Privacy Policy

Remi Labs, Inc. (“Remi,” “Remi HQ,” “we,” “us,” or “our”)

Effective date: July 16, 2026

This Privacy Policy explains how Remi collects, uses, discloses, and retains personal information when you visit remihq.com, request a quote, contact us, interact with our marketing, or otherwise use a service that links to this Policy. It also explains the choices and rights available to you and how to contact our Data Protection Officer (“DPO”).

This Policy does not govern information processed solely on behalf of a business customer under a contract, employee information covered by an internal notice, or job-applicant information covered by a separate applicant notice. A third-party lender, financing platform, contractor, or website may provide its own notice and act as a separate business or controller for information it collects directly.

Contents

  • 1. Scope and our role
  • 2. Personal information we collect
  • 3. Website trackers and what they can see
  • 4. Sources of personal information
  • 5. How we use personal information
  • 6. How we disclose personal information
  • 7. Sale, sharing, and targeted advertising
  • 8. Retention
  • 9. Security
  • 10. Your privacy rights
  • 11. How to make a request
  • 12. Cookies, consent, and universal opt-out signals
  • 13. Children and teens
  • 14. Communications choices
  • 15. Third-party services
  • 16. Changes to this Policy
  • 17. Contact us
  • 18. State-specific supplements

1. Scope and our role

For the activities described in this Policy, Remi generally determines why and how personal information is processed and therefore acts as a “business” or “controller” under applicable U.S. state privacy laws. In some business-to-business settings, Remi may instead process information under a customer’s instructions; the customer’s notice will govern that processing.

Our public website is intended for U.S. users. If you provide information about another person—such as a co-owner or household member—you should have authority to do so and should provide that person with this Policy when appropriate.

2. Personal information we collect

CategoryExamplesPrimary uses
Contact and identityName, email address, telephone number, company name, and communication preferences.Respond to requests; provide quotes; authenticate and route requests; communicate about services.
Property and projectStreet address, city, state, ZIP code, property or roof details, project notes, photographs or documents you choose to provide.Assess service availability; estimate, plan, and deliver roofing or related work; support contracts and warranties.
Commercial and transactionServices requested or purchased, quote history, contract status, customer-support history, invoices, and warranty records.Provide services; administer customer relationships; accounting; dispute, fraud, and legal compliance.
Financing and paymentFinancing interest, referral/status information, billing details, and payment tokens or transaction references. A lender or processor may collect a full application or payment-card data directly under its own notice.Facilitate a requested financing referral or payment; reconcile transactions; comply with accounting and legal obligations.
Device and internet activityIP address, browser and device type, operating system, language, approximate location derived from IP, page URL, referrer, timestamps, pages viewed, links or buttons clicked, and interaction or performance events.Operate, secure, debug, and improve the website; measure use; prevent fraud; obtain analytics and attribution, subject to your choices.
Online and advertising identifiersCookie IDs, consent/preference IDs, Google Analytics identifiers, Meta Pixel identifiers such as _fbp or _fbc when present, and campaign/ad identifiers.Remember preferences; deduplicate events; measure campaigns; personalize or target advertising where permitted and not opted out.
InferencesLikely interests, campaign attribution, service-area or company-domain associations, and audiences inferred from website activity or submitted information.Understand demand, route leads, measure marketing, and tailor communications or advertising where permitted.
CommunicationsEmails, call or text records, form submissions, support messages, feedback, and any information you include.Respond, provide support, document preferences, and resolve issues.
Sensitive informationWe do not ask for precise geolocation, biometric identifiers, health data, account passwords, Social Security numbers, or full payment-card numbers through ordinary website forms.If unexpectedly received, restrict use to the requested service, security, legal compliance, or deletion as appropriate.

Information you choose to provide

Our quote forms may request your first and last name, property street address, city, state, ZIP code, telephone number, and email address. A business or materials form may request company name, website, business email, and telephone number. Please do not place Social Security numbers, financial-account credentials, medical information, or other unnecessary sensitive information in free-text fields or uploaded documents.

3. Website trackers and what they can see

When a tracker is allowed to run, the tracker provider ordinarily receives the network and browser data needed to deliver its script or request—for example IP address, browser/user-agent information, page URL, referring URL, time, and an event or tag identifier. Cookies or similar identifiers may allow events to be linked across visits. The table below distinguishes observed website components from optional features that require account-level confirmation.

Service / statusData ordinarily visibleConfiguration-dependent capability and controlProposed retention
Google Tag Manager (observed)Loads and sequences tags. The container request exposes network/device data and the current page; the container’s own data collection depends on the tags and variables configured inside it.Form variables, query strings, data-layer values, or custom events can be forwarded if configured. Export and review the container; prohibit raw form values and sensitive URL parameters.Operational configuration; retain change and consent evidence for 5 years.
Google Analytics 4 (observed)Page and session events, cookie/device identifier, page URL/referrer, device/browser, approximate location, and engagement/performance data. Google states IP addresses are used in transit and are not logged or stored by Analytics.Custom dimensions, user IDs, ad signals, and detailed events only if enabled. Prohibit direct identifiers and sensitive data.Configure event/user-data retention to 14 months and disable reset-on-new-activity unless justified.
Meta Pixel (observed; multiple IDs)Page URLs, event names and time, IP address, browser/device data, Meta/cookie identifiers such as _fbp or _fbc when present, and campaign attribution.Automatic events, clicked-element/form-submission signals, hashed email/phone through advanced matching, or server-side Conversions API data only if enabled. Inventory five observed pixel IDs, remove duplicates, and verify payloads.Remi-controlled advertising/audience data: target 180 days; provider retention is governed by provider terms and must be confirmed.
HubSpot (observed)Anonymous pageviews, IP address, cookie/online identifiers, timestamps, referral/campaign data, and device/browser information. A later form or email interaction may associate prior browsing with a CRM record.Intent/company-domain signals, ad integrations, embedded forms, chat, and additional CRM enrichment if enabled. Disable unnecessary intent access and control cookies through the CMP.Anonymous/lead history: 24 months after last interaction unless it becomes a customer record.
PostHog (code observed)Product analytics may collect pageviews, clicks, form-submission events, device/session data, and performance information.Session replay can capture navigation and mouse movement; console or network capture may be enabled. Replay code loaded during review, but an actual recording was not proven. Keep replay off; if re-enabled, use prior opt-in, masking, and a 30-day maximum.Product analytics: 12 months. Session replay: disabled; 30 days maximum if approved and consented.
Google Maps (observed)IP address, device/browser data, map request and usage events. If a person searches or interacts with a map, the provider may receive the location or place queried.Precise device location only if the user separately enables location permission. Do not request precise location unless necessary and consented.Follow provider configuration; Remi should not retain precise device location from the public site.

4. Sources of personal information

  • You, including through forms, calls, emails, texts, contracts, support requests, and in-person interactions.
  • Your device and browser, through logs, cookies, pixels, SDKs, tags, and similar technologies, subject to applicable consent and opt-out choices.
  • Affiliates, contractors, installation or service partners, financing partners, lead/referral partners, and business customers, where permitted.
  • Public records and publicly available sources, such as property, professional, or business information.
  • Advertising, analytics, CRM, identity, fraud-prevention, and security providers that return campaign, attribution, or risk information.

5. How we use personal information

  • Provide, personalize, maintain, and support the services you request, including quotes, property/project review, contracts, work coordination, warranties, and customer support.
  • Communicate with you and honor your channel and consent preferences.
  • Facilitate a financing referral or transaction you request; lenders independently determine eligibility under their own notices and terms.
  • Operate, secure, troubleshoot, and improve our websites, systems, products, and services.
  • Measure website usage, marketing performance, and campaign attribution; create aggregate reporting; and, with required consent or where not opted out, support targeted advertising.
  • Detect, investigate, and prevent fraud, abuse, security incidents, unlawful conduct, and violations of our terms.
  • Comply with law, respond to legal process, protect rights and safety, maintain records, and establish or defend legal claims.
  • Complete a merger, financing, acquisition, reorganization, bankruptcy, or transfer of all or part of the business, subject to appropriate safeguards.

6. How we disclose personal information

Recipient categoryPurpose and data context
Service providers / processorsHosting, cloud, security, CRM, communications, support, analytics, payment, document, project-management, and professional-service providers that process information for Remi under contract.
Advertising and analytics servicesMeta, Google, HubSpot, and similar providers may receive online identifiers, internet activity, approximate location, and inferences for measurement or targeted advertising, subject to consent and opt-out choices.
Installation, project, and business partnersContractors, suppliers, referral partners, and other parties involved in estimating, scheduling, supplying, or performing requested work.
Financing and payment partnersLenders, financing platforms, and payment processors when you request financing or payment processing. Their separate notices govern information they collect directly.
Affiliates and corporate transactionsAffiliated entities and parties to a proposed or completed corporate transaction, with confidentiality and use restrictions appropriate to the transaction.
Authorities and protection of rightsCourts, regulators, law enforcement, litigants, insurers, counsel, and other parties when reasonably necessary for law, safety, security, investigation, or legal claims.
At your directionA recipient you direct us to contact or another person with your consent.

7. Sale, sharing, and targeted advertising

We do not sell personal information for money. Some state laws use “sell,” “share,” or “targeted advertising” broadly. Allowing advertising technologies such as Meta Pixel to receive online identifiers, internet activity, approximate location, or related inferences for cross-context behavioral advertising may fall within those definitions even when no money changes hands.

You may opt out by selecting “Your Privacy Choices” in the website footer, setting advertising cookies to “off,” emailing privacy@remihq.com, or using a legally recognized universal opt-out signal such as Global Privacy Control. We process a recognized signal as an opt-out for the browser or device that sends it and, when we can reasonably associate the signal with your account or profile, for that associated profile. You may need to repeat the choice on another browser or device.

We do not knowingly sell or share personal information of people under 18 or use their personal information for targeted advertising. We do not knowingly use sensitive personal information to infer characteristics or for purposes that require a “Limit the Use of My Sensitive Personal Information” link.

8. Retention

We retain personal information only as long as reasonably necessary for the purposes described below, including legal, accounting, security, contract, warranty, dispute, and fraud-prevention needs. A legal hold, active dispute, backup-restoration cycle, or statutory obligation may extend a period. When information is no longer needed, we delete, deidentify, or securely dispose of it. Deidentified information is maintained without attempting to reidentify it except as permitted by law.

Record or systemRetention standard
Consent, opt-out, and suppression records5 years after the last preference; a minimal suppression record may be kept longer to continue honoring an opt-out.
Raw website and security logs90 days, unless needed for an incident, fraud investigation, legal claim, or legal hold.
Google Analytics 414 months for event- and user-level data under Remi’s setting; aggregate reports may remain without direct identifiers.
PostHog analytics / replay12 months for product analytics. Session replay is disabled; if later enabled with consent, maximum 30 days.
Meta advertising / attributionTarget 180 days in Remi-controlled audiences and reporting; provider-side retention is governed by provider terms and settings.
HubSpot anonymous visitor / lead history24 months after last interaction, unless associated with an active customer or required suppression record.
Quote requests and abandoned leads24 months after last meaningful interaction, unless a longer period is needed for a complaint, consent record, fraud prevention, or legal claim.
Customer, project, contract, and warranty recordsFor the relationship or warranty term, then generally 7 years, or longer if required by contract or law.
Financing referral and status records24 months if no transaction results; generally 7 years if associated with a completed transaction or legal/accounting obligation.
Payment and accounting recordsGenerally 7 years. We retain transaction references or processor tokens, not full payment-card numbers, where feasible.
Support and routine communications3 years, unless the communication is part of a customer/project, complaint, legal, or security record with a longer period.
Privacy requests and verificationAt least 24 months, and longer only if needed to demonstrate compliance or resolve a dispute.

9. Security

We use administrative, technical, and physical safeguards designed to protect personal information based on its nature and risk. These include access controls, security and privacy governance, vendor risk review, encryption where appropriate, monitoring, incident response, and deletion requirements. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe information you provided to us is at risk, contact privacy@remihq.com promptly.

10. Your privacy rights

Subject to applicable law and exceptions, we offer the following rights to U.S. residents. Some rights are provided voluntarily in states that do not require them.

RightWhat it means
Know / accessConfirm whether we process your personal information and obtain access to it, including categories, sources, purposes, and recipient categories where required.
CorrectCorrect inaccurate personal information, considering the nature and purpose of the information.
Delete / be forgottenAsk us to delete personal information about you. We may retain information needed for a legal exception, such as a contract, warranty, security, legal obligation, or claim.
PortabilityReceive certain information you provided to us in a portable and, where feasible, readily usable format.
Opt outOpt out of sale, sharing, targeted advertising, and certain profiling that produces legal or similarly significant effects, as applicable.
Limit / withdraw consentLimit certain uses of sensitive personal information and withdraw consent for consent-based processing, where applicable.
List of third partiesIn states that require it, request a list of specific third parties or categories of third parties to which we disclosed personal information.
AppealAppeal our refusal to act on a request. If an appeal is denied, we will explain how to contact the appropriate state attorney general when required.
Non-discriminationReceive equal service and pricing and not be retaliated against for exercising a privacy right, subject to lawful differences reasonably related to the value of data.

11. How to make a request

Email privacy@remihq.com to connect with our DPO and state the right you want to exercise. You may also use the “Your Privacy Choices” link in our website footer or our Privacy Request form. If the CCPA applies to Remi, you may also call 916-999-7497.

Please provide enough information to locate relevant records, such as your name, email address, phone number, property/service address, and the nature of your relationship with Remi. Do not send identity documents unless we specifically request them through a secure channel. We verify requests using information already associated with the record and request only what is reasonably necessary. If we cannot verify a request, we may limit our response as permitted by law.

We generally respond within 45 days. We may extend once when reasonably necessary and permitted, and we will notify you of the reason. We will respond to an appeal within the period required by your state. Requests are ordinarily free; we may charge or decline only when the law permits, such as for manifestly unfounded, excessive, or repetitive requests.

An authorized agent may submit a request where permitted. We may require proof of the agent’s authority and may ask you to verify your identity or confirm the request directly. A parent or legal guardian may submit a request for a minor.

12. Cookies, consent, and universal opt-out signals

We group website technologies into strictly necessary, analytics, functionality, and advertising categories. Strictly necessary technologies support security, forms, preference storage, and core site operation. Analytics, session-replay, and advertising technologies are disabled until the required choice is made. You can change a choice at any time through “Your Privacy Choices.” Withdrawing consent does not affect processing that occurred lawfully before withdrawal.

We honor Global Privacy Control and other universal opt-out mechanisms required by applicable law. Browser “Do Not Track” settings do not have a single legally standardized meaning; except where treated as a legally recognized opt-out signal, we do not respond to them. Blocking all cookies may affect website features.

13. Children and teens

Our services and website are not directed to children. We do not knowingly collect personal information online from children under 13 without verifiable parental consent as required by the Children’s Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506 and 16 C.F.R. part 312. We do not knowingly sell or share personal information of people under 18 or process it for targeted advertising. If you believe a minor submitted information, email privacy@remihq.com so we can review and delete it as appropriate.

14. Communications choices

You may unsubscribe from marketing emails using the link in the message. You may opt out of marketing texts by replying STOP or following the instructions in the message. Transactional or service communications may continue when necessary for a request, contract, project, warranty, security, or legal obligation. Privacy choices for cookies and targeted advertising are separate from consent to receive calls, texts, or emails.

15. Third-party services

Our website may link to or embed services operated by others, including lenders, payment processors, maps, social-media platforms, and recruiting providers such as BambooHR. Their privacy notices govern information they collect for their own purposes. We encourage you to review those notices. Remi is not responsible for a third party’s independent privacy practices.

16. Changes to this Policy

We may update this Policy to reflect changes in law, technology, vendors, or our practices. We will post the revised version and update the effective date. If required, we will provide additional notice or obtain consent before materially different processing. Prior versions may be requested from privacy@remihq.com.

17. Contact us

18. State-specific supplements

These supplements apply only when the cited law applies to Remi and the person or processing at issue. They add to, and do not reduce, the national rights described above. Thresholds, exemptions, and definitions vary; Remi will evaluate applicability annually and when practices materially change.

California

The California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), Cal. Civ. Code §§ 1798.100–1798.199.100, provides rights to know/access, correct, delete, portability, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive nondiscriminatory treatment. California’s online-policy statute is Cal. Bus. & Prof. Code §§ 22575–22579 (“CalOPPA”).

CCPA categoryExamplesPast-12-month treatment / expected use
IdentifiersName, email, phone, address, IP address, cookie and advertising IDsCollected; disclosed to service providers; shared with advertising/analytics providers where enabled
Cal. Civ. Code § 1798.80(e) customer-record informationName, address, phone, and related contact/customer recordsCollected; disclosed to service providers, project/financing partners, and at your direction
Commercial informationQuotes, services requested or purchased, project, contract, and warranty recordsCollected; disclosed to service providers and project/financing partners
Internet or electronic network activityBrowsing, page, click, interaction, referrer, performance, and security eventsCollected; disclosed to service providers; shared for advertising where enabled
Geolocation dataApproximate location derived from IP; property address supplied by youCollected; approximate location may be shared for analytics/advertising where enabled
Professional or employment-related informationCompany/business contact information; applicant data under a separate noticeCollected where provided; disclosed to relevant service providers or business partners
InferencesCampaign attribution, likely interests, service-area or company associationsCreated; disclosed/shared for analytics, routing, and advertising where enabled
Sensitive personal informationNot requested through ordinary website forms; may be unexpectedly submittedNot used or disclosed to infer characteristics or for purposes requiring a limitation link

For CCPA purposes, Remi does not sell personal information for money. In the preceding 12 months, advertising technologies may have “shared” identifiers, internet activity, approximate geolocation, and related inferences with advertising/analytics providers for cross-context behavioral advertising. Use “Your Privacy Choices,” a recognized GPC signal, or the methods in Section 11 to opt out. Remi does not knowingly sell or share personal information of consumers under 16 and applies an under-18 internal rule. Remi does not offer a financial incentive for personal information unless separate written terms are provided.

California Civil Code § 1798.83 (“Shine the Light”) may permit certain residents to request information about disclosures of personal information to third parties for their own direct-marketing purposes. Send requests to privacy@remihq.com with “California Shine the Light” in the subject line.

Comprehensive state privacy laws

Depending on applicability, residents may have rights under the following laws. Remi’s national process covers access/confirmation, correction, deletion, portability, opt-out, consent withdrawal/limitation, appeal, and nondiscrimination even where a particular statute provides a narrower set.

StateLaw and citation
ColoradoColorado Privacy Act, Colo. Rev. Stat. §§ 6-1-1301–6-1-1314; implementing rules, 4 CCR 904-3.
ConnecticutConnecticut Data Privacy Act, Conn. Gen. Stat. §§ 42-515–42-526, as amended, including Public Act 25-113 effective July 1, 2026.
DelawareDelaware Personal Data Privacy Act, 6 Del. C. §§ 12D-101–12D-111.
FloridaFlorida Digital Bill of Rights, Fla. Stat. §§ 501.701–501.722; limited statutory scope and thresholds apply.
IowaIowa Consumer Data Protection Act, Iowa Code ch. 715D.
IndianaIndiana Consumer Data Protection Act, Ind. Code art. 24-15.
KentuckyKentucky Consumer Data Protection Act, KRS §§ 367.3611–367.3629.
MarylandMaryland Online Data Privacy Act, Md. Code, Commercial Law §§ 14-4601–14-4613.
MinnesotaMinnesota Consumer Data Privacy Act, Minn. Stat. §§ 325M.10–325M.21.
MontanaMontana Consumer Data Privacy Act, Mont. Code Ann. §§ 30-14-2801–30-14-2817, as amended.
NebraskaNebraska Data Privacy Act, Neb. Rev. Stat. §§ 87-1101–87-1130.
New HampshireNew Hampshire privacy law, N.H. Rev. Stat. Ann. §§ 507-H:1–507-H:12.
New JerseyNew Jersey Data Privacy Act, N.J.S.A. §§ 56:8-166.4–56:8-166.19.
OregonOregon Consumer Privacy Act, Or. Rev. Stat. §§ 646A.570–646A.589.
Rhode IslandRhode Island Data Transparency and Privacy Protection Act, R.I. Gen. Laws §§ 6-48.1-1–6-48.1-10.
TennesseeTennessee Information Protection Act, Tenn. Code Ann. §§ 47-18-3301 et seq.
TexasTexas Data Privacy and Security Act, Tex. Bus. & Com. Code ch. 541.
UtahUtah Consumer Privacy Act, Utah Code §§ 13-61-101–13-61-404.
VirginiaVirginia Consumer Data Protection Act, Va. Code §§ 59.1-575–59.1-585.

Universal opt-out signals and appeals

Where required—including under applicable laws in California, Colorado, Connecticut, Delaware, Montana, New Jersey, Oregon, and Texas—we process legally recognized universal opt-out signals for sale, sharing, or targeted advertising. Other state requirements may become effective or be amended over time, and Remi applies the same control nationally where feasible. If we deny a request, reply to our decision or email privacy@remihq.com with “Privacy Appeal.”

Minnesota and Oregon transparency rights

Minnesota residents may request information about profiling decisions and challenge certain profiling outcomes as provided by Minn. Stat. §§ 325M.10–325M.21. Oregon residents may request, where required, a list of the specific third parties to which we disclosed personal data under Or. Rev. Stat. §§ 646A.570–646A.589. Use the process in Section 11.

Nevada

Nevada Revised Statutes §§ 603A.300–603A.360 require certain website operators to provide notices and a process to opt out of a defined category of sale. Remi does not sell covered information for monetary consideration as defined by Nevada law, but Nevada residents may submit a verified opt-out request to privacy@remihq.com. If Remi ever collects “consumer health data” covered by Nevada Revised Statutes §§ 603A.400–603A.490, a separate Consumer Health Data Privacy Policy and applicable consent/authorization process will be provided.

Washington consumer health data

Remi does not intend to collect consumer health data through the public website. Washington’s My Health My Data Act, RCW ch. 19.373, can apply broadly to information linked to health status or an attempt to seek health services. If covered consumer health data is unexpectedly received, Remi will restrict its use and provide rights, consent, deletion, and a separate policy as required. Do not submit health information in website forms.

Biometric information

Remi does not use the public website to collect biometric identifiers for identification. Before implementing facial geometry, voiceprints, fingerprints, or similar identifiers, Remi will complete a privacy impact assessment and implement any required notice, written consent, retention/destruction schedule, security, and vendor controls under laws such as the Illinois Biometric Information Privacy Act, 740 ILCS 14/1 et seq.; Texas Business & Commerce Code § 503.001; and Washington RCW ch. 19.375.

Vermont future readiness

Vermont Act 145 (2026), codified at 9 V.S.A. ch. 61A, §§ 2415a et seq., was enacted June 16, 2026 and is scheduled to take effect January 1, 2028. Remi will reassess applicability and update this Policy and operational controls before that date.

States without a comprehensive consumer privacy statute

Even where a state does not currently have a generally applicable comprehensive consumer privacy statute, sectoral, website, security, interception, biometric, consumer-health, marketing, records-disposal, and breach-notification laws may apply. Remi extends the national rights and controls in this Policy where feasible, subject to verification and legal exceptions. All 50 states have breach-notification requirements; Remi’s incident-response process evaluates the law of each affected resident.