Privacy Policy
Last updated: August 16, 2026
The short version
- If you filled out a request form, your details go to the one business you chose — nobody else.
- The business that referred you sees only that a referral happened. Not your phone, email, or message.
- We don't sell your information. We don't run ads. We don't build profiles to market to you.
- We measure QR scans using a one-way hash of your IP address and country-level location only — never your street, city, or precise location.
- You can ask us to delete your information at any time: hello@rootsreferrals.com.
Roots Referrals LLC ("Roots", "we", "us") is a referral tool for local service businesses. This policy explains what we collect, why, who sees it, and what you can do about it. It covers www.rootsreferrals.com, app.rootsreferrals.com, and the business profile pages we host.
Two very different groups use Roots, so we've split this by who you are.
If you're a customer who scanned a QR code or tapped a link
You don't need an account, and we don't ask you to make one.
What you give us
When you submit a request to a business through Roots, we collect what you type into that form — typically your first and last name, phone number, email address, and a note about what you need. The business receiving your request may add its own questions (for example, property type or how urgent the job is). Those answers come to us too.
What we collect automatically
When you open a business's Roots page, we log the visit so that business can see its page is working and so we can credit the right referral. That record includes:
- A one-way hashed version of your IP address. We do not store your actual IP address.
- Country and region only. We deliberately do not collect your city, street, or GPS location.
- Device type, operating system family, and browser family — not a unique device fingerprint.
- The page that referred you, and the time of the visit.
Who sees your request
This is the part most people want to know, so we'll be specific.
| Who | What they see |
|---|---|
| The business you chose | Everything you submitted: name, phone, email, your message, and any answers to their questions. They need it to contact you. |
| The business that referred you | Only that a referral happened — your name and the date. Not your phone number, email address, or message. |
| Anyone else | Nothing. We don't sell, rent, or share your information with other businesses, data brokers, or advertisers. |
If you recommend a business to a friend
Roots does not send messages to your friends on your behalf. When you use the "recommend to a friend" option, your own phone or email app opens with a message ready to send — you send it, from your own number or address. We record that a recommendation was created and, if your friend follows the link, that it worked, so the business knows the referral came from you.
If you're a business using Roots
To run your account we collect and store:
- Account details — your name, email address, phone number, and password (or your Google sign-in, if you use it). We never see or store your Google password.
- Business profile — business name, trade, service area, hours, year established, bio, logo, and the photos you upload. This information is public on your Roots page, which is the point of it.
- Your network — who you invited, who accepted, and the vouches you wrote. Vouches you write about a partner are shown publicly on your page.
- Referral activity — leads sent and received, status updates, response times, and any revenue ranges you choose to log.
- Billing — handled by Stripe. Your full card number never touches our systems.
You are responsible for the customer information you receive through Roots. Please treat it the way you'd want your own information treated, and use it only to respond to the request.
Cookies and similar technology
We keep this minimal. We do not use advertising cookies or third-party ad trackers.
- A short-lived attribution identifier (about 7 days) so that if you scan a QR code and submit a request later, the right business gets credit.
- A recommendation token, stored briefly in your browser, used for the same purpose.
- A session cookie to keep businesses signed in.
- Product analytics to understand which features get used, and error monitoring so we can find bugs.
Companies that help us run Roots
We use a small number of service providers, and only for the purpose listed. They are not permitted to use your information for their own purposes.
| Provider | What for |
|---|---|
| Supabase | Database, sign-in, and file storage |
| Cloudflare | Hosting and content delivery |
| Resend | Sending notification and account emails |
| Stripe | Subscription payments |
| PostHog | Product analytics |
| Sentry | Error monitoring |
| Kit | Marketing email, for people who opt in |
| Optional sign-in |
How long we keep things
Customer requests are kept as long as the receiving business has an active account, because it's their record of the job. Business accounts and their content are kept while the account is open. Scan and page-view records, which are already hashed and non-identifying, are kept in aggregate for reporting. If you ask us to delete your information, we do so as described below.
Your choices and rights
Whoever you are and wherever you live, you can ask us to:
- Tell you what information we hold about you.
- Correct anything that's wrong.
- Delete your information.
- Send you a copy of it.
Email hello@rootsreferrals.com and we'll take care of it, normally within 30 days. We won't charge you or make you jump through hoops, and we won't treat you differently for asking.
One honest limitation: if you submitted a request to a business, that business also holds your details in its own records. We'll delete our copy and tell you who received it, but you may also want to contact them directly.
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act, other U.S. state privacy laws, or the GDPR. We apply the rights above to everyone rather than making you prove where you live. We do not sell personal information or share it for cross-context behavioral advertising, as those terms are defined by those laws.
Security
Connections are encrypted in transit. Access to customer information is restricted so that only the business a request was sent to can see it. IP addresses are hashed before storage. No system is perfectly secure, and we won't pretend otherwise — but if a breach ever affected your information, we would notify you as required by law.
Children
Roots is for businesses and their adult customers. It's not intended for anyone under 18, and we don't knowingly collect information from children.
Changes to this policy
If we change this policy in a way that matters, we'll update the date at the top and, for material changes affecting account holders, email you. Continuing to use Roots after a change means the updated policy applies.
Contact us
Questions, requests, or concerns:
Roots Referrals LLC
hello@rootsreferrals.com
7901 4th St N, STE 300
St. Petersburg, FL 33702