Privacy Policy

Last updated: May 10, 2026

1. Plain-English summary

  • We collect what we need to run SatelliteQuotes — nothing more.
  • Contractor data (your account) and lead data (your homeowners) are kept separate per account. We never share leads between contractors.
  • We don't sell your data, and we don't use it to train AI models.
  • You can export or delete your data any time by emailing us.

2. Who we are

“SatelliteQuotes” refers to the company operating the service at satellitequotes.com. For privacy questions email privacy@satellitequotes.com.

3. What we collect

From contractors (account holders)

  • Account info: name, email, company name, phone, service area.
  • Billing info: handled by Stripe; we store only a Stripe customer reference and last-4 of the card.
  • Configuration: your pricing rules, materials catalog, branding, team notification emails.
  • Usage: pages you visit in the dashboard, error logs, performance traces. We do not use third-party advertising trackers.

From homeowners (widget submissions)

  • Name, email, phone, property address, IP address (only at moment of submission, for spam protection).
  • Roof measurement, selected materials, generated estimate range, optional marketing consent flag.
  • Referrer / UTM parameters of the page the widget was embedded on.

4. Why we collect it

  • To run the Service — host your dashboard, deliver lead notification emails, serve the widget.
  • To bill you (Stripe).
  • To send the homeowner a confirmation email on the contractor's behalf.
  • To detect abuse and protect your account.
  • To send you product updates and educational content (you can unsubscribe at any time).

5. Who we share data with

We use a small set of sub-processors. Each is bound by their own privacy policy and DPA with us:

  • Supabase — Postgres database + authentication (US-East).
  • Vercel — application hosting and edge functions.
  • Resend — outbound transactional email.
  • Stripe — payment processing.
  • Mapbox — geocoding and base maps (only the addresses you search are sent; no identifiers).
  • FEMA USA Structures (public dataset) — building footprints for roof detection.

We share contractor “lead” data only with you (the contractor who owns the lead). We do not sell or rent lead data.

6. How long we keep it

  • Active account data: as long as your account is open.
  • After account closure: 30 days, then deleted (unless you request earlier deletion).
  • Email logs (delivery receipts): 90 days.
  • Billing records: 7 years (legally required).

7. Your rights

Regardless of where you live, you can:

  • Request a copy of the data we hold about you.
  • Ask us to correct or delete your data.
  • Ask us to stop sending marketing emails (the unsubscribe link in every email also does this).
  • If you're in the EU/UK, lodge a complaint with your data protection authority.
  • If you're in California, exercise CCPA rights including data portability and opt-out of sale (we don't sell — but the right exists).

Email privacy@satellitequotes.com for any of the above; we respond within 30 days.

8. Security

We host on Vercel and Supabase, both SOC 2 Type II compliant. All traffic is encrypted in transit (TLS 1.3). Database backups are encrypted at rest. Passwords are hashed with bcrypt via Supabase Auth — we never see plaintext. We use principle-of-least-privilege for internal access and require 2FA on every admin account.

If we ever discover a breach affecting your data, we'll notify you within 72 hours and report to the appropriate regulators within the legally required window.

9. Cookies

We use first-party cookies for authentication (Supabase session) and CSRF protection. We don't use any third-party advertising or cross-site tracking cookies.

10. Children

The Service is not intended for users under 18. We do not knowingly collect data from children.

11. Changes to this policy

We'll email you about material changes at least 14 days before they take effect.