RoofLog — Privacy Policy
Draft — subject to revision following legal review.
RoofLog Privacy Policy
Effective: 2026-08-16
Gieson Co, a Florida corporation ("we", "us"), operates RoofLog, a rooftop asset inventory service for commercial property management companies and their contractors, available at https://therooflog.com (the "Service").
This policy explains what information we collect, why, who we share it with, and what choices you have. It applies to the Service, to our mobile applications for iOS and Android, and to our website.
RoofLog is a business-to-business product. It is designed to hold records about buildings and equipment, not information about consumers or households.
1. Our two roles
Which parts of this policy apply depends on what kind of information is involved.
We are a service provider (processor) for Workspace content. When a property management company subscribes to RoofLog, it creates a Workspace containing its buildings, roofs, equipment records, photographs, and service history. We host and process that content on that company's instructions and on its behalf. That company decides what goes in, who may see it, and how long it stays. If you are an employee or contractor and want content in a Workspace corrected or removed, contact the company that controls it — we will refer your request to them.
We are a controller for account and website information. Information we need to run the business — your account registration details, authentication records, support correspondence, billing contacts, and server logs — is handled by us for our own purposes, as described below.
2. Information you give us
Account information. Name, business email address, and password when you register. Passwords are stored only as a cryptographic hash; we never see or store your password in readable form.
Third-party sign-in. You may sign in with a Google, Microsoft, or Apple account instead of a password. If you do, we receive your name and email address from that provider to create and identify your account. We do not receive your password, and we do not gain access to your email, files, calendar, or contacts. Your use of the sign-in provider is governed by that provider's own privacy policy. If you sign in with Apple and choose to hide your email address, we receive only Apple's relay address.
Workspace and role information. The organization you belong to, your role (administrator, member, contractor, or billing manager), your access level, and which Workspaces you have been granted access to.
Contractor profile information. If you are a contractor, the company you work for and the contact details you choose to record on your profile, so the customers who grant you access know who you are.
Billing contact information. Name, email, billing address, and purchase order details where applicable. We do not currently collect or process payment card numbers. If card payments are added, they will be handled by a third-party payment processor and this policy will be updated before that happens.
Support communications. Anything you send us by email or through the Service, including the content of your message.
Training progress. Which training modules you have completed, and whether you prefer video or written format, recorded against your account so the Training tab can show your progress.
3. Information in Workspaces
Workspace content is normally about property and equipment rather than people, but some of it can relate to individuals:
- Building and roof information — addresses, geographic coordinates, roof sections, roof membrane type, install year and warranty, and tenant bay outlines with their suite labels.
- Equipment and component records — asset type, location, make, model, serial number, capacity, year, condition rating, bay or suite served, attachment fixture, and warranty, maintenance, and drain-service dates.
- Service history — notes on work performed, dates, cost where recorded, and the account of the person who recorded it.
- Photographs uploaded by users and contractors. Photographs are taken on active job sites and may incidentally capture people, vehicles, license plates, or nearby property. Photographs taken through the Service, or carrying the metadata already, are stored with the GPS position and time they were captured, which is used to place and verify equipment locations.
- Voice notes — audio recordings made by users, and the written transcripts produced from them (see Section 5).
- Typed notes entered against a unit or roof.
- Record attribution — which account created or last modified a record, proposed a change, or approved one, and when. Workspace administrators can see this.
The Terms of Service ask customers not to upload photographs of identifiable individuals or personal information unrelated to equipment documentation, and not to submit sensitive personal information. The Service is not designed for it.
4. Information collected automatically
Server logs. Our hosting provider records standard request information — IP address, browser and device type, pages requested, referring page, and timestamps — for security, abuse prevention, and troubleshooting.
Cookies. We use cookies only where they are strictly necessary for the Service to function:
| Cookie | Purpose | Duration | |---|---|---| | Authentication session | Keeps you signed in and secures your session | Session / until sign-out | | Active workspace | Remembers which Workspace you were last working in | Up to 12 months |
We do not use analytics, advertising, marketing, profiling, session-replay, or third-party tracking cookies. We do not use pixels or web beacons. We do not track you across other websites, and we do not respond to Do Not Track signals because we do not perform the tracking those signals are meant to limit.
Our mobile applications contain no advertising identifier, no analytics software development kit, and no third-party tracking. They request camera, photo library, microphone, and location permissions only for the features described in Section 3, and only when you use them. Location is never collected in the background.
Email delivery information. Our email provider records whether a message was delivered, bounced, or failed, so we can tell whether notifications are reaching you.
5. AI-assisted features
Three features in the Service use artificial intelligence, each provided by a third party listed in Section 7. This section describes exactly what leaves the Service, and when.
5.1 Voice-note transcription. When you record a voice note, the audio is sent to our transcription provider and the resulting text is written into the notes ledger for that unit or roof. Both the audio and the transcript are stored in your Workspace.
5.2 Equipment nameplate reading. When you ask the Service to read an equipment data plate, that photograph is sent to our AI provider, which proposes manufacturer, model, serial number, and capacity values. Proposals go to your Workspace's approval queue and never change a record on their own.
5.3 Support assistant. The in-app chat assistant answers questions from our published product documentation. By default it has no access to Workspace content at all. It can look up information from your own Workspace only where two separate permissions are both in force:
- an administrator of that Workspace has enabled support-assistant data access in Workspace settings, and
- you have enabled it for that specific conversation.
When enabled, access is read-only, limited to that one Workspace, and never extends to any other organization's data. The assistant cannot change, create, or delete anything. Conversations are not stored on our servers — closing the browser tab clears them.
5.4 No training on your information. We use our AI providers under commercial terms that do not permit them to use content submitted through the Service to train or improve their models, and we do not use Workspace content or account information to train machine learning models ourselves.
5.5 Output is not verified. Transcripts, nameplate readings, and assistant answers are generated automatically and may be inaccurate or incomplete. They are proposals and convenience aids, not verified information.
5.6 Turning them off. A customer may ask us to disable any or all AI-assisted features for its Workspaces, at no change to what it pays.
6. How we use information
We use information to:
- provide, operate, and secure the Service, and to authenticate you;
- send transactional and service messages — Workspace invitations, password resets, maintenance, drain-service, and warranty notifications, and notices about the Service or these policies;
- respond to support requests;
- bill for subscriptions and collect payment;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- diagnose problems and improve reliability and functionality; and
- comply with law and enforce our Terms.
We do not sell personal information. We do not share personal information for targeted or cross-context behavioral advertising. We do not use Workspace content to train machine learning models.
We may produce aggregated, de-identified statistics about how the Service is used — for example, average equipment age across the platform. As described in the Terms of Service, such statistics never identify a customer, a user, a building, an address, or an individual equipment record.
7. Who we share information with
Service providers. We use the following, and only for the purposes shown:
| Subprocessor | Purpose | Location | |---|---|---| | Vercel Inc. | Application hosting, server logs | United States | | Supabase Inc. | Database, authentication, file and photo storage | United States (us-east-1) | | Google LLC — Maps Platform | Maps, satellite imagery, geocoding | United States | | OpenAI, L.L.C. | Voice-note transcription; nameplate reading | United States | | Anthropic PBC | In-app support assistant | United States | | Resend | Transactional and notification email | United States | | GoDaddy | Domain registration and DNS | United States | | Apple (iCloud) | Our own company email only | United States |
Each is bound to use information only to provide services to us. Where you sign in with Google, Microsoft, or Apple, that provider also processes your sign-in under its own policy.
Within your Workspace. Content you add to a Workspace is visible to others with access to it — including your organization's administrators and any contractors your organization has granted access. Administrators can see who created and changed records.
Never between Workspaces. Separation between organizations is enforced in the database itself. A contractor who works for several of our customers uses one account, but can never see, query, or export one customer's data while working in another's Workspace.
Google Maps. Map and satellite features load directly from Google in your browser. Google may collect information about that interaction under its own Privacy Policy and the Google Maps/Google Earth Additional Terms. This happens between your browser and Google and is not controlled by us.
Legal and safety. We may disclose information where required by law, valid legal process, or to protect the rights, safety, or property of any person. Where we are legally permitted to do so, we will notify the affected customer before disclosing Workspace content.
Business transfers. If the business is sold, merged, or reorganized, information may transfer as part of that transaction. The acquirer remains bound by this policy, or you will be notified of any material change before it takes effect.
8. Where your information is stored
Your Workspace content — including equipment records, photographs, and voice recordings — is stored in the United States (Supabase, us-east-1 region), and other processing also occurs in the United States.
By using the Service, you understand that information is stored and processed in the United States. The Service is intended for business use in the United States and is not offered to individuals in the European Economic Area or the United Kingdom as consumers.
9. How long we keep information
- Workspace content is kept for as long as the customer's subscription is active. After termination, the customer may export it for 30 days, after which we may delete it from the production Service. We will delete it sooner on the customer's written request.
- Account information is kept while the account is active and for a reasonable period afterward for security and record-keeping.
- Support-assistant conversations are not stored on our servers.
- Server logs are kept for a limited period for security and troubleshooting.
- Billing records are kept as long as required by tax and accounting law.
- Deletion from routine encrypted backups occurs on our standard backup rotation rather than immediately.
Closing an account does not delete the records that person created. If you ask us to close your login, your access is revoked and your personal contact details are removed, but the buildings, equipment records, photographs, notes, and service history recorded in a customer's Workspace remain that customer's records. This is deliberate: deleting a person must never destroy a building's equipment history. If the displayed name also needs removing, ask and we will anonymize the attribution.
10. Security
We protect information using measures appropriate to its sensitivity, including:
- encryption in transit (HTTPS) and encryption at rest for stored data, photographs, and recordings;
- database-level tenant isolation, so records in one Workspace are not accessible from another;
- password hashing, with credentials never stored in readable form;
- restricted administrative access on a need-to-know basis, protected by multi-factor authentication; and
- reputable infrastructure providers with their own security programs.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting personal information, we will notify affected customers and any required regulators as the law requires and without undue delay.
You are responsible for keeping your credentials confidential and for who you grant Workspace access to.
11. Your choices and rights
Your account. You can view and update your profile information in the Service at any time, and you can ask us to close your account.
Workspace content. Because a customer organization controls its Workspace, requests to access, correct, or delete content within one should go to that organization. If you send such a request to us, we will forward it and assist as the law requires.
Communications. Service and transactional messages — invitations, password resets, security notices, and maintenance and warranty alerts — are part of the Service and cannot be switched off separately while your account is active, because they are what the Service does. Any marketing email we send will include an unsubscribe link, and unsubscribing from marketing does not affect service messages.
State privacy rights. Depending on where you live, you may have rights to know what personal information we hold, to obtain a copy, to correct it, to request deletion, and not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of in that respect. To make a request, contact us at support@therooflog.com. We will verify your identity before acting, and you may use an authorized agent. If we decline a request, we will explain why.
12. Children
The Service is for business use and is not directed to children. We do not knowingly collect information from anyone under 18. If we learn we have, we will delete it.
13. Changes to this policy
We may update this policy. If changes are material, we will update the effective date above and notify customers by email or in the Service before the change takes effect. Continued use after that date means you accept the updated policy.
14. Contact us
Questions, concerns, or privacy requests:
Email: support@therooflog.com Mail: Gieson Co — registered-agent mailing address pending designation; until it is published here, please use the email address above.
Gieson Co. · RoofLog · https://therooflog.com