Policy revision: October 3, 2026
Introduction
This policy explains how Top Choice Roofers handles information on topchoiceroofers.com, including information you provide when requesting an estimate.
Information We Collect
We collect the details you provide in a form, email or call. If you use address suggestions, the address text you type goes to Google Maps Platform before you submit. Our hosting and security systems also process technical request information needed to run and protect the site.
How We Use Information
We use your details to respond, discuss your project, prepare for appointments, and operate and secure the website. For new accepted estimate requests, we may also use the limited server-side Meta ad measurement described below. We do not replay requests submitted before this policy change.
Cookies
This server-side Meta event does not load Meta Pixel or set a browser advertising cookie. If you opt out of future Meta measurement here, we set a first-party preference cookie in this browser for one year. Clearing cookies or using another browser or device can remove that preference.
Service Providers and Other Recipients
Providers help us host the site, offer address suggestions and deliver estimate notifications. When server-side ad measurement is enabled for an eligible new request, Meta also receives the limited event described below. We do not send your phone number or text-message permission to Meta for this event.
Text Messaging Privacy and Data Use
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Links to Other Websites
Our website may include links to external sites not operated by us. We are not responsible for the privacy practices or content of those third-party websites.
Data Security
We take reasonable precautions to protect the limited data we collect. However, no internet transmission or electronic storage method is completely secure.
Children’s Privacy
Our site is not directed to individuals under the age of 13. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy periodically. Updates will be posted on this page with a revised “Effective Date.”
QuickBooks connection
Top Choice Roofers LLC operates this optional connection for authorized staff and approved company tools. It is separate from homeowner estimate forms. Requesting an estimate does not connect a QuickBooks account.
How the staff QuickBooks connection handles data
An authorized administrator signs in and reviews Intuit's accounting API permission. Access to company information and accounting operations is limited by separately enabled capabilities, staff authority and connector grants. This section does not represent which capabilities are currently enabled.
For an authorized operation, we may process only the company information and accounting data needed for it. We store encrypted authorization tokens, identifiers linking authorized staff accounts and connectors to the approved QuickBooks company, token-expiration details, access grants and technical request records. Approved connectors receive only the bounded response allowed by their credential, not Intuit tokens.
Vercel hosts the gateway, Supabase provides restricted server-side storage, and Intuit processes QuickBooks authorization and API requests. Approved company connectors, including Muse when enrolled, may receive bounded responses under their access grants. These providers have their own applicable terms and privacy policies.
Active encrypted tokens support the connection. Revoked access records and request history remain available for security and reconciliation; they are not automatically deleted when access ends. If provider cleanup is unresolved, encrypted token material remains restricted for that work. After confirmed provider cleanup, the gateway clears that token material from its cleanup record while retaining confirmation metadata. There is no general automatic-purge schedule or promise of immediate deletion across providers or logs.
For connection help or a request to review or delete retained information, contact j.thoma@topchoiceroofers.com. Requests require human review of identity, authority, available deletion capabilities and any applicable legal obligations. A request does not itself delete data or disconnect an account. Do not send passwords, tokens, connector credentials or accounting records.
First-party website analytics
Analytics notice revised October 7, 2026. Website analytics and historical collection are enabled. Disabling collection does not delete any historical records already stored.
When website analytics is enabled, we use a random temporary visit ID to understand the public pages and actions followed during a visit. The ID is stored in this tab’s session storage and expires after 30 minutes. A new tab, expiry or blocked session storage can start a new visit. We do not connect it to your name, email, phone, property address, form answers, account or another device. A temporary ID is pseudonymous, not fully anonymous.
Our analytics store receives the temporary ID, action order, approved public page and entry-page paths, page views, estimate-link and phone clicks, accepted-form actions, and a broad screen-size category. Entry-source details include the referring website’s public registrable domain with subdomains, paths and queries removed; whether the source came from a referrer or an approved source tag; a limited medium category; and an approved campaign code when available. We do not store arbitrary URL tags, click IDs or full referrer URLs in this analytics store. Missing referrers are recorded as “Direct / unknown,” not proof of a direct visit.
Our hosting provider may supply an approximate country, state, city and location for a request. When historical collection is enabled, we round the coordinates to 0.1 degree before sending location information to our analytics store—about 11 km north/south, with east/west distance varying by latitude. We keep that approximate area with the visit’s UTC day and ordered public-page actions so authorized existing global administrators can explore a map and individual recorded sessions. These are not GPS or property locations. Mobile networks, VPNs and other routing can make them inaccurate; missing locations remain unknown. Without historical collection, country and state are used only in separate grouped page-view counts, not individual journeys. Our analytics store does not receive IP addresses, user-agent information, unrounded coordinates or form contents. Infrastructure providers still process ordinary network requests under their hosting and security practices.
Our server hashes the temporary visit ID. Historical session records, when collected, keep the UTC day, source, entry page, approximate area when available, and up to 500 ordered actions per session. They do not automatically expire. This detailed history is restricted to authorized existing global administrators; its counts include individual sessions and small totals, so it is not fully anonymous. Exact event times are not kept in this historical store. The separate operational journey records still expire after 24 hours and daily grouped counts after 90 days. Those deletions are checked hourly; collection stops if maintenance has not been verified within 24 hours. Analytics does not identify unique people, prove calls were placed, or measure completed sales.
Routine hosting and database logs, along with backup copies, follow separate retention schedules and may persist longer than these analytics-table limits.
Use “Turn off website analytics” at the bottom of any public page to stop future collection in this browser. We save only an off preference, not a tracking ID, in a cookie for up to 180 days. Global Privacy Control also stops collection. Clearing cookies or changing browsers removes the saved choice. Turning it off does not delete earlier historical sessions or undo recorded aggregate counts. Contact us for other privacy requests. It does not affect estimate requests or the separate Meta choices below.
Meta ad measurement
Effective date for this measurement: September 30, 2026 at 5:58 PM EDT.
For an estimate request we accept on or after the effective date stated above, if you provide an email address and have not opted out, our server may send Meta a Lead event. It contains a SHA-256 hash of the email, your browser’s user-agent information, the time of acceptance, the server-assigned Contact or campaign page URL without tracking parameters, and a random event ID. Meta may match it to an account and use it to measure and deliver advertising. A hashed email is not anonymous.
Click-ID measurement starts October 3, 2026 at 6:00 PM EDT. On ad-1 through ad-5 only, for eligible new requests accepted on or after that date, if the landing address contains one Meta click ID (fbclid), we may also send Meta an fbc identifier made from that value and the time the page first observed it. This is an unverified browser-supplied attribution signal; it does not prove a valid ad click or the requester’s identity. It does not affect whether we respond to your estimate request. We do not replay earlier requests.
We do not send Meta your raw email, name, phone number, property address, roof answers, message, text-message choice, browser cookies, fbp, the full landing address, other query parameters, or visitor IP address in this server event. Meta receives ordinary network information from our server connection.
We do not send this event when you leave email blank, use the browser’s Global Privacy Control signal, or opt out below in this browser. This choice applies to future requests from this browser. A confirmation-page control may stop a still-pending event, but neither choice can recall an event already sent to Meta. Contact us for other privacy requests.
Meta handles information it receives under its Privacy Policy.
Contact Us
For questions about this Privacy Policy or your information, call +1 740-206-9622. Calling does not automatically stop an event or remove information already received by Meta.
Google Address Suggestions
If you use address suggestions in an estimate form, the address text you type is sent to Google Maps Platform so Google can return possible matches. Selecting a suggestion returns the address parts needed for the form. You may choose manual address entry instead. Google processes this information under the Google Privacy Policy.

