Privacy Policy
Last updated: April 28, 2026
1. Who We Are
RoofRecon Pro ("RoofRecon," "we," "our," or "us") is a software-as-a-service platform operated by Veteran Masonry Inc. and its affiliated entities. Our platform provides satellite-derived roof measurement, insurance claim documentation, and storm correlation services to licensed roofing contractors and related professionals.
This Privacy Policy describes how we collect, use, disclose, and protect information about you when you use our website, platform, and related services (collectively, the "Services").
2. Information We Collect
2.1 Information You Provide Directly
- Account registration data: name, email address, company name, phone number, license number
- Property addresses submitted for report generation
- Damage photographs and associated metadata (including GPS coordinates extracted from EXIF data)
- Insurance claim information: carrier name, claim number, adjuster contact details
- Electronic signatures and associated signer information
- Payment information (processed by Stripe; we do not store card numbers)
2.2 Information Collected Automatically
- IP address and approximate geographic location
- Browser type, operating system, and device identifiers
- Pages visited, features used, and session duration
- API request logs (endpoint, timestamp, response status)
2.3 Information from Third Parties
- Satellite imagery and roof geometry data from Google Solar API
- Historical weather and storm event data from NOAA and Open-Meteo
- Authentication data from Supabase (OAuth provider)
3. How We Use Your Information
- To generate, store, and deliver roof measurement reports
- To process insurance claim documentation and facilitate adjuster communication
- To send transactional emails (report completion, claim status updates, weekly digests)
- To process payments and manage subscription billing
- To detect and prevent fraud, abuse, and security incidents
- To improve platform accuracy, performance, and feature quality
- To comply with applicable legal obligations
We do not sell your personal information to third parties. We do not use your data to train AI models without explicit consent.
4. Data Sharing and Disclosure
We share your information only in the following circumstances:
- Service providers: Stripe (payments), Postmark (email delivery), Supabase (authentication), AWS S3 (file storage), Google (mapping and satellite data)
- Adjuster portal: When you generate a share link, the recipient can access the report data you have authorized for sharing
- Homeowner portal: When you generate a homeowner portal link, the linked homeowner can access the data fields you have enabled
- Legal requirements: When required by law, court order, or to protect the rights, property, or safety of RoofRecon, our users, or the public
5. Data Retention
We retain your account data for as long as your account is active. Reports and associated photographs are retained for a minimum of 7 years to support insurance claim documentation requirements. Deleted reports are soft-deleted (marked with a deletion timestamp) and permanently purged after 30 days. Electronic signatures are retained for 10 years.
You may request deletion of your account and associated data by contacting us at [email protected]. Certain data may be retained longer where required by law or for legitimate business purposes (e.g., fraud prevention, dispute resolution).
6. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Portability: Export your report data in machine-readable format (CSV/ZIP)
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated data
- Objection: Object to processing of your data for certain purposes
- Restriction: Request restriction of processing in certain circumstances
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
7. Security
We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest for sensitive data, HTTP security headers (HSTS, X-Frame-Options, X-Content-Type-Options), rate limiting on authentication endpoints, and access controls limiting data access to authorized personnel. No security measure is perfect; we encourage you to use strong, unique passwords and to notify us immediately of any suspected unauthorized access.
8. Cookies and Tracking
We use session cookies for authentication. We do not use third-party advertising cookies. Analytics data (page views, feature usage) is collected via self-hosted analytics and is not shared with advertising networks. You may disable cookies in your browser settings, but this will prevent you from logging in.
9. Children's Privacy
Our Services are intended for licensed roofing contractors and business professionals. We do not knowingly collect personal information from individuals under the age of 18.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email at least 14 days before the changes take effect. Continued use of the Services after the effective date constitutes acceptance of the updated policy.
11. Contact
For privacy-related inquiries, data subject requests, or to report a security concern:
Email: [email protected]
Mailing address: Veteran Masonry Inc., Cleveland, Ohio