01
No advertising or behavioural tracking
The MVP does not use advertising pixels, cross-site behavioural tracking, session replay or client-supplied tracking scripts in the homeowner assessment.
A client cannot add arbitrary JavaScript, CSS or analytics to a branded journey. Optional non-essential cookie consent is therefore not used to disguise a tracking layer that the product does not need.
02
Essential staff authentication
Staff sign-in uses security cookies needed to establish and refresh a Supabase authentication session. Six-digit email codes are the normal verification and sign-in method; an authenticator is an optional account security control.
These controls are essential to provide a private staff workspace and are not used for advertising.
03
Seven-day device-local journey recovery
Before a verified report handoff, in-progress homeowner answers are stored in that browser for up to seven days so the same device can continue. The draft is not a lead, does not create an account and is not a permission for contact.
The browser removes an expired draft. A homeowner can clear the journey sooner by using the assessment's clear/restart control or by clearing site data for Rootsly in browser settings.
- Do not use the recovery feature on a shared device if another person should not see the draft.
- Private report access is separate and is not stored as a permanent public URL.
04
Bounded first-party attribution
Rootsly may accept a small allowlisted source identifier in a same-site assessment URL, such as the slug of a Rootsly Guide. It does not retain arbitrary campaign strings, personal information or third-party identifiers.
Subdomain and widget context can identify the client experience, but host routing never replaces database tenancy or authorisation.
05
Privacy-conscious first-party events
Rootsly may count bounded server-side journey events to understand where a journey succeeds or fails. The aggregate event boundary does not store an individual answer, email, address, network address, property or persistent homeowner session record.
Operational and security logs use internal identifiers and correlation IDs; they must not contain report contents, financial answers, consent wording, access tokens or secrets.