Privacy Policy
Last updated: May 22, 2026
1. Overview
Eaveside (“Eaveside,” “we,” “us,” or “our”) provides roofing business management software that helps contractors manage leads, estimates, jobs, invoicing, scheduling, and related operations. This Privacy Policy explains what information we collect, how we use and share it, how we protect it, and the choices you have. It applies to the Eaveside web application and related services (the “Service”).
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information We Collect
- Account & profile data — your name, email address, phone number, password credentials, role, and company details you provide when you register or are invited to a workspace.
- Customer & job data — records you create and manage in the CRM, such as contacts, properties, leads, estimates, proposals, jobs, material orders, invoices, and related documents and photos.
- Usage & device data — log data, IP address, browser and device type, pages viewed, and feature interactions, collected automatically to operate and improve the Service.
- Integration data — information exchanged with third-party services you choose to connect, including Intuit QuickBooks Online (see §4) and Google Gmail/Calendar (see §5).
- Communications — messages, emails, and SMS you send or receive through the Service, and support requests you submit to us.
Mobile information and SMS consent. We do not share mobile phone numbers, text-messaging originator opt-in data, or consent records with third parties or affiliates for their own marketing or promotional purposes. We may share this information only with service providers that help us deliver and support the messaging service, or when required by law. Those providers may use the information only to perform services for us and may not use it for their own marketing. You can opt out of text messages at any time by replying STOP; reply HELP for assistance. Message frequency varies, and message and data rates may apply.
3. How We Use Information
We use the information we collect to:
- provide, operate, maintain, and secure the Service;
- authenticate users and manage access within your company workspace;
- process estimates, invoices, payments, and synchronize data with services you connect;
- communicate with you about your account, updates, and support;
- analyze usage to improve features, reliability, and performance; and
- comply with legal obligations and enforce our terms.
We do not sell your personal information, and we do not use data obtained through third-party integrations for advertising.
4. Third-Party Integrations (incl. Intuit QuickBooks)
When you connect a third-party service such as Intuit QuickBooks Online, you authorize Eaveside to access and exchange the data needed for that integration through the provider’s API. For QuickBooks Online this typically includes customers, invoices, payments, items, accounts, classes, and tax codes. We access this data only with your authorization and use it solely to provide the integration’s features — for example, syncing customers and invoices between Eaveside and your QuickBooks company.
We do not sell, rent, or share QuickBooks data with third parties for their own purposes, and we do not use it for advertising. You can disconnect QuickBooks at any time from Settings → Integrations, which revokes our access tokens and stops further data exchange. Your use of QuickBooks remains subject to Intuit’s own privacy policy and terms.
5. Google User Data (Gmail & Calendar)
If you choose to connect your Google account, Eaveside requests your permission to access the following Google user data through Google’s APIs, and uses each scope solely to provide the corresponding user-facing feature:
- Read Gmail messages (
gmail.readonly) — to sync your email into the CRM so incoming and outgoing messages appear on the relevant contact, customer, and job communication timelines. - Send Gmail messages (
gmail.send) — to send email from your connected mailbox when you compose a message or document from within the Service, so replies return to your own inbox. - Manage app-created calendar events (
calendar.app.created) — to add, update, and remove the appointments you schedule in Eaveside on your Google Calendar. This scope only lets the Service manage events it created; it does not read your other calendar events.
We access this data only with your authorization, store OAuth tokens encrypted at rest, and use the data solely to provide and improve these user-facing features. We do not sell or rent your Google data, do not use it for advertising, and do not transfer it to others except as necessary to provide these features, to comply with applicable law, or as part of a merger or acquisition. No human at Eaveside reads your Gmail data except with your explicit consent, where necessary for security or to comply with applicable law, or where the data has been aggregated and anonymized for internal operations. You can disconnect your Google account at any time from My Account or Settings → Integrations, which revokes our access tokens and stops further data exchange.
Eaveside’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Your use of Google services also remains subject to Google’s own privacy policy.
6. How We Share Information
We share information only in the following circumstances:
- Within your workspace — with other authorized users of your company account, according to their roles and permissions.
- Service providers — vendors who process data on our behalf under contract, such as cloud hosting, database, email, SMS, and payment providers, limited to what they need to perform their services.
- Integrations you authorize — services you choose to connect, such as Intuit QuickBooks Online or Google.
- Legal & safety — when required by law, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets.
7. Data Retention & Security
We retain personal and business data for as long as your account is active or as needed to provide the Service, resolve disputes, and meet legal obligations. When you disconnect an integration, the associated access tokens are revoked and deleted. When you close your account, we delete or de-identify your data within a commercially reasonable period, except where retention is required by law.
We use industry-standard safeguards to protect your data, including encryption in transit (TLS) and encryption at rest for sensitive credentials such as integration access and refresh tokens. No method of transmission or storage is completely secure, but we work to protect your information and continuously improve our security practices.
8. Your Rights & Choices
Depending on your location, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. Residents of California (CCPA/CPRA) and the EEA/UK (GDPR) may have additional rights, including the right not to be discriminated against for exercising them. To exercise any of these rights, contact us at the address below; we will respond as required by applicable law. You can also manage much of your data directly within the Service.
9. Children’s Privacy
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Service. Your continued use of the Service after an update constitutes acceptance of the revised policy.
11. Contact
Questions or requests regarding this policy or your data? Contact us at privacy@eaveside.com.