HomeRoots Privacy Policy

Version: 2026-09-25.v8 · Effective date: September 25, 2026

1. Introduction

HomeRoots is a software service that helps homeowners build a digital record of their home and connect with independent contractors for service, repair, and improvement work. This Privacy Policy explains what personal information HomeRoots collects from you, how we use it, who we share it with, how long we keep it, and the choices you have. It applies to your use of the HomeRoots websites and the HomeRoots mobile apps once released. If you have questions, contact us at `support@gethomeroots.com`.

2. Who we are

"HomeRoots", "we", "us", and "our" refer to HomeRoots LLC, a Washington limited liability company, which operates the Service. HomeRoots is the data controller for personal information you provide to us through the Service. The sub-processors listed in Section 10 act as data processors under our instructions.

3. Information we collect

We collect personal information in three main ways: information you give us, information generated by your use of the Service, and information from third parties.

3.1 Information you give us

3.2 Information generated by your use of the Service

3.3 Information from third parties

We do not purchase marketing lists, advertising profiles, or social-graph data about you from third parties.

4. How we use your information

We use your personal information to:

We do not sell your personal information. We do not "share" your personal information for cross-context behavioral advertising as those terms are defined under California law.

5. Sharing and disclosure

5.1 With contractors you choose

When you start a project, you may choose to share parts of your home record with the matched contractor(s): selected rooms and spaces and their details, selected items and appliances, selected documents, your home profile, and only if you opt in exterior photos. Contractors receive a point-in-time snapshot of only what you chose to share for that specific project, isolated to that project.

Before you accept anything, a contractor sees an approximate or masked location and your first name and last initial only. Your full name and full street address are revealed to a contractor only when a job is booked, you approve a site visit, or you directly hire that contractor.

If your home record has co-owners, each co-owner has access to the one shared home record and to the project communications on it.

Your Pros are part of your home record and, like the rest of it, are shared with the co-owners of that home. HomeRoots does not share the notes, labels or contact details you save in Your Pros with the contractor they describe or with any other contractor, and does not use them to contact anyone. HomeRoots does not match the details you save against contractor accounts to connect a saved Pro automatically: a saved Pro is connected to a contractor's HomeRoots profile only when a member of your home chooses to connect it. If you connect a saved Pro, your notes, labels and contact details stay private to your home, and connecting does not give that contractor access to your home record or to any project.

Invitation links. If HomeRoots lets you invite a saved Pro who is not connected to a HomeRoots profile, it does so by creating an invitation link for you to share. HomeRoots does not send the invitation: it does not email or text the contractor, and creating a link does not notify the contractor. You decide whether to share the link, with whom and how, and HomeRoots does not know how or with whom you share it. Anyone who has the link can use it until it has been used, it expires, or it is turned off. The invitation does not show your name, your home address, your home record, or anything you saved in Your Pros. HomeRoots keeps the status of each invitation, and a record of which contractor account used it, so that the invitation works, so that a used, expired or turned-off link cannot be used again, and so that your household can be told when that contractor can be connected. When the contractor's HomeRoots profile is publicly visible as described in Section 5.2, we may let the members of your home know, for example with an in-app notification, and show them that profile so that you can decide whether to connect it to your saved Pro. Creating a contractor account or using an invitation link does not connect the contractor to your saved Pro, does not make a contractor's profile publicly visible, and does not give the contractor access to your home record or to any project.

5.2 Contractor profiles, and what is publicly visible

A contractor with an eligible, active HomeRoots account has a contractor profile. A contractor profile may be publicly visible: it may be viewed by anyone, including people who do not have a HomeRoots account and are not signed in; it may be shared by its web address; it may be listed in, and found through, HomeRoots' own public search and browse features; and it may be indexed by search engines and appear in search results. HomeRoots does not guarantee that any profile is indexed or that it appears in any particular search result. There is no separate setting for marketplace listing. When HomeRoots offers public search or browse features, a profile that is otherwise publicly visible may be included in them on the same basis as the rest of its public visibility, and stops being included when that public visibility ends. A contractor profile is publicly viewable only while that contractor's account is active and eligible. Profiles belonging to accounts that are not yet published, suspended, closed, or deleted are not served publicly.

A publicly visible contractor profile may show: the business name; the profile description the contractor writes; the business city and business state; the service categories and trades the contractor selects; the profile photo, portfolio photos, portfolio collections and captions the contractor uploads; the public phone number, public email address and public website address the contractor chooses to publish; when the contractor joined HomeRoots; credential information as described below; and reviews as described below.

Business location. A contractor's business city and business state may appear on that contractor's HomeRoots profile. The street address, suite or unit, and postal code of a contractor's business address are not published as profile fields. A business address is the address of the business itself and is separate from the service area, which describes where the contractor works. HomeRoots does not verify a business address; it is information the contractor provides, and HomeRoots may use it as one signal when reviewing credential or licence information.

Credentials. For a professional license marked "License verified," HomeRoots shows only scoped public-record-check information such as license type, issuing state, review date, optional expiration date, and a masked last four characters of the license number. HomeRoots does not show the full license number, license owner name, or license document. For insurance, a publicly visible profile shows only that insurance information is on file; the carrier, policy type, and coverage amounts are shown only to signed-in homeowners. For certifications, a profile may show the certification title, issuer, and expiration date. Credential documents themselves are never published on a publicly visible profile: an uploaded insurance or certification document can be opened only by signed-in users the document is shown to, through short-lived, access-controlled links, and the Service displays the notices described in the Terms of Service with those documents.

Reviews. When a homeowner completes a project and submits a review, that review may appear on the contractor's profile, including where that profile is publicly visible. A published review may show the rating, the written feedback the reviewer submitted, and the date it was submitted. A review is shown under a shortened reviewer label rather than the reviewer's full name. Except for information a reviewer chooses to include in their written feedback, HomeRoots does not add the reviewer's full name, email address, phone number, home address, account identifier, or project details to a published review. Written feedback is published as the reviewer wrote it; HomeRoots does not scan, edit or remove personal information from it, so please do not include personal information you do not want published. Photos attached to a review are not published on a publicly visible profile.

What is not published. A publicly visible contractor profile does not show the contractor's legal name, private phone number, private email address, street address, suite or unit, postal code, payment or payout details, tax information, or internal account, billing, or capacity state. Apart from the reviews described above, HomeRoots does not put a homeowner's personal information, home record, or project information on a contractor's profile.

5.3 With HomeRoots personnel

Members of our team in privileged support, trust-and-safety, and platform-operations roles may view per-project message contents and attachments inside HomeRoots' internal tooling. Other authorized staff may see only the per-project communication index and cannot read message bodies or open attachments.

This access is permitted only to respond to a support request, investigate a reported safety, harassment, or fraud concern, resolve a dispute or complaint, comply with a legal obligation, or operate, maintain, secure, or improve the Service. The staff member must enter a reason at view time, and every such access writes a record to our internal audit log.

5.4 With sub-processors

We use third-party services to operate the Service. See Section 10 for the full list with privacy-policy links. Sub-processors process your information only under our instructions and only as needed to provide the contracted service.

5.5 In legal and safety contexts

We may disclose your information when we believe in good faith that doing so is necessary to comply with a subpoena, court order, search warrant, or other valid legal process; enforce our Terms of Service; protect the rights, property, or safety of HomeRoots, our users, or the public; or investigate, prevent, or take action regarding suspected illegal activity, fraud, or violations of our terms. Where the law permits, we will attempt to notify you before disclosing your information in response to compelled legal process.

5.6 In a business transition

If HomeRoots is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, or sale of assets, your personal information may be transferred as part of that transaction. We will give notice before your information becomes subject to a materially different privacy policy.

6. AI and automated processing

HomeRoots uses AI, currently Claude provided by Anthropic, to help with specific assistive homeowner-facing tasks: classifying and enhancing project descriptions you type, suggesting service categories, and suggesting item details from a photo of a product label you scan.

Data we send to the AI provider is limited to the content needed for the specific task, such as a project description you typed or a photo of a product label you scanned. We do not send the content of messages between you and a contractor, the contents of documents you store in your home record, contractor credential documents, or payment data to the AI provider.

The AI provider acts as a processor. It processes the content we send under its commercial data-handling terms and states that it does not use API content to train its general-purpose models. HomeRoots does not rely on the AI provider as long-term storage for your records.

AI is assistive, not autonomous. Suggestions are shown to you for review; you can edit, reject, or replace them before they are saved. AI does not accept quotes on your behalf, does not move money, does not share your data with contractors, and does not resolve disputes.

HomeRoots does not use AI to make decisions that produce legal effects on you or similarly significant effects. Where automated logic is involved, such as matching nearby contractors to your request, it operates on objective criteria such as service area and the service category you request, and does not use protected-class information.

7. Retention

We keep your personal information only as long as we need it for the purposes described in this policy. Some windows are tied to legal obligations. Default retention windows:

When records are subject to multiple categories, the longest applicable retention window applies. Records subject to active legal hold are retained until the hold is released. After the retention window ends, we delete or de-identify the records. De-identified, aggregate statistics may be retained indefinitely.

8. Your rights and choices

Depending on where you live, you may have rights under applicable privacy law. These rights generally include the right to know or access the personal information we hold about you; the right to correct inaccurate information; the right to delete your personal information, subject to exceptions; the right to receive your information in a portable format; the right to opt out of "sale" or "sharing"; the right to non-discrimination for exercising a privacy right; and, in some states, the right to appeal a declined request.

How to exercise your rights. You can delete your account yourself from within the Service at Settings > Legal & privacy > Danger zone. You can request a copy of your data in-app from Settings > Legal & privacy. You may also exercise any of these rights by emailing `support@gethomeroots.com` with the subject line "Privacy Request" and telling us which right you want to exercise and the email address associated with your account. We will follow up with confirmation questions before honoring a request, acknowledge it within 5 business days, and complete it within 30 days of acknowledgement, unless we need a reasonable extension permitted by applicable law.

Limits on deletion. We may decline or delay a deletion request when we are required by law to keep the records; when the records are needed to resolve an active dispute, complete an in-flight service request, or fulfill a contract; or when the records are needed for fraud prevention, security incident response, or compliance with legal process.

Authorized agents. If you authorize someone else to make a privacy request on your behalf, we will ask both of you to confirm the authorization before we act on it.

Managing your information in-app. You can edit your profile information directly in Settings. You can also manage who has access to your shared home record from the Household section of Settings; some household actions are limited to the home owner.

9. Children's privacy

The Service is intended for adults. You must be at least 18 years old to use the Service. The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, please contact `support@gethomeroots.com` and we will delete it.

10. Sub-processors

We use the following sub-processors to operate the Service. Each processes your information only under our instructions and only as needed, and each publishes its own privacy policy.

We will update this list when we add or remove sub-processors. Material changes that involve a new category of data or a new region are announced before they take effect.

11. Cookies and tracking

HomeRoots uses a small number of strictly-necessary cookies and similar technologies. We do not use cookies for advertising, marketing analytics, or cross-site behavioral profiling.

Because the cookies we set are strictly necessary for the Service to function, most browsers do not require a separate consent banner for them. You can clear cookies and local storage at any time through your browser's privacy controls; doing so will sign you out and reset stored UI preferences. If we ever add a non-essential tracker, we will give you the ability to opt out and update this section.

12. Security

We take reasonable, industry-standard measures to protect personal information. All traffic between your browser and HomeRoots is encrypted in transit. Application data and uploaded files are encrypted at rest by our database and storage providers. We enforce row-level security policies on every database table so that one user's data is not visible to another user. HomeRoots staff who can access user records use multi-factor authentication; access to message contents is restricted to specific authorized staff, requires a reason, and is logged. We isolate payment data: full card numbers go directly to Stripe and never traverse HomeRoots servers. Contractor credential documents are stored in a private, access-controlled storage bucket and are never served from a fixed public URL.

No system is perfectly secure. If we become aware of a security incident affecting your personal information, we will notify you in accordance with applicable law. To report a security concern, email `support@gethomeroots.com` with the subject "Security Report". We do not currently run a public bug-bounty program.

13. Changes to this policy

We may update this policy from time to time. The current active version, the version string, and the effective date are visible at `/privacy` in each HomeRoots app. When we make a material change, we will publish the new versioned policy and require you to re-accept the new policy the next time you sign in, and where applicable send notice by email.

14. Contact us

To exercise a privacy right, ask a privacy question, or report a concern, email `support@gethomeroots.com` with the subject line "Privacy Request". A mailing address is available on request.