Saved estimates

Estimate payloads, private share tokens, names, and email fields designated in the database are encrypted. Access tokens are stored as hashes. Anyone with an unclaimed private link can access that estimate.

Saved estimates are prospective planning records. They are not reused as completed-job observations or contractor survey responses, and estimator location text is never copied into the cost dataset.

Voluntary cost-data research

A cost-data submission is created only after you open the separate contribution form, provide the required structured fields, and affirm research consent and accuracy. The application does not request or store a name, email, provider or customer name, street address, ZIP code, invoice number, photograph, free-text note, saved-estimate ID, IP address, or user-agent string with the research record. Hosting and security providers may still process ordinary request metadata under their own operational policies, so raw records are described as submitted without direct identifiers rather than guaranteed anonymous.

Completed-job records, contractor survey answers, and provider asking prices stay in separate evidence channels and are pending until reviewed. Raw values are not published. A service-by-project-type-by-metro cell is suppressed until one primary completed-job or contractor-survey channel has at least 10 qualifying records and the cell has adequate source diversity; provider statements never count as completed jobs. Published snapshots contain aggregates, channel sample counts, time windows, and methodology rather than row-level data.

Each accepted submission receives a secret withdrawal link. Its secret is stored in the URL fragment, which is not sent in the page or deletion-API path. Anyone holding the full link can delete the raw submission. Withdrawal leaves only the random submission ID and a withdrawn disposition on a suppression list so stale offline exports cannot reintroduce the record; that tombstone contains none of the submitted cost facts.

Pending raw records are retained for no more than 24 months; accepted raw records are retained for no more than 36 months from submission for audit and reproducibility. An operational sweep suppresses and deletes expired or rejected records at least monthly and before every export. Withdrawal removes the raw record and excludes it from future releases, but it cannot reliably remove an individual contribution from a previously published aggregate that no longer contains row-level data.

Email

Email is used for passwordless authentication and optional updates only when consent is selected. It is not requested by the cost-data forms, and no estimate or contact information is sent to providers.

Analytics

Vercel Web Analytics may record aggregate interaction and page information. Credential-bearing saved-estimate and submission-withdrawal URLs are excluded from application analytics. Analytics events must not contain totals, metro selections, email addresses, record IDs, access tokens, customer details, or property details.

Do not enter property-owner names, access codes, or sensitive details in the estimator's optional location field.

Requests

Use a submission's secret withdrawal link to delete it. Because research records have no name, email, account, or address attached, Ed in Park City LLC cannot safely locate one from your identity alone if the link is lost. Contact powerwashingproviders@tinycall.com for general privacy questions, but do not send an access code, customer name, or other sensitive property information by email.