Truss

Privacy Policy

Last updated September 29, 2026

This policy explains what Truss (TheRoofingCRM) collects, why we collect it, who can see it, and how to ask us to change or delete it. It covers the contractor workspace at myroofingtools.com and the public links you send to homeowners.

Who this is for

Truss is a contractor operating system. Your company creates a workspace, invites seats, and keeps a job book: leads, homeowners, estimates, invoices, photos, texts, mail, and the calendar.

For your company’s account, billing, and seat logins, we decide how that information is used. For the homeowner and job records you type in or upload, your company is the business that owns that book. We host it so you can run the job. You are responsible for telling homeowners why you have their information and for having a reason to text, email, or photograph them.

Information we collect

We collect what you and your teammates put in Truss, what is needed to sign you in, and a small amount of technical data so the product stays up.

  • Account: name, email, password (stored by our auth provider), title, role, company name, and optional phone, photo, and email signature.
  • Job book: contacts, leads, jobs, estimates, invoices, expenses, payments, tasks, notes, calendar events, training progress, and company files.
  • Field media: job photos, receipts, logos, and other files you upload. Photo storage is built so a deleted shot can be restored; do not upload anything you cannot keep.
  • Field location: the last GPS ping from a signed-in phone (storm mode) or the desk map, so the office can see where the crew is. Homeowners do not see those dots.
  • Messages: SMS and iMessage threads you send or receive through the connected text provider, plus Gmail you connect and mail Truss sends on your behalf.
  • Payments: checkout and deposit status through Stripe. We do not store full card numbers.
  • Public activity on a digital card: anonymous opens and taps (call, text, email, site, payment) so the office can see which card was used. Link-preview crawlers are filtered out.
  • E-sign trail on a proposal: IP address, device, the unique link, consent, and a hash of the document. That certificate is office-only.
  • Technical: sign-in session, browser local data (for example your Home layout), basic server logs, and Microsoft Clarity recordings of how pages are used.

How we use it

We use this information to run Truss for your company: sign-in, the job book, sharing a proposal or invoice, sending a text or email you asked us to send, card payments you start, QuickBooks posting you approve, EagleView orders you place, and reminders such as a task that is due.

If you use Ask Cassio, the question and the records needed to answer it are sent to the language-model provider configured on the host so the assistant can act in your book. Do not paste secrets you do not want a model to see.

When we share it

We do not sell your job book. We share information with the services that actually move the work, and only as needed:

  • Supabase — sign-in, database, and realtime updates.
  • Backblaze B2 — file and photo storage.
  • Stripe — card checkout and deposits.
  • Photon — outbound texts for each office's project.
  • Resend — estimate, invoice, invite, and other product email (from no-reply@trockroofer.com).
  • Google — Calendar and Gmail if a seat connects their Google account.
  • QuickBooks Desktop — via the Web Connector when you approve a push.
  • EagleView — when you order or pull a roof report.
  • OpenAI or Anthropic — only when someone uses the assistant.
  • Microsoft Clarity — page usage and session recordings so we can see how the product is used.

Public and guest links

A share link for an estimate, invoice, Page, or portal shows the homeowner only that document. They do not get a CRM login. A public digital card shows the name, title, photo, and contact paths you put on the card.

Anyone with the link can open it. Treat those URLs like a document you handed over. You can expire or replace a link from the job.

Cookies and local storage

Truss uses a sign-in cookie so you stay logged in, local storage for things like your Home module layout, and Microsoft Clarity to record how pages are used. See the Cookie Policy for the short list. We do not run advertising pixels.

Retention and deletion

Your company controls the job book. Company admins can remove seats, soft-delete jobs, and take down a card. Closing the company or asking us to delete an account removes the workspace we host for you, subject to backups and records we must keep for security, billing, or law.

Job photos are stored so a trash action can be undone. If you need a file gone from storage, write us and we will confirm what the bucket still holds.

Your choices

You can update your profile in Truss, disconnect Google, turn off a calendar share, and unsubscribe from marketing mail with the link on that message.

If you are in a place that grants access, correction, or deletion rights, email us. We will need enough detail to find the right company and seat. Homeowners should start with the contractor who collected their information; we will help that company if they ask.

Children

Truss is a business tool. It is not directed at children under 16. Do not create a seat for a child.

Security

Each company’s book is separated in the database. Seats see what their role allows. Login As is an office tool: it lets an allowed admin work as another seat inside the same company. It is not a way to open another contractor’s book.

Changes

If we change this policy in a way that matters, we will update the date at the top of the page. Keep using Truss after that date means you have seen the new policy.

Questions: privacy@trockroofer.com