Your reading should not become a sales ambush.
Private pre-publication draft: this notice explains the intended data design and what the current code actually does. It is not a launch-ready privacy policy. It must be reviewed and completed for the final legal entity, mailing address, vendors, retention periods, and applicable state requirements before public traffic or data collection.
Review record
- Author
- Understanding Roofing. No individual author is credited yet.
- Legal review
- Not completed. This notice has had no review by a qualified adviser.
- Publisher entity
- Not established. There is no named legal entity or mailing address yet.
- Last substantive update
- Not recorded. Page-level revision history is not published yet.
- Next review due
- Before any public traffic reaches this site.
A privacy notice with no reviewer and no named entity behind it is a draft, and it says so here rather than implying otherwise. See the editorial policy for how corrections to this page are handled.
Optional analytics
Google Tag Manager is wired with Consent Mode defaults that deny analytics and advertising storage until a visitor allows analytics. Exact calculator entries stay local; after consent, only documented coarse categories such as material family, an area or result band, and the page-performance measurements described below may be measured. Names, email addresses, phone numbers, street addresses, raw form values, exact project locations, and identifier-bearing URLs must never enter GTM or GA4.
Advertising storage, ad user data, and ad personalization are denied at all times in the current code, including after a visitor allows analytics. Page-view and interaction events are dropped before they reach the data layer rather than sent and tagged as non-consented. The consent decision itself is recorded either way, so a denial is not mistaken for a visitor who never answered.
The one thing that is measured before you choose
Page-performance measurements are produced by the first paint, before any consent decision can exist. Up to twelve of them are held in the page’s memory rather than discarded: each is a metric name, a number, and a good, needs-improvement, or poor rating, and none of them describes who you are or what you typed. They are sent only if you then choose “Allow analytics” during that visit. Choosing essential only discards them, and so does closing the page. Nothing leaves your browser in between.
What this site stores on your device
The site’s own code sets no cookies. It writes one key to your browser’s local storage, and only after you make a choice.
| Name | Type | Purpose and values | Lifetime |
|---|---|---|---|
| understanding-roofing-analytics-consent | Local storage, first party | Records your analytics choice as the literal value “granted” or “denied”. Written only when you answer the consent dialog, and read on each page load to restore that choice. It stays on your device and is never sent to our server. | Until you clear site data for this domain |
| Google Tag Manager and Google Analytics | Third-party cookies and storage | Loaded only when a container ID is configured for the deployment, and permitted to write analytics storage only after you allow analytics. The exact names, values, and lifetimes Google sets are not documented here yet; that list has to be completed from the live container before launch. | Not documented yet |
| Cloudflare Turnstile | Third-party storage | The human-verification widget loads only where an email form is present and only when a site key is configured. What it stores is controlled by Cloudflare and is not documented here yet. | Not documented yet |
Email and buying guides
Email forms collect only the information needed to send the requested resource or newsletter. Newsletter consent is explicit and separate from guide delivery. The production system will retain the consent timestamp, form source, disclosure version, and suppression status.
What a submission actually sends today
- Your email address, and a first name if you choose to give one.
- Whether you ticked newsletter consent, and which form you used.
- A hidden timestamp for when the form was opened, used to reject scripted submissions.
- A Cloudflare Turnstile verification token.
The request goes to this site’s own endpoint, which verifies the token with Cloudflare and then passes your address to Resend, the email provider, to store the contact and send the message. Cloudflare sees your connecting IP address in order to verify and rate-limit the request. Delivery failures are logged as a stage and an error code without your address. Retention and deletion procedures at the provider are not documented here yet.
Installer sharing
No contact or project information will be sent to installers without a later, separate consent flow that identifies what will be shared, with whom, and why.
Your choices and requests
Use the “Privacy choices” control at the foot of any page, below the footer, to allow or deny optional analytics; it opens the consent dialog, rewrites the stored key above, and takes effect immediately. Clearing site data in your browser removes the key entirely and returns the site to its denied-by-default state. Every newsletter will include an unsubscribe mechanism.
Global Privacy Control
If your browser sends a Global Privacy Control signal, this site treats it as a request to keep optional analytics off. The signal is read before any stored choice is, so it also overrides a stored “Allow analytics” for as long as your browser sends it. The stored value is left in place rather than erased: turning the signal off restores the choice you made instead of silently discarding it. There is no control here to override the signal, and the consent dialog does not offer you one — it says the signal is being honored instead.
Access, correction, and deletion
Until a production request route exists, write to hello@understanding-roofing.com. What can honestly be done today is limited: an email address can be removed from the provider’s contact list, and the consent key is yours to clear at any time. There is no verified-identity request process, no defined response window, and no data-retention schedule yet.
What this notice does not cover yet
- The Global Privacy Control signal is detected and honored as described above, but whether that satisfies every state’s opt-out mechanics—an authorized-agent route, a “Do Not Sell or Share” link, or a specific response window—has not been checked by a qualified adviser.
- There is no named legal entity, mailing address, data-protection contact, or governing-law statement.
- Retention periods, sub-processor list, and international transfer terms are not stated.
- The site is not offered to children, and no age-verification mechanism exists.