Ridgely CRM Inc
Privacy Policy
Effective August 31, 2026 · Version 2026-08-31
This policy explains what Ridgely CRM Inc does with information when a contracting company uses Ridgely. It covers our relationship with you, the company using the software — your own customers should read the privacy policy you publish, which the app hosts for you.
Two kinds of information
Your account information — the names, work emails, phone numbers and roles of the people at your company who use Ridgely, plus your company’s own details and billing information. We hold this to run your account, and we decide how it is used.
Your business data — your customers, their addresses, the photographs of their roofs, your proposals, invoices and messages. We hold this on your behalf. You decide what goes in and what happens to it; we process it to provide the service, and for nothing else. We do not sell it and we do not use it to train anything.
What we record automatically
Some information reaches us without anyone typing it in. Every request to Ridgely arrives with an IP address and a browser and device description, and our hosting and database providers keep short-lived request logs containing them. We use these to keep the service running and secure — diagnosing faults, and rate-limiting the public parts of the app so that lead forms and proposal links cannot be hammered by a script. Those rate-limiting counters are keyed to an IP address, expire within minutes and are deleted.
Two places keep it for longer, on purpose. When someone signs a proposal we store the IP address and browser alongside the signature and a hash of the document, and we keep them for as long as the signed proposal exists — that record is what makes an electronic signature provable later, and a signature without it is worth much less to you in a dispute. We do the same when a company accepts these terms at signup, as evidence of who agreed and when.
We do not use any of this to build a profile of you, we do not combine it with information from other websites, and we do not sell or share it.
Location
Two features record where something happened, and both are worth knowing about rather than discovering.
If your company uses the time clock, Ridgely records the precise location of each punch — clock-in, the start and end of lunch, and clock-out — along with the address it corresponds to. It is recorded at the moment of the punch only; the app does not follow anyone between punches and does not run in the background. Your employer decides whether to use the time clock at all, sees this information, and is responsible for telling their staff about it. We hold it for them and use it for nothing else.
Photographs taken on a phone often carry the coordinates of where they were taken inside the image file. When a photo is uploaded to a job we read that and store it with the photo, so pictures can be tied to the right property.
Cookies
Ridgely sets three cookies. All three are necessary for the app to work, and there are no advertising, analytics or cross-site tracking cookies anywhere in the product.
| Cookie | What it does | How long |
|---|---|---|
| sb-… (Supabase auth) | Keeps you signed in and identifies your session. Without it the app cannot tell who you are. | The browser session, or about a year if you tick “Remember me”. |
| ridgely_keep_signed_in | Remembers whether you asked to stay signed in, so your session lasts the right length on that device. | About a year. |
| abrc_active_loc | Remembers which branch you last had selected, so the app opens where you left it. | About a year. It is not cleared by signing out. |
You can block or delete cookies in your browser, but the sign-in ones cannot be refused and still leave a working app — without them we have no way to tell who you are between one page and the next.
The app also keeps things in your browser’s local storage, which is not a cookie but is stored on your device just the same: unsent drafts of forms you are filling in, which columns you have chosen on a table, and whether you have dismissed a prompt. It stays on your device, is never sent anywhere for tracking, and clearing your browser data removes it.
Text messages
Texting works two ways here, and the difference matters. When your company texts your customers — appointment reminders, crew-arrival notices, proposal links — you are the sender and we are the delivery pipe. Collecting consent, honouring opt-outs and registering accurately with the carriers are your obligations, set out in our Terms of Service. We pass your message and the recipient’s number to our messaging provider to deliver it, and do nothing else with either.
We also text your own staff — work-order dispatch notices, crew links, and account or security messages — at the mobile numbers you enter for them. Message frequency varies and message and data rates may apply. Reply STOP to any of these to opt out, or HELP for help; you can also turn off notification types in the app. Agreeing to receive texts is never a condition of buying or using Ridgely, and we may still need to reach you about your account by other means.
We do not share mobile numbers, opt-in records, or consent to be texted with any third party or affiliate for their own marketing, and we never sell them. Numbers go to our messaging provider for the sole purpose of delivering the message you or your company sent.
Who else processes it
These providers handle data on our behalf so the service can work:
- Supabase — Database and account authentication
- Vercel — Application hosting
- Stripe — Subscription billing, and card payments made to your company
- Twilio — Text messages and calls sent from the app
- Resend / SendGrid — Email delivery and inbound email replies
- Google Maps — Address lookup and autocomplete
Address lookup and autocomplete are provided by Google Maps Platform. When you type an address into Ridgely, what you type is sent to Google to return suggestions, and Google’s handling of it is governed by the Google Privacy Policy, which applies to that part of the service in addition to this one.
We share what is necessary for each of them to do its job and nothing more. We will also disclose information where the law requires it, and we will tell you when we are allowed to.
Which of us is answerable
United States privacy laws divide the world into the party that decides why information is held and the party that merely holds it. For your account information we are the first — the “business” under California law, the controller elsewhere — and the rights described below are exercised against us. For your business data we are the second: a service provider acting on your instructions and no one else’s. If one of your customers or employees asks to see or delete what is held about them, the request belongs to you, and we will help you answer it. If they come to us directly we will pass them to you and tell them we have.
What we collect, by category
This table covers the information we hold as a business — about your company and the people at it who use Ridgely. It is not a list of everything in your account, because the rest of what is in there belongs to you.
| Category | What it means here |
|---|---|
| Identifiers | Name, work email address, phone number, account and company IDs, IP address. |
| Customer records | Company name, business address, billing contact, contractor licence number. |
| Commercial information | Your subscription plan, billing history, and the record of what you have bought from us. |
| Internet or network activity | Request and error logs, pages and features used, browser and device description, and whether an email we sent you was delivered. |
| Professional or employment information | Job title, role and permissions, branch assignment, whether someone is paid hourly, commission rate, and hours recorded on the time clock. |
| Geolocation dataSensitive | Approximate location from an IP address; and, where a company uses the time clock, the precise location of each clock-in, lunch and clock-out punch. |
| Account credentialsSensitive | The sign-in details for your account. Passwords are set and checked by our authentication provider; we never see or store them. |
It comes from you and from the people at your company, except for the network information, which arrives with the request itself. We disclose it for business purposes to the providers listed above and to our professional advisers, and we will disclose it where the law compels us. The two categories marked sensitive are used only to provide the service you asked for — signing you in, and recording a punch. We never use them to infer anything about anyone’s characteristics, and California’s right to limit their use is therefore already satisfied by how we work.
We do not sell personal information and we do not share it for cross-context behavioural advertising. We have never done either. There is no advertising technology in this product, so there is nothing to opt out of — and because we do not sell or share, we have no actual knowledge of selling or sharing the information of anyone under 16.
For the avoidance of doubt, we do not collect any of the following:
- Government identification numbers — no Social Security, driver's licence or passport numbers.
- Bank account or payment card numbers. Card details go directly to Stripe and never reach our servers.
- Race, ethnicity, religion, political opinions, union membership, sexual orientation, or health information.
- Biometric information, and no facial or voice recognition of any kind.
California privacy rights
If you live in California, the CCPA as amended by the CPRA gives you the right to know what we have collected about you and where it went, to get a copy of it, to have it corrected if it is wrong, to have it deleted, and to limit the use of sensitive information. You also have the right not to be treated differently for exercising any of them — we will not refuse service, change your price, or give you a worse product because you asked.
Ask at privacy@ridgelycrm.com. We will confirm who you are before we act, which usually means replying from the address already on the account; if a request is broad enough that being wrong would matter, we may ask for more. An authorised agent can act for you with written permission, and we will still verify you directly. We answer within 45 days and will tell you if we need the further 45 days the law allows.
Some rights have limits we would rather state than surprise you with. We cannot delete what we are required to keep — billing and tax records, and the evidence attached to a signed contract. And where the request concerns your own customers’ information rather than your own, it goes to the company whose account holds it.
If you live in another U.S. state
Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and a growing list of others give broadly the same rights — access, a portable copy, correction, deletion, and an opt-out of targeted advertising and profiling that has a legal or similarly significant effect. We do neither of those last two at all. Use the same address and we will handle it the same way; which rights apply depends on where you live.
Several of those states also give you the right to appeal if we turn a request down. If we do, we will say why, and you may reply to that message to appeal it. We will answer an appeal within 45 days, explain the outcome in writing, and tell you how to complain to your state Attorney General if you are still unsatisfied. Appealing costs nothing.
Where your data is held
Ridgely runs in the United States and your data is stored there. Some of the providers listed above operate globally and may process limited information — a support request, an error log — from elsewhere. Where information covered by UK or European law reaches us, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum to them, and we will send you the details on request. If you need a data processing agreement for your own compliance, ask at privacy@ridgelycrm.com and we will sign one.
Keeping it safe
Data is encrypted in transit and at rest, access is restricted to the people who need it to operate and support the service, and each company’s data is separated from every other company’s. No system is perfect; if we ever have a breach affecting your data we will tell you promptly and tell you what we know.
How long we keep it
For as long as your account is open. After you close it we keep your data for 30 days so you can export it or change your mind, and then we delete it. Billing records are kept as long as tax and accounting rules require, and backups age out on their own within a further 30 days.
Doing it yourself
Most of what the rights above describe does not need us at all. You can see, correct and export your data from inside Ridgely whenever you like, and an admin at your company can do the same for anyone on the team. Where a request needs us — deletion, or something the app will not let you reach — write to privacy@ridgelycrm.com.
Changes
If we change this policy we will post the new version here with a new effective date, and tell you if the change is material.
Children
Ridgely is software for running a business, and it is not intended for children. We do not knowingly collect information from anyone under 13, and we do not direct any part of the service at them. If you believe a child’s information has reached us, tell us at privacy@ridgelycrm.com and we will delete it.
Contact
Ridgely CRM Inc — privacy@ridgelycrm.com
543 Leisure Street, Livermore, CA 94551