Effective Date: August 13, 2026 · Version: 1
This Privacy Policy explains how RoofQuery LLC, an Oregon limited liability company, doing business as RoofQuery ("RoofQuery," "we," "us," or "our"), handles information in connection with the RoofQuery services described in our Terms of Service.
RoofQuery is a business-to-business service. Our customers are contractors, roofers, estimators, software providers, and other business users. We are not designed for, marketed to, or intended for personal or household use.
1. Two Different Roles
It matters which of these two roles we are in, because they carry different responsibilities.
We control our own account data. Information about the customers who hold RoofQuery accounts — the person who signed up, their email, their company, their billing, how they use the service — is information we decide the purposes for and hold in our own right.
We process property data on our customers' instructions. When a customer submits an address to order a report, we look up and measure the property they asked us to. We do not decide which properties are submitted, why they are submitted, or who is entitled to the results. That is the customer's decision, under Section 3 of the Terms of Service, and the customer is responsible for having a lawful purpose and any permission required.
If you are a property owner or occupant and want to know why a report about your property exists, contact the company that supplied the report to you. We usually cannot tell you, because we do not hold the reason.
2. Information We Collect
2.1 Account information
- Name, business name, and email address given at signup.
- Authentication credentials. We run our own authentication — there is no third-party sign-in provider, and signing in to RoofQuery does not create an account with anyone else. Passwords are stored only as salted hashes on our own infrastructure; we never see, store, or transmit a plaintext password, and we cannot recover one for you.
- Company branding you upload for reports — logo, company name, address, public phone and email.
2.2 Order and property information
- The address, coordinates, and map selection you submit.
- The report type, scope, notes, and any client details you attach to an order.
- Measurements, geometry, diagrams, and other output produced for that order.
- Aerial and satellite imagery of the property, obtained from third-party imagery providers.
Property information can include personal information. An address is often a home. If you attach a property owner's name, phone number, or email to an order, that is personal information you have chosen to send us, and you are responsible for being entitled to do so.
2.3 Billing information
- Credit balance, transactions, holds, refunds, and invoice records.
- We do not store card numbers. Payment card details are entered directly with our payment processor, Stripe, and we receive only a token, the last four digits, the card brand, and the result.
2.4 Technical and log information
- IP address, browser user agent, request paths, timestamps, and response codes.
- API key usage — which key made which request, and when. We never store the plaintext of an API key, only a hash of it.
- Webhook deliveries we send you, including the payload and your endpoint's response.
- Callbacks and responses exchanged with our measurement provider.
2.5 Agreement acceptance records
When you accept our Terms of Service or another agreement, we record the acceptance: the email address and user identifier of the signed-in person who accepted, the account, the date and time from our servers, the IP address, the browser user agent, the version and a cryptographic hash of the exact document shown, the wording of the checkbox, and whether the document was scrolled through. We keep a generated copy of the document as accepted.
We keep these records because they are the evidence of the agreement between us. See Section 8.
2.6 Support communications
Emails and messages you send us, and our replies.
3. Why We Use It
We use the information described above for the following purposes, and no others:
- Providing the service — producing reports, delivering them, and generating branded PDFs and diagrams.
- Accounts and access — signing you in, issuing and validating API keys, and scoping data to your account.
- Billing — charging credits, auto-recharge, refunds, invoices, and responding to chargebacks.
- Support and diagnostics — investigating a failed order, a missed webhook, or a disputed measurement.
- Security and abuse prevention — detecting unauthorized access, fraud, scraping, and misuse.
- Legal and compliance — meeting our obligations, responding to lawful requests, and establishing or defending legal claims.
- Service communications — order status, delivery notifications, billing notices, and changes to our agreements.
- Improving our service and models — training, testing, and benchmarking the measurement models and algorithms that produce reports. See Section 4.
- Marketing our own service — reaching businesses like yours with advertising for RoofQuery. See Section 5.
We do not sell your information. We do not sell personal information to anyone, and we do not provide your order data, client details, or property data to advertising platforms.
4. Improving Our Service and Models
This is the use described in Section 7 of the Terms of Service, and it is worth being specific about.
What we use. The addresses and coordinates ordered, the imagery and property data obtained for them, the measurements and other output produced, revision requests and the corrections that followed, and feedback you send us. In short: what was ordered, what we produced, and where we got it wrong.
Why. Corrections are the most useful signal we have. When a measurement comes back wrong and a revision fixes it, that pair teaches the system more than a thousand orders that went fine — so revision data in particular is used to improve accuracy over time.
What this does not include. We do not use your logo, branding, or trade dress for this. We do not publish or disclose your data in any form that identifies you or an individual client of yours, other than in aggregated or de-identified form. We do not disclose your client lists or your pricing to anyone.
This use continues after an account closes, and data may be retained for it. A model cannot be un-taught something by deleting the row it learned from, and we would rather say so than imply a deletion that does not happen.
5. Advertising
We advertise RoofQuery to businesses, and we use third-party advertising platforms to do it.
For that purpose we may provide an advertising platform with hashed identifiers — typically an email address put through a one-way hash before it leaves our systems — so the platform can tell whether an existing customer is already in its audience, and so we can reach businesses that look similar. The platform does not receive your address list, your orders, your property data, your client details, or anything about the reports you have run.
One thing to be clear about, because "hashed" is often used to imply more than it delivers: a hashed email is still personal information. Hashing makes it unreadable, not anonymous — the platform matches it against a hash of an address it already holds. We treat it as personal information, and this Policy covers it accordingly.
Advertising audiences are part of how we operate the business, and inclusion is not something Customer can switch off. This does not affect the service communications described in Section 3, and any marketing email we send carries an unsubscribe link as described in Section 10.
6. Who We Share It With
We share information only as needed to run the service:
- Measurement and imagery providers, who receive the property address, coordinates, and any photographs or files you supply with an order, to the extent needed to produce or source the measurements and imagery for that order. This is how a report gets made; an order cannot be fulfilled without it.
- Stripe, our payment processor, for payments, invoices, and credit balances.
- Our hosting and database provider, which stores the data described here.
- Cloudflare, whose bot-check runs on our sign-in and sign-up forms.
- Advertising platforms, which receive hashed identifiers only, as described in Section 5. They do not receive your orders, property data, or client details.
- Professional advisers — lawyers, accountants, auditors — where needed.
- A successor, in a merger, acquisition, financing, or sale of assets.
- Authorities or other parties, where we reasonably believe disclosure is required by law, or necessary to establish or defend a legal claim, prevent fraud, or protect someone's safety.
We do not share your data with your competitors, and we do not provide other customers with access to your orders, reports, or account.
7. Where Data Is Held
Our systems are hosted in the United States. If you access RoofQuery from elsewhere, your information is transferred to and processed in the United States, which may have different data-protection laws than your country.
8. How Long We Keep It
Reports are not retained as a service. As set out in Section 11 of the Terms of Service, RoofQuery makes no commitment to retain any report, and may delete one at any time. Delivery happens at completion, over the API and your webhook, and keeping your own copy is your responsibility. Any copy that remains available in the dashboard is a convenience, not an archive.
Other categories:
- Account records — kept while the account is open, and afterwards as needed for tax, accounting, and legal purposes.
- Billing records — kept as long as required by law and for the period in which a payment can be disputed.
- Acceptance records — kept indefinitely. An agreement can be disputed long after it ends, and a record of it that has been deleted proves nothing.
- Technical logs, webhook deliveries, and provider exchanges — kept for diagnostics and dispute resolution. These are not currently pruned on a fixed schedule; we may introduce one.
- Support communications — kept for as long as needed to handle the matter and any follow-up.
9. Security
- All traffic is encrypted in transit.
- API keys are stored only as hashes; the plaintext is shown once, at creation, and never again. If you lose a key, you generate a new one — we cannot recover it.
- Authentication runs on our own infrastructure. Passwords are stored only as salted hashes and never in a readable form.
- Card details never reach our servers.
- Uploaded logos and generated agreement copies are held in storage that grants no public read access; every read passes back through a server that checks who is asking.
- Access to production data is limited to staff who need it.
No system is perfectly secure. If you believe your credentials have been exposed, revoke the affected API key in the dashboard and contact us immediately at [email protected].
10. Your Choices and Rights
Access, correction, and export. You can see and edit your account information, branding, API keys, and order history in the dashboard. For anything you cannot reach there, contact us.
Deletion. You may ask us to close your account and delete your data. We will do so, except where we must keep something — billing records, acceptance records, and anything needed to establish or defend a legal claim. We will tell you what we are keeping and why.
Marketing email. We send service and transactional messages, which are part of running your account and cannot be switched off while it is open. Any marketing email we send carries an unsubscribe link, and unsubscribing stops marketing email without affecting your account. Advertising audiences are described in Section 5.
Regional rights. Depending on where you are, you may have additional rights — to access, correct, delete, restrict or object to processing, to portability, or to withdraw consent. You may also have the right to complain to your data-protection authority. We do not discriminate against anyone for exercising a privacy right.
To exercise any of these, email [email protected] from the address on your account. We may need to verify who you are before acting, particularly for deletion.
If you are a property owner or occupant asking about a report on your property, please read Section 1 first: contact the company that gave you the report. Where we can identify what you are asking about, we will help; often we cannot, because we hold the property data on a customer's instructions and not our own.
11. Cookies
We use a small number of strictly necessary cookies. We do not run advertising or cross-site tracking cookies on the dashboard, and we run no third-party analytics there. Our public marketing pages may carry advertising or measurement tags for the purposes described in Section 5.
- A session cookie on the dashboard, which keeps you signed in. Removing it signs you out.
- A separate session cookie on our staff console.
- Cloudflare's bot-check sets its own cookie on the sign-in and sign-up forms to distinguish people from automated traffic.
12. Children
The service is for business use and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
13. Changes
We may update this Policy. The current version and its effective date are always published at https://roofquery.com/privacy, and every published version is kept with its own version number and effective date.
For a material change we will give notice by email or in the dashboard before it takes effect. Continuing to use the service after that means the updated Policy applies.
14. Contact
Privacy questions, requests, and complaints: [email protected]
RoofQuery LLC 29265 Hale Rd, Scappoose, OR 97056