Notice: This policy applies to both RoofMetric and Gutter IQ, two applications operated by The Elite Company from Texas, United States. Throughout this document, "we," "us," "our," and "the Service" refer collectively to those applications and the company.
1. What this policy covers
This Privacy Policy explains what information we collect when you use RoofMetric or Gutter IQ (including the web app, iOS app, and our public homeowner estimate page at /get-estimate), how we use it, who we share it with, and your rights regarding that information. By using the Service, you agree to the practices described here.
2. Information we collect
Account information
- Name, email address, password (stored as a one-way hash)
- Company name, business address, phone number, license number, website
- Profile photo and company logo (if uploaded)
- Payment method (handled by Stripe; we do not store full card numbers)
Customer and project data you enter
- Information about your customers: name, email, phone, property address
- Roof and property measurements (computed from satellite imagery, LiDAR, AR, or your manual sketches)
- Estimates, invoices, change orders, photos, and documents you create or upload
- Notes, tasks, and pipeline-stage tracking
Information from homeowners using our public estimate page
When a homeowner submits a request through our public estimate page, we collect their name, email, phone (optional), property address, roof measurements, and any qualifying answers they provide. This information is shared with the contractor(s) that match the homeowner's location and who claim the lead.
OAuth and integration data
If you connect your Google or Microsoft account for email or calendar features, we receive and store refresh tokens that allow us to send email and create calendar events on your behalf. We only request the minimum scopes necessary:
- Gmail / Outlook: permission to send mail from your account
- Google Calendar: permission to create, read, and update events on your primary calendar, and to read your email address
Google API Services User Data Policy. RoofMetric and Gutter IQ's use and transfer to any other app of information received from Google APIs will adhere to the
Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties, do not use it for advertising, do not allow humans to read it (except with your explicit consent, for security investigations, or to comply with law), and do not use Google user data for purposes other than providing the Service.
Automatically collected information
- IP address, browser type, operating system, device identifiers
- Usage data: pages visited, features used, timestamps, error reports
- Approximate geolocation (derived from IP, only for fraud prevention and lead distribution)
3. How we use information
- Provide and operate the Service (estimates, CRM, measurements, email/calendar sync, lead distribution)
- Send transactional emails (account confirmations, password resets, lead notifications, invoice receipts)
- Process payments via Stripe
- Match homeowner-submitted leads to contractors based on service area
- Detect and prevent fraud, abuse, and security threats
- Provide customer support
- Improve the Service (aggregate, non-identifying analytics)
- Comply with legal obligations
4. Who we share information with
Service providers (sub-processors)
We share data with vendors who help operate the Service. They are bound by confidentiality agreements and process data only on our instructions:
- Stripe — payment processing, billing
- Vercel — application hosting
- Neon Database — primary database
- Amazon Web Services (SES) — outbound transactional email
- Cloudflare R2 — file storage (photos, PDFs, documents)
- Google — Maps, Solar API, Calendar, Gmail (when you connect an account)
- Anthropic, Replicate — AI-assisted roof detection and document analysis
- Google Analytics — aggregated usage analytics
Contractors and customers
When you submit a homeowner lead through our public estimate page, the contractor who claims that lead receives your contact information so they can follow up. Contractors can see information you provided in the request form (name, email, phone, address, qualifying answers, appointment preferences).
Legal disclosures
We may disclose information when required by law, subpoena, or legal process; to protect our rights or the safety of users; or in connection with a sale, merger, or acquisition of our business (in which case we will notify you).
5. Your rights and choices
- Access and correction: you can view and edit your account information at any time in your profile settings.
- Deletion: you can request deletion of your account by contacting us at the email below. We will delete personal data within 30 days, except where retention is required by law (e.g., tax records).
- Email opt-out: you can unsubscribe from marketing emails using the link in any such email. Transactional emails (receipts, lead notifications) cannot be opted out of while you have an active account.
- OAuth revocation: you can disconnect Google or Microsoft integrations at any time from your profile settings, or revoke access directly in your Google / Microsoft account.
- Data export: contact us to request a copy of your data in a portable format.
California residents (CCPA / CPRA)
If you reside in California, you have additional rights: to know what personal information we collect, to delete it, to correct it, and to opt out of any sale or sharing of personal information. We do not sell personal information. To exercise any of these rights, email us at the address below.
Texas residents (Texas Data Privacy and Security Act)
If you reside in Texas, you have the right to confirm whether we process your personal data, access it, correct it, request deletion, and opt out of certain processing activities such as targeted advertising. To exercise these rights, email us at the address below.
6. Data security
We protect your data using industry-standard practices: TLS encryption in transit, encrypted database connections, hashed passwords, OAuth tokens stored encrypted at rest, restricted internal access, and security monitoring. No system is perfectly secure; if we become aware of a breach affecting your personal data, we will notify you in accordance with applicable law.
7. Data retention
We retain account and customer data for as long as your account is active. After cancellation, we retain data for up to 90 days for restoration purposes, then delete or anonymize it. Financial records (invoices, payment receipts) are retained for at least 7 years as required by tax law.
8. Children's privacy
The Service is intended for business use by adults. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided personal information to us, contact us and we will delete it promptly.
9. International users
The Service is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. and may be subject to U.S. legal process.
10. Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, remember your preferences, and measure usage. You can disable cookies in your browser settings, but parts of the Service may not function properly without them.
11. Third-party links
The Service may link to third-party websites or services. Their privacy practices are governed by their own policies, not this one.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by a prominent notice in the app at least 14 days before the changes take effect. The "Last updated" date at the top reflects the latest revision.
13. Contact us
Questions about this Privacy Policy or your data? Email us:
The Elite Company
Email: privacy@theelitecompany.com
State of organization: Texas, United States