1Introduction
This Privacy Policy explains how OneRoof Labs LLC, a Colorado limited liability company located at 655 S Sierra Madre Street, Colorado Springs, Colorado 80903 ("OneRoof," "we," "us," or "our"), collects, uses, discloses, and protects personal information in connection with the OneRoof CRM platform, including our websites, web and mobile applications, APIs, and related services (the "Services").
This Policy should be read together with our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service.
2Scope and Our Two Roles
OneRoof CRM is a business-to-business platform used by roofing and home-services contractors ("Customers"). We handle personal information in two distinct capacities:
2.1 As a business/controller. For personal information about our Customers, their Authorized Users, website visitors, and prospective customers (for example, account-registration data, billing data, usage data, and enquiries submitted through a form on our website, which are stored in our own CRM so we can respond), OneRoof acts as a "business" or "controller" and this Policy governs directly.
2.2 As a service provider/processor. For personal information that a Customer collects, uploads, or generates about its own leads, prospects, homeowners, applicants, property owners, and other individuals ("Consumers"), OneRoof acts as a "service provider" or "processor" that processes such information only on the Customer's behalf and instructions. The Customer — not OneRoof — is the "business"/"controller" of that data and is responsible for its own privacy notices, legal bases, and for honoring Consumer rights. Our processing of that data is governed by our Data Processing Addendum (DPA) and the Customer's instructions. If you are a Consumer and wish to exercise rights over your information, please contact the Customer (the contractor) that collected it; we will direct your request to them.
3Personal Information We Collect
Depending on how the Services are used, the following categories of personal information may be collected and processed:
3.1 Account and contact data — name, business name, email address, telephone number, mailing address, role, and login credentials of Customers and Authorized Users.
3.2 Consumer/lead data (processed on Customers' behalf) — names, telephone numbers, email addresses, physical and mailing addresses, and notes about Consumers; additional contacts and joint owners; dates of birth; employment, employer, job-title, and income information; prior-residence and landlord information; and damage/lead scoring.
3.3 Sensitive information — Social Security numbers; financial-account information (including bank-account links established through Plaid); consumer-screening, background, or income-verification information; and precise geolocation (see 3.7). We apply field-level encryption to certain sensitive fields as described in Section 8.
3.4 Communications content — call metadata and, where enabled by the Customer, call recordings; text messages (SMS/MMS) sent or received through the Services, together with the consent records and opt-out status for the numbers involved; emails sent through the Services and, where a Customer connects a Google account, incoming email content read via the Gmail API; internal notes and team messages; and proposals, contracts, and related documents. (Note: SMS/text messaging is not currently an active feature.)
3.5 Files and media — photographs (including job-site, property, and damage photos), receipts, uploaded documents (such as insurance certificates, tax forms, licenses, permits), roof-measurement reports, and electronic signatures (captured as images).
3.6 Third-party-sourced and public-record data — property and property-owner information obtained through prospecting and skip-tracing providers and public records, including owner names, telephone numbers, email addresses, approximate ages, property characteristics, valuation, equity, and mortgage information. Individuals in this category generally have no prior relationship with the Customer, and the data may be inaccurate or out of date. This data is not a "consumer report" and is not provided by a "consumer reporting agency" under the federal Fair Credit Reporting Act (FCRA); neither OneRoof nor its Customers may use it to determine eligibility for credit, insurance, employment, housing, or any other FCRA "permissible purpose."
3.7 Location data — for field canvassing features, the approximate or precise geolocation of Authorized Users' devices (e.g., real-time location during door-knocking) and the locations of properties and canvassing zones.
3.8 Payment data — billing contact information and limited payment-method metadata. Full payment-card numbers are collected and processed directly by our payment processor (Stripe); we do not store full card numbers.
3.9 Device, usage, and log data — IP address, device and browser information, app version, access tokens, audit-log events (such as logins, authorization decisions, and access to certain sensitive records), and operational logs generated by our infrastructure.
4Sources of Personal Information
We obtain personal information from: (a) Customers and Authorized Users who enter or upload it; (b) Consumers who provide it to a Customer (e.g., during a sales or canvassing interaction or electronic-signature flow); (c) third-party data and skip-tracing providers and public records; (d) connected third-party integrations the Customer authorizes (such as Google/Gmail/Calendar, telephony, measurement, and supplier providers); and (e) automatically from devices and our systems through use of the Services.
5How We Use Personal Information
As a service provider/processor, we use Consumer data only to provide the Services on the Customer's behalf and on its instructions. For data for which we are a business/controller, and to operate the Services generally, we use personal information to:
- provide, maintain, secure, and support the Services and authenticate users;
- process transactions, billing, credits, and usage-based charges;
- enable features the Customer uses, including telephony/dialer, email, calendar sync, proposals and e-signature, prospecting, measurement ordering, and material catalog/ordering;
- provide AI-assisted features (such as document review and data extraction, proposal generation, and an in-app assistant) as described in Section 9;
- communicate with Customers about the Services, including service, security, and administrative messages;
- monitor, detect, prevent, and address fraud, abuse, security incidents, and technical issues, and enforce our Terms;
- maintain audit and business records and comply with legal obligations; and
- develop and improve our products using aggregated, de-identified, or anonymized data that does not identify any individual.
We do not sell personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under applicable U.S. state privacy laws, and we have not done so in the preceding twelve (12) months. We do disclose personal information to service providers for the business purposes described in Section 6. Where a Customer uses the prospecting/skip-tracing features, the platform obtains property-owner information from third-party data providers and makes it available to that Customer for the Customer's own lawful business use; we do not use that data to serve advertising or for any purpose other than providing the feature.
5.1 Sensitive personal information. We use and disclose Social Security numbers, financial-account information, precise geolocation, and other "sensitive personal information" (as defined under the CPRA and comparable laws) only for the purposes permitted under those laws — namely, to perform the Services requested, to provide the features the Customer uses, to ensure security and integrity, and as otherwise permitted by law. We do not use sensitive personal information to infer characteristics about a consumer.
6How We Disclose Personal Information
6.1 Service providers / sub-processors. We disclose personal information to vendors that process it on our behalf to deliver the Services, under contractual confidentiality and data-protection obligations. These include, by function:
- Cloud infrastructure, storage, and compute — Cloudflare (including object storage, edge compute, and image processing) and Amazon Web Services (managed database hosting);
- Telephony and call recording — Telnyx;
- AI/LLM processing — Anthropic (Claude) and Google (Gemini);
- Email and calendar — Google (Gmail and Google Calendar), and a transactional email provider (Twilio Inc. / SendGrid);
- Mapping and geocoding — Google Maps;
- Property/owner data and skip-tracing — our property & owner data provider (and similar data providers);
- Roof measurement — EagleView (and other measurement providers);
- Building-materials catalog and ordering — ABC Supply;
- Document rendering and electronic signature — our DocumentAI service;
- Payments and billing — Stripe (including Stripe Billing); billing and onboarding are coordinated through an OneRoof-operated billing portal service;
- Financial-account linking (where enabled) — Plaid.
A current list of sub-processors is maintained in our Data Processing Addendum and/or at onerooflabs.com/subprocessors.
6.2 At the Customer's direction. We disclose Consumer data to third parties when the Customer enables an integration or instructs us to do so.
6.3 Legal and safety. We may disclose personal information when we believe in good faith it is necessary to comply with law, legal process, or governmental requests; to enforce our Terms; or to protect the rights, property, or safety of OneRoof, our Customers, Consumers, or others.
6.4 Business transfers. In connection with a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as a business asset, subject to this Policy.
6.5 Aggregated/de-identified data. We may disclose aggregated or de-identified information that cannot reasonably identify an individual.
We do not disclose personal information to third parties for their own independent marketing.
7Data Retention
We retain each category of personal information for as long as needed to provide the Services and to fulfill the purposes described in this Policy, after which we delete, de-identify, or anonymize it, unless a longer period is required or permitted by law. We determine retention periods based on the nature and sensitivity of the data, the purpose for which it is processed, the duration of the Customer's account, and applicable legal, accounting, security, and audit obligations. Specific practices include:
| Category | Retention |
|---|---|
| Account, contact, and Customer/Consumer records | For the duration of the Customer's account; deleted or returned following termination per the Terms and DPA, except as required or permitted by law |
| Stored email message bodies and attachments (Gmail integration) | Purged after a defined window (by default, 90 days); limited metadata (subject, snippet, message identifiers) may be retained longer |
| Sensitive information (SSN, financial-account, screening, precise geolocation) | Retained only as long as needed for the Customer's stated purpose and applicable law; deleted/returned on account termination |
| Call recordings (where enabled) | Retained per the Customer's configuration and stored with the associated call record until deleted |
| Audit logs and billing/usage records (including prospecting/credit activity) | Retained indefinitely as needed for security, accounting, fraud-prevention, and legal-compliance purposes; these may persist after related data is deleted |
| Backups | Retained for a limited period and overwritten in the ordinary course |
Disconnecting a Google account or using available self-service deletion tools removes associated stored Google data as described in Section 9.
8Security
We maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect personal information, including: encryption in transit (TLS); field-level encryption at rest (AES-256-GCM) for certain sensitive fields, including Social Security numbers, stored email content, and stored third-party OAuth refresh tokens; salted, iterated password hashing; role-based access control and least-privilege access; logical multi-tenant isolation enforced at the database layer; refresh-token rotation and reuse detection; rate limiting and security headers; and audit logging of sensitive operations. No security measure is perfect or impenetrable, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and for configuring available security features appropriately.
8.1 Financial data. Where the Services process consumer financial information (such as income, screening, financing, or Plaid-linked bank-account data), we handle it consistent with applicable law, including the Gramm-Leach-Bliley Act and the FTC Safeguards Rule to the extent applicable. Bank-account connections established through Plaid are handled in accordance with Plaid's own privacy practices, and we do not receive or store users' online-banking credentials.
9AI Features and Google API Services
Google API Services · Limited Use
9.1 AI features. Certain features use artificial-intelligence and machine-learning models, including third-party models provided by Anthropic and Google, to review and extract data from documents and images, analyze calls, generate and edit proposals, and provide an in-app assistant. Content submitted to these features may be transmitted to and processed by those providers solely to provide the feature. To the extent provided in our agreements with these providers, content submitted through these features is not used to train their general-purpose models. Data obtained from Google APIs under restricted scopes (including Gmail gmail.readonly data) is never used to train or improve any artificial-intelligence or machine-learning model, and is processed by AI features only to the limited extent necessary to provide the prominent, user-facing feature the user has requested. AI outputs are probabilistic, may be inaccurate, and should be independently verified.
9.2 Google API Services — Limited Use. OneRoof CRM's use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, when a Customer connects a Google account (including the gmail.readonly, Gmail send, and Google Calendar scopes), OneRoof:
- (a) only uses access to Google user data to provide or improve user-facing features that are prominent in the requesting application's interface (such as logging incoming emails to the matching contact, sending email on the user's behalf, and synchronizing appointments with Google Calendar);
- (b) does not use Google user data for serving advertisements;
- (c) does not transfer or sell Google user data to third parties for advertising, market-research, or other unrelated purposes, and only transfers it as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with user notice; and
- (d) does not allow humans to read Google user data unless (i) we first obtain the user's affirmative agreement for specific messages, (ii) it is necessary for security purposes or to comply with applicable law, or (iii) the data is aggregated and anonymized for internal operations in accordance with applicable privacy and other laws.
For clarity, Google user data obtained under restricted scopes is not used for serving advertising, is not sold, is not used to train or improve generalized or third-party artificial-intelligence/machine-learning models, and is not used for the "develop and improve our products" purpose described in Section 5; any AI processing of Gmail content is performed by service providers acting under our instructions solely to deliver the user-facing feature.
A user may disconnect a connected Google account at any time in the Services' settings, which revokes our access and triggers deletion of associated stored Google data, and may also use the in-product self-service deletion option for Google-sourced data.
9AMicrosoft Identity & Sign-In
Microsoft Identity · Sign-In Only
9A.1 Purpose. OneRoof uses Microsoft's identity platform (Azure Active Directory / Microsoft Entra ID) solely to authenticate users who choose "Sign in with Microsoft." We do not use Microsoft's identity platform for any purpose other than sign-in and account provisioning.
9A.2 Scopes and data received. The scopes we request are minimal — OpenID Connect sign-in (openid, email, profile) — used to read basic profile information (your name, email address, and a tenant/user identifier) for account creation and login only. We do not request access to your mailbox, files, directory, or other Microsoft 365 resources for the sign-in feature.
9A.3 How the data is used. Microsoft account data is used only to authenticate you and provision or match your OneRoof account. It is not sold, is not shared for advertising, and is not used to train or improve any artificial-intelligence or machine-learning model.
9A.4 Revoking access; governing terms. You may revoke OneRoof's access at any time through your Microsoft account permissions (for example, at your Microsoft account's "Apps and services that can access your data" settings, or via your organization's Microsoft Entra admin). OneRoof adheres to the Microsoft APIs Terms of Use and applicable Microsoft Platform policies. As required by Microsoft, our publicly posted Terms of Service and this Privacy Policy govern the "Sign in with Microsoft" experience.
10Cookies and Similar Technologies
The Services use strictly necessary browser storage technologies — including browser localStorage (for example, to hold authentication tokens) and session storage — to authenticate users, maintain sessions, and remember preferences. We do not currently use third-party advertising or cross-site tracking technologies in the application. Some third-party services and embedded components may set their own cookies or storage subject to their privacy policies. You can clear local browser storage and control cookies through your browser settings, though doing so may affect functionality (for example, logging you out).
11Your Privacy Rights
11.1 Consumers. If your personal information is in the Services because a Customer (a contractor) collected it, that Customer controls the data. Please direct requests to access, correct, delete, or opt out to that Customer. We will assist our Customers in responding to such requests as required by the DPA and applicable law.
11.2 Customers and Authorized Users. Subject to applicable law and verification, you may request to access, correct, update, port, or delete personal information for which we are the controller, and may object to or restrict certain processing. To make a request, contact us at compliance@onerooflabs.com.
11.3 State privacy rights. Depending on your state of residence (including under the Colorado Privacy Act (CPA), the California Consumer Privacy Act as amended by the CPRA, and comparable laws in Virginia, Connecticut, Utah, and other states), you may have rights to: confirm whether we process your personal information; access, correct, or delete it; obtain a portable copy; opt out of the sale or sharing of personal information, of targeted advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects; and limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising or targeted advertising, and we do not use personal information for profiling that produces legal or similarly significant effects without a lawful basis.
11.4 Right to limit sensitive personal information. As described in Section 5.1, we use sensitive personal information only for purposes permitted by law and do not use it to infer characteristics about a consumer. Because we do not use or disclose sensitive personal information beyond those permitted purposes, we are not required to offer, and do not currently offer, a separate "Limit the Use of My Sensitive Personal Information" mechanism. If this changes, we will update this Policy and provide the required choice.
11.5 Universal opt-out / Global Privacy Control. Where required by the Colorado Privacy Act and other applicable laws, we will treat a recognized universal opt-out mechanism (such as the Global Privacy Control) as a valid request to opt out of any sale, sharing, or targeted advertising. Because we do not engage in such activities, such signals do not change our processing, but we will honor them as applicable.
11.6 How to exercise rights; verification; timelines; appeals. To exercise rights for personal information for which we are the controller, contact compliance@onerooflabs.com or submit a request through our online request form at onerooflabs.com/privacy-request. We will verify your identity by matching information you provide against information in our records (and may request additional information for sensitive requests); we will not use verification information for any other purpose. You may use an authorized agent, in which case we may require proof of the agent's authorization and verification of your identity. We will respond within the time required by applicable law (generally 45 days, extendable by an additional 45 days where permitted, with notice). If we deny your request, you may appeal by replying to our decision or emailing compliance@onerooflabs.com with the subject "Privacy Appeal"; we will respond to appeals within the period required by applicable law (under the CPA, 45 days, extendable by 60 days), and if we deny the appeal we will inform you how to contact your state Attorney General. We will not discriminate against you for exercising your rights.
11.7 Consumers. If your personal information is in the Services because a Customer collected it, please direct your request to that Customer; see Section 11.1.
11.8 California "Shine the Light." We do not disclose personal information to third parties for their own direct-marketing purposes.
12Children's Privacy
The Services are intended for business use by adults and are not directed to children under 18. We do not knowingly collect personal information from children, and we do not knowingly sell or share the personal information of consumers under 16 years of age. If you believe a child's information has been provided to us, contact compliance@onerooflabs.com and we will take appropriate steps to delete it.
13Call Recording Notice
Where a Customer enables call recording, calls placed or received through the Services may be recorded, and call audio and related content may be processed by our telephony provider (Telnyx) and, where the Customer enables AI call features, by AI providers to generate transcription or analysis solely to provide that feature. Customers are responsible for providing any legally required notices and obtaining any legally required consents from call participants, including in two-party/all-party consent jurisdictions. If you are a call participant and have questions about a recorded call, contact the Customer that placed or received the call.
13AText Messaging (SMS/MMS) & Mobile Opt-In
13A.1 When we text you. If you give consent — for example by checking a consent box on our website form or in the Services — we may send you text messages at the mobile number you provide. Consent is collected separately for marketing messages and for transactional messages (account notifications and two-factor authentication codes), and neither consent is a condition of purchase or of submitting any form.
13A.2 Frequency, rates, and opt-out. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP to any message, or get help by replying HELP. We honor opt-outs promptly and record them against your contact record. Opting out of marketing messages does not stop transactional messages you have separately consented to receive, such as security codes.
13A.3 We do not share or sell mobile opt-in data. Mobile phone numbers and SMS consent records collected for messaging are never shared or sold to third parties for their own marketing purposes. They are disclosed only to the messaging and telephony providers that deliver the messages on our behalf (see Section 6), and to authorities where legally required.
13A.4 Messages our Customers send. Where a Customer uses the Services to text its own leads or homeowners, the Customer is the sender and is responsible for obtaining consent, honoring opt-outs, and complying with the Telephone Consumer Protection Act and carrier requirements. If you received a text from a contractor using OneRoof, reply STOP to opt out and contact that contractor with any questions.
14International Users
The Services are operated from, and intended for use within, the United States. If you access the Services from outside the United States, you understand that your information will be processed in the United States, which may have different data-protection laws than your jurisdiction.
15Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will revise the "Last Updated" date and provide additional notice as required by law (such as in-product or email notice). Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
15.1 Accessibility. We are committed to making this Policy accessible. If you have a disability and need this Policy provided in an alternative accessible format, contact compliance@onerooflabs.com and we will work to accommodate your request.
16Contact Us
OneRoof Labs LLC
Attn: Privacy / Compliance
655 S Sierra Madre Street, Colorado Springs, Colorado 80903
Email: compliance@onerooflabs.com
Terms of Service: onerooflabs.com/terms
Sub-processor list: onerooflabs.com/subprocessors