Privacy policy
Effective date: 2026-05-25 · Last updated: 2026-05-25
CostPatch is operated by H19 Research Group LLC. This privacy policy describes what data we collect, how we use it, and your rights as a user — applicable globally, with specific provisions for residents of the EU, UK, California, and other jurisdictions with strong consumer privacy laws.
1. Information we collect
We collect three categories of data:
Automatically collected (every visitor)
- Server logs — IP address, user agent, referring URL, requested URL, timestamp. Stored for 30 days for security analysis and abuse prevention.
- Analytics cookies — Google Analytics 4 (GA4) places cookies that record anonymized usage data: pages viewed, time on site, device type, approximate geolocation (state-level only).
- Cloudflare — our CDN provider sets security cookies and may collect IP addresses for DDoS protection. See Cloudflare's privacy policy.
Voluntarily submitted
- Email submissions — when you email us at [email protected] or similar addresses, your email and message content are stored in Gmail (Google Workspace).
- Lead-gen form submissions — when you request quotes via embedded forms from our affiliate partners (Networx, Bark, Angi, etc.), the data you submit goes DIRECTLY to those partners. We do not store this data on CostPatch servers. See partner privacy policies linked at the form.
- Future email signups — we may add email newsletter signup in the future. If so, this section will be updated and signup will be explicitly opt-in.
2. How we use your data
- Site analytics — to understand which articles are most useful and improve content priorities
- Lead-gen referrals — to route your quote requests to relevant contractors (only when you initiate this via embedded forms)
- Email replies — to respond to inquiries you send us
- Security and abuse prevention — server logs may be reviewed if we detect bot traffic, scraping attempts, or other abuse
3. What we DON'T do
- We don't sell your data to data brokers, marketing lists, or any third party
- We don't track you across other websites — we don't use cross-site tracking pixels (Facebook Pixel, Twitter pixel, etc.)
- We don't store credit card or payment information — we don't sell anything directly, so we never see your payment data
- We don't share your data with our affiliates unless you explicitly request a quote routing via their forms
4. Third-party services we use
| Service | Purpose | Data shared | Privacy policy |
|---|---|---|---|
| Google Analytics 4 | Site analytics | Anonymized usage | |
| Google AdSense (when activated) | Display advertising | Ad personalization data | Google Ads |
| Cloudflare | CDN + DDoS protection | IP address | Cloudflare |
| Networx (when used) | Lead-gen routing | Quote form submissions | Networx |
| Bark (when used) | Lead-gen routing | Quote form submissions | Bark |
| Google Workspace | Email ([email protected] etc.) | Emails you send us |
5. Cookies
CostPatch uses the following cookie categories:
- Essential cookies — session cookies used for site security (Cloudflare). Cannot be disabled.
- Analytics cookies — Google Analytics 4 cookies. You can opt out via Google Analytics Opt-out Browser Add-on.
- Advertising cookies (when AdSense is active) — Google's ad personalization cookies. You can opt out at Google Ads Settings.
6. Your rights
EU and UK (GDPR / UK GDPR)
You have the right to: access your data, request correction, request deletion, restrict processing, port your data, object to processing, and not be subject to automated decision-making. Email [email protected] with "GDPR Request" in the subject and we'll respond within 30 days.
California (CCPA/CPRA)
California residents have the right to: know what personal information is collected, know whether it's sold (we don't sell), request deletion, opt out of sale (we don't sell), and non-discrimination for exercising these rights. Email [email protected].
Other jurisdictions
Residents of jurisdictions with consumer privacy laws (Virginia VCDPA, Colorado CPA, etc.) have equivalent rights. Same email contact applies.
7. Data retention
- Server logs: 30 days
- Email correspondence: retained while ongoing, archived after 12 months of inactivity
- Analytics aggregates: per Google Analytics 4 default (14 months, anonymized)
- Lead-gen form data: held by partners (Networx, Bark, etc.), not us
8. Children's privacy
CostPatch is intended for adults (18+). We do not knowingly collect data from anyone under 13. If you believe a minor has submitted data, please email us immediately and we'll delete it.
9. International data transfers
CostPatch servers are located in the United States. Visitors from outside the US should be aware that your data may be transferred to and processed in the US. By using the site, you consent to this transfer.
10. Changes to this policy
We may update this privacy policy from time to time. Material changes will be flagged with a banner on the homepage for 30 days. The "Last updated" date at the top of this page always reflects the most recent version.
11. Contact
Privacy-related questions or requests: [email protected]