Skip to main content
Legal

Privacy Policy

Last updated: August 2026

RKServicesPDX (“we”, “us”) is a local project consulting and local services business based in Portland, Oregon. This policy explains what information we collect through this website and our mobile app, how we use it, who we share it with, how long we keep it, and the choices and rights you have. We wrote it in plain English on purpose.

Information we collect

  • Contact details you submit: name, email, phone (optional), and service address when you request a quote.
  • Service photos: before/after photos taken on the job, with your consent.
  • Account info: if you sign in to the customer portal, your email address, a securely hashed password, and — if you use them — your Google or Apple sign-in identifier.
  • Payment info: Stripe or PayPal handles card, bank, wallet, and eligible Klarna payment details on its hosted checkout. We do not store full card or bank-account numbers; we keep payment status, amount, provider references, and limited payer details needed for receipts, refunds, fraud prevention, and reconciliation.
  • Marketing-campaign attribution: when you arrive from an ad or referral, the URL parameters (UTM source / medium / campaign, ad click IDs) are captured so we know which channels work. Stored only within your current browser tab unless you've accepted the Preferences cookie category.
  • Analytics data (only if you've consented): anonymous usage stats from Google Analytics 4 and session replay from Microsoft Clarity.
  • Marketing identifiers (only if you've consented): Meta Pixel, TikTok Pixel, Google Ads, and Bing UET cookies used for ad attribution and conversion tracking.
  • Device and usage info: basic, aggregated server logs (IP, user-agent, timestamp) used for security and to keep the site running.

How we use it

  • Respond to inquiries and deliver the services you requested.
  • Schedule appointments and send appointment, ETA, and status updates by email, or by phone if we do not have an email address for you.
  • Improve the site's reliability, security, and user experience.
  • Measure marketing-campaign effectiveness - which ads, search keywords, or pages actually bring people who need our help.
  • Meet legal, tax, and accounting obligations (invoices, receipts).
  • We do not sell your personal information for money.

Third parties we share with

We rely on a small number of well-known infrastructure providers and (when you give consent) marketing-analytics tools. Each only sees what it needs to do its job. Links go to each provider's own privacy policy.

  • Turso - database that stores leads, quotes, and account records. Privacy policy.
  • Google Workspace (Gmail and Calendar) - sends transactional and internal operations email and supports staff appointment scheduling. It can receive the customer contact, service, address, schedule, and internal job details needed for those tasks. Privacy policy.
  • Stripe - hosted payment processing for cards and supported wallets. Klarna may appear through Stripe when the purchase and customer are eligible; Klarna may perform its own identity or credit checks. Privacy policy.
  • PayPal (when enabled) - hosted payment processing for invoices. PayPal handles full card and bank details; we receive the transaction status and limited payer details needed to reconcile the payment. Privacy policy.
  • Twilio (when enabled) - SMS for appointment confirmations and status updates. Privacy policy.
  • Sentry - application error monitoring and crash diagnostics. Receives error events and stack traces, which can include your IP address and the page you were on when something broke. Privacy policy.
  • Sign in with Google - when you choose this option, Google authenticates you and shares your email and basic profile with us so we can create and access your account. Privacy policy.
  • Sign in with Apple - when you choose this option, Apple authenticates you and shares your email (or a private relay address) so we can create and access your account. Privacy policy.
  • Web Push services (when enabled) - deliver browser push notifications if you opt in. Receive a device push token, not your identity. Privacy policy.
  • OpenStreetMap Nominatim - admin-only address geocoding used to verify service-area coverage. Receives the address being checked. Privacy policy.
  • Google Analytics 4 - anonymous traffic + engagement analytics. Loads only after you accept Analytics cookies. Privacy policy.
  • Microsoft Clarity - heatmaps + session replay. Loads only after you accept Analytics cookies. Privacy policy.
  • Microsoft Ads (Bing UET) - conversion tracking for Microsoft Ads campaigns. Loads only after you accept Marketing cookies. Privacy policy.
  • Meta (Facebook + Instagram) Pixel - ad attribution + retargeting. Loads only after you accept Marketing cookies. Privacy policy.
  • TikTok Pixel - ad attribution + retargeting. Loads only after you accept Marketing cookies. Privacy policy.
  • Google Ads - conversion tracking. Loads only after you accept Marketing cookies. Privacy policy.

Legal bases (GDPR / UK GDPR)

For visitors in the EU, UK, or EEA, we rely on the following legal bases. The applicable basis depends on what data is being processed and why.

  • Contract: we need your contact details and service address to deliver the service you requested.
  • Consent: marketing + analytics cookies load only after you grant consent through the cookie banner. You can withdraw consent at any time.
  • Legitimate interest: essential first-party performance telemetry, basic security logging, and fraud prevention.
  • Legal obligation: tax and accounting records we're required to keep under U.S. and Oregon law.

Your rights

No matter where you live, you can ask us to:

  • See what data we hold about you (right of access).
  • Correct anything that's wrong (right of rectification).
  • Delete your data, subject to legal-retention limits (right to erasure).
  • Get a copy in a portable format (data portability).
  • Withdraw consent for marketing / analytics cookies at any time via the Cookie Settings button in the footer or on the /cookie-policy page.
  • Tell us not to share your data with marketing or analytics partners (see /do-not-sell).

To make any of these requests, see /data-deletion for the exact process, or email [email protected].

For data portability specifically, signed-in customers can self-serve a full machine-readable export from /portal/settings - the “Download my data” button hits the export endpoint and returns a JSON file containing the customer-safe data linked to your account: identity and security-event history without secrets, leads, locations, customer records, quotes, jobs, photos, reviews, payment and refund history, messages, recurring-service records, consent/suppression records, and the audit-log entries you yourself triggered. Internal staff notes, credentials, raw payment-provider events, and internal job-cost data are never included.

For deletion specifically, signed-in customers can delete their own account immediately from /portal/settings - the “Delete my account now” option immediately removes the account, credentials, linked photos, and direct identifiers from active systems. It also replaces free-text service details with neutral values. Photo deletion is attempted at the storage provider during the request; a provider failure is recorded in a deletion-only queue for authorized retry and escalation. We keep de-identified financial and operational records (such as totals, statuses, and timestamps with no name, email, phone, address, or customer notes attached) where required for tax, fraud, dispute, or legal purposes. You can also email us to request deletion.

How quickly we respond: we act on rights requests within 45 days. If your request is complex or you've made several, we may extend by another 45 days, and we'll tell you why within the first 45.

Correcting your information (rectification): if something we hold about you is wrong, email [email protected] and tell us what to fix, or - if you have a portal account - update your details directly at /portal/settings. We'll correct it and, where required, ask the partners we shared it with to do the same.

Appealing a decision: if we deny your request, you may appeal by emailing [email protected] with the subject APPEAL. We'll respond to your appeal within 60 days. If we deny it, Oregon residents may also raise the matter with the Oregon Department of Justice.

California residents (CCPA / CPRA)

If you live in California, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

  • Right to know what categories of personal information we collect, the sources, and the purposes.
  • Right to delete personal information we collect from you.
  • Right to correct inaccurate personal information.
  • Right to opt out of the sale or sharing of personal information with third parties for cross-context behavioral advertising.
  • Right to limit use of sensitive personal information.
  • Right to non-discrimination for exercising any of these rights.

We do not sell your personal information for money. We may “share” it (in the CPRA sense) with marketing and analytics partners - but only after you grant consent through the cookie banner. To opt out at any time, use the cookie banner, the Cookie Settings button in the footer, or visit /do-not-sell.

We do not request Social Security numbers, health data, biometric identifiers, or financial-account credentials. We may derive coordinates from the service address you provide solely to check service-area coverage and travel time. We do not use that location for behavioral advertising, and it is removed with a verified deletion request.

Oregon residents (OCPA)

The Oregon Consumer Privacy Act, effective July 1, 2024, gives Oregon residents rights similar to California's: the right to know, to correct, to delete, to obtain a portable copy, and to opt out of targeted advertising, profiling for decisions with legal effect, and the sale of personal data. We extend those rights to all Oregon residents as a good-faith posture, regardless of whether we meet the statute's commercial thresholds. To exercise any of these rights, email [email protected] or use /data-deletion.

Cookies & tracking

Essential cookies (sign-in, security, your saved cookie choices) are always on. Analytics, marketing, and preferences cookies load only after you grant consent through the cookie banner. See the cookie policy for the full list of cookies, who sets them, and how long they last.

Global Privacy Control (GPC) and Do Not Track signals

We honor the Global Privacy Control signal sent by your browser or a privacy extension. If your browser sends GPC=1 when you arrive, we automatically record a “reject non-essential” cookie choice - no analytics or marketing scripts load. You can still revisit Cookie Settings and opt into specific categories if you want. We also do not load tracking pixels for any visitor in response to a legacy Do Not Track header until they explicitly grant consent through the cookie banner.

Data security & safeguards

We protect the data we hold using commercially reasonable technical and organizational measures:

  • All traffic between your browser and our site is encrypted with HTTPS / TLS.
  • Customer portal sessions use signed, expiring tokens. Passwords are never stored in readable form — only a salted bcrypt hash — and you may instead sign in with Google or Apple.
  • Database access is restricted to a small number of authorized accounts with audit logging.
  • Full card and bank-account data is handled on Stripe or PayPal hosted checkout and is not stored by our servers. Eligible Klarna transactions are also handled through Stripe and Klarna.
  • Lead records and service-photo metadata are behind application access controls. Job-photo files live in private, self-hosted storage and are streamed only after RKS verifies the logged-in customer or staff member is authorized for that job. Public catalog images use a separate public subtree. A photo uploaded before a lead is submitted receives an unguessable public link that is not cached and stops being served after 24 hours.
  • We patch and update our hosting, dependencies, and tooling on a regular cadence.

No system is perfectly secure. If you have a security concern, email [email protected] and we'll respond within one business day.

Authorized agents

California and Oregon residents may designate an authorized agent to make privacy requests on their behalf. We require: (1) a signed written authorization from you to the agent, and (2) verification of your identity (typically a reply confirming the email and phone on file). To submit an authorized-agent request, email [email protected] with the subject AUTHORIZED AGENT REQUEST and attach the authorization. We aim to respond within 15 business days.

International transfers

We operate the site's application compute in the United States. Our self-hosted media storage is also in the United States. Most analytics and marketing tools we use are U.S.-based. If you access the site from outside the United States, your data is transferred to and processed in the United States. For EU/UK visitors we rely on the providers' published transfer mechanisms (Standard Contractual Clauses or equivalent - see each provider's privacy policy linked above).

How long we keep it

  • Leads with no conversion: retained for up to 2 years unless you request deletion sooner.
  • Temporary lead photos uploaded before a lead is submitted: the public link expires after 24 hours. Expired files are reclaimed from a bounded temporary storage pool.
  • Customer, quote, job, payment, and refund records: identifying details are removed on a verified deletion request. De-identified amounts, statuses, provider references, and timestamps may be retained for up to 7 years for tax, accounting, fraud, dispute, and legal obligations.
  • Service photos: their database records are removed immediately after the files are queued for deletion. We attempt media-file deletion during the request and record failures in a deletion-only queue for authorized retry and escalation.
  • Email suppression records: the minimum email and opt-out status may be retained as long as needed to honor your request not to receive marketing or outreach. We do not use that record for any other purpose.
  • Security audit records: direct identifiers and customer free text are removed with account deletion; the de-identified action, entity type, and timestamp may be retained for up to 7 years.
  • Server logs: retained 90 days.
  • Third-party telemetry (analytics + ad pixels): subject to each vendor's retention. GA4 defaults to 14 months for event-level data; Microsoft Clarity defaults to 12 months; Bing UET (Microsoft Ads) retains for up to 13 months.

Children

Our services aren't directed at children under 13 and we don't knowingly collect information from them. When you create an account we ask for your date of birth and block account creation for anyone under 13 on the server, before any account is made - this is enforced in our systems, not just by a checkbox. If we learn we've received personal information from a child under 13 through any other channel, we will delete it.

Changes to this policy

We may update this policy occasionally. The “last updated” date at the top reflects the most recent change. Material changes will be communicated through the site or by direct email to active customers.

Contact

Questions about this policy or a data request? Email [email protected] or call (971) 757-0248.

CallChatQuote