What data we gather when you request a chimney pro
Booking a chimney or fireplace service through our local team requires only the essentials needed to route your request to a vetted local pro and let them complete the job: your name, the service address, a phone number for confirming the visit, an optional email if that is how you prefer to hear from us, and a brief note on what the chimney is doing. For the majority of homeowners that is the full extent of it. We never request date of birth, Social Security number, a driver license, or a card kept on file unless a specific service path genuinely demands it.
Should you apply for financing through a lending partner, the lender gathers any extra details directly from you — name, address, date of birth, Social Security number, and employment data for the credit decision. That information travels straight to the lender rather than passing through us; we neither view nor retain it. The lender's own privacy policy controls how it is handled. All we learn is whether you were approved and for how much, which lets us set the financed portion of the work.
For homeowners who have had work completed, the assigned local pro keeps a job record: visit dates, work performed, materials installed, technician notes, and completion photos. That record is what enables later warranty support and answers follow-up questions such as which liner spec was used previously. Records are kept while the customer relationship is active and for seven years past the final service date for warranty and tax purposes, after which they are purged from active systems.
How the information is used and who has access
Customer data serves a single purpose set: scheduling, performing, documenting, and following up on chimney work. We do not sell or rent customer lists and we do not hand customer data to marketing partners. Inside our local team, the people who can view a given record are the coordinators who route appointments, the local pro assigned to that specific job, the staff who process billing, and the operations lead reviewing quality. No one beyond that limited circle touches customer records.
When card or bank payments run through a processor — a PCI-compliant provider handling card-not-present transactions — that processor sees only what it needs for the individual charge. It does not receive your job history, your contact preferences, or anything else. It keeps the transaction record for the span financial rules require (generally seven years) under its own security duties.
On the public site we run Google Analytics 4 with IP anonymization plus Google Ads conversion tracking, so Google receives aggregated, anonymized visit and conversion data. Google's handling of that data is bound by its privacy policy and the data-processing terms attached to our analytics account. We send Google no personally identifiable details from customer records, and we have enabled no user-level or device-graph linking that would tie analytics back to a named individual.
Your privacy choices and how to use them
As our customer, you may ask what information we hold about you, ask us to correct anything inaccurate, and ask us to delete data no longer needed for its original purpose. Send a written request (email works) to the contact address in this policy. We answer verified requests within thirty days. Verification simply means confirming you are the person the data concerns, which we do by matching your request to the record using details only you would know.
Florida law (and many state laws) gives you the right to opt out of the sale of personal information. Because we do not sell personal information at all, there is nothing here to opt out of. If you ever suspect data you gave us reached an unauthorized third party, send us the specifics and we will look into it. Across every customer relationship so far, no such event has happened, and we treat any such concern as a priority.
You can leave marketing communications whenever you wish. Emails from us — usually appointment reminders, follow-ups, or the occasional update — carry an unsubscribe link that takes effect immediately. Texts (sent only for live appointment coordination, never marketing) accept a STOP reply to opt out. Our calls are limited to confirming or rescheduling booked work; we place no outbound sales or telemarketing calls.
Security, retention, and our breach response
Customer data lives on infrastructure run by established hosting providers (currently Vercel for the site and a managed Postgres database, both encrypted in transit and at rest) and in cloud productivity tools (currently a business email suite for customer correspondence). Access runs through individual staff accounts that all require two-factor authentication, and the operations lead reviews access logs on a regular cadence for anything unusual.
Retention tracks operational need: active customer records persist while the relationship is active, financial records stay for the seven years tax rules require, and consented marketing lists remain until you opt out. When data is removed, it is removed from active storage and from backups on a documented schedule. The seven-year financial window is a legal floor, not a goal — we delete records as soon as they are no longer needed past it.
If a breach ever affected personally identifiable information of our customers, our process is to contain it within twenty-four hours of detection, scope it within seventy-two hours, notify affected customers in writing within thirty days regardless of the minimum any state sets, and report to the relevant regulators as the law requires. We have had no breach to date and have put practical technical and operational safeguards in place to keep it that way. Were one to occur, we would not downplay or stall — we would tell affected customers promptly and plainly what happened and what we are doing about it.
