Legal

Privacy Policy

The records your company puts into ContractorX belong to your company. This policy explains what we collect, who processes it, where it lives, how it is protected, how long it is kept, and, plainly, how we use it to improve the platform.

This applies to ContractorX and to every site and product we operate under it: contractorx.co, rooferx.com (RooferX), solarsalesx.com (SolarSalesX), and tradesmenx.com (TradesmenX). RooferX, SolarSalesX and TradesmenX are the ContractorX platform presented for a particular trade, not separate services. Where this page says ContractorX, the Services, or we, it means all of them.

Last updated August 20, 2026. Questions about anything here? Contact us.

Who we are, and who this covers

ContractorX LLC, a Florida limited liability company with its principal place of business at 2525 Ponce de Leon Blvd., Coral Gables, Florida 33134, operates contractorx.co and the ContractorX platform, including the RooferX and SolarSalesX experiences and our mobile apps.

This policy covers two different relationships, and the difference decides who you ask for what:

  • You visit our site, or you administer an account. We decide how that information is used. We are the controller, and this policy governs it.
  • A contractor uses the platform to run their business. The records they put in, including information about homeowners and prospects, are theirs. We process it on their instructions as their processor, and their own privacy notice governs it. If you are a homeowner or customer of a contractor who uses ContractorX and you want your information accessed, corrected, or deleted, contact that contractor. If you reach us first we will route the request to them, and we will not answer it substantively ourselves.
  • We are also an independent controller for platform and usage information, aggregated data, the account and billing details of administrative contacts, and processing we do for security, fraud prevention, legal compliance, and product improvement. That is described under “How we improve the platform” below.

What we collect

  • Account and company information. Names, work email addresses, phone numbers, company details, roles and permissions, and workspace configuration.
  • Records you put into the platform. Leads and contacts, properties and measurements, deals, proposals, contracts and signatures, permits, schedules, work orders, job photos, purchase orders, invoices, payments, and messages sent through the platform.
  • Usage and device information. Log data, IP address, browser and device type, which features are used, session details, outcomes of the work, and error reports.
  • Location and camera data from the mobile apps. With permission, the field apps attach location to a visit and use the camera for job photos. Both are optional, requested at the point of use, and revocable in device settings.
  • Communications with us. What you send when you contact us, request a demo, or open a support case.
  • Payment information. Card and bank details are handled by a PCI-compliant payment processor. We do not store full card numbers and we do not take custody of funds.

Some categories are not permitted in the platform at all, including protected health information, government identification numbers, financial account credentials, biometric identifiers, and consumer report information. The full list is in the Acceptable Use Policy.

How we use it

  • To provide, maintain, and secure the platform, including sign-in, permissions, and keeping each company's data separate.
  • To perform the work you ask for: pricing a job, drafting a permit packet, sending a proposal or invoice, scheduling work, syncing email and calendar when you connect them.
  • To provide support and investigate issues.
  • To monitor reliability, prevent fraud and abuse, and keep accounts safe.
  • To meet legal, tax, and accounting obligations and to enforce our agreements.
  • To send service and administrative messages, and marketing you can opt out of at any time.

How we improve the platform, stated plainly

Our customer agreement grants us broad rights to learn from how the platform is used, and you should understand them rather than discover them. We may use the records in the platform and the usage information it generates, including in identifiable form, to:

  • Operate, monitor, secure, troubleshoot, and support the platform.
  • Analyze and improve the platform and our other products.
  • Build new features, analytics, benchmarks, and indices.
  • Train, tune, evaluate, and validate the models we deploy across our customer base.

These rights continue after an account ends, for data lawfully collected while it was active. Models, weights, benchmarks, and derived analytics cannot be disaggregated or unlearned, so deleting records does not require us to retrain a model. The limits we hold ourselves to are firm:

  • We do not sell personal information, and we do not share it for cross-context behavioral advertising.
  • We do not license or disclose customer records in identifiable form to third parties, except to subprocessors under equivalent written protections, where law compels us, in a merger or sale of the business, or with written consent.
  • We do not publish or market customer records in identifiable form, or name a customer as the source of a published output, without their written consent.
  • We honor verified requests to opt out of the use of personal information for model training where the law provides that right. Those requests are routed through the contractor who controls the record.
  • Aggregated and de-identified data that cannot identify a company, a user, or a person is ours to use for benchmarking, research, and product development.

Automated features

Features that build a deal from a description, draft a permit packet, or answer a question about your own records send the relevant content to model providers we engage as subprocessors under contract, to produce your result. A person on your team reviews and approves the output before it is used: the automation prepares work, it does not sign contracts, submit filings, or move money on its own.

Who else processes it

We engage subprocessors to run parts of the service, in these categories, each processing within the United States: application hosting and content delivery; managed database, authentication, and object storage; background job and event processing; geospatial, mapping, and property analytics; payment processing; transactional and notification email; diagnostics and error monitoring; and AI-assisted feature processing.

The identity of our specific vendors is confidential and is not published, as a security measure. We disclose the current subprocessor list to customers on reasonable written request under confidentiality, within ten business days, and we give at least 30 days notice before adding a new subprocessor that will process personal information, so a customer can object on documented data protection grounds. Every subprocessor is bound by written obligations no less protective than ours, and we remain fully liable for their performance.

Beyond subprocessors, information goes to:

  • Services a company chooses to connect, under that provider's own terms.
  • The company's own administrators, who can see and manage the records and activity in their workspace.
  • Authorities, where required by law or valid legal process. We challenge overbroad or unlawful demands, disclose only the minimum required, and tell the affected customer unless we are legally prohibited.
  • A successor, if ContractorX is involved in a merger, acquisition, financing, or sale of assets, subject to this policy.

Connecting QuickBooks Online

A company can choose to connect its QuickBooks Online account so the records it already keeps in ContractorX appear in its own accounting file. The connection is optional, is started by an administrator of that company, and can be ended at any time from the same screen. We are not affiliated with Intuit, and what happens to data inside QuickBooks is governed by Intuit’s own terms and privacy policy.

We request a single permission, accounting. We do not request payroll access, and we do not request payment-processing access.

The connection exists to write a company’s own records out, not to collect data in:

  • We send records the company already created in ContractorX: customers, invoices, payments, purchase orders and bills, job costs, commissions, and bank deposits.
  • We read the chart of accounts, so an administrator can choose which account each kind of record posts to, and we read transaction totals so we can check the two systems agree.
  • We do not copy a company’s QuickBooks bookkeeping into ContractorX. QuickBooks information is never sold, never used for advertising, and never used to train models.

What we keep is deliberately small: the QuickBooks company identifier, the access and refresh tokens, a map of which ContractorX record corresponds to which QuickBooks record, and a log of each sync attempt so a failure can be explained and retried. Tokens are encrypted with AES-256-GCM before they are written, are held in a table no customer account can read and only the service itself can reach, are never written to logs, and are never shared with another company or with a third party.

Disconnecting revokes the tokens at Intuit and erases them from our systems. The record map and the sync history are kept under the retention terms below, so that reconnecting later resumes cleanly rather than duplicating a company’s books, and they are deleted with the rest of the account.

Where it is processed

We process and store personal information in data centers located in the United States. We do not transfer it outside the United States without the customer’s prior written consent and an appropriate transfer mechanism. Personnel or subprocessors located outside the United States may be permitted remote access solely for support and maintenance, under access controls and confidentiality obligations, and we disclose those arrangements to a customer on request.

How it is protected

We protect information with layered, industry-standard safeguards: encryption in transit and at rest, strict separation between customers so one company’s data is never reachable from another’s, role-based access with least privilege, multi-factor authentication support, separation of production from test environments, audit logging and monitoring of security-relevant activity, formal change and vulnerability management, and background-screened personnel who are trained, bound by confidentiality, and lose access the day they leave. Vendors are diligenced and bound in writing before they touch anything.

We describe our safeguards at this level on purpose. Publishing the internal detail of how a system is defended helps the people trying to get past it. Customers who need specifics for a security review can request them under confidentiality through the contact page, and we answer security questionnaires as part of that process.

No system is perfectly secure. If we confirm a security incident affecting a customer’s personal information, we notify that customer without undue delay and within 72 hours, with what happened, what was affected, what it likely means, what we are doing, and who to talk to, updated as we learn more. We support customers in meeting their own notification duties. Customers must tell us within 24 hours if credentials are compromised or someone reaches their workspace who should not have.

How long it is kept

We keep account information while the account is active, and customer records for as long as the customer keeps them in the platform. Customers can export at any time. After an account ends there is a 30-day retrieval window to export data in a structured, machine-readable format, after which we delete records from active production systems and will do so within 90 days, except where law requires retention or a dispute is pending. Backup copies expire on their ordinary rotation and stay protected until they do. Platform data, usage information, aggregated data, and trained models survive as described under “How we improve the platform”.

Your choices and rights

Depending on where you live you may have the right to access, correct, delete, restrict, or object to processing, to receive a portable copy, and to withdraw consent. Residents of some states, including California, also have the right to know what is collected and to opt out of sale or sharing, neither of which we do. Exercising a right never triggers discriminatory treatment.

To exercise a right, use the contact page. If the information sits in a contractor’s workspace, we route the request to them because they control it. The platform gives our customers built-in tools to access, correct, export, and delete records so they can respond directly. You can opt out of marketing email using the unsubscribe link in any such message; service and account messages continue.

Children

The platform is built for businesses and is not directed to children. Information about individuals known to be under 16 may not be put into it at all. If you believe a child has provided us information, contact us and we will delete it.

Changes, and how to reach us

We update this policy when the platform or the law changes. The date at the top reflects the current version, and material changes are announced in the product or by email before they take effect. This version is effective as of August 20, 2026.

Questions, requests, or complaints: reach us through the contact page and mark your message “Privacy”. If you are not satisfied with our response you may have the right to complain to your local data protection authority. See also the Terms of Use, Data and Your Company, the Acceptable Use Policy, and the Cookie Policy.