HVAC Estimators ("we," "us," or "our") operates the website hvacestimators.net (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Service. Please read this policy carefully. By using the Service, you consent to the data practices described in this policy.
1. Information We Collect
We collect the following categories of information:
a) Information You Provide Directly
- Account Information: When you register, we collect your email address and an optional display name. If you sign in via a third-party provider (e.g., Google), we receive your name and email from that provider.
- HVAC Project Submissions: ZIP code, project type (new installation, replacement, or repair), total cost, labor cost, material cost, project date, equipment details (brand, model number, serial number, tonnage, SEER rating, HSPF, EER, refrigerant type, voltage, amperage, breaker size, airflow CFM), and optional notes.
- Contractor Profile Information: Company name, account type (contractor or residential), and phone number.
- Contact Form Submissions: Name, email address, and message content when you use our contact form.
- Waitlist Sign-ups: Email address and ZIP code when you sign up to be notified about pricing data in your area.
b) Information Collected Automatically
- Usage Data: Pages visited, features used (searches performed, submissions created, brand comparisons viewed), timestamps, and referral source.
- Device Information: Browser type and version, operating system, screen resolution, and device type (mobile or desktop).
- Log Data: IP address, access times, and error logs for debugging and security monitoring.
2. How We Use Your Information
- Provide the Service: Display aggregated HVAC pricing data, enable price comparisons by ZIP code, and allow you to manage your submissions.
- Generate API Keys: For contractors, we generate and store hashed API keys to authenticate programmatic submissions.
- Improve the Service: Analyze usage patterns, identify popular features, and fix bugs.
- Communicate: Respond to your contact form inquiries and send transactional emails related to your account (e.g., password resets, email verification).
- Security: Detect and prevent fraud, abuse, and unauthorized access through rate limiting and authentication.
- Legal Compliance: Comply with applicable laws and respond to legal requests.
3. How Your Data Is Shared
a) Public Data
HVAC pricing submissions (ZIP code, project type, costs, equipment details, and notes) are displayed publicly in aggregated form to help homeowners and contractors compare pricing. Your personal identity (name, email) is never attached to public submissions.
b) We Do NOT Sell Your Data
We do not sell, rent, or trade your personal information to third parties for marketing or any other purpose.
c) Service Providers
We use the following third-party services to operate the Service. These providers have access to your data only as necessary to perform their functions:
- Hosting & Database: Our backend infrastructure stores your account and submission data with encryption at rest and in transit.
- Analytics: We use Vercel Analytics to track page views and feature usage. No personally identifiable information is sent to analytics.
- Error Monitoring: We use Sentry to capture and diagnose application errors. Error reports may include anonymized request data but not personal information.
- Advertising: We use Google AdSense to display advertisements on this Service. Google, as a third-party vendor, uses cookies to serve ads based on your prior visits to this website and other sites on the Internet. Google's use of advertising cookies enables it and its partners to serve ads based on your visit to our Service and/or other sites on the Internet. You may opt out of personalized advertising by visiting Google Ads Settings.
d) Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4. Data Security
We implement industry-standard security measures to protect your information:
- All data is encrypted in transit (TLS/HTTPS) and at rest.
- API keys are hashed using SHA-256 before storage; plain-text keys are never persisted.
- Row-Level Security (RLS) policies ensure users can only access and modify their own data.
- Rate limiting prevents abuse (maximum 10 submissions per 24-hour period per user).
- Authentication tokens are managed securely with automatic expiration.
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
5. Data Retention
We retain your account information and submissions for as long as your account is active or as needed to provide the Service. If you delete your account, your profile data will be removed. Pricing submissions you contributed may remain in aggregated, anonymized form to maintain the integrity of community data.
6. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Update or correct inaccurate information via your account settings.
- Deletion: Delete your submissions through the dashboard, or request full account deletion by contacting us.
- Portability: Request your data in a machine-readable format.
- Objection: Object to certain data processing activities.
To exercise these rights, contact us at hello@hvacestimators.net.
7. Cookies & Local Storage
We use cookies and browser local storage to:
- Maintain your authenticated session so you don't have to log in on every page.
- Remember your preferences (e.g., theme settings).
- Collect anonymous analytics data to understand how the Service is used.
- Serve relevant advertisements through Google AdSense. These cookies allow Google and its partners to show you ads based on your browsing history on this and other sites.
You can disable cookies in your browser settings, but some features of the Service may not function properly without them. To opt out of interest-based advertising by Google, visit Google Ads Settings or aboutads.info.
8. Children's Privacy
The Service is not intended for individuals under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.