Privacy Policy
SupSonic
OVERVIEW
SupSonic ("we," "our," "the tool") is a documentation and scope identification tool for roofing professionals. This Privacy Policy describes how we collect, use, store, and protect information when you use our service.
INFORMATION WE COLLECT
Account Information
When you create an account, we collect your name, email address, and organization name. This information is used for account management, communication, and providing our services.
Uploaded Documents & OCR Data
Users upload insurance estimate documents for processing. These documents are processed using OCR (optical character recognition) to extract text content including roofing line items, quantities, measurements, and scope details. This extracted OCR data is stored in our database for the purpose of providing supplement recommendations within the SupSonic tool.
Uploaded insurance estimates may contain personally identifiable information such as policyholder names, addresses, phone numbers, and policy numbers. This information may be present in the OCR-extracted data stored in our system as part of the document processing workflow.
Location Data
Job location data (ZIP code) is used to provide location-specific supplement recommendations. For example, Gulf Coast wind zone items or Dallas-area Ordinance & Law triggers are surfaced based on the job's geographic location. Location data is stored as part of your job records.
Usage Data
We collect standard usage data including pages visited, features used, and interaction patterns. This data helps us improve the product and diagnose issues.
HOW WE USE YOUR DATA
Your uploaded estimate data is used solely within the SupSonic tool to provide supplement recommendations. We do not sell, share, or provide your data to third parties for marketing, advertising, or any purpose outside of delivering SupSonic's services.
Specifically, your data is used to:
- Process uploaded estimates and generate supplement recommendations
- Provide location-specific recommendations based on job ZIP code
- Maintain your account and job history
- Communicate with you about your account and our services
- Improve our recommendation engine and product features
PAYMENT INFORMATION
We do not store credit card numbers, bank account details, or other payment credentials. All payment processing is handled by Stripe, Inc. Stripe's handling of your payment information is governed by the Stripe Privacy Policy. We receive only confirmation of payment status and basic subscription details (plan type, billing period) from Stripe.
THIRD-PARTY SERVICES
We use the following third-party services to operate SupSonic: Google Cloud (document processing), Render (application hosting), Supabase (database and authentication), Stripe (payment processing — we never store payment credentials), Sentry (error monitoring), and UptimeRobot (uptime monitoring). These services process data only as needed to provide their respective functions. No uploaded document content is shared with third parties for advertising, model training, or any purpose unrelated to operating SupSonic.
COOKIES & ANALYTICS
We use essential cookies for authentication and session management. These cookies are required for the service to function and cannot be disabled.
We may use analytics tools to understand how users interact with SupSonic. Analytics data is used solely for product improvement and is not shared with third parties for advertising purposes.
DATA SECURITY
We implement industry-standard security measures including encryption in transit (TLS) and at rest, secure cloud infrastructure, role-based access controls, and regular security reviews.
SupSonic is built to SOC 2 security standards. Formal SOC 2 audit is planned for 2026.
DATA RETENTION
Account information is retained while your account is active. Extracted OCR data and job records are retained to provide our services and maintain your job history. Upon account deletion, all associated data is permanently removed from our systems.
YOUR RIGHTS
You have the following rights regarding your personal data:
- Right to Know: You have the right to know what personal data we collect, how it is used, and what categories of data we maintain about you.
- Right to Delete: You may request deletion of your account and all associated personal data at any time from your account settings or by contacting us. Upon deletion, all associated data will be permanently removed from our systems.
- Right to Opt-Out of Sale: We do not sell your personal information to third parties. Your data is used solely to provide our services.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
- Right to Correct: You may update your personal information at any time through your account settings.
How to Exercise Your Rights: You can delete your account data from the Settings page in your dashboard. For other requests, contact us at the email below.
California Residents (CCPA Notice): Under the California Consumer Privacy Act (CCPA), California residents have additional rights including the right to request disclosure of data collected and the right to request deletion. We collect only the categories of personal information described in this policy (account information, usage data, and uploaded documents for processing). We do not sell personal information. To submit a verifiable consumer request, use the account deletion feature in your dashboard settings or contact us directly.
CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will notify users of material changes via email or in-app notification.
CONTACT
If you have questions about this Privacy Policy or our data handling practices, please contact us at support@supsonicapp.com.