One operator, one inbox, one purpose.
This policy explains what Concrete Authority ("we," "us," "our") collects, why, who we share it with, and the choices you have. Concrete Authority is operated from North Carolina, United States, and serves customers in Texas and elsewhere. We are the controller (under U.S. state privacy laws) / business of the personal data described here.
This policy covers our marketing website (concreteauthority.dev), our intake and contact forms, our checkout and onboarding flow, the customer HQ account at hq.concreteauthority.dev, and the customer accounts and websites we build and host. It does not cover third-party websites we link to, which have their own privacy practices. Because our product is sold to businesses, most of the personal data we handle is business-contact information about contractors and their staff.
The information you give us, and almost nothing else.
Information you give us directly
When you submit a form, check out, or send us content during onboarding, you give us a small, specific set of information:
- Identity and contact details. Your name, your business name, the email address you want us to use, and (optionally, on some forms) your phone number.
- Where you work. Your city / home base and the service area (the cities you actually drive to).
- About your business. The services you offer (driveways, patios, slabs, stamped, and so on), your current website or Google Business Profile URL if you have one, and any free-text notes you choose to add (existing branding, photos, things to avoid).
- Checkout details. When you authorize a build, your email, phone, and business name. If you separately choose to subscribe, we also keep the subscription disclosure, affirmative enrollment action, and related billing references described below.
- Content for your site. During preview intake and final onboarding, richer content for the website we build, including text about your business and images you upload (such as a logo, a hero image, and gallery photos). Uploaded images are stored with our hosting provider (see Who sees it).
- Account details. If you use your customer account at hq.concreteauthority.dev, we store your login email, a securely hashed password if you set one, and the session data needed to keep you signed in.
- Messages. Anything you send us through the contact form, by email, or during support.
Payment information
When you pay for your build or your AI Office Manager subscription, your card and billing details are entered into and processed directly by Stripe, our payment processor. Full card numbers and sensitive card data never touch our own servers. We receive and store only non-sensitive transaction information: for example, your email, phone, business name, the amount, payment status, and Stripe reference IDs needed to operate billing and your subscription. (More on Stripe in Who sees it and Payment security.)
Information we collect automatically
- Technical, usage, and log data. Our servers and analytics providers may collect basic technical and usage data, such as IP address, browser or device type, referring URL, pages viewed, interactions, timestamps, and performance measurements. We use it for security, analytics, advertising measurement, and site performance.
- Anti-spam and security signals. To stop bots and abuse on our forms, we use Cloudflare Turnstile, a privacy-friendly CAPTCHA alternative. Supported form submissions may provide a verification token and basic technical signals, including your IP address, to Cloudflare for bot/abuse detection. We also rate-limit form submissions: we take your IP address (and, for some forms, your email or phone) and store a one-way hashed value plus a timestamp so we can spot repeated abusive submissions. These short-lived anti-spam records are pruned automatically (currently after about 30 days).
- Cookies and similar technologies. We may use first-party cookies and third-party analytics technologies. See Cookies, analytics, and anti-bot.
What we do NOT collect
We don't collect, and our forms do not ask for:
- Your Social Security number, driver's license, or any government ID.
- Bank account numbers, ACH details, or full card numbers (Stripe handles card entry).
- Your customer lists or business records. When a homeowner submits a form through a website we host for a contractor, we process and store the submitted contact and project details on that contractor's behalf, as described under Homeowner leads.
- Precise location data or sensitive personal information through our analytics tools.
We also do not intentionally collect sensitive personal data (such as precise geolocation, government IDs, or data about children). Please don't send us sensitive information you don't need to.
To build your site, and to talk to you about it.
We use the information above to:
- Build the customized preview you requested, and then build, launch, and host your finished site.
- Send your preview link, status updates, and the final hand-off.
- Reply to questions about your build, your site, or your account.
- Process the one-time $2,997 build charge once you authorize it, and, if you separately subscribe, set up and run the optional $297 monthly AI Office Manager, including its readiness-based 30-day trial, renewals, failed payments, and cancellations. Subscription billing runs through Stripe, including a self-serve billing portal for your payment method, invoices, and cancellation.
- Send you transactional and account email (receipts, status, service notices).
- Send infrequent product updates. You can unsubscribe from these at any time.
- Understand website traffic and performance, improve the site, and measure the effectiveness of our marketing.
- Keep the service secure: prevent bots, spam, fraud, and abuse, and diagnose problems.
- Meet legal, tax, and accounting obligations.
We do not engage in profiling or automated decision-making that produces legal or similarly significant effects about you. No decision affecting your account, pricing, or service is made solely by automated means without human involvement.
Opt-in only, with a paper trail.
The AI Office Manager subscription is opt-in and available only after readiness. If you subscribe, we retain the exact disclosure, Agreement, Terms, and Privacy versions; their cryptographic evidence; the displayed trial and first-charge dates; your affirmative action and acceptance time; subscription status and billing-period dates; and Stripe Checkout, subscription, and invoice references. We retain these records for the period stated in the Customer & Service Agreement to evidence consent, honor cancellation, and handle billing disputes or chargebacks. We do not store your card number; Stripe does that.
Data we hold on your behalf.
When we build and host a website for your contracting business, homeowners can submit estimate requests, contact messages, and instant-estimate answers through that site. Those submissions (the homeowner's name, contact details, project details, and estimate answers) are stored in our central database on your behalf and delivered to you. Limited recovery records may be kept when a submission cannot be matched to the correct customer site. For this data, you are the business the homeowner is dealing with, and we act as your service provider: we store and deliver it for you, we do not use it for our own marketing, and we do not sell it.
Marketing consent, with evidence. If a homeowner ticks the optional marketing checkbox on your site, we record the exact consent wording, its version, and the time it was granted, so the consent is documented. Any marketing email sent under that consent includes an unsubscribe link, and unsubscribe requests are honored across the board. Service and notification email for these sites is sent from our sending domains, including servicereplies.com.
Homeowner rights. Homeowners can exercise their privacy rights through the contact details published on the contractor's own website, or by emailing us at support@concreteauthority.dev.
Providers that help us run and measure the site.
We share information with a small set of service providers and analytics providers that help us run, improve, and measure the business. Service providers process data for the purposes below. Analytics providers may process technical and usage data under their own privacy terms and our selected settings. We do not authorize any provider to sell your data on our behalf.
| Service provider | Role | What it handles |
|---|---|---|
| Stripe (stripe.com) | Payment processing (PCI DSS Level 1 service provider) | Card entry and billing for the one-time build charge and the recurring AI Office Manager subscription, including the self-serve billing portal. Stores the payment/customer record and limited transaction metadata (e.g. email, phone, business name, amount, references). Full card numbers stay with Stripe. |
| GoHighLevel / "HighLevel" (gohighlevel.com) | Customer relationship management (CRM) | Stores your contact details (name, email, phone, business name) and your Website Build record: the intake and site details we use to build and manage your project (service area, services, site content, uploaded image references, payment and subscription status, etc.), plus notes from your form submissions. |
| Cloudflare (cloudflare.com) | Application hosting, object/configuration storage, database connectivity, and security | Serves our website, your preview, and your finished site; runs our application code (Workers); stores your uploaded images and site files in R2 and routing/configuration data in KV; connects Workers to our Neon database through Hyperdrive; and provides Turnstile anti-bot/CAPTCHA and DDoS/security protection on our forms. Cloudflare is not our canonical relational database store. |
| Analytics and advertising measurement providers | Website analytics and campaign measurement | May receive technical and usage data, such as IP address, browser or device information, referring pages, pages viewed, interactions, and performance measurements, to help us understand traffic, improve the site, and measure marketing effectiveness. The providers and tools we use may change over time. |
| Neon (neon.tech) | Managed PostgreSQL database | Stores our canonical application records, including customer, business, account, website-build, subscription and transaction metadata; contractor and homeowner lead records; consent evidence; marketing suppression records; and related operational history. Neon does not receive or store full payment card numbers. |
| Resend (resend.com) | Email delivery | Sends transactional and notification email: preview links, status updates, download links, contact-form messages, and account/billing notices, from our sending domains, including concreteauthority.dev and servicereplies.com. Resend keeps email-sending logs but does not use your data for its own purposes. |
| Google Workspace (workspace.google.com) | Team email inbox | Our support@concreteauthority.dev inbox, which receives privacy requests, contact-form inquiries, and operational notifications (which can include your name, email, phone, business name, and message content). |
A note on our internal operations email: when you submit certain forms or complete checkout, we send ourselves an operational notification (via Resend, into our Google Workspace inbox) so our team can fulfill your order. These notifications can include your name, email, phone, business name, and the internal reference IDs for your build.
Other lawful disclosures. We may also disclose information: to comply with a valid legal request (subpoena, court order, or law), and we'll tell you when we're allowed to; to protect our rights, safety, or property, or yours; and in connection with a business transfer (merger, acquisition, or sale of assets), in which case this policy will continue to govern your data or you'll be notified of any change.
International transfers. Our providers are U.S.-based and may process or store data in the United States or other countries, so your data may be transferred across borders. Where required for EU/UK data, our providers rely on appropriate safeguards (such as Standard Contractual Clauses) under their own data-processing terms. We do not intentionally target EU/UK visitors, so this transfer language is precautionary.
Your card stays with Stripe.
Payments are processed by Stripe, a PCI DSS Level 1 service provider (the most stringent level). When you pay, your card details are collected and processed directly by Stripe; they do not transit or get stored on our servers. We retain only non-sensitive details Stripe returns to us (such as card brand and last four digits, if shown) and the transaction/subscription references we need to run billing. See Stripe's Privacy Policy.
The bare minimum to keep the site working.
- Cookies and similar technologies. We use a small set of first-party cookies for essential functionality, such as session state, form integrity, and remembering preferences. Our analytics providers may also use cookies, pixels, browser beacons, or similar technologies, depending on the provider and our configuration. You can control cookies through your browser settings, although blocking essential cookies may affect some site features.
- Analytics. We use, and may change, third-party analytics and advertising measurement providers to understand page traffic, referrals, site performance, and campaign effectiveness. These providers may collect the technical and usage data described above and process it under their own privacy policies. We use these tools to measure and improve our website and marketing. If we use them for targeted advertising or in a way that applicable law treats as a sale or sharing of personal data, we will update this policy and provide any required notice, consent, or opt-out choice before doing so.
- Turnstile / anti-bot. As noted in What we collect, we use Cloudflare Turnstile and hashed-identifier rate-limiting to detect bots and abuse on our forms. These are used for security and fraud prevention only. Not advertising. See Cloudflare's Privacy Policy.
- Do Not Track. Some browsers send a "Do Not Track" (DNT) signal. There is no industry-standard response to DNT, so our practices do not change based on that signal. We do honor the Global Privacy Control (GPC) opt-out signal where the law requires.
- Opt-out preference signals. Where required by law, we honor recognized browser opt-out signals such as Global Privacy Control (GPC).
Only as long as we need it.
We keep personal data only as long as we need it for the purposes above, then delete or de-identify it.
- Lead and inquiry data (forms, contact messages): kept while we're pursuing or supporting the relationship, then for a limited period after.
- Customer, account, and transaction data (your Website Build record, billing history): kept for the life of your account and for the period we're required to keep it for tax, accounting, and legal purposes.
- Subscription / recurring-billing consent records: see Recurring billing.
- Homeowner leads we hold for contractors: kept while the contractor's site and service are active, per our agreement with them, along with the marketing-consent evidence records that document a homeowner's choice.
- Anti-spam rate-limit records: short-lived (currently pruned after about 30 days).
- Marketing opt-out records: kept so we can honor your unsubscribe.
Risk-appropriate safeguards, and honest limits.
We use reasonable, risk-appropriate administrative, technical, and physical safeguards: encryption in transit (TLS), access controls, anti-bot/abuse protection (Turnstile), and reliance on security-certified providers (Stripe is PCI DSS Level 1; Cloudflare provides our hosting/security layer). No method of storage or transmission is 100% secure, so we can't guarantee absolute security, but we work to protect your information and to limit who can access it.
If a breach occurs. If we learn of a security incident that compromises your personal data, we will investigate promptly and notify you and any required regulators as the law requires, without unreasonable delay. Texas law (Texas Business & Commerce Code Chapter 521) requires us to notify affected Texas residents and, for larger incidents, the Texas Attorney General; we will comply with these and any other applicable breach-notification obligations in the states where our affected customers live.
We do not sell or "share" your data.
We do not sell your personal data, and we do not currently "share" it for cross-context behavioral (targeted) advertising. We disclose data to the providers described in Who sees it so they can operate, improve, and measure our services. We don't sell leads or provide personal data to marketplaces or data brokers.
Under Texas and California law, a "sale" can include disclosing personal data to a third party for monetary or other valuable consideration. Our current provider disclosures are for the business purposes described in this policy, not for targeted advertising. We also do not sell or process for targeted advertising any sensitive or biometric data, so the TDPSA's mandated sale-notices do not apply to us.
If this ever changes, we will update this policy, clearly and conspicuously disclose it, and provide the opt-out the law requires before doing so.
You can ask, change, delete, or export. Any time.
Regardless of where you live, our baseline policy is the same: you can ask us to access, correct, delete, or export your data, and you can unsubscribe from marketing at any time.
Rights for U.S. state residents (Texas, California, and other states with privacy laws)
Depending on your state, you may have the right to:
- Know / access the personal data we hold about you and how we use it.
- Correct inaccurate personal data.
- Delete your personal data (subject to legal exceptions, such as tax records of completed transactions).
- Obtain a portable copy of your data in a machine-readable format.
- Opt out of the sale of personal data, targeted advertising, and certain profiling. (Not applicable here. We don't do any of these.)
Texas residents (TDPSA). This policy describes the categories of personal data we process, our purposes, the categories of third parties we share with, and how to exercise your rights. We will respond to a rights request within 45 days (we may extend once by another 45 days where reasonably necessary, and will tell you if we do). If we deny your request, you may appeal within a reasonable time by emailing us with "privacy appeal" in the subject line; we will respond to an appeal within 60 days. If we deny the appeal, we will tell you how to submit a complaint to the Texas Attorney General, who enforces the TDPSA, at texasattorneygeneral.gov.
California residents (CCPA/CPRA). Given our size, we likely are not a "business" subject to the CCPA, but we will honor reasonable access, correction, deletion, and portability requests anyway, and we will not discriminate against you for exercising any privacy right. For the 12 months preceding this policy, we have collected the following categories of personal information (as defined by the CCPA): identifiers (name, email, phone, business name, IP address); commercial information (services purchased, subscription plan, transaction history); internet/network activity (log and usage data); and customer content (uploaded images and site text). We collect it from the sources described in What we collect, for the business purposes described in How we use it, and we retain each category per How long we keep it. We do not sell or share any category, and we do not collect or use sensitive personal information for purposes that would require a "limit" option.
Rights for EU/UK residents (GDPR / UK GDPR)
If GDPR applies, you have rights to access, rectification, erasure, restriction, portability, and objection, and to withdraw consent at any time. You may also lodge a complaint with your local supervisory authority. Our legal bases are described in How we use it.
How to exercise your rights
Email support@concreteauthority.dev with "privacy request" in the subject line so it routes cleanly. To protect your data, we'll take reasonable steps to verify your identity (usually by matching details we already hold) before acting. If you do not have an account with us, we may need to ask for additional information to locate your data and confirm your identity before we can respond. If an authorized agent submits a request for you, we may ask for proof of authorization. The first reasonable request is free; we may decline or charge for requests that are manifestly excessive or repetitive, as the law allows.
This site isn't for children.
Concrete Authority is a business-to-business product for concrete contractors. It is not directed to children. We do not knowingly collect personal data from anyone under 18, and we never knowingly collect data from children under 13 (COPPA) or process a known child's data, which the TDPSA treats as sensitive data requiring verifiable parental consent we do not seek. If you believe a minor has submitted information to us, contact us and we will delete it.
We'll tell you, and we'll date it.
We update this policy when we change how we handle data. The "Last updated" date at the top always reflects the current version. Material changes (new categories of data, new uses, or a new service provider) trigger a notice to active customers (by email or a prominent notice on the site). Older versions are archived; if you want to compare, just ask.
Support inbox.
Privacy questions, requests, complaints, or anything you want a second look at. Email us:
Postal address:
210 Harmon Creek Road #1004, Kernersville, NC 27284
Concrete Authority is operated from North Carolina.
Texas residents may also contact the Office of the Texas Attorney General regarding the TDPSA.