Privacy Policy
RoofStack Privacy Policy
Last updated: May 24, 2026
RoofStack provides roofing business software, communication tools, customer portals, marketing tools, integrations, and related services. This policy explains what information we collect, how we use it, and how users can control or request deletion of their data.
Information We Collect
We may collect the following information when you use RoofStack:
- Account information such as name, email address, phone number, company name, role, and login details.
- Company and business information such as branches, users, customers, jobs, estimates, production records, invoices, payments, and communications.
- Customer and lead information entered, imported, or synced by a company using RoofStack.
- Files and media uploaded into RoofStack, including photos, documents, signatures, forms, and recordings where enabled.
- Integration data from connected services such as calendars, accounting platforms, payment processors, phone providers, email providers, social media accounts, and advertising platforms.
- Usage, device, browser, security, and diagnostic data used to operate, protect, and improve the service.
How We Use Information
RoofStack uses information to:
- Provide and secure the RoofStack platform.
- Process customer workflows, estimates, inspections, production activity, payments, communications, and reporting.
- Operate connected tools such as XStudio, XCONNECT, XBlast, XVoIP, XCOMS, XCADEMY, and related RoofStack modules.
- Send service messages, notifications, support responses, and account-related communications.
- Support integrations authorized by users or companies.
- Prevent abuse, protect accounts, troubleshoot issues, and comply with legal obligations.
Connected Accounts and Social Platforms
When a user connects a third-party account, RoofStack only requests access needed to provide the selected feature. For social platforms, this may include profile, page, post, media, comment, insights, advertising, or messaging data depending on the permissions approved by the user and the provider.
Connected accounts can be disconnected from the related RoofStack settings page. Disconnecting stops future syncing and removes stored authorization tokens from active use.
Sharing Information
RoofStack does not sell personal information. We may share information with service providers, integration partners, payment processors, communication providers, support tools, or infrastructure providers as needed to operate RoofStack. We may also disclose information when required by law, security, fraud prevention, billing, audit, or dispute resolution needs.
Company-Controlled Data
Many records in RoofStack are controlled by the company account that created or imported them. If you are a customer, homeowner, employee, subcontractor, supplier, agency, or other portal user, your request may need to be reviewed with the company that controls the related business record.
Data Retention
RoofStack keeps information for as long as needed to provide the service, maintain business records, comply with legal obligations, resolve disputes, prevent fraud, enforce agreements, and support audit or security needs. Some information may be deleted, anonymized, or retained in limited form depending on the record type and legal requirements.
Security
We use administrative, technical, and operational safeguards designed to protect RoofStack data. No system can be guaranteed to be perfectly secure, but we work to protect information from unauthorized access, misuse, and loss.
Your Choices
You can request access, correction, disconnection, or deletion of your data by contacting RoofStack support.
Privacy requests: support@roofstack.io
Data deletion instructions: https://roofstack.io/data-deletion/
Contact
If you have questions about this Privacy Policy or a data request, contact RoofStack support and include enough information for us to identify the account, company, or connected service.
