Remi Labs, Inc. (“Remi,” “Remi HQ,” “we,” “us,” or “our”)
Effective date: July 16, 2026
This Privacy Policy explains how Remi collects, uses, discloses, and retains personal information when you visit remihq.com, request a quote, contact us, interact with our marketing, or otherwise use a service that links to this Policy. It also explains the choices and rights available to you and how to contact our Data Protection Officer (“DPO”).
This Policy does not govern information processed solely on behalf of a business customer under a contract, employee information covered by an internal notice, or job-applicant information covered by a separate applicant notice. A third-party lender, financing platform, contractor, or website may provide its own notice and act as a separate business or controller for information it collects directly.
For the activities described in this Policy, Remi generally determines why and how personal information is processed and therefore acts as a “business” or “controller” under applicable U.S. state privacy laws. In some business-to-business settings, Remi may instead process information under a customer’s instructions; the customer’s notice will govern that processing.
Our public website is intended for U.S. users. If you provide information about another person—such as a co-owner or household member—you should have authority to do so and should provide that person with this Policy when appropriate.
| Category | Examples | Primary uses |
|---|---|---|
| Contact and identity | Name, email address, telephone number, company name, and communication preferences. | Respond to requests; provide quotes; authenticate and route requests; communicate about services. |
| Property and project | Street address, city, state, ZIP code, property or roof details, project notes, photographs or documents you choose to provide. | Assess service availability; estimate, plan, and deliver roofing or related work; support contracts and warranties. |
| Commercial and transaction | Services requested or purchased, quote history, contract status, customer-support history, invoices, and warranty records. | Provide services; administer customer relationships; accounting; dispute, fraud, and legal compliance. |
| Financing and payment | Financing interest, referral/status information, billing details, and payment tokens or transaction references. A lender or processor may collect a full application or payment-card data directly under its own notice. | Facilitate a requested financing referral or payment; reconcile transactions; comply with accounting and legal obligations. |
| Device and internet activity | IP address, browser and device type, operating system, language, approximate location derived from IP, page URL, referrer, timestamps, pages viewed, links or buttons clicked, and interaction or performance events. | Operate, secure, debug, and improve the website; measure use; prevent fraud; obtain analytics and attribution, subject to your choices. |
| Online and advertising identifiers | Cookie IDs, consent/preference IDs, Google Analytics identifiers, Meta Pixel identifiers such as _fbp or _fbc when present, and campaign/ad identifiers. | Remember preferences; deduplicate events; measure campaigns; personalize or target advertising where permitted and not opted out. |
| Inferences | Likely interests, campaign attribution, service-area or company-domain associations, and audiences inferred from website activity or submitted information. | Understand demand, route leads, measure marketing, and tailor communications or advertising where permitted. |
| Communications | Emails, call or text records, form submissions, support messages, feedback, and any information you include. | Respond, provide support, document preferences, and resolve issues. |
| Sensitive information | We do not ask for precise geolocation, biometric identifiers, health data, account passwords, Social Security numbers, or full payment-card numbers through ordinary website forms. | If unexpectedly received, restrict use to the requested service, security, legal compliance, or deletion as appropriate. |
Our quote forms may request your first and last name, property street address, city, state, ZIP code, telephone number, and email address. A business or materials form may request company name, website, business email, and telephone number. Please do not place Social Security numbers, financial-account credentials, medical information, or other unnecessary sensitive information in free-text fields or uploaded documents.
When a tracker is allowed to run, the tracker provider ordinarily receives the network and browser data needed to deliver its script or request—for example IP address, browser/user-agent information, page URL, referring URL, time, and an event or tag identifier. Cookies or similar identifiers may allow events to be linked across visits. The table below distinguishes observed website components from optional features that require account-level confirmation.
| Service / status | Data ordinarily visible | Configuration-dependent capability and control | Proposed retention |
|---|---|---|---|
| Google Tag Manager (observed) | Loads and sequences tags. The container request exposes network/device data and the current page; the container’s own data collection depends on the tags and variables configured inside it. | Form variables, query strings, data-layer values, or custom events can be forwarded if configured. Export and review the container; prohibit raw form values and sensitive URL parameters. | Operational configuration; retain change and consent evidence for 5 years. |
| Google Analytics 4 (observed) | Page and session events, cookie/device identifier, page URL/referrer, device/browser, approximate location, and engagement/performance data. Google states IP addresses are used in transit and are not logged or stored by Analytics. | Custom dimensions, user IDs, ad signals, and detailed events only if enabled. Prohibit direct identifiers and sensitive data. | Configure event/user-data retention to 14 months and disable reset-on-new-activity unless justified. |
| Meta Pixel (observed; multiple IDs) | Page URLs, event names and time, IP address, browser/device data, Meta/cookie identifiers such as _fbp or _fbc when present, and campaign attribution. | Automatic events, clicked-element/form-submission signals, hashed email/phone through advanced matching, or server-side Conversions API data only if enabled. Inventory five observed pixel IDs, remove duplicates, and verify payloads. | Remi-controlled advertising/audience data: target 180 days; provider retention is governed by provider terms and must be confirmed. |
| HubSpot (observed) | Anonymous pageviews, IP address, cookie/online identifiers, timestamps, referral/campaign data, and device/browser information. A later form or email interaction may associate prior browsing with a CRM record. | Intent/company-domain signals, ad integrations, embedded forms, chat, and additional CRM enrichment if enabled. Disable unnecessary intent access and control cookies through the CMP. | Anonymous/lead history: 24 months after last interaction unless it becomes a customer record. |
| PostHog (code observed) | Product analytics may collect pageviews, clicks, form-submission events, device/session data, and performance information. | Session replay can capture navigation and mouse movement; console or network capture may be enabled. Replay code loaded during review, but an actual recording was not proven. Keep replay off; if re-enabled, use prior opt-in, masking, and a 30-day maximum. | Product analytics: 12 months. Session replay: disabled; 30 days maximum if approved and consented. |
| Google Maps (observed) | IP address, device/browser data, map request and usage events. If a person searches or interacts with a map, the provider may receive the location or place queried. | Precise device location only if the user separately enables location permission. Do not request precise location unless necessary and consented. | Follow provider configuration; Remi should not retain precise device location from the public site. |
| Recipient category | Purpose and data context |
|---|---|
| Service providers / processors | Hosting, cloud, security, CRM, communications, support, analytics, payment, document, project-management, and professional-service providers that process information for Remi under contract. |
| Advertising and analytics services | Meta, Google, HubSpot, and similar providers may receive online identifiers, internet activity, approximate location, and inferences for measurement or targeted advertising, subject to consent and opt-out choices. |
| Installation, project, and business partners | Contractors, suppliers, referral partners, and other parties involved in estimating, scheduling, supplying, or performing requested work. |
| Financing and payment partners | Lenders, financing platforms, and payment processors when you request financing or payment processing. Their separate notices govern information they collect directly. |
| Affiliates and corporate transactions | Affiliated entities and parties to a proposed or completed corporate transaction, with confidentiality and use restrictions appropriate to the transaction. |
| Authorities and protection of rights | Courts, regulators, law enforcement, litigants, insurers, counsel, and other parties when reasonably necessary for law, safety, security, investigation, or legal claims. |
| At your direction | A recipient you direct us to contact or another person with your consent. |
We do not sell personal information for money. Some state laws use “sell,” “share,” or “targeted advertising” broadly. Allowing advertising technologies such as Meta Pixel to receive online identifiers, internet activity, approximate location, or related inferences for cross-context behavioral advertising may fall within those definitions even when no money changes hands.
You may opt out by selecting “Your Privacy Choices” in the website footer, setting advertising cookies to “off,” emailing privacy@remihq.com, or using a legally recognized universal opt-out signal such as Global Privacy Control. We process a recognized signal as an opt-out for the browser or device that sends it and, when we can reasonably associate the signal with your account or profile, for that associated profile. You may need to repeat the choice on another browser or device.
We do not knowingly sell or share personal information of people under 18 or use their personal information for targeted advertising. We do not knowingly use sensitive personal information to infer characteristics or for purposes that require a “Limit the Use of My Sensitive Personal Information” link.
We retain personal information only as long as reasonably necessary for the purposes described below, including legal, accounting, security, contract, warranty, dispute, and fraud-prevention needs. A legal hold, active dispute, backup-restoration cycle, or statutory obligation may extend a period. When information is no longer needed, we delete, deidentify, or securely dispose of it. Deidentified information is maintained without attempting to reidentify it except as permitted by law.
| Record or system | Retention standard |
|---|---|
| Consent, opt-out, and suppression records | 5 years after the last preference; a minimal suppression record may be kept longer to continue honoring an opt-out. |
| Raw website and security logs | 90 days, unless needed for an incident, fraud investigation, legal claim, or legal hold. |
| Google Analytics 4 | 14 months for event- and user-level data under Remi’s setting; aggregate reports may remain without direct identifiers. |
| PostHog analytics / replay | 12 months for product analytics. Session replay is disabled; if later enabled with consent, maximum 30 days. |
| Meta advertising / attribution | Target 180 days in Remi-controlled audiences and reporting; provider-side retention is governed by provider terms and settings. |
| HubSpot anonymous visitor / lead history | 24 months after last interaction, unless associated with an active customer or required suppression record. |
| Quote requests and abandoned leads | 24 months after last meaningful interaction, unless a longer period is needed for a complaint, consent record, fraud prevention, or legal claim. |
| Customer, project, contract, and warranty records | For the relationship or warranty term, then generally 7 years, or longer if required by contract or law. |
| Financing referral and status records | 24 months if no transaction results; generally 7 years if associated with a completed transaction or legal/accounting obligation. |
| Payment and accounting records | Generally 7 years. We retain transaction references or processor tokens, not full payment-card numbers, where feasible. |
| Support and routine communications | 3 years, unless the communication is part of a customer/project, complaint, legal, or security record with a longer period. |
| Privacy requests and verification | At least 24 months, and longer only if needed to demonstrate compliance or resolve a dispute. |
We use administrative, technical, and physical safeguards designed to protect personal information based on its nature and risk. These include access controls, security and privacy governance, vendor risk review, encryption where appropriate, monitoring, incident response, and deletion requirements. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe information you provided to us is at risk, contact privacy@remihq.com promptly.
Subject to applicable law and exceptions, we offer the following rights to U.S. residents. Some rights are provided voluntarily in states that do not require them.
| Right | What it means |
|---|---|
| Know / access | Confirm whether we process your personal information and obtain access to it, including categories, sources, purposes, and recipient categories where required. |
| Correct | Correct inaccurate personal information, considering the nature and purpose of the information. |
| Delete / be forgotten | Ask us to delete personal information about you. We may retain information needed for a legal exception, such as a contract, warranty, security, legal obligation, or claim. |
| Portability | Receive certain information you provided to us in a portable and, where feasible, readily usable format. |
| Opt out | Opt out of sale, sharing, targeted advertising, and certain profiling that produces legal or similarly significant effects, as applicable. |
| Limit / withdraw consent | Limit certain uses of sensitive personal information and withdraw consent for consent-based processing, where applicable. |
| List of third parties | In states that require it, request a list of specific third parties or categories of third parties to which we disclosed personal information. |
| Appeal | Appeal our refusal to act on a request. If an appeal is denied, we will explain how to contact the appropriate state attorney general when required. |
| Non-discrimination | Receive equal service and pricing and not be retaliated against for exercising a privacy right, subject to lawful differences reasonably related to the value of data. |
Email privacy@remihq.com to connect with our DPO and state the right you want to exercise. You may also use the “Your Privacy Choices” link in our website footer or our Privacy Request form. If the CCPA applies to Remi, you may also call 916-999-7497.
Please provide enough information to locate relevant records, such as your name, email address, phone number, property/service address, and the nature of your relationship with Remi. Do not send identity documents unless we specifically request them through a secure channel. We verify requests using information already associated with the record and request only what is reasonably necessary. If we cannot verify a request, we may limit our response as permitted by law.
We generally respond within 45 days. We may extend once when reasonably necessary and permitted, and we will notify you of the reason. We will respond to an appeal within the period required by your state. Requests are ordinarily free; we may charge or decline only when the law permits, such as for manifestly unfounded, excessive, or repetitive requests.
An authorized agent may submit a request where permitted. We may require proof of the agent’s authority and may ask you to verify your identity or confirm the request directly. A parent or legal guardian may submit a request for a minor.
We group website technologies into strictly necessary, analytics, functionality, and advertising categories. Strictly necessary technologies support security, forms, preference storage, and core site operation. Analytics, session-replay, and advertising technologies are disabled until the required choice is made. You can change a choice at any time through “Your Privacy Choices.” Withdrawing consent does not affect processing that occurred lawfully before withdrawal.
We honor Global Privacy Control and other universal opt-out mechanisms required by applicable law. Browser “Do Not Track” settings do not have a single legally standardized meaning; except where treated as a legally recognized opt-out signal, we do not respond to them. Blocking all cookies may affect website features.
Our services and website are not directed to children. We do not knowingly collect personal information online from children under 13 without verifiable parental consent as required by the Children’s Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506 and 16 C.F.R. part 312. We do not knowingly sell or share personal information of people under 18 or process it for targeted advertising. If you believe a minor submitted information, email privacy@remihq.com so we can review and delete it as appropriate.
You may unsubscribe from marketing emails using the link in the message. You may opt out of marketing texts by replying STOP or following the instructions in the message. Transactional or service communications may continue when necessary for a request, contract, project, warranty, security, or legal obligation. Privacy choices for cookies and targeted advertising are separate from consent to receive calls, texts, or emails.
Our website may link to or embed services operated by others, including lenders, payment processors, maps, social-media platforms, and recruiting providers such as BambooHR. Their privacy notices govern information they collect for their own purposes. We encourage you to review those notices. Remi is not responsible for a third party’s independent privacy practices.
We may update this Policy to reflect changes in law, technology, vendors, or our practices. We will post the revised version and update the effective date. If required, we will provide additional notice or obtain consent before materially different processing. Prior versions may be requested from privacy@remihq.com.
These supplements apply only when the cited law applies to Remi and the person or processing at issue. They add to, and do not reduce, the national rights described above. Thresholds, exemptions, and definitions vary; Remi will evaluate applicability annually and when practices materially change.
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), Cal. Civ. Code §§ 1798.100–1798.199.100, provides rights to know/access, correct, delete, portability, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive nondiscriminatory treatment. California’s online-policy statute is Cal. Bus. & Prof. Code §§ 22575–22579 (“CalOPPA”).
| CCPA category | Examples | Past-12-month treatment / expected use |
|---|---|---|
| Identifiers | Name, email, phone, address, IP address, cookie and advertising IDs | Collected; disclosed to service providers; shared with advertising/analytics providers where enabled |
| Cal. Civ. Code § 1798.80(e) customer-record information | Name, address, phone, and related contact/customer records | Collected; disclosed to service providers, project/financing partners, and at your direction |
| Commercial information | Quotes, services requested or purchased, project, contract, and warranty records | Collected; disclosed to service providers and project/financing partners |
| Internet or electronic network activity | Browsing, page, click, interaction, referrer, performance, and security events | Collected; disclosed to service providers; shared for advertising where enabled |
| Geolocation data | Approximate location derived from IP; property address supplied by you | Collected; approximate location may be shared for analytics/advertising where enabled |
| Professional or employment-related information | Company/business contact information; applicant data under a separate notice | Collected where provided; disclosed to relevant service providers or business partners |
| Inferences | Campaign attribution, likely interests, service-area or company associations | Created; disclosed/shared for analytics, routing, and advertising where enabled |
| Sensitive personal information | Not requested through ordinary website forms; may be unexpectedly submitted | Not used or disclosed to infer characteristics or for purposes requiring a limitation link |
For CCPA purposes, Remi does not sell personal information for money. In the preceding 12 months, advertising technologies may have “shared” identifiers, internet activity, approximate geolocation, and related inferences with advertising/analytics providers for cross-context behavioral advertising. Use “Your Privacy Choices,” a recognized GPC signal, or the methods in Section 11 to opt out. Remi does not knowingly sell or share personal information of consumers under 16 and applies an under-18 internal rule. Remi does not offer a financial incentive for personal information unless separate written terms are provided.
California Civil Code § 1798.83 (“Shine the Light”) may permit certain residents to request information about disclosures of personal information to third parties for their own direct-marketing purposes. Send requests to privacy@remihq.com with “California Shine the Light” in the subject line.
Depending on applicability, residents may have rights under the following laws. Remi’s national process covers access/confirmation, correction, deletion, portability, opt-out, consent withdrawal/limitation, appeal, and nondiscrimination even where a particular statute provides a narrower set.
| State | Law and citation |
|---|---|
| Colorado | Colorado Privacy Act, Colo. Rev. Stat. §§ 6-1-1301–6-1-1314; implementing rules, 4 CCR 904-3. |
| Connecticut | Connecticut Data Privacy Act, Conn. Gen. Stat. §§ 42-515–42-526, as amended, including Public Act 25-113 effective July 1, 2026. |
| Delaware | Delaware Personal Data Privacy Act, 6 Del. C. §§ 12D-101–12D-111. |
| Florida | Florida Digital Bill of Rights, Fla. Stat. §§ 501.701–501.722; limited statutory scope and thresholds apply. |
| Iowa | Iowa Consumer Data Protection Act, Iowa Code ch. 715D. |
| Indiana | Indiana Consumer Data Protection Act, Ind. Code art. 24-15. |
| Kentucky | Kentucky Consumer Data Protection Act, KRS §§ 367.3611–367.3629. |
| Maryland | Maryland Online Data Privacy Act, Md. Code, Commercial Law §§ 14-4601–14-4613. |
| Minnesota | Minnesota Consumer Data Privacy Act, Minn. Stat. §§ 325M.10–325M.21. |
| Montana | Montana Consumer Data Privacy Act, Mont. Code Ann. §§ 30-14-2801–30-14-2817, as amended. |
| Nebraska | Nebraska Data Privacy Act, Neb. Rev. Stat. §§ 87-1101–87-1130. |
| New Hampshire | New Hampshire privacy law, N.H. Rev. Stat. Ann. §§ 507-H:1–507-H:12. |
| New Jersey | New Jersey Data Privacy Act, N.J.S.A. §§ 56:8-166.4–56:8-166.19. |
| Oregon | Oregon Consumer Privacy Act, Or. Rev. Stat. §§ 646A.570–646A.589. |
| Rhode Island | Rhode Island Data Transparency and Privacy Protection Act, R.I. Gen. Laws §§ 6-48.1-1–6-48.1-10. |
| Tennessee | Tennessee Information Protection Act, Tenn. Code Ann. §§ 47-18-3301 et seq. |
| Texas | Texas Data Privacy and Security Act, Tex. Bus. & Com. Code ch. 541. |
| Utah | Utah Consumer Privacy Act, Utah Code §§ 13-61-101–13-61-404. |
| Virginia | Virginia Consumer Data Protection Act, Va. Code §§ 59.1-575–59.1-585. |
Where required—including under applicable laws in California, Colorado, Connecticut, Delaware, Montana, New Jersey, Oregon, and Texas—we process legally recognized universal opt-out signals for sale, sharing, or targeted advertising. Other state requirements may become effective or be amended over time, and Remi applies the same control nationally where feasible. If we deny a request, reply to our decision or email privacy@remihq.com with “Privacy Appeal.”
Minnesota residents may request information about profiling decisions and challenge certain profiling outcomes as provided by Minn. Stat. §§ 325M.10–325M.21. Oregon residents may request, where required, a list of the specific third parties to which we disclosed personal data under Or. Rev. Stat. §§ 646A.570–646A.589. Use the process in Section 11.
Nevada Revised Statutes §§ 603A.300–603A.360 require certain website operators to provide notices and a process to opt out of a defined category of sale. Remi does not sell covered information for monetary consideration as defined by Nevada law, but Nevada residents may submit a verified opt-out request to privacy@remihq.com. If Remi ever collects “consumer health data” covered by Nevada Revised Statutes §§ 603A.400–603A.490, a separate Consumer Health Data Privacy Policy and applicable consent/authorization process will be provided.
Remi does not intend to collect consumer health data through the public website. Washington’s My Health My Data Act, RCW ch. 19.373, can apply broadly to information linked to health status or an attempt to seek health services. If covered consumer health data is unexpectedly received, Remi will restrict its use and provide rights, consent, deletion, and a separate policy as required. Do not submit health information in website forms.
Remi does not use the public website to collect biometric identifiers for identification. Before implementing facial geometry, voiceprints, fingerprints, or similar identifiers, Remi will complete a privacy impact assessment and implement any required notice, written consent, retention/destruction schedule, security, and vendor controls under laws such as the Illinois Biometric Information Privacy Act, 740 ILCS 14/1 et seq.; Texas Business & Commerce Code § 503.001; and Washington RCW ch. 19.375.
Vermont Act 145 (2026), codified at 9 V.S.A. ch. 61A, §§ 2415a et seq., was enacted June 16, 2026 and is scheduled to take effect January 1, 2028. Remi will reassess applicability and update this Policy and operational controls before that date.
Even where a state does not currently have a generally applicable comprehensive consumer privacy statute, sectoral, website, security, interception, biometric, consumer-health, marketing, records-disposal, and breach-notification laws may apply. Remi extends the national rights and controls in this Policy where feasible, subject to verification and legal exceptions. All 50 states have breach-notification requirements; Remi’s incident-response process evaluates the law of each affected resident.