Privacy Policy
The short version: Roots is a business tool. Dealer groups put their customer records into it, and those records belong to the dealer group — we process them only to run the service for that customer, and we never sell them. On this website we collect very little: no advertising trackers, no cookies, and a booking form that is Google's, not ours.
1. Who we are and what this covers
“Roots”, “we” and “us” mean Silver Ram Holdings LLC, the operator of the Roots unified client data platform. This policy covers:
- The website at myroots.work;
- The Roots console at app.myroots.work and its API at api.myroots.work (together, the “Service”), as used by people our customers authorize (“Users”).
It does not cover the websites, apps or practices of the dealer groups that use Roots. If you are a car buyer or service customer of one of those businesses, their own privacy notice governs how they handle your information.
2. Our two roles
Customer Data — we act for our customers
Our customers (typically automotive dealer groups) load records into the Service from their own systems: dealer management systems, CRMs, service drives, survey tools and similar sources. These records can include their customers’ names, contact details, household members, vehicles, VINs, sales and service history, consent and opt-out preferences, and derived values such as value bands and handling rules (“Customer Data”).
For Customer Data we are a service provider / processor. The dealer group decides what goes in and why, and is responsible for having a lawful basis and giving any notices its customers are owed. We use Customer Data only to provide, secure and support the Service for that customer, as described in our agreement with them. We do not sell it, share it across customers, or use it for our own marketing. Requests from individuals about Customer Data — to access, correct or delete it — should go to the dealer group; if they reach us, we will pass them on.
Everything else — we decide
For website visitors, User account details and business contacts, we decide how the information is used, as described in the rest of this policy.
3. What we collect
When you visit myroots.work
- Aggregate traffic measurements via Cloudflare Web Analytics — page views, referrer, browser and country. It sets no cookies, does not fingerprint you, and does not track you across sites.
- Standard server and security logs kept by our hosting provider (such as IP address, user agent and request time) to deliver the site and defend it against abuse.
The website sets no cookies of its own and runs no advertising or social-media pixels. Fonts are loaded from Google Fonts, which receives your IP address when your browser fetches them.
When you book a walkthrough
Booking uses Google Calendar appointment scheduling. The details you enter (name, email, anything you add) go to Google and reach us as a calendar booking. Google’s own privacy policy applies to what happens inside that form. We use the details to hold the meeting and follow up about it.
When you use the Service
- Account information — name, work email, organization, role and rooftop assignments, provided by you or your employer. Sign-in is handled by WorkOS; we never see or store your password.
- Session cookies — a strictly necessary, encrypted cookie that keeps you signed in. It is not used for tracking or advertising.
- Audit and usage records — which records a User viewed or changed, when, and from which scope. These exist so our customers can govern access to their data, and we keep them as part of the Service.
- Diagnostics — error reports (via Sentry) containing technical details such as the page, browser and stack trace, used to find and fix faults.
4. How we use information
- To provide, operate, secure and support the Service;
- To authenticate Users and enforce the permissions our customers configure;
- To diagnose errors and improve reliability and performance;
- To respond to enquiries and arrange walkthroughs;
- To send service, security and account notices;
- To meet legal obligations and enforce our Terms of Service.
We do not sell personal information, share it for cross-context behavioral advertising, or use Customer Data to train general-purpose models.
5. Service providers
We rely on a small number of providers, each bound by contract to use the information only to provide their service to us:
| Provider | What they do for us |
|---|---|
| Cloudflare | Hosting, network delivery, security and privacy-friendly web analytics |
| Supabase | Managed Postgres database that stores Service data |
| WorkOS | Sign-in, single sign-on and user directory |
| Sentry | Application error monitoring |
| Appointment booking, calendar and web fonts |
We may also disclose information if required by law, to protect the rights and safety of our customers, Users or others, or as part of a merger or acquisition — in which case this policy, or one at least as protective, would continue to apply.
6. Security
Data is encrypted in transit and at rest. Access inside the Service is enforced in the database itself — row-level security and column masking by role, tier and rooftop — not just in the interface. Every profile view is written to an audit log. No system is perfectly secure, but we will notify affected customers without undue delay if we become aware of a breach involving their data.
7. Retention
We keep Customer Data for as long as our customer’s account is active, and delete or return it after the agreement ends as that agreement specifies. Account information is kept while the account is active. Logs and diagnostics are kept only as long as needed for security and troubleshooting. Booking details are kept as ordinary business correspondence.
8. Your choices and rights
Depending on where you live — including under U.S. state privacy laws such as the California Consumer Privacy Act — you may have the right to know what personal information we hold about you, to get a copy, to correct or delete it, and not to be discriminated against for exercising those rights. To make a request, email us at the address below. We will verify the request and respond within the time the law allows.
If your request concerns Customer Data held on behalf of a dealer group, please contact that business directly; we will support them in responding.
9. Where data is processed
Roots is operated from the United States and our providers may process information in the United States and other countries. Where required, we use appropriate safeguards for transfers.
10. Children
The website and Service are for businesses and are not directed to children under 16. We do not knowingly collect their personal information.
11. Changes to this policy
We will post any update here and change the effective date above. If a change is material, we will tell customers in advance by email or in the Service.
12. Contact
Questions or requests: [email protected]
Silver Ram Holdings LLC, 540 E Broadway, Haverhill, MA 01830