Privacy Policy

Last updated: April 6, 2026

Sobray ("we", "us", "our") operates the website sobray.co and the application at app.sobray.co (together, the "Service"). This privacy policy explains how we collect, use, and protect your information when you use our Service.

This policy has not been reviewed by legal counsel and may be updated at any time. We encourage you to review it periodically.

Information We Collect

Account Information

When you create an account, we collect your email address and display name. You can sign up with email and password or through Google OAuth. Authentication is handled by our database provider, Supabase.

Addresses

When you request a roof measurement, we collect the street address you enter. Addresses are stored in your account's report history so you can access past measurements.

Payment Information

Subscription payments are processed by Stripe. When you subscribe, your payment card details are collected directly by Stripe on their secure checkout page. We never receive or store your full credit card number. We store only your Stripe customer ID and subscription ID to manage your billing.

Usage Analytics

We use PostHog to track anonymous usage analytics such as page views, feature usage, and funnel progression. Events are tied to your user ID but do not include personally identifiable information like your name, email, or addresses. Automatic event capture is disabled — we only track specific, intentional events.

Technical Data

Our hosting providers (Cloudflare and Render) may collect standard technical data such as IP addresses, browser type, and request timestamps through normal web server operation.

How We Use Your Information

  • To provide and operate the roof measurement service
  • To process subscription payments and manage your billing
  • To communicate with you about your account (e.g., password reset emails)
  • To improve our service through aggregated, anonymized analytics
  • To prevent abuse and ensure the security of the service

Third-Party Services

We use the following third-party services to operate Sobray. Each receives only the data necessary for its function:

Supabase — Provides authentication and database storage. Stores your email, password hash, and report data. Privacy Policy

Stripe — Processes subscription payments. Receives your email and payment card details entered on Stripe's checkout page. Privacy Policy

Google Maps Platform — Provides aerial satellite imagery. The address you enter is sent to Google to retrieve images of the roof. Privacy Policy

PostHog — Provides anonymous usage analytics. Receives your user ID and usage events. No personally identifiable information is sent. Privacy Policy

Cloudflare — Provides DNS and content delivery. May process IP addresses and standard request data. Privacy Policy

Render — Hosts the application. May process IP addresses and standard request data. Privacy Policy

Cookies and Local Storage

  • Authentication tokens — Stored in your browser's local storage to keep you logged in between visits.
  • Analytics cookies — PostHog sets session cookies for anonymous usage tracking. These are not used for cross-site tracking or advertising.

We do not use any third-party advertising or tracking cookies.

Data Retention

  • Account and report data is retained for as long as your account is active.
  • Temporary processing files (satellite images, intermediate calculations) are automatically deleted after each measurement is completed.
  • Analytics data is retained according to PostHog's standard retention policies.
  • If you delete your account, your data will be removed from our database. Some data may persist in encrypted backups for a limited time.

Your Rights

  • Access — You can request a copy of the data we hold about you.
  • Deletion — You can request that we delete your account and all associated data by emailing us.
  • Correction — You can request corrections to inaccurate information.

To exercise any of these rights, contact us at support@sobray.co.

Data Security

We use encryption in transit (HTTPS) across all services. Data stored in our database and payment systems is encrypted at rest. Access to production data is restricted. However, no method of transmission over the internet is 100% secure, and we cannot guarantee the absolute security of your data.

Children's Privacy

Sobray is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this privacy policy from time to time. Changes will be reflected with an updated "Last updated" date at the top of this page. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

Contact

If you have questions about this privacy policy, contact us at support@sobray.co.