Who we are
Tailgate Office is operated by Tailgate Office, LLC, a Maryland company founded by the web agency Data Processing LLC. We build quoting, missed-call and hiring tools for home-service contractors.
This website has three parts. The public pages are a marketing site with one contact form — request a trial, ask for the agency partner kit, or send a question. There is a member area at /members/ where contractors who start a trial log in to run the product; that part has accounts, team logins and stored business data, described in its own section below. And there is an agency console at /agency/ for the web agencies that resell the product to their own clients — if you bought through one of them, the section headed “If an agency partner runs your account” is the one to read. All three sign in at /login/. What is still true everywhere: no payment card data is collected anywhere on this site, because no payment processor is connected — there are no card numbers to lose, because we never have them.
Questions about anything on this page: support@tailgateoffice.com or (301) 268-1943.
Read this first
This is a plain-English policy we publish for transparency. It describes what we actually do, in words we would use on the phone.
It is not legal advice, to you or to us, and it should be reviewed by the company’s attorney before public launch. If anything here ever conflicts with what we actually do, tell us — the fix is to change the practice or change the page, same day.
What we collect
Two places, and only two: the form you filled in, and the pageview record our own analytics writes when you open a page. Here is the complete list of both, and why each line is on it. The form first.
| What | Why we ask for it |
|---|---|
| Name | So the reply starts with your name and not “Dear Sir or Madam”. |
| Company name | So we know which business we are setting a trial up for. |
| Website | Optional, on the trial form. So we can see your business and your account knows where your quote form will go; it is copied to your account. |
| It is how we answer you. | |
| Phone | Some people would rather talk. We call the people who prefer calls. |
| Trade | A fencing company and a cleaning company need different setups. Knowing the trade makes the first reply useful instead of generic. |
| City, state and ZIP | Optional. So we know which market you work in, can say something useful about your area, and can point a partner referral at the right person. Three separate fields on the form; none of them is required. |
| Plan interest | So we provision the product you actually asked about, not a pitch for all four. |
| Message | Whatever you chose to write. We read it; nothing scans it for keywords. |
| IP address | Recorded automatically with the submission. Used for form security and rate limiting of trial and partner submissions — it is how we keep bots from flooding the form. |
| Timestamp | Recorded automatically, so we know when the inquiry came in and how embarrassingly long we took to answer it. |
| Where you came from | Only when the link you followed carries a short tag (src or utm_source, such as call or google-ads): the tag, saved as a note on your inquiry, so we know which of our own links and calls bring people in. It is never matched to the visitor analytics below. |
That is the whole form list. No payment card data is collected anywhere on this site. Data you enter inside the member area after you start a trial is separate, and it is described in its own section below. If a field is not in the table above or that section, the public form does not collect it.
And what our own analytics record
Since August 9, 2026 this site counts its own visitors, with software we wrote, running on our server. No Google Analytics, no vendor, no copy of this anywhere else. Here is every field it writes.
| What | Why we record it |
|---|---|
| Date and time | When the page was opened. It is how “visits this week” becomes a number. |
| Page path and title | Which page you opened. So we can tell which pages get read and which ones nobody finds. |
| Referring site | Where you arrived from. On a normal page we keep only the host — “google.com”, not the full address. On a 404 page we keep the whole referring URL, because that is the only way to find the broken link and fix it. |
| Traffic source label | A one-word bucket: direct, google, facebook, another site’s host name, or internal. It is how we know whether writing blog posts is worth the evenings. |
| Device type, browser family, OS family | Desktop, mobile or tablet, plus the browser and operating system family. Worked out from the User-Agent your browser sends. The raw User-Agent string is not stored — only those three general labels. |
| HTTP status | 200 or 404. A page quietly 404ing for a month is the sort of thing we would rather find in a report than in an angry email. |
| Campaign tags on the link you clicked | Only the marketing parameters — utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid, fbclid, msclkid, ref and plan — so we can tell which ad or link sent you. Nothing else from the address bar is kept, because a query string can carry a token or an email address and none of that belongs in an analytics table. |
| Visitor and session IDs | The random numbers in the tg_vid and tg_sid cookies. They separate a returning reader from a new one and group your pages into one visit. Random numbers only — no personal data in either. |
| IP address — temporarily | Recorded with the pageview and deleted as soon as the location lookup finishes. If location lookup is switched off, the record is marked done immediately and the address goes with it. We do not keep visitor IPs in the analytics data. |
| Approximate location | Country, state or region, and city — so we know whether we are being read in Maryland or Manitoba. Only present when the optional location lookup described below is switched on; it is off by default. Never a street address and never precise coordinates. |
And what is deliberately not in it: no name, no email, no phone number, no raw User-Agent, no keystrokes, no session recording, no scroll or mouse tracking, and nothing at all about where you go after you leave. Bot and crawler traffic is filtered out and never recorded, and signed-in administrators are excluded by default so our own clicking does not pollute the numbers.
These records are never joined to your form submission. If you send us an inquiry, we cannot tell you which pages you read before you did, because the two sets of data are not connected and we did not build the wire that would connect them.
The member area — the part behind a login
Since we launched the member portal, this site is no longer only a marketing page. Contractors who start a trial log in at /members/ to run the product, and that creates a second, separate set of data. Here is what it holds and how it is treated.
| What | Why it exists |
|---|---|
| Member accounts & team logins | Your name, email and a hashed password (never the password itself), plus any logins you add for your own staff. It is how you and your team sign in and run the tools. |
| Your business profile & settings | Business name, phone number, hours, pricing rules and message templates — the configuration that makes the product yours. |
| Leads and conversations | Quotes, rescued-call threads and applicants your account captures, stitched into a shared inbox. This is your customers’ and applicants’ data, held so we can run the service for you. |
| Your office records | The customers, jobs, estimates, invoices and crew you keep in the office tools, and the emails those tools send your customers for you (estimates, invoices, your replies, and the quote follow-ups, visit reminders, review, repeat-service and referral emails you switch on), which go out under your business’s name. Your records about your own work, held so the tools can run. |
| Homeowners’ IP addresses | Recorded with a quote request, a message sent through your website form, an estimate a customer accepts, and a photo upload. Used to stop one address flooding your forms and, for an estimate, as part of the record of who accepted it. A texting consent given through your website also keeps the address, the browser type and the page it was given on, with the consent record, for the five years described under Retention. Otherwise they are kept for as long as the record they came with. |
| Photos homeowners attach to quote requests | When a contractor’s quote form asks for photos, the homeowner’s own browser shrinks each photo (longest side at most 2,000 pixels) and re-saves it as a JPEG, which removes location and camera details. It is then sent straight to a private Amazon S3 storage bucket run by Amazon Web Services in its US East (N. Virginia) region, encrypted at rest. Up to five per request. Only the business the request went to sees them, in its logged-in inbox, through links that stop working within about an hour. They never change the price, are never public, and are not in emails, webhooks or CSV exports, which carry only how many there were. Who can see them: that business’s team logins. An agency partner cannot open the inbox. Our staff only reach them when support or a deletion request needs it. |
| Message outbox & logs | Outgoing texts are written to an outbox and a message log. There is no SMS gateway connected yet, so queued messages are held, not delivered — the outbox exists so nothing is lost when texting goes live. Opt-out and suppression records live here too. |
| Webhook endpoints & delivery logs | If you point our webhooks at your own software, we store the endpoint URL, its signing secret and a log of delivery attempts, so you can see what fired and replay it. |
| A login session cookie | Signing in — at /login/, for the member portal, the agency console or our own admin — sets a first-party PHP session cookie that keeps you logged in. It is covered in the cookie section below and on the cookie policy. |
What is still not here: no payment card data. We take no card for a trial or for your subscription, so there is nothing of yours to charge or to leak. If you connect your own Stripe account so your customers can pay your invoices online, they pay on Stripe’s own checkout page: the card goes to Stripe and the money to your Stripe account, never through us, and we keep only whether the invoice was paid and Stripe’s reference for that checkout. Your Stripe key is stored encrypted.
What we do with member-area data: we use it only to run the service for your account. We do not sell it, we do not share your leads or applicants with other contractors, and you can export all of it to CSV any time — including for 90 days after you cancel. Photos homeowners attach to quote requests are the one exception: the export says how many there were, not the photos, and they are deleted 90 days after you cancel, so save any you need. Apart from Stripe, when you connect your own account for online payments (above), one thing goes to someone else, and only when you ask: if you claim the free NapkinPrice install, we send your business name, contact details and website to Data Processing, LLC, who do the install, and nothing more. The terms cover the deal; this policy covers the handling.
If an agency partner runs your account
Some contractors buy Tailgate Office directly from us. Others get it from the web agency that built their website, and that agency signs in to a console at /agency/ to run the accounts in its book. If that is you, there is a second party with access to your account, and you should know exactly what they can and cannot see.
What your agency can see and do
Agency logins, agency branding settings and partner invoice documents live in the same private database as everything else on this page, and are treated the same way.
What it cannot do
There is deliberately no “log in as this client”. The console never impersonates a member. An agency partner cannot sign in as you, and the console does not give them a way to read an individual lead, an individual applicant, or the contents of a conversation in your inbox — what it produces is counts and totals, not transcripts.
Nor can it reach any account outside its own book. Every figure and every action is scoped to the accounts belonging to that agency, and that ownership is checked on each request.
Who you contract with. If you bought through a partner, your commercial relationship is with them: they set your price, they invoice you, and they are the ones who pause or cancel your plan. We hold and run the data as described on this page either way. If the partnership ends, tell us — we will move the account to a direct one, or export it and delete it, whichever you ask for.
What we use it for
Three things with what you send us, and exactly one thing with the visit records. If a use is not on this list, we do not do it.
Responding to you
You asked us something, we answer it. We contact leads by email or by phone, by hand, in response to the request they sent — that is the entire trigger. Submitting a form emails an alert to our own office address so a person sees your inquiry. Starting a trial emails you your username and a link to choose a password. After that the service emails you only about your account: getting-started notes on days 3, 10 and 20 of a trial; a reminder five days before the trial ends and another on its last day; a password reset when you ask for one; a security notice when your password, your saved Stripe key, your team's logins or your alert address change; an invitation to anyone you add to your team; a notice when you activate, pause, un-pause or cancel on Billing; a confirmation if you claim the free install; and the alerts about your own business (a new quote, message or applicant, an accepted estimate, reminders before the licence, insurance and bond dates you save run out, and a weekly summary you can switch off). None of it is marketing, and we do not send you marketing text messages.
Setting up what you asked for
If you requested a trial or the agency partner kit, we use what you submitted to provision it. A trial is set up automatically the moment you submit the form (a submission our spam check holds waits for a person to look at it first, and an address that already has an account keeps that account), which is why the trade and plan fields matter.
Operating the business
Keeping a record of who asked for what and when, following up on open inquiries, and knowing which conversations we still owe someone. Ordinary bookkeeping, not profiling.
The one use for the analytics: working out which pages people actually read, which referrals actually send anyone, and which links are broken — so we can fix and improve the site. They are not used for advertising, not used to build a profile, never sold or shared, and never linked back to a lead or a customer record.
When our texting products start delivering for customers, a business using them will text only people who contacted it first, under the TCPA, with carrier registration filed per business. One kind of text is promotional: a single follow-up about a price estimate, which a business has to switch on, and which goes only to someone who ticked a separate, optional box on that business’s quote form agreeing to it. The SMS terms and SMS privacy page linked beside that box explain those texts for each business. No SMS gateway is connected today, so nothing texts yet. That whole subject has its own page, and it is a better read than this one.
What we never do with your data
Our business is selling software to contractors. It is not selling contractors to anyone else. Your form submission is a conversation with us, and it stays one — and the record of the pages you read is a number in our own database, not a product.
There is no “trusted partners” paragraph coming, because there are no trusted partners. The only outside services that can ever see anything about a visit are Google Fonts, which serves our typeface and so sees your IP address (described further down), the optional location lookup described further down, which only ever receives an IP address to turn into a city name, and Amazon Web Services, which stores the photos homeowners attach to quote requests for us and sees the IP address and the ordinary request details of a browser sending or loading one. Email has one more: every message we send, from the office alert about your form to the emails listed above, goes through our mail relay, SMTP2GO, which sees each message’s addresses and contents in order to deliver it. If any of this ever changes, this policy changes first and the effective date at the top moves — you will not find out from a retargeting ad.
Where your data lives
Form submissions are stored in a private Microsoft SQL Server database on servers in the United States operated for us by Data Processing LLC, our affiliated hosting company. The admin area that can read it sits behind authentication with a login lockout.
The analytics pageview records live in that same private database, on those same servers. That is what “self-hosted analytics” means here: there is no analytics vendor in the picture and no second copy of this data anywhere in the world.
Photos homeowners attach to quote requests are the exception to all of that (photo uploads are not switched on for any account yet, as of September 2026; this section is in place for when they are). The photos themselves are stored for us by Amazon Web Services, in a private Amazon S3 bucket in its US East (N. Virginia) region, with all public access blocked and Amazon-managed encryption at rest. Our database keeps a record of each photo: which request it came with, its size, and when it was stored or deleted. It also notes the internet address a photo upload came from (for newer IPv6 addresses, only the network part), so that one connection cannot flood the form, and normally erases that address within three hours; the record of the upload itself goes after 30 days. Amazon stores the photos for us and is given no other use of them.
We are a small company, and we will not pretend otherwise. We do not have a SOC 2 report or an ISO certificate to wave at you. What we have is a short list of protections we actually run, verified in the code, listed on the right.
We use transport encryption (HTTPS) on the production domain, so the form travels to us encrypted in transit.
Protections we actually run
Third parties and cookies
This is normally the long section. Ours has three first-party cookies on a normal visit, one outside request your browser makes on our public pages, and one optional server-side lookup that is switched off by default. Quote photos add Amazon, described below.
One outside request: Google Fonts
Our pages load the Poppins typeface from Google Fonts. When your browser fetches the font file, Google receives your IP address as part of serving it — that is how the web works, and we would rather tell you than hope you do not ask.
That is the only third-party request your browser makes from our public pages. No third-party analytics scripts, no ad pixels, no social widgets, no tag managers — our own analytics record the visit on our server rather than loading anything into your browser.
Quote photos are the other one. When a contractor’s quote form takes photos, the homeowner’s browser sends them straight to Amazon, and when the contractor’s inbox shows them, the contractor’s browser loads them from Amazon. Amazon receives what any server receives from a browser: its IP address and the standard details sent with every request, which are the type of browser and the website the quote form is on, which that website’s own settings may send as the full page address (for an upload), or our inbox (for a photo being shown). Nothing else about the visit. If we switch on Amazon’s access logs for that storage to look into misuse, those logs hold the same details and are deleted after 30 days.
Three cookies on a normal visit, all of them ours
The site sets one first-party session cookie for form security — the same cookie keeps you signed in once you log in at /members/, /agency/ or /admin/ — plus two first-party analytics cookies: tg_vid (a random ID, two years, new versus returning) and tg_sid (a random ID, 30 minutes, groups your pages into one visit). All three are HttpOnly and SameSite=Lax, and Secure when you are on HTTPS. There are no advertising cookies and no third-party cookies here at all.
There is a fourth, tg_admin, but you will almost certainly never have it: it is only ever set in one of our own administrators’ browsers, and all it does is keep our clicking out of the visitor numbers. Same flags, no personal data.
The full story — names, purposes, durations, and what happens if you block them — is on the cookie policy page. It is still mercifully short.
The one place our analytics send anything out: optional location lookup
Our analytics can turn a visitor’s IP address into an approximate location — country, state or region, city. That feature is off by default. While it is off, nothing about your visit ever leaves our server.
If an administrator switches it on, the IP address is sent to whichever lookup service is configured — ip-api.com, ipinfo.io or ipapi.co — for the single purpose of translating that address into a place name. Nothing travels with it: no name, no page, no cookie, no other field from the record. Each unique IP is sent at most once and the answer is cached, so the same address is not looked up again.
Either way, the IP address is deleted from our own record as soon as the lookup is finished, and what we keep is a country, a state or region and a city. Never a street address, never coordinates. This lookup is the only outside service our server ever sends a visitor’s IP address to; the others that can see anything about a visit (Google Fonts, Amazon for quote photos, and SMTP2GO for email) are named under “What we never do with your data”, and we would rather name them than leave you to find out.
How long we keep it, and your choices
No invented retention schedule, and no forms-within-forms to exercise your rights. An email does it.
Retention
We keep lead records until the business relationship ends or you ask us to delete them — whichever comes first.
You will see policies quoting precise retention windows like “36 months” for lead data. We do not have a justified number like that, so we are not going to print one to look thorough. The honest answer is the sentence above.
Consent and opt-out records do have a justified number: five years. When someone agrees to texts from a business that uses Tailgate Office, refuses them, replies STOP, or unsubscribes from its emails, we keep that record (the number or address, what was agreed to or refused and in what words, and when, and for a consent given on a website form, the IP address, browser type and page address it came from) for five years after the last of those events, even after the lead or the rest of the account’s data is deleted. It is the proof that the choice was honoured, and it has to outlast the four years in which a claim under the federal telephone consumer law can be brought.
Analytics pageview records are different, because a machine can delete those on a schedule: they are removed automatically after a configurable period, 730 days — two years — by default. That is a real setting in the software, not a number chosen to look tidy on a policy page.
So are photos attached to quote requests. Photos from a form that was never sent are deleted automatically, usually within two days. Photos that arrived with a request are deleted when the business deletes them, 90 days after the business cancels or its free trial ends without a plan, and two years after the request at the latest (a real setting, like the analytics one). A photo deleted in the app is removed from Amazon’s storage within 24 hours. A homeowner can ask the business, or email us, to have their photos deleted sooner.
Access, correction, deletion
Email support@tailgateoffice.com and ask. We will tell you what we hold about you, fix it if it is wrong, or delete it if you want it gone. The one thing a deletion leaves is a consent or opt-out record, for the five years described under Retention: deleting it would remove the proof that your “stop” was respected.
This works for anyone. We do not check your jurisdiction before honoring the request. Our service is aimed at US businesses, and we do not claim GDPR representation or CCPA registered-agent machinery — but the underlying courtesy is universal: it is your information, and you can see it or take it back.
Children
This site sells business software to contractors. It is not directed at anyone under 16, and we do not knowingly collect information from anyone under 16. If you believe a minor has submitted our form, email support@tailgateoffice.com and we will delete the record.
Changes to this policy
If what we collect or how we use it changes, this policy gets updated before or at the same time as the change, and the effective date at the top moves. That is exactly what happened here: on August 9, 2026 we added our own self-hosted visitor counting, launched the member portal and opened the agency console, so this page grew an analytics table, the member-area section, the agency-partner section, the location-lookup disclosure and a new date on the same day. On September 14, 2026 it named Tailgate Office, LLC as the business and described the free install. On September 15, 2026 it gained how long consent and opt-out records are kept, and the one promotional text a business can send through our platform, only to someone who agreed to it. On September 23, 2026 the form table gained “Where you came from”, the day the form started keeping a link’s tag on the inquiry. On September 24, 2026 it listed every email the service sends, said trials are set up automatically, added the website field, the office’s records and the homeowner IP addresses kept with them, paying invoices through a contractor’s own Stripe account, Google Fonts and our mail relay, SMTP2GO.
We will not quietly swap the page and hope nobody kept a copy. The current version is always at this address, dated.
Contact
Privacy questions, access requests, corrections, deletions, or “what exactly do you have on me”:
Tailgate Office is operated by Tailgate Office, LLC. Related reading: the cookie policy and our texting compliance page.
A public form, a private member login. No third-party trackers.
When you are ready to try the product, the trial is 30 days, no credit card — and you already know exactly what happens to the form data and to the record of this visit.