Privacy Policy
In effect from September 28, 2026. Version 2026-09-28.
PermitBot is software that roofing contractors use to run their jobs. This page says what information it holds, who else can touch it, and what you can do about it. It describes what the product actually does — if a practice is not described here, it is because the product does not do it.
Who we are
PermitBot is operated by River Marketing Inc., a company registered in California, United States. The product is at https://crm.thepermitbot.com.
Write to us about anything on this page at privacy@thepermitbot.com, or by post:
River Marketing Inc.1507 E Jefferson Wy, Apt 110
Simi Valley, CA 93065
United States
The two relationships on this page
Most of the personal information inside PermitBot is not about our customers. It is a contractor’s record of their customers: a homeowner’s name and address, the photographs of their roof, the contract they signed. That homeowner never visited this site and has no account here. So there are two different relationships, and almost everything below depends on which one you are in.
- You and us. You are reading this site, or you hold an account in an organisation that uses PermitBot. We decide what is collected and why, and this policy is our answer for it.
- A contractor and their customer. A contractor puts a homeowner’s details into their own organisation. They decide what is collected and why. We hold it and act on their instructions, and we do not use it for any purpose of our own.
If you are a homeowner and a roofing company keeps your details here: the company you hired is the one to ask. They can correct or delete your record themselves, in the product, on the same day. If you do not know who to ask, or they will not answer, write to privacy@thepermitbot.com and we will pass the request on and help them carry it out. We will not change or delete a contractor’s records on our own initiative, because they are that company’s books, not ours — unless the law requires us to.
What is collected
| Category | What it is | Where it comes from |
|---|---|---|
| Account information | Name, email address, hashed password, role in the organisation, and sign-in times. | Given by the account holder when they register or are invited. |
| Business information | Company name, contractor licence number and type, EIN, and insurance, bond and workers' compensation policy numbers. The EIN and the three policy numbers are encrypted at rest; the licence number is not, because it is printed on quotes, permits and exports and is a matter of public record with the CSLB. | Entered by the organisation in its own settings. |
| The organisation's own customer records | Homeowner names, phone numbers, email and street addresses, job photographs, contracts, permits and signatures. | Entered or uploaded by the organisation. This is the organisation's data about its own customers; the organisation decides what is collected and why. |
| Field worker records | Name, mobile number, an access code, and the time they last used it. | Entered by the organisation for the crew on its jobs. |
| Signing records | When a homeowner signs a document, the signature image, the time, and the IP address the signature came from. The IP address appears in the contract dossier the organisation can export. | Captured at the moment of signing. It is what makes the signature evidence of who signed and when, which is the point of keeping it. |
| Location, when a crew member agrees to share it | When a crew member opens the field portal, the phone's position is used to put the nearest jobs first. If they agree to share it with the office, the portal sends the position again every few minutes while it is open on screen, and the latest position, the time and the job they last opened are stored and shown on the organisation's crew map, together with whether that position is at one of the organisation's jobs. Only the latest position is kept, overwritten each time, never a history; nothing is collected while the portal is closed; and stopping sharing removes the stored position. | The browser, and only after the person allows it. The portal explains what is sent and why before anything is stored, reminds them once a day while they share, and lets them stop at any time. Precise geolocation is a sensitive category under the CCPA, which is why it is described here in full. |
| Technical information | Pages viewed and performance timings, collected without cookies. Server error records, which keep the failing page and a reference number. | Collected automatically when the product is used. |
Four things in that table are worth saying in full.
- An enquiry you send us. If you write to us through a contact form on our website or the “Contact / Report a bug” form inside the product (which also sends the address of the page you were on, and any screenshots you choose to attach), answer our questionnaire about how you get permits, or leave your details at the end of one of our games, your name, email address, phone number and message (for the questionnaire, your answers and your company name; for a game, which story or jobs you played, how it went and your business name) are sent to our own inbox as an email. They are not saved into the product’s database. While the form is open we count recent submissions per internet address in the server’s memory, to slow down automated abuse; that count is discarded within the hour and never written down. (src/app/api/contact/route.ts, src/components/SupportButton.tsx, src/lib/supportAttachments.ts, src/app/survey/SurveyClient.tsx, src/app/game/GameClient.tsx, src/app/play/PlayClient.tsx)
- Signing a document as a homeowner. When you sign a contract or a form through a link a contractor sent you, we store your signature, anything you typed on the form, the time, and the internet address the signature came from. The address is kept as evidence that the signature was really made, and it appears in the paperwork the contractor can print. (src/app/api/projects/[id]/signature/route.ts)
- The field portal on a phone. When a crew member opens the field portal, the browser asks their permission to share their location, and the portal first tells them what happens to it. The position is always used to put the nearest jobs first. If they also agree to share it with the office, the portal sends it again every few minutes while it is open on screen, and we store their latest position, the time, and the job they last opened, and show them on the organisation's crew map to the people who schedule crews, including whether that position is at one of the organisation's jobs. Only the most recent position is kept, overwritten each time, not a history of movements. Nothing is collected while the portal is closed. While they share, the portal reminds them once a day; they can stop at any time from the Jobs screen, and stopping removes the stored position. Refusing costs them nothing: the jobs are simply listed without the office seeing where they are. (src/app/api/field/locate/route.ts, src/app/api/field/position/route.ts, src/lib/fieldLocation.ts, src/components/field/FieldLocationNotice.tsx)
- When a page breaks. The error screen shows a reference number. We record that number with the failing address, the error message and — when we can tell — which account and organisation hit it, so that a support call can find the cause. Those records are deleted after 30 days. (src/lib/errorEvents.ts)
What it is used for
- Running the product: showing an organisation its own jobs, customers and files.
- Signing you in, and sending the code that confirms it is you.
- Sending the transactional email the product depends on: invitations, password resets and sign-in codes.
- Answering support requests, and finding the cause of a fault you report.
- Keeping the service secure and available, and detecting abuse.
We do not use any of it to build a profile of you, and we do not use one organisation’s records to do anything for another.
Every email we send an account holder is one of those: a sign-in code, a password reset, an invitation, a confirmation that an address changed. We do not send you marketing, and there is no list to be added to — which is also why there is no unsubscribe link on them. They stop when the account is closed.
Cookies
There are three, and no others. All three are strictly necessary: each one exists so that signing in works, and switching any of them off would break it. None of them are used for advertising, and none of them follow you to another website.
| Cookie | What it does | How long it lasts | Strictly necessary |
|---|---|---|---|
authjs.session-token | Keeps you signed in. Without it every page would ask for your password again. | Up to 7 days | Yes |
rc_td | Remembers a device you chose to trust, so a sign-in code is not emailed on every visit from it. | 30 days | Yes |
rc_2fa | Carries the fact that you just entered a correct sign-in code, for the few seconds between entering it and being signed in. | Minutes | Yes |
Because there is nothing here to consent to beyond making sign-in work, there is no cookie banner. If we ever add a cookie that is not strictly necessary, this table changes and so does that answer.
How we measure use of the site
We count page views and page-load timings through our hosting provider’s analytics. It sets no cookies and does not identify you; it tells us that a page was slow or that a screen is never opened. There is no third-party analytics or advertising script anywhere in the product.
Do Not Track, and tracking across other sites
Some browsers can send a “Do Not Track” signal. We do not respond to it, and the honest reason is that there is nothing here for it to switch off: we set no advertising or analytics cookies, we run no advertising scripts, and we do not follow anyone between websites. Treating the signal as a setting would suggest there is a version of this site that does those things, and there is not.
No third party is permitted to collect personal information about your activity across other websites through PermitBot.
Who else touches it
We run this on other companies’ infrastructure, and a few services do specific jobs for us. Each one is listed with what it does and where it does it. They act on our instructions and may not use anything they see for their own purposes.
| Company | What it does for us | Where |
|---|---|---|
| Vercel Inc. | Application hosting, serverless functions, file storage, and cookieless page-view analytics. | United States (functions pinned to San Francisco) |
| Prisma Data Platform | The PostgreSQL database holding every record in the product. | United States (us-west-1) |
| Brevo (Sendinblue) | Sends transactional email: invitations, password resets, and sign-in codes. | European Union |
| GitHub, Inc. | Holds the nightly off-site backup. Rows leave the database as an archive here every night and files weekly — deliberately, because a backup stored beside the thing it protects is not a backup. | United States |
| Google LLC (Gemini API) | Reads uploaded documents to extract fields, drafts quote text, and generates roof visualisations. It receives the specific document or photo involved in that request. | United States |
Two of those deserve a sentence more. Our email provider receives the address and name of the person a message is going to, because that is what sending it requires. The Gemini service receives only the material involved in the request being made: the invoice or receipt being read, the photograph being visualised, the quote being drafted, or the records the in-product assistant looked up to answer a question that was asked of it. Nothing is sent to it in the background, and no request happens without somebody in the product asking for it. (src/lib/assistant/chat.ts, src/app/api/extract-invoice/route.ts, src/app/api/sales/visualize/route.ts)
A small number of people at River Marketing Inc. hold a platform-administrator account. It can see the list of accounts and organisations, the billing records and the error log, and the people who operate the service can reach the database itself when a fault requires it. That access exists so that faults can be fixed and accounts supported, and it is not used for anything else.
We will also disclose information where the law requires it of us, and no further.
What we never do
- No payment card details are collected or stored. The product has no payment processor connected.
- No advertising or tracking cookies are set, and no data is shared with advertising networks.
- Personal information is not sold, and is not shared for cross-context behavioural advertising.
Messages sent through PermitBot
The product can prepare a WhatsApp message about a job — an inspection date, a permit, progress photographs. It does not send it. It composes the text and opens it in the sender’s own WhatsApp, with the recipient and the message already filled in, and a person presses send. The message therefore comes from the contractor’s own number and the contractor is the sender of it. We have no WhatsApp account in this, see no reply, and hold no record of what was sent. (src/lib/whatsapp/link.ts, src/components/whatsapp/ShareToWhatsApp.tsx)
Getting a homeowner’s agreement to be messaged is the contractor’s responsibility, and our terms say so.
Payment cards
There is no payment processor connected to PermitBot. Plans and subscriptions exist inside the product as records; no card number, expiry date or bank detail is ever asked for, sent or stored here, so there is none to lose.
Where it is kept, and for how long
- The database and the files are in the United States. Our email provider is in the European Union, so an address we send a message to reaches the EU on its way out.
- An organisation’s records — its jobs, customers, photographs and documents — are kept for as long as that organisation has an account, and deleted when it asks us to delete them. A closed account is kept 30 days so it can still be retrieved, then erased: the records, the files in storage, and the logins that belonged to nobody else. (src/lib/tenantErasure.ts)
- Error records are deleted after 30 days.
- We take a backup every night and keep the off-site copies for up to 90 days. Deleting a record removes it from the product immediately; the copies that already exist roll off on that schedule.
Seeing, correcting and deleting your information
Where the product lets you do it yourself, that is the fastest route.
- If you hold an account: open My Account in the product. Your name, email address, role and organisation are shown there, and you can change your email address and your password on that screen. For anything else — including your name — ask an administrator in your organisation, or write to us and we will correct it.
- If you run an organisation: the records are yours to edit and delete in the product, and an owner can download the whole organisation as one file from Settings — every client, project, invoice, payment and file reference in it.
- If you are a homeowner in a contractor’s records: ask that contractor, or write to us and we will route it to them, as described at the top of this page.
- Anything else: email privacy@thepermitbot.com with enough detail for us to find the record. We reply within 45 days. To make sure we are not handing your information to somebody else, we answer an account holder at the email address on the account, and we confirm a homeowner’s request with the contractor whose records it is in.
Your rights under California law
California’s Consumer Privacy Act gives residents the right to know what is held about them, to have it corrected, to have it deleted, to opt out of its sale or of its sharing for cross-context behavioural advertising, and not to be treated worse for asking. We honour all of those, by the routes in the section above. The opt-outs have nothing to act on: we do not sell personal information and we do not share it for advertising.
On the law’s own terms, River Marketing Inc. is below the thresholds that make a business subject to that Act — annual gross revenue above $25 million as adjusted for inflation, the personal information of 100,000 or more California consumers or households, or half of its revenue from selling or sharing personal information. We are stating that plainly rather than claiming a coverage we do not have or hiding behind one we might. If we cross a threshold, those obligations attach to us and this page will say so; the rights above are honoured either way, today.
The exemption that once kept business contacts out of that Act has expired, so somebody whose details are here because they work for a company — a supplier, a permit runner, a partner — has the same rights as anyone else.
If information is lost or exposed
California law (Civil Code §1798.82) requires anyone holding a Californian’s personal information to tell them if it is taken by somebody who should not have it, and there is no minimum size below which that stops applying. If it happens here, we will tell the affected people without unreasonable delay, and say what was taken and what we have done about it. Where the information belongs to a contractor’s customers we will tell the contractor immediately, because it is their notice to give and their customers to reach — and we will help them give it.
Security
Passwords are stored as one-way hashes and are never readable, by us or by anybody else. Traffic is encrypted in transit. Sign-in can require a code sent to your email address, and it does for accounts created since September 2026. Inside an organisation, what each person can see is decided by their role and by the specific permissions an administrator has given them, and a crew member’s access code can be switched off in a moment.
One thing is worth knowing rather than discovering: job photographs and permit documents are stored at long, unguessable web addresses that work for anyone holding the link. That is deliberate — those links are sent to homeowners who have no account, and a link that stops working is a support call. Contracts, signed documents, receipts and exports are not handled that way: the product serves those only to someone signed in who is allowed to see them. (src/lib/blobPolicy.ts)
Children
PermitBot is a tool for businesses. It is not directed at children, we do not knowingly collect information from anyone under 16, and there is nothing in it that a child would have reason to use.
Changes to this policy
When this policy changes in substance, we change the version and the date at the top of the page and email the administrator of every organisation with an account, at the address on that account, before the new version takes effect. A correction to a typo does not get a new version — asking people to re-read the same document for a comma is how they learn to stop reading it. The version in effect is always the one shown at the top of this page.
How to reach us
Email privacy@thepermitbot.com for anything about this policy, or support@thepermitbot.com for help with the product. By post:
River Marketing Inc.1507 E Jefferson Wy, Apt 110
Simi Valley, CA 93065
United States
Our Terms of Service cover what an organisation using PermitBot is responsible for, including the information it collects about its own customers.