Privacy Policy
Last updated: May 2026
Your privacy matters to us. This policy explains what information we collect, how we protect it, and your rights under Florida law (FIPA) and federal privacy regulations.
1. Overview
HALOFIX USA LLC ("HALOFIX," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website, mobile application, and platform services (collectively, the "Service").
We comply with the Florida Information Protection Act (FIPA), the Children's Online Privacy Protection Act (COPPA), and other applicable privacy laws. We write this policy in plain language so it is easy to understand.
2. What Data We Collect
We collect only the information needed to provide our services. We do not collect more than necessary.
| Data Type | Examples | How We Use It |
|---|---|---|
| Contact Info | Name, email address, phone number | To create your account and communicate with you |
| Address | Home address, service location | To match you with nearby heroes |
| Payment Method | Credit card last 4 digits (full numbers stored by Stripe) | To process payments for services |
| GPS Location | GPS coordinates during active booking | To track hero arrival and service location |
| Service Details | Photos of repair needs, job descriptions | To match you with the right hero |
| Communications | Messages, calls, support tickets | To coordinate service and provide support |
We do not collect sensitive information like Social Security numbers, health records, or biometric data unless legally required for specific hero verification purposes.
3. How We Use Data
We use your personal information to:
- Provide Services: Create your account, process bookings, and coordinate with heroes
- Match You with Heroes: Use your location and service needs to find available, qualified heroes
- Communicate: Send booking confirmations, arrival notifications, and service updates
- Process Payments: Handle billing and payments through our secure payment processor
- Ensure Compliance: Meet legal requirements, verify hero licenses, and prevent fraud
- Improve Our Service: Analyze usage patterns to make our platform better (using anonymized data only)
We only use your data for the purposes listed here. If we ever want to use it for something else, we will ask for your permission first.
4. No Lead Selling — Your Data Stays With Us
We Never Sell Your Personal Data
We never sell, rent, or share your personal data with advertisers or lead brokers. Your information is used only to provide you with home services through our platform.
We only share your data in these limited circumstances:
- With Your Hero: Once a hero accepts your job, we share your contact information and address so they can perform the service
- Service Providers: We use trusted companies (like Stripe for payments, Twilio for texts) that help us run our platform. They are contractually bound to protect your data.
- Legal Requirements: We may share data if required by law, such as to comply with a court order or government request
- Emergencies: To protect your safety or the safety of others in an emergency
5. GPS & Location Data
We collect GPS location data, but only when you have an active booking. Here is how it works:
- When: dispatch updates is active only during the period between hero dispatch and job completion
- What: We track the hero's location to show you their estimated arrival time
- How Long: GPS coordinates are stored for 10 minutes in temporary memory (Redis cache) and then automatically deleted
- Permanent Records: We keep only milestone events (job started, hero arrived, job completed) — not continuous location history
Your Control
You can disable location sharing in your device settings, but this may prevent real-time hero tracking features from working.
6. AI & Automated Decision Making
We use artificial intelligence to help improve our services. Here is what you should know:
- AI Estimates: When you upload photos for an estimate, our AI analyzes them to provide an approximate cost range. These are estimates only — final quotes come from heroes after inspection.
- Hero Matching: Our system uses algorithms to suggest heroes based on location, availability, and expertise. You always choose which hero to book.
- Fraud Detection: Automated systems help us detect suspicious activity to protect your account.
- Human Review: Important decisions (like account suspension or dispute resolution) always involve human review.
You have the right to request human review of any automated decision that significantly affects you. Contact us at privacy@halofixusa.com to request a human review.
7. Call Recording Notice
Two-Party Consent Notice
Calls may be recorded. By continuing, you consent to recording.
Under Florida Law §934.03 (two-party consent), we notify all callers that calls may be recorded. Here is how it works:
- Notice: An automated message plays at the start of each call informing you that the call may be recorded
- Purpose: We record calls for quality assurance, training, and to resolve disputes
- Retention: Call recordings are kept for 90 days unless related to a dispute, in which case they are kept until the dispute is resolved
- Access: You may request a copy of recordings involving you by contacting privacy@halofixusa.com
If you do not wish to be recorded, you may end the call and contact us via email or through our website chat.
8. SMS/Text Messaging Terms
By providing your phone number and checking the SMS consent box during booking, you agree to receive transactional text messages from HALOFIX USA LLC related to your home service bookings. These messages may include:
- Booking confirmations and appointment reminders
- Hero dispatch and arrival notifications
- Service completion and payment updates
- Digital warranty and receipt delivery
Message frequency varies based on your service bookings. Message and data rates may apply. You can opt out at any time by replying STOP to any message. For help, reply HELP or contact us at support@halofixusa.com or call (786) 550-2580.
Your consent to receive SMS is not a condition of purchasing services. We will never share your phone number with third parties for marketing purposes.
If you have separately opted in to receive promotional communications, HALOFIX USA LLC may also send you promotional SMS messages including seasonal maintenance reminders, exclusive discounts for existing customers, and warranty renewal offers. Promotional SMS consent is separate from transactional SMS consent and is not required to use our services.
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All SMS opt-in data is retained solely by HALOFIX USA LLC and is not shared with service providers (Heroes) or partners for their independent marketing use.
Supported carriers include but are not limited to: AT&T, T-Mobile, Verizon, Sprint, and other major US carriers.
How to Opt Out of SMS
- Reply STOP to any message to unsubscribe immediately
- Reply HELP to any message for assistance
- Email: support@halofixusa.com
- Call: (786) 550-2580
- You will receive a one-time confirmation message after opting out
9. Third-Party Data Processors
We share data with the following service providers (processors) to operate our platform. Each processor is contractually bound to use your data only for the purposes described.
| Processor | Purpose | Data Shared | DPA Status |
|---|---|---|---|
| Cloudflare | CDN, DDoS protection, DNS | IP address, request metadata | standard terms |
| Google Analytics | Website analytics and conversion tracking | IP address, device info, browsing behavior | standard terms |
| Make (Integromat) | Workflow automation (booking notifications, CRM sync) | name, email, phone, booking details | standard terms |
| Retell AI | AI voice agent for inbound calls | phone number, call audio, call transcript | standard terms |
| Stripe | Payment processing, Hero payouts (Connect) | name, email, payment method, bank account (Heroes) | signed |
| Supabase | Database, authentication, file storage | all platform data (encrypted at rest) | standard terms |
| Twilio | SMS notifications and verification | phone number, SMS content | standard terms |
| Vercel | Application hosting, edge functions, image optimization | IP address, request metadata, server logs | standard terms |
10. Communications Monitoring
In-platform messages between Residents and Heroes are monitored by automated systems to enforce our Anti-Circumvention Policy. The system filters attempts to share personal contact information (phone numbers, email addresses, physical addresses, URLs, social media handles, and payment app handles) to protect both parties and maintain marketplace integrity.
Flagged messages are reviewed by automated systems and, where necessary, human moderators. Message content is retained per our data retention schedule below.
11. Data Retention
We keep your data only as long as necessary for business, legal, and tax purposes. Our retention periods comply with IRS and EEOC requirements:
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account credentials | Until account deletion + 30 days | Service provision; 30-day grace for accidental deletion |
| Background check results | 3 years from check date | FCRA §604(b); EEOC guidance on recordkeeping |
| Booking & transaction records | 7 years | IRS Rev. Proc. 98-25 (tax records); FL statute of limitations |
| Call recordings (Retell AI) | 90 days | Quality assurance; FL §934.03 two-party consent obtained at call start |
| Chat / messaging logs | 7 years | Dispute resolution; anti-circumvention evidence |
| Cookies & analytics data | 26 months from last interaction | Google Analytics default retention; industry standard |
| Hero insurance documents | Duration of Hero account + 3 years | Claims tail coverage; FL statute of limitations for negligence |
| Payment method tokens | Until user removes or account deletion | PCI DSS — tokenized only; raw card data never stored |
| Photos uploaded by Residents | 7 years | Warranty Vault documentation; dispute resolution |
| Profile information | Until account deletion + 30 days | Service provision; regulatory hold if under investigation |
| Reviews & ratings | Indefinite (public content) | Consumer transparency; anonymized upon account deletion |
| Server / access logs | 12 months | Security incident investigation; abuse prevention |
After these periods expire, we securely delete or anonymize your data. You can request earlier deletion by exercising your right to deletion (see "Your Rights" below), though we may need to retain certain records for legal compliance.
12. Data Security
We take security seriously and use industry-standard measures to protect your data:
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- Database Security: We use Supabase with Row-Level Security (RLS) to ensure users can only access their own data
- Access Controls: Strict role-based access limits who at HALOFIX can view personal data
- Multi-Factor Authentication: Required for all administrative access
- Regular Reviews: We conduct security reviews on an ongoing basis and engage third-party security audits and penetration testing as appropriate to platform risk
- Employee Training: All staff are trained on data privacy and security practices
No system is 100% secure, but we work hard to protect your information. If you discover a security issue, please report it responsibly to security@halofixusa.com.
13. Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Ask us to fix inaccurate or incomplete information
- Deletion: Request that we delete your personal data (subject to legal retention requirements)
- Portability: Request your data in a machine-readable format
- Opt Out: Stop receiving marketing communications at any time
- Human Review: Request a human review of any automated decision
How to Exercise Your Rights
- Online: Account Settings → Privacy
- Email: privacy@halofixusa.com
- Response Time: We respond within 45 days (may extend by 45 days for complex requests)
- Verification: We will verify your identity before processing requests to protect your privacy
14. Children's Privacy (COPPA)
No Users Under 13
HALOFIX is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use our platform or provide any personal information.
We comply with the Children's Online Privacy Protection Act (COPPA), a federal law designed to protect children's privacy online.
If you are a parent or guardian and believe your child under 13 has provided personal information to us, please contact us immediately at privacy@halofixusa.com. We will delete the information promptly.
15. Global Privacy Control (GPC)
HALOFIX USA honors the Global Privacy Control (GPC) browser signal. When we detect a GPC signal from your browser, we treat it as a valid opt-out of the sale or sharing of your personal information, as required by the CCPA/CPRA.
You can enable GPC in supported browsers (Firefox, Brave, DuckDuckGo) or via browser extensions. No additional action is required on your part.
16. Florida Residents' Rights (FIPA)
Florida Information Protection Act (FIPA)
Under Florida Statute §501.171, Florida residents have specific rights regarding their personal information:
- Data Security: We implement reasonable safeguards to protect your personal information from unauthorized access, use, or disclosure
- Breach Notification: In the unlikely event of a data breach affecting your personal information, we will notify you within 30 days of discovery as required by FIPA
- Right to Know: You have the right to know what personal information we collect and how we use it
- Access and Correction: You may request access to your personal information and correction of any errors
Reporting a Breach: If you suspect a data breach involving HALOFIX, contact us immediately at privacy@halofixusa.com or call our security hotline.
17. Background Check Data (FCRA §604(b)(2))
If you apply to join HALOFIX as a Hero (independent service professional), we may obtain one or more consumer reports about you from a consumer reporting agency in accordance with the Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681b(b)(2)(A). These reports may include criminal history, identity verification, Florida DBPR license verification, motor vehicle records, and FDLE sex offender registry searches.
A standalone written disclosure and your written authorization are required and provided before any consumer report is obtained. See the full standalone disclosure at /fcra-disclosure.
You have the right under FCRA §1681g to request a copy of any consumer report obtained about you and to dispute inaccurate information directly with the consumer reporting agency. Before any adverse action is taken based on a consumer report, we will provide you with a pre-adverse action notice, a copy of the report, and a summary of your rights, with at least five business days to respond.
18. Right of Publicity (Fla. Stat. §540.08)
Florida Statute §540.08 protects your name, photograph, and likeness from commercial use without your express written or oral consent. Where HALOFIX USA LLC uses a Resident's or Hero's name, photograph, profile picture, before-and-after work photos, review excerpts, or other likeness in marketing materials (including the public website, social media, advertising, or case studies), we obtain your express consent in advance.
Default behavior: Profile photos, names, and content you upload are used only inside the platform for booking and review functionality. Marketing use requires a separate opt-in.
You may revoke consent for prospective marketing use at any time by emailing privacy@halofixusa.com. Revocation does not affect materials already printed or published before we receive your request, but we will not produce new marketing materials using your likeness after revocation.
19. California Residents' Rights (CCPA/CPRA)
California Consumer Privacy Act (CCPA/CPRA)
California residents have the right to:
- Know what personal information we collect, use, and disclose
- Delete personal information, subject to legal exceptions
- Opt out of the sale or sharing of personal information
- Correct inaccurate personal information
- Limit use of sensitive personal information
- Non-discrimination for exercising these rights
To exercise these rights, visit our Do Not Sell or Share page or email privacy@halofixusa.com. We respond within 45 days.
20. Policy Changes
We may update this Privacy Policy from time to time. When we make material changes:
- We will post the updated policy on this page with a new "Last updated" date
- We will notify you via email or through the platform at least 30 days before material changes take effect
- For significant changes affecting how we use your data, we may request your renewed consent
Your continued use of HALOFIX after the effective date of updated terms constitutes acceptance of the changes.
19. Contact for Privacy Requests
If you have questions about this Privacy Policy, want to exercise your privacy rights, or need to report a privacy concern:
Privacy Officer
Email: privacy@halofixusa.com
Online: Account Settings → Privacy
Response Time: 45 days (may extend for complex requests)
For general support questions, please use the Help Center or contact support@halofixusa.com.
Related legal documents: