Privacy Policy

JavaScript is disabled. Some interactive features are unavailable. To manage cookies, please use your browser settings. You can still submit data requests via the email addresses provided below.

Effective Date:

Last Updated: January 15, 2025

Welcome to contractorcalctools. Your privacy is important to us. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our website and services.

By using our services, you agree to the practices described in this policy. Please read it carefully.

1. Information We Collect

We collect information to provide and improve our services. Here's what we may collect:

Category Description Retention
Personal Data Name, email, phone number (when you provide them) 5 years after last activity
Usage Data Pages visited, calculator inputs, feature usage 24 months
Cookies & Tracking Session IDs, preference cookies, analytics data Up to 13 months
Device & Log Data IP address, browser type, OS, access timestamps 12 months
Payment Data Transaction IDs (full card details handled by processor) 7 years (legal requirement)
Personal Data — More Details

Examples: Name, email address, phone number, postal address, account credentials.

How collected: Directly from you via contact forms, account registration, newsletter signups, or customer support.

Retention: Typically 5 years after your last activity or account closure to meet legal and tax obligations.

Usage Data — More Details

Examples: Which calculators you use, calculation inputs (aggregated, not linked to identity unless logged in), pages viewed, time spent on site.

Purpose: To improve our tools and understand what features are most valuable.

Retention: 24 months, then aggregated or anonymized.

Device & Log Data — More Details

Examples: IP address, browser version, operating system, referring URL, access times.

Purpose: Security, fraud prevention, troubleshooting, and service optimization.

Retention: 12 months, then deleted or anonymized.

2. How We Use Your Data

We use collected information for the following purposes:

  • Provide Services: Operate calculators, process requests, deliver content. (Legal basis: Contract)
  • Account Management: Create and manage your account. (Legal basis: Contract)
  • Communication: Respond to inquiries, send updates, provide support. (Legal basis: Legitimate Interest, Consent for marketing)
  • Improvement: Analyze usage patterns to enhance features. (Legal basis: Legitimate Interest)
  • Security: Detect and prevent fraud, abuse, and threats. (Legal basis: Legitimate Interest, Legal Obligation)
  • Legal Compliance: Meet regulatory and legal requirements. (Legal basis: Legal Obligation)
Legal Bases Explained (GDPR)
  • Consent: When you explicitly agree (e.g., marketing emails, analytics tracking).
  • Contract: When processing is necessary to fulfill a service you requested.
  • Legitimate Interest: When we have a valid business reason, balanced against your rights (e.g., security, improvement).
  • Legal Obligation: When required by law (e.g., tax records, legal requests).

3. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance functionality, remember preferences, and analyze usage.

Types of Cookies

Type Purpose Examples Opt-Out
Necessary Essential for site functionality Session ID, CSRF token Cannot disable
Preferences Remember your settings Theme, language, consent Browser / Settings
Analytics Understand usage patterns _ga, _gid (Google Analytics) Cookie Settings / GA Opt-out
Advertising Personalized ads Ad network cookies Cookie Settings / Ad Choices
Full Cookie List
Cookie Name Provider Purpose Expiry
cc_consent contractorcalctools Stores cookie preferences 90 days
session_id contractorcalctools Session management Session
_ga Google Analytics user identifier 2 years
_gid Google Analytics daily visitor ID 24 hours

4. Analytics & Advertising

Analytics

We may use Google Analytics to understand how visitors interact with our site. This service uses cookies to collect anonymized usage data.

How to opt out:

Advertising

We may display third-party advertisements. Advertising partners may use cookies to show ads relevant to your interests.

How to opt out:

5. Third-Party Services & Processors

We work with trusted third-party service providers. These processors are contractually bound to protect your data.

Category Provider Purpose Privacy Policy
Hosting [Hosting Provider] Website hosting & CDN [Link]
Email [Email Provider] Transactional emails [Link]
Analytics Google Analytics Usage analytics Google Privacy
Payments [Payment Provider] Payment processing [Link]
Data Transfer Safeguards

When data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards:

  • Standard Contractual Clauses (SCCs): EU-approved contract terms for international transfers
  • Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
  • Data Processing Agreements (DPAs): Binding contracts requiring data protection

Contact us to request copies of relevant safeguards.

6. Data Retention & Deletion

We retain your data only as long as necessary for the purposes described, or as required by law.

Retention Summary

  • Account data: 5 years after account closure
  • Usage analytics: 24 months (anonymized after)
  • Support inquiries: 3 years from resolution
  • Financial records: 7 years (legal requirement)
  • Marketing consent records: Until consent is withdrawn + 3 years
  • Cookie consent: 90 days (then re-prompted)

Deletion Requests

You can request deletion of your personal data at any time. See the Data Request section below for instructions.

7. Your Rights Under GDPR

If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights:

  • Right of Access: Request a copy of your personal data we hold
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion ("right to be forgotten")
  • Right to Restriction: Limit how we process your data
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Object to processing based on legitimate interests or direct marketing
  • Right to Withdraw Consent: Withdraw consent at any time (doesn't affect prior processing)

To exercise these rights, use our Data Request Form or contact our Data Protection Officer.

Data Protection Officer (DPO) Contact

DPO Name: [Data Protection Officer Name]

Email: dpo@contractorcalctoolstools.com

Address: [Company Address]

We will respond within 30 days. You may also lodge a complaint with your local supervisory authority (e.g., ICO in UK, CNIL in France).

8. Your Rights Under CCPA (California Residents)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Right to Know

You can request disclosure of:

  • Categories of personal information we've collected
  • Specific pieces of personal information we hold about you
  • Sources of the information
  • Business purposes for collection
  • Categories of third parties with whom we share data

Right to Delete

You can request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, completing transactions, security purposes).

Right to Correct

You can request correction of inaccurate personal information we maintain about you.

Right to Opt-Out of Sale/Sharing

We do not sell your personal information. We do not share personal information for cross-context behavioral advertising. If this changes, we will provide a clear "Do Not Sell or Share My Personal Information" link.

Right to Limit Use of Sensitive Information

You can limit our use of sensitive personal information to what is necessary for providing services.

Non-Discrimination

We will not discriminate against you for exercising your CCPA rights. You will receive equal service and pricing.

How to Submit a Request

California residents can submit requests by:

Verification: We will verify your identity before processing. You may designate an authorized agent to make requests on your behalf.

Response time: 45 days (may be extended by an additional 45 days with notice).

9. International Data Transfers

Your data may be transferred to and processed in countries outside your region, including the United States and other jurisdictions where our service providers operate.

We implement appropriate safeguards for international transfers:

  • Standard Contractual Clauses (SCCs): EU-approved contractual terms
  • Data Processing Agreements: Binding contracts with all processors
  • Adequacy Decisions: Transfers to countries with adequate protection levels
  • Supplementary Measures: Additional technical and organizational safeguards where needed

Contact us at privacy@contractorcalctoolstools.com for information about specific safeguards applicable to your data.

10. Data Security

We implement robust technical and organizational measures to protect your personal data:

  • Encryption in Transit: All data transmitted using HTTPS/TLS 1.2+
  • Encryption at Rest: Sensitive data encrypted in our databases
  • Access Controls: Role-based access limited to authorized personnel only
  • Authentication: Strong password policies and multi-factor authentication for staff
  • Regular Audits: Periodic security assessments and vulnerability scanning
  • Employee Training: Staff trained on data protection and security practices
  • Incident Response: Documented procedures for breach detection, containment, and notification
  • Vendor Security: Security assessments of third-party processors

Important: While we strive to protect your data, no system is 100% secure. We cannot guarantee absolute security of data transmitted over the internet.

Report Security Issues

If you discover a security vulnerability or have concerns, please report them immediately to:

Security Contact: security@contractorcalctoolstools.com

11. Children's Privacy

Our services are intended for users aged 18 and older, or 16 and older with parental consent in the EU/UK. We do not knowingly collect personal information from children under 13 years of age (or under 16 in jurisdictions where applicable).

If we discover we have collected data from a child:

  • We will promptly delete the information
  • We will notify the parent or guardian if identifiable
  • We will take steps to prevent future collection

Parents and guardians: If you believe your child has provided personal information to us, please contact us immediately at privacy@contractorcalctoolstools.com so we can take appropriate action.

13. Automated Decision-Making & Profiling

We currently do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on you.

Our calculators process the data you input to generate results, but these are tools for your reference and do not constitute automated decisions about you.

If we implement automated decision-making in the future:

  • We will update this policy with clear information
  • We will provide a way to request human review
  • We will explain the logic involved and potential consequences

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How We Notify You

  • We will update the "Last Updated" date at the top of this page
  • For material changes, we may notify you via email (if you've provided one)
  • We may display a prominent notice on our website
  • For significant changes affecting your rights, we may request renewed consent

We encourage you to review this policy periodically. Your continued use of our services after changes constitutes acceptance of the updated policy.

Version History
  • v1.0 — January 15, 2025: Initial public release
  • Draft — January 1, 2026: Internal review version

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

General Privacy Inquiries

Data Protection Officer

EU Representative

If required under GDPR Article 27:

  • Name: [EU Representative Name]
  • Address: [EU Address]
  • Email: [EU Representative Email]

Response Time: We aim to respond to all inquiries within 5 business days.

Request Your Data

Use the tools below to exercise your data protection rights. We'll help you generate the appropriate request.

Generate a Data Request Email

Select your request type and provide your email. We'll create a pre-filled email for you to send.

Identity Verification

To protect your privacy, we may need to verify your identity before processing requests. Please be prepared to provide:

  • The email address associated with your account or inquiries
  • Account username or customer ID (if applicable)
  • Additional verification information if requested

Response Timeframes

  • GDPR requests: Within 30 days (may extend by 60 days for complex requests)
  • CCPA requests: Within 45 days (may extend by 45 days with notice)
  • Other requests: Typically within 30 days

If we cannot fulfill your request, we will explain why and inform you of your right to appeal or complain to a supervisory authority.

Our Commitment to Privacy

Our promise: We believe in transparency and respect for your data. We only collect what we need, we protect what we collect, and we give you control over your information.

  • ✓ No hidden trackers beyond what's disclosed
  • ✓ No selling of personal information
  • ✓ Clear controls for your preferences
  • ✓ Responsive to your requests

Questions? Contact us anytime. Manage cookies via Cookie Settings.

Developer Compliance Checklist (Internal Use)

TODO items for server-side implementation and legal review:

  • ☐ Implement /api/privacy-requests endpoint for DSAR handling
  • ☐ Create /api/consent-log for audit trail
  • ☐ Generate /sitemap.xml including this page
  • ☐ Create /api/sitemap.json for programmatic access
  • ☐ Maintain data mapping documentation
  • ☐ Collect and store vendor DPA records
  • ☐ Create detailed retention schedule document
  • ☐ Set up 30-day DSAR response alerts/automation
  • ☐ Configure analytics to check consent flags before loading
  • ☐ Add server-side CSP headers (supplement meta tag)
  • ☐ Implement cookie consent server-side validation
  • ☐ Set up breach notification procedures
  • ☐ Schedule annual policy review
  • ☐ Legal team final review and sign-off