1. Introduction
HomeRoots is a software service that helps homeowners build a digital record of their home and connect with independent contractors for service, repair, and improvement work. This Privacy Policy explains what personal information HomeRoots collects from you, how we use it, who we share it with, how long we keep it, and the choices you have. It applies to your use of the HomeRoots websites and the HomeRoots mobile apps once released. If you have questions, contact us at `support@gethomeroots.com`.
2. Who we are
"HomeRoots", "we", "us", and "our" refer to HomeRoots LLC, a Washington limited liability company, which operates the Service. HomeRoots is the data controller for personal information you provide to us through the Service. The sub-processors listed in Section 10 act as data processors under our instructions.
3. Information we collect
We collect personal information in three main ways: information you give us, information generated by your use of the Service, and information from third parties.
3.1 Information you give us
- Account information: email address, password stored as a one-way hash by our authentication provider, and the role you choose at signup.
- Profile information: display name, optional phone number, optional profile photo. For contractors: business name, service categories, service area, professional-license information, insurance information, certification information, and credential documents you choose to upload.
- Home record information: property address, home type, year built, spaces and rooms, items and appliances, exterior details and photos, maintenance tasks, notes, and documents you upload.
- Service request information: descriptions of work you want done, preferred timing, photos or attachments you upload, and the parts of your home record you choose to share with contractors.
- Messages and attachments: the content of messages you send through in-platform, per-project messaging and any files you attach. See Section 5 for how messaging data is handled.
- Payment information: when you pay through HomeRoots Pay, Stripe collects card details directly from your browser. HomeRoots does not see or store full card numbers. We retain a payment-processor token, the last four digits of the card, the brand, and an expiration month and year so you can recognize a saved card. For contractors, Stripe Connect collects business identity information for the connected account; HomeRoots receives the Connect account identifier and capability status.
- Contractor credential documents: professional-license documents if you choose to upload them, insurance certificates, and certification documents.
- Support correspondence: when you email `support@gethomeroots.com` or submit a support form, we receive the content of your message.
3.2 Information generated by your use of the Service
- Authentication and session data: IP address at sign-in, browser user agent, session timestamps. Our authentication provider sets session cookies.
- Usage activity: pages visited, in-app actions, request, job, quote and credential state changes, message read timestamps, and notification read timestamps.
- Error and reliability telemetry: when something breaks, we record an error correlation ID and contextual data for diagnostics.
- Audit logs: administrative actions taken by HomeRoots staff are recorded with the staff member's identity, the action, the target, the reason entered, and a timestamp. Free-text fields in audit logs are sanitized to redact email-shaped, phone-shaped, and payment-identifier strings before storage.
3.3 Information from third parties
- Stripe: we receive payment-processing status, dispute notifications, and Connect account capability changes from Stripe.
- CPSC recall feeds: we match the make and model information you save against the U.S. Consumer Product Safety Commission's free public recall feed to surface recalls relevant to your home. We do not send your personal information to CPSC.
- AI suggestions: when you use a scan feature on a product label, we send that photo to our AI provider to suggest item details for your review. We do not send the content of documents you store in your home record to the AI provider. See Sections 6 and 10.
We do not purchase marketing lists, advertising profiles, or social-graph data about you from third parties.
4. How we use your information
We use your personal information to:
- Operate the Service: create your account; render your dashboard; deliver messages; route service requests; process payments; remind you of appointments; surface recalls; and display contractor credentials.
- Provide customer support: respond to your support emails; investigate issues you report; help resolve disputes; confirm identity before honoring data-export or deletion requests.
- Maintain safety, prevent fraud, and protect platform integrity: investigate reported safety or harassment concerns; investigate suspected fraud; and run automated checks that flag in-platform messages containing language suggesting payment or contact outside HomeRoots, so they can be routed to authorized staff for review. We enforce the Terms of Service.
- Comply with legal obligations: respond to subpoenas, court orders, and other valid legal process; satisfy tax-record retention obligations; comply with applicable consumer-protection, payments, and privacy laws.
- Maintain security and reliability: detect and investigate intrusions, brute-force attempts, and abuse; diagnose customer-impacting bugs; restore service after an incident.
- Improve the product: we use aggregate, de-identified statistics about how the Service is used. We do not use the content of your messages or your home record to train AI models.
- Communicate about HomeRoots: send transactional emails such as account confirmation, password reset, receipts, job updates, and service messages, and where you have given permission, periodic product-update emails you can unsubscribe from at any time.
We do not sell your personal information. We do not "share" your personal information for cross-context behavioral advertising as those terms are defined under California law.
5. Sharing and disclosure
5.1 With contractors you choose
When you start a project, you may choose to share parts of your home record with the matched contractor(s): selected rooms and spaces and their details, selected items and appliances, selected documents, your home profile, and only if you opt in exterior photos. Contractors receive a point-in-time snapshot of only what you chose to share for that specific project, isolated to that project.
Before you accept anything, a contractor sees an approximate or masked location and your first name and last initial only. Your full name and full street address are revealed to a contractor only when a job is booked, you approve a site visit, or you directly hire that contractor.
If your home record has co-owners, each co-owner has access to the one shared home record and to the project communications on it.
5.2 With homeowners viewing contractor credentials
Homeowners may see limited credential information about contractors shown in the marketplace. For a professional license marked "License verified," HomeRoots shows only scoped public-record-check information such as license type, issuing state, review date, optional expiration date, and a masked last four characters of the license number. HomeRoots does not show homeowners the full license number, license owner name, or license document by default.
For insurance and certification documents, homeowners may see lightweight metadata and may open active uploaded documents through short-lived, access-controlled links. The Service displays the notices described in the Terms of Service with those documents.
5.3 With HomeRoots personnel
Members of our team in privileged support, trust-and-safety, and platform-operations roles may view per-project message contents and attachments inside HomeRoots' internal tooling. Other authorized staff may see only the per-project communication index and cannot read message bodies or open attachments.
This access is permitted only to respond to a support request, investigate a reported safety, harassment, or fraud concern, resolve a dispute or complaint, comply with a legal obligation, or operate, maintain, secure, or improve the Service. The staff member must enter a reason at view time, and every such access writes a record to our internal audit log.
5.4 With sub-processors
We use third-party services to operate the Service. See Section 10 for the full list with privacy-policy links. Sub-processors process your information only under our instructions and only as needed to provide the contracted service.
5.5 In legal and safety contexts
We may disclose your information when we believe in good faith that doing so is necessary to comply with a subpoena, court order, search warrant, or other valid legal process; enforce our Terms of Service; protect the rights, property, or safety of HomeRoots, our users, or the public; or investigate, prevent, or take action regarding suspected illegal activity, fraud, or violations of our terms. Where the law permits, we will attempt to notify you before disclosing your information in response to compelled legal process.
5.6 In a business transition
If HomeRoots is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, or sale of assets, your personal information may be transferred as part of that transaction. We will give notice before your information becomes subject to a materially different privacy policy.
6. AI and automated processing
HomeRoots uses AI, currently Claude provided by Anthropic, to help with specific assistive homeowner-facing tasks: classifying and enhancing project descriptions you type, suggesting service categories, and suggesting item details from a photo of a product label you scan.
Data we send to the AI provider is limited to the content needed for the specific task, such as a project description you typed or a photo of a product label you scanned. We do not send the content of messages between you and a contractor, the contents of documents you store in your home record, contractor credential documents, or payment data to the AI provider.
The AI provider acts as a processor. It processes the content we send under its commercial data-handling terms and states that it does not use API content to train its general-purpose models. HomeRoots does not rely on the AI provider as long-term storage for your records.
AI is assistive, not autonomous. Suggestions are shown to you for review; you can edit, reject, or replace them before they are saved. AI does not accept quotes on your behalf, does not move money, does not share your data with contractors, and does not resolve disputes.
HomeRoots does not use AI to make decisions that produce legal effects on you or similarly significant effects. Where automated logic is involved, such as matching nearby contractors to your request, it operates on objective criteria such as service area and the service category you request, and does not use protected-class information.
7. Retention
We keep your personal information only as long as we need it for the purposes described in this policy. Some windows are tied to legal obligations. Default retention windows:
- Payment records and tax-related transaction history: 7 years after the transaction.
- Per-project messages and attachments between homeowners and contractors: 1 year after the related service request, project, or dispute reaches a final state, after which the thread is archived for an additional period as required by applicable law or active disputes.
- Contractor credential documents: 3 years after the contractor's account becomes inactive, unless a longer retention period is required by an active claim, dispute, chargeback, or legal hold.
- Profile information: retained while your account is active. After account deletion, retained for 90 days for recovery purposes, then deleted, except records subject to legal hold.
- Home record information: retained while your account is active and deleted on the same schedule as your profile.
- Audit logs of administrative access: 7 years.
- Security and access logs: 90 days for routine logs; longer if needed for an active security investigation.
- Error and reliability telemetry: per Sentry's retention defaults.
- AI provider request content: subject to the AI provider's published retention; HomeRoots does not request extended retention, and we retain the result only if you save it to your record.
When records are subject to multiple categories, the longest applicable retention window applies. Records subject to active legal hold are retained until the hold is released. After the retention window ends, we delete or de-identify the records. De-identified, aggregate statistics may be retained indefinitely.
8. Your rights and choices
Depending on where you live, you may have rights under applicable privacy law. These rights generally include the right to know or access the personal information we hold about you; the right to correct inaccurate information; the right to delete your personal information, subject to exceptions; the right to receive your information in a portable format; the right to opt out of "sale" or "sharing"; the right to non-discrimination for exercising a privacy right; and, in some states, the right to appeal a declined request.
How to exercise your rights. You can delete your account yourself from within the Service at Settings > Legal & privacy > Danger zone. You can request a copy of your data in-app from Settings > Legal & privacy. You may also exercise any of these rights by emailing `support@gethomeroots.com` with the subject line "Privacy Request" and telling us which right you want to exercise and the email address associated with your account. We will follow up with confirmation questions before honoring a request, acknowledge it within 5 business days, and complete it within 30 days of acknowledgement, unless we need a reasonable extension permitted by applicable law.
Limits on deletion. We may decline or delay a deletion request when we are required by law to keep the records; when the records are needed to resolve an active dispute, complete an in-flight service request, or fulfill a contract; or when the records are needed for fraud prevention, security incident response, or compliance with legal process.
Authorized agents. If you authorize someone else to make a privacy request on your behalf, we will ask both of you to confirm the authorization before we act on it.
Managing your information in-app. You can edit your profile information directly in Settings. You can also manage who has access to your shared home record from the Household section of Settings; some household actions are limited to the home owner.
9. Children's privacy
The Service is intended for adults. You must be at least 18 years old to use the Service. The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, please contact `support@gethomeroots.com` and we will delete it.
10. Sub-processors
We use the following sub-processors to operate the Service. Each processes your information only under our instructions and only as needed, and each publishes its own privacy policy.
- Stripe: payments processing, Stripe Connect for contractor payments, and dispute and chargeback management. Data shared: card payment details collected directly by Stripe, name, email, billing address, transaction amount and related metadata, and contractor identity, business, and bank-account information for Connect. Region: United States. Privacy policy: stripe.com/privacy.
- Supabase: application database, authentication, storage, realtime, and edge functions. Data shared: structured application data, uploaded documents and attachments, authentication tokens. Region: United States. Privacy policy: supabase.com/privacy.
- Anthropic: Claude API for assistive classification, label-photo suggestions, and service-category suggestions. Data shared: the content you submit for AI processing, such as project descriptions and scanned label photos. Not message contents, not the contents of stored home-record documents, not contractor credential documents, not payment data. Region: United States. Privacy policy: anthropic.com/legal/privacy.
- Resend: transactional and authentication email delivery. Data shared: email address, message subject and body, delivery metadata. Region: United States. Privacy policy: resend.com/legal/privacy-policy.
- Upstash: rate limiting and an ephemeral key-value store backing security controls. Data shared: hashed identifiers used as rate-limit keys and short-lived counters. Region: United States. Privacy policy: upstash.com/trust/privacy.
- Vercel: web application hosting and runtime for the homeowner, contractor, admin, and marketing sites. Data shared: HTTP request metadata and application logs. Region: United States. Privacy policy: vercel.com/legal/privacy-policy.
- Sentry: application error tracking and reliability telemetry. Data shared: error stack traces, route and browser metadata, scrubbed payloads, and error correlation IDs. We configure Sentry to scrub email, phone, and payment identifiers from captured payloads. Region: United States. Privacy policy: sentry.io/privacy.
- Cloudflare: Cloudflare Turnstile bot-challenge and anti-abuse checks on our auth surfaces. Data shared: IP address and browser signals collected by the Turnstile widget. Region: United States. Privacy policy: cloudflare.com/privacypolicy.
We will update this list when we add or remove sub-processors. Material changes that involve a new category of data or a new region are announced before they take effect.
11. Cookies and tracking
HomeRoots uses a small number of strictly-necessary cookies and similar technologies. We do not use cookies for advertising, marketing analytics, or cross-site behavioral profiling.
- Strictly necessary - authentication: a session token set by Supabase Auth in your browser keeps you signed in across pages and identifies you to the server so security policies return the right data.
- Strictly necessary - security / anti-bot: Cloudflare Turnstile widget cookies on the auth pages differentiate real users from automated bots.
- Strictly necessary - preferences: local-storage entries set by the app remember small UI preferences on your device.
- Operational telemetry: the Sentry SDK may set a short-lived browser identifier to correlate a frontend error with its server context.
Because the cookies we set are strictly necessary for the Service to function, most browsers do not require a separate consent banner for them. You can clear cookies and local storage at any time through your browser's privacy controls; doing so will sign you out and reset stored UI preferences. If we ever add a non-essential tracker, we will give you the ability to opt out and update this section.
12. Security
We take reasonable, industry-standard measures to protect personal information. All traffic between your browser and HomeRoots is encrypted in transit. Application data and uploaded files are encrypted at rest by our database and storage providers. We enforce row-level security policies on every database table so that one user's data is not visible to another user. HomeRoots staff who can access user records use multi-factor authentication; access to message contents is restricted to specific authorized staff, requires a reason, and is logged. We isolate payment data: full card numbers go directly to Stripe and never traverse HomeRoots servers. Contractor credential documents are stored in a private, access-controlled storage bucket and are never served from a fixed public URL.
No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you in accordance with applicable law. To report a security concern, email `support@gethomeroots.com` with the subject "Security Report". We do not currently run a public bug-bounty program.
13. Changes to this policy
We may update this policy from time to time. The current active version, the version string, and the effective date are visible at `/privacy` in each HomeRoots app. When we make a material change, we will publish the new versioned policy and require you to re-accept the new policy the next time you sign in, and where applicable send notice by email.
14. Contact us
To exercise a privacy right, ask a privacy question, or report a concern, email `support@gethomeroots.com` with the subject line "Privacy Request". A mailing address is available on request.