What we collect, why, and what we don't do with it.
Effective 2026-07-08. TMH Consulting, Inc. d/b/a Callback HQ (“Callback HQ,” “we,” “us”).
The short version
We collect what we need to run Callback HQfor you — your account info, the inspection-related documents you upload or connect, and the messages we exchange with homeowners on your behalf. We don't sell your data, we don't use your inspection reports or homeowner communications to train external AI models, and we delete the data we're holding for you when you cancel and ask.
Tracking technologies & your consent (CIPA / CCPA)
We do not run any advertising or analytics tracking until you opt in. Under California's Invasion of Privacy Act (CIPA) and the California Consumer Privacy Act (CCPA/CPRA), we treat third-party tags as something you choose, not something we impose. On your first visit you'll see a consent banner with Accept all, Reject all, and Preferences. Nothing that communicates with Google loads unless and until you allow it.
- Default state is “denied.” Before you make a choice, we apply Google Consent Mode v2 with advertising and analytics storage set to denied. No Google tag script is downloaded and no identifiers are set.
- Recipient we may share with on consent: if you enable Advertising, we load the Google Ads tag (measurement ID AW-18247811360) operated by Google LLC, which then receives your IP address, device/browser information, and on-site activity to measure ad conversions. This is the only third-party tracking recipient on this site.
- Withdraw anytime.Use the “Privacy choices” control in the footer or the fixed button on every page to change or revoke your choice. Revoking stops the tag from loading on subsequent page loads.
- Global Privacy Control (GPC).If your browser sends a GPC signal, we treat it as a valid request to opt out of sharing for cross-context behavioral advertising — advertising stays off by default and we don't load the Google tag unless you explicitly turn it back on.
- We retain your consent choice for up to 180 days (stored locally in your browser), then ask again.
California residents' rights. You have the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of the sale or sharing of your personal information for cross-context behavioral advertising. We honor opt-out preference signals (GPC) as described above. We do not knowingly sell personal information, and we do not share it for cross-context behavioral advertising unless you opt in to Advertising tracking here.
To exercise any California privacy right, or to ask a question about tracking on this site, contact our compliance team at TMH Consulting, Inc.: info@tmhconsult.com or (760) 239-9417.
Who this policy covers
This policy describes how we handle data for two groups of people:
- Subscribers — inspection-company owners and staff who sign up at callback-hq.com, log in, and use the app.
- Homeowners — the end customers of our subscribers, who submit guarantee-claim callbacks via the embedded intake form and receive replies sent from our platform.
For homeowner data, the inspection company that owns the workspace is responsible for that data, and we process it on the inspection company's behalf and under its instructions. Please contact the inspection company directly for access or deletion of homeowner data, or email us at info@callback-hq.com and we'll route the request.
What we collect
From subscribers
- Account info: email address, name (if provided), password hash, workspace name.
- Business info you upload: inspection agreement PDF, Standards of Practice PDF or preset choice, brand logo, accent color, sending email address.
- Inspection reports:when you connect Google Drive, we read the file metadata for your inspections folder (titles, modification dates) and pull report PDFs on-demand when a homeowner's callback needs analysis. We don't exfiltrate or warehouse your full Drive.
- Payment info: handled entirely by Stripe. We store the Stripe customer + subscription IDs and the subscription state (trial/active/canceled/etc.). We never see card numbers.
- Product telemetry:basic server logs (IP, user-agent, route, timestamp, response code) used to keep the service running and to debug. We don't run third-party ad/analytics trackers on the app.
From homeowners (via the intake form)
- Name, email, phone (optional), property address.
- The inspection date and inspector name they enter.
- The free-text description of their issue, work status, and any files (photos, quotes, receipts) they upload.
This data is bound to the inspection company that owns the workspace. Other subscribers cannot see it.
How we use it
- To match a homeowner's callback to the right inspection report and run the cited analysis + reply draft.
- To send approved replies under your domain via Resend, and to thread homeowner responses back onto the originating claim.
- To bill you (Stripe) and to send transactional product emails (password reset, inspector invites, delivery receipts).
- To keep the service running, prevent abuse, and support you when you ask for help.
We do notuse your inspection reports, agreements, SoPs, claims, or homeowner messages to train any external (third-party) AI model. The Claude API requests we send to Anthropic carry your data for the single inference and are subject to Anthropic's zero-retention enterprise terms; same for OpenAI embeddings.
Who we share it with (sub-processors)
We use a small set of vetted providers to run the service. Each only sees the data they need for their job:
- Supabase (Postgres + Auth + Storage) — hosts your account, documents, and claims. US-region.
- Vercel — hosts and runs the app.
- Stripe — payments + subscription billing. Card data goes directly to Stripe; we never see it.
- Anthropic (Claude API) — analysis + reply drafting. Zero-retention contractually enforced.
- OpenAI — text embeddings for document retrieval. Zero-retention contractually enforced.
- Resend — outbound + inbound email delivery under your verified domain.
- Google APIs — Drive metadata + on-demand report read, only for the folder you authorize.
- Google Ads (Google LLC)— only on the public marketing site, and only if you opt in to Advertising via the consent banner. See “Tracking technologies & your consent” above.
We don't sell personal information, and we don't share it for cross-context behavioral advertising unless you opt in to Advertising tracking. If you don't opt in (or you send a Global Privacy Control signal), no advertising tag is loaded.
How long we keep it
- Active accounts: as long as your subscription is live.
- Canceled accounts:30 days of grace, then we delete the workspace's claims, documents, replies, and uploaded files. Account metadata (email + audit trail) is retained for a further 12 months for billing / dispute reasons, then deleted.
- Server logs: 30 days.
You can also request earlier deletion any time — see “Your rights” below.
Your rights
Depending on your US state of residence (for example, California, Colorado, Virginia, and other states with comprehensive privacy laws), you may have some combination of these rights:
- Access — get a copy of the personal data we hold about you.
- Correction — fix anything inaccurate.
- Deletion — have us remove it (subject to legal retention requirements).
- Portability — receive your data in a machine-readable format.
- Opt-out of sale/sharing— n/a for us because we don't do this, but worth saying explicitly.
- Withdraw consent— for anything we're processing on consent.
To exercise any of these, email info@callback-hq.com. We'll respond within 30 days (or within the time your state law requires). Homeowners should contact the inspection company that owns the workspace directly; if you can't reach them, email us and we'll route the request.
Security
Data in transit is encrypted with TLS. Data at rest in Supabase is encrypted at the storage layer. Row-level security is enforced on every database table so a subscriber can only ever read their own tenant's rows. Webhooks from Resend and Stripe are signature-verified before we act on them. Production secrets live in Vercel's encrypted env-var store, not in source.
No system is perfectly secure. If we ever experience a material breach that compromises your data, we'll notify you and the relevant authorities within the timelines applicable to where you live.
United States only
Callback HQ is intended for use solely within the United States of America. Our infrastructure is located in the United States, and the service is controlled, operated, and directed only to users located in the United States. We make no representation that the service or this policy complies with the data-protection or privacy laws of any country other than the United States. If you access the service from outside the United States, you do so on your own initiative and are responsible for compliance with your local laws.
Children
Callback HQis a B2B product for inspection companies. We don't knowingly collect personal information from anyone under 16. If you believe a child has provided us data, email info@callback-hq.com and we'll delete it.
Changes to this policy
We'll update the effective date at the top whenever we make a material change. For substantial changes that affect how we use your data, we'll email account owners at least 30 days before the change takes effect.
Contact
Privacy questions, requests, complaints — email info@callback-hq.com or write to TMH Consulting, Inc. d/b/a Callback HQ, 711 Center Dr, Suite 1056188, San Marcos, CA 92069.
This policy is governed by the laws of California.