Privacy Policy
Last updated: August 26, 2026
This policy explains what information Roots, Inc.(“Roots,” “we,” “us”) collects, why we collect it, and who else sees it. It covers this website and the Roots software our customers use to run their businesses.
The short version
- This website sets no advertising or analytics cookies and does not track you across other sites.
- We do not sell your information, and we do not share it with anyone for their own marketing.
- If you are a Roots customer, your business data is yours. We hold it to run the service for you.
- If you are a homeowner whose lawn-care company uses Roots, that company decides what happens to your information. We handle it on their instructions.
Who this policy covers
Three different groups of people show up in Roots, and we hold different responsibilities for each.
Visitors to this website
Anyone reading rootssuite.com. We decide what is collected here, and this policy governs it directly.
Businesses that use Roots
Lawn-care companies and their staff. We decide what account information we need to provide the service, and this policy governs that too.
Customers of the businesses that use Roots
Homeowners and property managers whose details live inside a lawn-care company’s Roots account. That company decides what to collect and how long to keep it. We process it on their behalf and under their instructions, which means requests about that information should go to them first. If you contact us instead, we will point you to the right business rather than act on the data ourselves.
What we collect on this website
When you use the contact form
Your name, email address, company name if you provide one, and the message you write. It is emailed to our team so we can reply. We keep the correspondence so we have context the next time we talk.
When something breaks
If a page throws an error, we record the error, the page it happened on, your browser type, and your IP address so we can fix it. This is error reporting only — no page-view tracking, no behavioral analytics, and no tracking cookies. Nothing is stored in your browser between visits.
Standard server logs
Our hosting provider records the usual request information, including IP addresses, as part of delivering and protecting the site.
Do Not Track
Some browsers can send a “Do Not Track” signal. This site does not track visitors across other websites or services, and it does not allow anyone else to, so there is no behavior for that signal to change — we treat every visitor as though it were set.
What Roots holds for the businesses that use it
When a lawn-care company runs its operation on Roots, the system holds the information that work requires:
- Account and staff information — names, work email addresses, phone numbers, roles, and permissions.
- Customer and property records — the business's own customers, service addresses, property measurements and notes.
- Job and scheduling records — visits, routes, services performed, and job photos taken in the field.
- Messages and calls — text messages and emails sent through Roots, call logs, and call recordings. For businesses using Roots calling, recording is on by default and can be turned off in settings. Recorded calls are also turned into written transcripts.
- Billing records — estimates, invoices, and payment records. Card details go directly to our payment processor; Roots does not store full card numbers.
- Technician location — while on the clock, the Roots mobile app records location so the business can see route progress and give customers accurate arrival times.
- Application records — for businesses applying pesticides or herbicides, the records and disclosures state law requires them to keep.
- Session recordings — sessions in the business-facing Roots app may be recorded for support and troubleshooting: the screens viewed and the interactions on them. Typed input is masked and not captured.
Three of these deserve a closer look
Technician location. Location is collected during working hours to support routing and arrival estimates, not to monitor people off the clock. The business using Roots decides whether to enable it and is responsible for telling its staff, and for meeting the employee-notice rules in its state.
Call recording. For businesses using Roots calling, recording is on by default and can be turned off in settings. Where recording requires the consent of everyone on the call, the business is responsible for obtaining it either way; Roots provides a spoken disclosure it can play at the start of a call. Recorded calls are also sent to a speech-to-text provider to produce a written transcript, so a call that is recorded may be read as well as heard. That provider is named in the list of service providers below, and it receives the recording for transcription only.
Session recordings.To support and troubleshoot the product, Roots may record sessions in the business-facing Roots app — the screens a staff member views and the interactions on them. Typed input is masked and not captured. Roots enables this recording, for a whole business or a single user, and recordings are kept for a limited period. This applies only to the staff-facing Roots application: it does not happen on this website, and it does not apply to the portal where a business’s own customers sign in.
How we use information
- To provide, maintain, and secure the service.
- To respond when you contact us.
- To send account and service notices — billing, security, and changes that affect how you use Roots.
- To diagnose errors and improve reliability.
- To meet legal and tax obligations, and to enforce our terms.
We do not sell personal information, and we do not share it with third parties for their own advertising.
Text messages and mobile information
Roots sends text messages on behalf of the businesses that use it — appointment reminders, on-the-way notices, and billing notices.
Mobile phone numbers and text-message consent are never sold, rented, or shared with third parties or affiliates for their marketing purposes. Phone numbers collected for text messaging are used only to deliver the messages the customer agreed to receive, and are shared only with the messaging providers that carry them.
Agreeing to receive text messages is never a condition of purchase. Message frequency varies, and message and data rates may apply. Reply STOP to any message to opt out, or HELP for help.
Service providers we share information with
We use a small set of established providers to run Roots. Each receives only what its job requires, and each is bound to protect it.
- Supabase
- Database, sign-in, and file storage for job photos, message attachments, and documents.
- Vercel
- Hosting and delivery for this website and the Roots applications.
- Postmark
- Sending email — contact-form messages, account email, and the email your business sends its customers.
- Twilio
- Text messages and phone calls, including call recordings, which are on by default for businesses using Roots calling.
- Deepgram
- Turning call recordings into written transcripts — every recorded call is transcribed automatically.
- Expo
- Delivering push notifications to the Roots mobile app on staff devices.
- Stripe
- Processing card and bank payments. Roots never stores full card numbers.
- Dropbox Sign
- Electronic signatures on estimates and contracts, including the document being signed and the signer's name and email address.
- PostHog
- Error monitoring and product usage inside the applications.
- Mapbox and Google Maps
- Displaying maps and turning service addresses into map locations.
- Anthropic
- Powering assistive features. Content sent for these features is not used to train their models.
- Intuit QuickBooks
- Accounting sync — only for businesses that choose to connect a QuickBooks account.
We also share information when the law requires it, and if Roots is ever part of a merger or acquisition, in which case this policy travels with it.
How long we keep information
Retention is set by the record type and by what state law requires of the business that owns it:
- Pesticide and herbicide application records — seven years, and ten years for businesses operating in New York and Maine.
- Invoices and payment records — seven years.
- Technician location history — ninety days.
- Account and customer records — for as long as the business has an active account, then per the schedule above.
- Website contact-form messages — for as long as they are useful to the conversation.
A business can also ask us to delete its data when it leaves. Records we are legally required to retain are the exception, and we will say which ones those are.
Your choices
- Text messages — reply STOP to any message to stop receiving them.
- Marketing email — use the unsubscribe link in any marketing message. Account and billing notices continue, because they are part of the service.
- Access, correction, or deletion — depending on where you live you may have the right to request a copy of your information, correct it, or have it deleted. Write to us and we will help. If your information sits inside a lawn-care company’s account, we will direct you to that company, which decides those requests.
- We do not sell personal information, so there is nothing to opt out of on that front.
Security
Information is encrypted in transit and at rest. Access inside Roots is scoped so one business can never see another’s data, and staff access is limited to what a role requires. No system is perfect, and we will not pretend otherwise — but security is treated as part of building the product, not an afterthought.
Children
Roots is business software and is not directed to children. We do not knowingly collect information from anyone under 13.
Changes to this policy
When this policy changes we will update the date at the top. If a change materially affects how we handle personal information, we will tell affected customers directly rather than rely on you noticing.
Contact us
Questions about this policy or about your information can go to privacy@rootssuite.com, or through our contact page.