1. Who we are
AARSSystem (“we”, “us”, or “our”) is a field-operations platform for roofing companies operated by Fresh Roof USA. We provide a CRM, territory mapping, storm tracking, and outreach tools for roofing sales representatives and managers. Our service is available at https://aarssystem.com.
2. Information we collect
We collect and process the following information:
- Account information: name, email address, password (hashed), company name, role, and profile picture (optional).
- Customer CRM data you enter: names, addresses, phone numbers, email addresses, job notes, appointments, photos, and roof measurements for your own customers.
- Location data: map-drawn territories, customer pin locations, and rep check-in locations you create inside the app.
- Google account data (optional, only if you connect): your Google account email address, basic profile info (name, picture), and OAuth refresh tokens used solely to send emails or create calendar events on your behalf.
- Usage data: features used, pages visited, errors encountered, and approximate session timestamps.
3. How we use Google user data
AARSSystem's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
If you connect your Google account, we only use your Google data to:
- Send emails via Gmail (
gmail.send): The app sends outreach emails (e.g. Storm Sweep hail notifications) from your Gmail account to the customer addresses you select. Emails appear in your Gmail Sent folder. We do NOT read, list, or modify existing emails in your inbox. - Create calendar events (
calendar.events): The app creates appointment events in your primary Google Calendar when you schedule jobs or generate a "Today's Route". We do NOT read, list, or delete events you did not create through our app. - Basic profile info (
userinfo.email, userinfo.profile): We use your Gmail address as the "From" field on sent emails, and your name as the display name.
We do not sell Google user data. We do not use Google user data for advertising. We do not use Google user data to train generalized or third-party AI/ML models. We only use it to provide the specific features you activated.
4. How data is stored and secured
- All data is stored in an encrypted MongoDB database hosted on enterprise cloud infrastructure.
- OAuth refresh tokens are stored server-side, bound to your user account, and only used to execute actions you initiate inside the app.
- All traffic uses HTTPS/TLS 1.2+ encryption in transit.
- Passwords are hashed with bcrypt; we never store or transmit plain-text passwords.
- Access to production data is limited to authorized personnel with multi-factor authentication.
5. Sharing and third parties
We do not sell your personal data. We share data only with:
- Google APIs — to send email or create calendar events on your behalf.
- Mapbox — to render maps and geocode addresses you type.
- RainViewer / IEM / NOAA — public weather radar and storm data providers (no user data sent).
- Anthropic Claude — to generate draft email text when you click "Draft & Review" (customer name + hail event details are sent; we do not send passwords or OAuth tokens).
- Law enforcement or regulators — only when required by valid legal process.
6. Your rights and revoking access
- Revoke Google access at any time: go to Settings → Storm Sweep → "Disconnect Gmail", or directly at myaccount.google.com/permissions. We immediately delete your OAuth refresh token.
- Delete your data: email support@aarssystem.com and we will permanently delete your account and all associated data within 30 days.
- Export your data: same email — we will provide a JSON export of your CRM records.
- Correct or update data: you may edit most of your data directly inside the app at any time.
7. Data retention
We retain CRM and account data as long as your account is active. If you close your account, we delete it within 30 days. Sent email logs (subject, recipient, timestamp — not body content older than 90 days) may be retained up to 12 months for support and audit purposes, then permanently deleted.
8. Children
AARSSystem is a B2B tool for roofing professionals and is not intended for anyone under 18. We do not knowingly collect data from children.
9. Changes to this policy
We may update this policy from time to time. Material changes will be posted here with an updated "Last updated" date, and notified via email when appropriate.