, we will ask both of you to confirm the authorization before we act on it.
Managing your information in-app. You can edit your profile information directly in Settings. You can also manage who has access to your shared home record from the Household section of Settings; some household actions are limited to the home owner.
9. Children's privacy
The Service is intended for adults. You must be at least 18 years old to use the Service. The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, please contact `support@gethomeroots.com` and we will delete it.
10. Sub-processors
We use the following sub-processors to operate the Service. Each processes your information only under our instructions and only as needed, and each publishes its own privacy policy.
- Stripe: payments processing, Stripe Connect for contractor payments, and dispute and chargeback management. Data shared: card payment details collected directly by Stripe, name, email, billing address, transaction amount and related metadata, and contractor identity, business, and bank-account information for Connect. Region: United States. Privacy policy: stripe.com/privacy.
- Supabase: application database, authentication, storage, realtime, and edge functions. Data shared: structured application data, uploaded documents and attachments, authentication tokens. Region: United States. Privacy policy: supabase.com/privacy.
- Anthropic: Claude API for assistive classification, label-photo suggestions, and service-category suggestions. Data shared: the content you submit for AI processing, such as project descriptions and scanned label photos. Not message contents, not the contents of stored home-record documents, not contractor credential documents, not payment data. Region: United States. Privacy policy: anthropic.com/legal/privacy.
- Resend: transactional and authentication email delivery. Data shared: email address, message subject and body, delivery metadata. Region: United States. Privacy policy: resend.com/legal/privacy-policy.
- Upstash: rate limiting and an ephemeral key-value store backing security controls. Data shared: hashed identifiers used as rate-limit keys and short-lived counters. Region: United States. Privacy policy: upstash.com/trust/privacy.
- Vercel: web application hosting and runtime for the homeowner, contractor, admin, and marketing sites. Data shared: HTTP request metadata and application logs. Region: United States. Privacy policy: vercel.com/legal/privacy-policy.
- Sentry: application error tracking and reliability telemetry. Data shared: error stack traces, route and browser metadata, scrubbed payloads, and error correlation IDs. We configure Sentry to scrub email, phone, and payment identifiers from captured payloads. Region: United States. Privacy policy: sentry.io/privacy.
- Cloudflare: Cloudflare Turnstile bot-challenge and anti-abuse checks on our auth surfaces. Data shared: IP address and browser signals collected by the Turnstile widget. Region: United States. Privacy policy: cloudflare.com/privacypolicy.
We will update this list when we add or remove sub-processors. Material changes that involve a new category of data or a new region are announced before they take effect.
11. Cookies and tracking
HomeRoots uses a small number of strictly-necessary cookies and similar technologies. We do not use cookies for advertising, marketing analytics, or cross-site behavioral profiling.
- Strictly necessary - authentication: a session token set by Supabase Auth in your browser keeps you signed in across pages and identifies you to the server so security policies return the right data.
- Strictly necessary - security / anti-bot: Cloudflare Turnstile widget cookies on the auth pages differentiate real users from automated bots.
- Strictly necessary - invitations: if you open a HomeRoots invitation link, a short-lived cookie may hold that invitation while you sign in or create an account, so that it can be completed. It expires within 24 hours.
- Strictly necessary - preferences: local-storage entries set by the app remember small UI preferences on your device.
- Operational telemetry: the Sentry SDK may set a short-lived browser identifier to correlate a frontend error with its server context.
Because the cookies we set are strictly necessary for the Service to function, most browsers do not require a separate consent banner for them. You can clear cookies and local storage at any time through your browser's privacy controls; doing so will sign you out and reset stored UI preferences. If we ever add a non-essential tracker, we will give you the ability to opt out and update this section.
12. Security
We take reasonable, industry-standard measures to protect personal information. All traffic between your browser and HomeRoots is encrypted in transit. Application data and uploaded files are encrypted at rest by our database and storage providers. We enforce row-level security policies on every database table so that one user's data is not visible to another user. HomeRoots staff who can access user records use multi-factor authentication; access to message contents is restricted to specific authorized staff, requires a reason, and is logged. We isolate payment data: full card numbers go directly to Stripe and never traverse HomeRoots servers. Contractor credential documents are stored in a private, access-controlled storage bucket and are never served from a fixed public URL.
No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you in accordance with applicable law. To report a security concern, email `support@gethomeroots.com` with the subject "Security Report". We do not currently run a public bug-bounty program.
13. Changes to this policy
We may update this policy from time to time. The current active version, the version string, and the effective date are visible at `/privacy` in each HomeRoots app. When we make a material change, we will publish the new versioned policy and require you to re-accept the new policy the next time you sign in, and where applicable send notice by email.
14. Contact us
To exercise a privacy right, ask a privacy question, or report a concern, email `support@gethomeroots.com` with the subject line "Privacy Request". A mailing address is available on request.