← Back to The Roofing Black Box
Privacy Policy
Last updated: June 18, 2026
Your data — and your clients' data — stays private. The information you
enter and the documents you upload are used only to generate your bid sheet and
proposal. We do not sell your data, we do not share it with advertisers, and we do not
keep your uploaded files or your clients' details after your documents are produced.
This policy explains what The Roofing Black Box ("Black Box," "we," "us") collects when
you use roofingblackbox.com (the "Service"), how we use it, and how it is protected.
By using the Service you agree to this policy.
1. Information we collect
- Account & contact info — the company name, email, phone, address,
and license number you enter. Your email is stored to run your free
trial, billing, and login.
- Content you enter — project and client details (names, addresses,
scope, pricing, warranty) you type to build a document.
- Documents you upload — plans, measurement/aerial reports, and photos
you provide so the Service can run the takeoff.
- Payment info — handled entirely by Stripe. We never see or store your
full card number.
- Technical & usage data — IP address and how many documents you've
generated, used to operate your trial/subscription and to prevent fraud and abuse.
2. How we use your information
- To read your documents and generate your bid sheet and proposal.
- To run your 7‑day free trial, one‑time purchases, and subscription.
- To log you in and keep your account secure.
- To detect and prevent fraudulent or abusive use.
We do not use your data for advertising, and we do not
sell or rent it to anyone.
3. Your documents and client information — how they're handled
This is the part that matters most when you're entering a client's information:
- Uploaded documents are processed transiently to run the takeoff and are
not stored on our servers after your documents are generated.
- The client and project details you enter are rendered into your bid sheet and
proposal and returned to you. We do not keep a copy of those finished
documents or the client details on our servers.
- The generated documents themselves are produced in your browser session and are between
you and your client.
4. How your data is protected
- Encrypted in transit — the entire site is served over HTTPS/TLS, so data
moving between your browser and our service is encrypted.
- Reputable infrastructure — the Service is hosted on Netlify; the limited
account data we retain (your email, usage count) is stored on Netlify's infrastructure,
which encrypts data at rest.
- Payments are isolated — card payments are processed by Stripe, a
PCI‑DSS Level 1 certified provider. We never store card numbers.
- Least data kept — we keep only what's needed to run your account
(email, usage, trial/subscription status). We don't retain your uploads or client data.
No method of transmission or storage is 100% secure, but we use industry‑standard measures
and keep the amount of data we hold to a minimum.
5. Third‑party processors
We share data only with the service providers needed to run Black Box:
- Anthropic (Claude AI) — your uploaded documents are sent to Anthropic's
API to run the takeoff. Per Anthropic's commercial terms, API data is not used to
train their models.
- Stripe — payment processing.
- Netlify — hosting and the secure store that holds your account email and
usage count.
These providers act on our behalf and are not permitted to use your data for their own
marketing.
6. Data retention & deletion
Uploaded documents and entered client details are not retained after your documents are
generated. Account data (email, usage count) is kept while your account is active. You can ask
us to delete your account data at any time by emailing us (see Contact). Payment records held
by Stripe are retained per Stripe's policies and applicable law.
7. Cookies & local storage
We use first‑party browser local storage on your device to remember your
form entries (so they survive a payment redirect) and your login — this stays on your device.
Stripe may set cookies during checkout to process your payment securely. We do not use
advertising or tracking cookies.
8. Your rights
Depending on where you live (including under GDPR and CCPA/CPRA), you may have the right to
access, correct, or delete your personal data, and to opt out of any sale of personal
information — which we do not do. To exercise any right, contact us below.
9. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly
collect data from children.
10. Changes to this policy
We may update this policy; we'll change the "Last updated" date above and, for material
changes, provide notice within the Service.
11. Contact
Questions or requests about your data: support@roofingblackbox.com.