Privacy Policy
Last updated: October 13, 2025
Castle Shields, Inc. respects your privacy and is committed to protecting your personal and property information.
This policy explains what we collect, how we use it, and how we protect it.
Information We Collect
- Personal Information: name, email, phone, billing address, payment details.
- Property Information: street address, city, state, ZIP, property type, year built, square footage, home value, occupancy status.
- Documentation You Upload: e.g., declarations pages and other supporting documents for eligibility verification with the cost-sharing community guidelines.
- Account and Usage Data: login activity, preferences, support history.
- Technical Data: IP address, device/browser details, and cookie data.
How We Use Information
- Evaluate eligibility for membership and community cost-sharing participation.
- Process payments and deliver platform services.
- Provide support and communicate about your account.
- Detect and prevent fraud and comply with legal obligations.
- Improve and secure our platform.
Sharing of Information
We do not sell or rent your information. We may share it with:
- Payment processors and financial institutions to complete transactions.
- Service providers that assist with document verification, hosting, analytics, and customer support.
- Authorities when required by law or legal process.
Third-Party Service Providers
We use the following third-party services to operate our platform:
- Google Firebase (Google LLC) — Cloud hosting, authentication, and data storage. Data processed in the United States.
- Elastic Email (Elastic Email Inc.) — Transactional email delivery. Processes email addresses and message content.
- Twilio (Twilio Inc.) — SMS and phone call services. Processes phone numbers and call/message content.
- NMI (Network Merchants) — Credit/debit card payment processing. Processes payment card data (PCI DSS compliant).
- PayPal (PayPal Holdings, Inc.) — Payment processing. Processes billing information under PayPal's own privacy policy.
- Google Analytics (Google LLC) — Website analytics and usage tracking. Collects anonymized browsing data and cookies.
- Google reCAPTCHA (Google LLC) — Spam and bot protection. Collects device and interaction data.
Data Security
We use administrative, technical, and physical safeguards such as encryption in transit (TLS/SSL), restricted access controls, secure cloud storage (Firebase/Google Cloud), and secrets management for API credentials.
Data Retention
We retain information for the following periods:
- Account data: Retained while your account is active, plus 30 days after deletion.
- Payment records: 7 years for tax and legal compliance.
- Support tickets: 3 years or until deletion is requested.
- Uploaded documents: Retained while your membership is active; deleted upon account closure.
- Analytics data: 26 months (Google Analytics default).
- Newsletter subscriptions: Until you unsubscribe or 2 years of inactivity.
Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data (Right to Erasure / Right to be Forgotten).
- Portability: Request your data in a machine-readable format.
- Opt-out: Opt out of marketing emails at any time via the unsubscribe link.
- Do Not Sell: We do not sell personal information. California residents may still submit a "Do Not Sell" request.
To exercise any of these rights, contact us at info@castleshields.com with "Privacy Rights Request" in the subject line. We will respond within 30 days.
California Privacy Rights (CCPA/CPRA)
California residents have the right to know what personal information is collected and how it is used, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell your personal information. To make a request, email info@castleshields.com.
Cookies and Tracking Technologies
We use the following types of cookies:
- Essential cookies: Required for authentication (Firebase Auth), session management, and site functionality. Cannot be disabled.
- Analytics cookies: Google Analytics (_ga, _gid) to measure site usage and improve the experience. Can be rejected via our cookie consent banner.
- Security cookies: Google reCAPTCHA uses cookies to distinguish human visitors from bots.
You can manage cookie preferences through our cookie consent banner or your browser settings. Disabling essential cookies may prevent login and core features from working.
Changes to this Policy
We may update this policy. Material changes will be posted on this page.