Draft — not legal advice
This is a starter draft generated for planning purposes. It must be reviewed and finalized by a licensed attorney before ADUVerified collects real user data or launches.
Legal
Privacy Policy
Last updated: 2026-05-30 (draft)
This Privacy Policy explains how ADUVerified (“ADUVerified,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you visit aduverified.com(the “Site”) or submit an inquiry through our form. ADUVerified is an advertising and matching service that connects U.S. homeowners with independent, third-party ADU builders. We are not a contractor, real estate broker, mortgage lender, architect, or settlement-service provider.
By using the Site or submitting an inquiry, you confirm that you have read and understood this Privacy Policy. If you do not agree, please do not use the Site or submit an inquiry.
1. Information we collect
We collect personal information in three ways: directly from you, automatically when you use the Site, and from limited third-party sources (described below).
a. Information you provide
When you submit the inquiry form, you provide:
- Identity & contact: first name, last name, email address, phone number, best time to be reached.
- Property location (approximate): U.S. state and ZIP code. We do not collect your exact street address.
- Project details: property ownership status, whether your property is in an HOA, lot size band, build type, square footage band, bedrooms, bathrooms, interest in pre-approved city plans, permit-process status, budget band, target timeline, financing approach, intended primary use, and whether you have received quotes previously.
- Optional notes:any free-text you add in the “anything else about your project” field (capped at 2,000 characters server-side).
- Consent records: the contact-consent checkbox you must check, the optional marketing-consent checkbox, the version identifier of the consent language you saw, and the timestamp.
- Attribution (optional): how you heard about us.
b. Information collected automatically
- Technical / device data: IP address, browser user-agent string, referring URL, and timestamps. We use this for security, fraud prevention, rate limiting, and operational troubleshooting.
- Site analytics: we use Plausible Analytics, a cookieless, privacy-respecting product that records aggregate, anonymized visit data (page views, country, browser family, referrer). Plausible does not set cookies, does not track you across sites, and does not collect personal information.
c. Information from third parties
We currently do not purchase or receive personal information about you from data brokers or other third parties. If that ever changes, we will update this Policy and notify users where required by law.
2. How we use your information
- Match you with builders. The primary purpose: to identify up to three ADU builders in your state and forward your inquiry to them so they can reach out with quotes.
- Communicate with you about your inquiry. Confirmation email after submission, plus follow-up about your match.
- Marketing (only if you opt in). Send tips, financing options, and updates if (and only if) you checked the optional marketing-consent box. You can unsubscribe at any time.
- Operate, secure, and improve the Site. Detect fraudulent or abusive activity, enforce our rate limits, fix bugs, and measure aggregate Site usage.
- Maintain consent records. Store the exact consent language you agreed to, with timestamp, IP, and user-agent, to comply with TCPA, CCPA/CPRA, and similar laws.
- Comply with law. Respond to legal process, enforce our Terms, and protect our rights and the rights and safety of others.
3. How we share your information
a. With matched ADU builders (third parties)
When you submit the inquiry form and provide consent, we share the information you provided — including identifiers (name, email, phone), approximate location (state, ZIP), and project details — with up to three matched ADU builders. Those builders receive your inquiry by email and may contact you directly. The builders are independent businesses, not ADUVerified employees or contractors; we do not control their privacy practices or their work. Builders pay us a per-lead fee in exchange for receiving your inquiry. Under the California Consumer Privacy Act (CCPA) as amended by the CPRA, this transfer is treated as a “sale” and “sharing” of personal information, and you have the right to opt out. See Section 6 — Your California privacy rights below.
b. With our service providers
We use third-party service providers who process information on our behalf under contract. They are not permitted to use your information for their own purposes. Current providers include:
- Supabase — secure database hosting (where your inquiry is stored).
- Resend — transactional email delivery (the messages to you and to matched builders).
- Replit Deployments — Site hosting and edge infrastructure.
- Plausible Analytics — privacy-respecting, cookieless aggregate analytics.
These providers receive only the information necessary to perform their function on our behalf.
c. For legal or safety reasons
We may disclose information when we reasonably believe it is necessary to comply with law, respond to lawful requests by public authorities, enforce our Terms, protect our rights or property, or protect the safety of any person.
d. In a business transfer
If ADUVerified is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or material change in use of your information.
e. With your consent
We may share your information for any other purpose disclosed to you at the time of collection or with your separate consent.
4. Data retention
- Inquiry & consent records: retained for as long as your record is needed for the matching service, dispute resolution, fraud prevention, or to meet legal obligations (typically up to 7 years for consent records under TCPA), and then deleted or anonymized.
- Marketing list:retained until you unsubscribe; after unsubscribe, kept only as a suppression record so we don't contact you again.
- Server logs & IP addresses: retained for approximately 30 days unless needed longer to investigate abuse.
- Analytics: Plausible stores only aggregated, anonymized data; we retain it for as long as the analytics account is active.
You can request deletion at any time (see Section 6). We will delete or anonymize your record unless we have a legal obligation to retain it (for example, to evidence consent for already-sent communications).
5. Communications & your choices
- Transactional emails (confirmation of your inquiry, builder match information): you receive these as part of the service you requested. You may unsubscribe by replying to ask us to stop, but we may not be able to complete the match if you do.
- Marketing emails & texts: you receive these only if you checked the optional marketing-consent box. Reply STOP to any SMS to opt out; click unsubscribe in any marketing email. We process opt-out requests within 10 business days and will honor them for at least 30 days as required by CAN-SPAM. See our SMS Terms for SMS-specific details.
- Update or correct your information: email privacy@aduverified.com (or chad@prismagentsolutions.com) with the correction. Please use the email you submitted with so we can verify identity.
6. Your California privacy rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you the rights described in this section. Other states with similar laws (e.g., Virginia, Colorado, Connecticut, Utah, Texas) provide analogous rights; we extend the same options to all U.S. residents as a matter of practice.
a. Categories of personal information we collect
- Identifiers (CCPA § 1798.140(v)(1)(A)) — name, email, phone, IP address, online identifier.
- Customer records (§ 1798.80(e)) — name, telephone number.
- Commercial information (§ 1798.140(v)(1)(D)) — your stated interest in obtaining ADU construction services, project intent, budget band, timeline.
- Internet or other electronic network activity (§ 1798.140(v)(1)(F)) — referring URL, browser user-agent.
- Geolocation data — approximate only (§ 1798.140(v)(1)(G)) — your state and ZIP code. We do not collect precise (GPS-level) geolocation.
- Inferences (§ 1798.140(v)(1)(K)) — we may derive basic lead-quality inferences (e.g., project size band) from the information you provide.
We do not knowingly collect sensitive personal information as defined in § 1798.140(ae) (e.g., Social Security number, government-issued IDs, financial-account credentials, precise geolocation, racial or ethnic origin, religious beliefs, biometric data, health data, sexual orientation, or contents of mail/email/SMS not sent to ADUVerified). You should not include such information in your project notes.
b. Sources and purposes
Sources: directly from you (the inquiry form), and automatically from your device (logs and analytics). Purposes: to provide the matching service, communicate with you, market to you if you opted in, secure the Site, and comply with law (as detailed in Section 2).
c. Categories we “sell” or “share”
We sell and share the following categories with matched ADU builders, because builders pay us per matched lead: identifiers, customer records, commercial information, and approximate geolocation. We do not sell or share sensitive personal information. We do not use or disclose information for cross-context behavioral advertising on third-party platforms.
d. Categories disclosed for business purposes
We disclose all of the categories above to our service providers (see Section 3.b) under contractual restrictions limiting their use to providing services to us. Such disclosures are not “sales” under the CCPA.
e. Your rights
- Right to know what personal information we have collected about you, the sources, the business or commercial purposes, and the categories of third parties with whom we shared it.
- Right to delete personal information we collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of your personal information. (See Section 6.f — this is the most relevant right for our service.)
- Right to limit use of sensitive personal information — we do not collect sensitive PI as defined by CPRA, so there is nothing to limit. If you believe we are processing sensitive PI about you, please contact us.
- Right to non-discrimination — we will not deny you service, charge you a different price, or provide a different quality of service because you exercised any of these rights.
f. How to opt out of the sale or sharing of your information
Email privacy@aduverified.com with the subject “Do Not Sell or Share My Personal Information.” In the body, include the email address you used to submit your inquiry so we can verify and locate your record.
We honor the Global Privacy Control (GPC) signal sent by your browser as a valid opt-out of sale and sharing for the browser/device that sent it.
Important practical note: the core service we provide — matching you with ADU builders — necessarily involves transferring your inquiry to those builders. If you opt out of sharing, we cannot complete the match, and the only useful thing we can do with your record is delete it. Opting out is therefore functionally equivalent to canceling your inquiry.
g. How to exercise your other rights
Email privacy@aduverified.com from the email address you used to submit your inquiry. We will respond within 45 days as required by the CCPA (we may extend once by another 45 days where reasonably necessary and will tell you). We will verify your identity by matching the email and, for sensitive requests, by asking a small number of additional questions about your inquiry.
h. Authorized agents
You may designate an authorized agent to make a request on your behalf. We will require the agent to provide written, signed authorization and we may also contact you directly to verify the request.
7. Children's privacy
The Site is intended for adults (18+) who own or are purchasing residential property. We do not knowingly collect personal information from children under 16. If you believe a minor has submitted information, please email privacy@aduverified.com and we will delete the record promptly. Under CPRA, we do not sell or share personal information of consumers we know to be under 16 without affirmative opt-in consent.
8. Security
We use reasonable administrative and technical safeguards designed to protect your information, including:
- HTTPS / TLS encryption for all Site traffic.
- Row-level security on our database tables (the public can insert a single inquiry but cannot read, update, or delete any data).
- Strict separation between public (anon) and administrative (service-role) credentials; administrative credentials are never exposed to the browser.
- Per-IP rate limiting and an anti-bot honeypot on the inquiry endpoint.
- Same-origin checks on form submissions to reduce cross-site abuse.
- Secrets and API keys stored outside the source repository.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we will notify you and any required authorities if we learn of a security incident affecting your personal information, as required by law.
9. International users
ADUVerified is a U.S. service intended for U.S. homeowners in the states we currently cover (California, Oregon, Washington, Colorado, Texas, Arizona). The Site and our data are hosted in the United States. If you access the Site from outside the U.S., you understand that your information will be transferred to and processed in the United States, which may have different data-protection rules than your home country.
10. Cookies and similar technologies
We use a minimal set of strictly-necessary cookies and local-storage items required to operate the Site (for example, to remember that you successfully submitted the inquiry). Our analytics provider, Plausible, is cookieless. We do not use third-party advertising cookies, retargeting pixels, or cross-site trackers. If that changes, this Policy will be updated and a cookie banner added where required by law.
11. Third-party links
The Site links to third-party websites (e.g., state ADU-program pages, official licensing boards). We are not responsible for the privacy practices or content of those sites. Read the privacy policies of any third-party site you visit.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent revision. If we make material changes (for example, adding new third-party recipients of your information, or new categories of data we collect), we will notify you by email (to the address you used to submit your inquiry) or by a prominent notice on the Site before the changes take effect.
13. Contact us
Questions, requests, or concerns about this Policy or your information:
- Email: privacy@aduverified.com
- Alternate email: chad@prismagentsolutions.com
- Mailing address: [Insert business mailing address before launch — required for CAN-SPAM compliance on marketing emails.]
14. Effective date
This Privacy Policy is effective as of the “Last updated” date shown above.