Privacy Policy
Effective August 22, 2026 · Updated September 30, 2026 · Cedar House Marketing LLC, Franklin, Tennessee ("Cedar House Stack," "we," "us")
Cedar House Stack is business software for roofing and trade companies: a CRM and field-sales platform used by the companies who subscribe to it ("customers") and the people on their teams ("users"). This policy explains what we collect, why, and the choices you have.
What we collect
- Account data — your name, work email, role, and password (stored only as a salted hash).
- Business records your company puts in — leads, jobs, customer contact details, addresses, estimates, signatures, insurance-claim details, photographs, invoices, payments, payroll and commission figures. Your company controls this data; we process it on their behalf to run the product.
- Usage and device data — sign-ins, actions taken in the app (kept in per-company access logs), approximate location when a field user records a door knock (GPS is the point of that feature), and the technical basics any web service receives (IP address, browser).
- Feedback — anything you send through "Report a problem."
How we use it
To run the product a company signed up for: showing their pipeline, generating their estimates, syncing their books, paying their reps. We use aggregate, de-identified usage to improve the product. We do not sell personal information, and we do not use customer business records for advertising.
Calendar connections (Google and Microsoft)
If you choose to connect your Google Calendar or Microsoft 365 calendar, Cedar House Stack requests the narrowest scope available (Google: calendar.events; Microsoft: Calendars.ReadWrite) and uses it for exactly one thing: creating, updating, and removing the calendar events that mirror appointments assigned to you in the CRM. We do not read your other calendar events, and calendar data is never used for advertising, never sold, and never transferred except as needed to provide this feature.
Cedar House Stack's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect either calendar at any time from the Schedule page; disconnecting deletes our stored tokens immediately. You can also revoke access from your Google Account permissions or Microsoft account settings.
Who processes data for us
We use a small set of service providers, each doing one job: cloud hosting and database (Render), file storage for photographs and documents (Cloudflare R2), payment processing (Stripe — card numbers go to Stripe directly and never touch our servers), print-and-mail (Lob), text messaging when enabled (Twilio), transcription and AI assistance (Deepgram, Anthropic), accounting sync when a company connects it (Intuit QuickBooks), and calendar sync when a user connects it (Google, Microsoft). Each receives only what its job requires.
Website analytics
Our public website pages (the home page, the trade pages, pricing, contact, the move guide and the blog) use Google Analytics to count visits and to see which pages people read and how they found us. Google Analytics sets cookies and receives your IP address, browser and device type, and the pages you view. We use it only to improve the website. It is not used inside the signed-in app or on any page a company sends to its own customers. You can block it in your browser's cookie settings or with Google's opt-out add-on at tools.google.com/dlpage/gaoptout.
Retention and deletion
Business records belong to the subscribing company and are kept while the account is active. Signed contracts, payment records, and consent/opt-out records are retained as legally required even when other data is removed. An unpaid or cancelled account goes read-only — nothing is deleted for non-payment — and a company can export its data or request deletion at any time.
Security
Data is encrypted in transit (TLS) and at rest by our hosting providers. Tenant isolation is enforced at the database layer, access to customer records is logged, two-factor authentication is available to every account and can be required company-wide, and backups are tested by restoring them.
Text messaging (SMS)
Some companies on the platform send service texts to their customers through Cedar House Stack: appointment confirmations and reminders, job-status follow-ups, and review requests. Message frequency varies with your project and is typically a few messages around each appointment or milestone. Message and data rates may apply.
Mobile numbers are never shared or sold. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party, excluding the aggregators and carriers required to deliver the messages.
Reply STOP at any time to opt out; opt-outs are honored permanently and automatically. Reply HELP for help, or contact the company serving you directly. Messages are sent only between 8am and 8pm in your region.
Your choices
- Texting: reply STOP to any message and it is honored across channels, permanently.
- Calendar and QuickBooks connections: disconnect anytime in-app.
- Access, correction, export, deletion: ask the company you work with, or contact us and we will route it with them.
Contact
Cedar House Marketing LLC · Franklin, Tennessee
cedarhousemarketingfirm@gmail.com
If this policy changes materially, we will note it here with a new effective date.