Legal
Privacy Policy
Last updated 27 August 2026. This explains what information RootTend collects, why, and who it's shared with — whether you're a garden center using RootTend or a customer of one.
Who this policy covers
Two different relationships are covered here. For a garden center's own staff accounts (owners and team members who log in to the dashboard), RootTend is the one deciding how that data is used — we're the "controller," in privacy-law terms. For a garden center's own customers — the people who register a purchase, get a lifecycle or weather email, or file a claim — the garden center is the controller and RootTend is acting on their behalf as a processor. If you're one of those customers and want your data corrected or removed, the fastest path is usually contacting the garden center directly, since it's their customer list; we're also reachable at support@roottend.com and will route the request.
Information we collect
From a garden center's staff accounts:
- Name, email address, and password (stored as a one-way hash, never in plain text).
- Phone number, if provided, along with a preferred contact method for internal notifications.
- Billing details when a plan is set up — handled directly by Stripe; RootTend stores a Stripe customer/subscription reference, not card numbers.
- The garden center's name, zip code (used to fetch local weather forecasts), and settings.
- If a staff member turns on claim notifications: a push-subscription endpoint for that browser (a URL the browser issues), the keys needed to send to it, and the device's user-agent so Settings can label the phone or computer. Notifications name the plant, not the customer, because they can appear on a locked screen at the counter.
- Questions a staff member types into the plant-care assistant, stored with their login so we can count usage and see which plants the library missed. The question is sent to Anthropic to generate the answer. These are staff horticultural questions, not customer records, but they can mention a customer or a plant if someone types that in.
From a garden center's customers:
- Name, email address, and optionally a phone number and zip code, provided when registering a purchase or filing a claim.
- Purchase details: plant name, category, purchase date, and price if entered.
- Guarantee claim details: a description, an optional photo, and any messages exchanged with the garden center about the claim.
- Which emails or texts were sent and whether they were opened where that's technically available, kept in a message log.
We don't collect this information ourselves for advertising, and we don't sell it. It's used to run the guarantee and marketing features the garden center has set up.
How information is used
- Starting and tracking a plant guarantee window, and managing claims filed against it.
- Sending lifecycle emails tied to a purchase — care instructions, feeding reminders, a guarantee-window notice, and (if the garden center hasn't turned it off) a review request or a win-back message after a long gap since the last purchase.
- Sending weather-triggered alerts — frost, heat, wind, heavy rain, and similar — only to customers whose purchase category is actually relevant to that condition.
- Letting garden center staff message a customer about an open claim, by email or text.
- Sending a browser notification to staff devices that have opted in, when a customer files a claim or replies on a claim thread.
- Answering staff questions about plants from this garden center's care library, and keeping those questions so we can improve coverage and apply the per-store usage ceiling.
- Operating the account itself: authentication, billing, and the platform-level dashboard a garden center's owner uses.
Who we share information with
We use a small number of third-party services to run RootTend, and share only what each one needs to do its job:
- Resend — delivers the emails RootTend sends (confirmations, care reminders, weather alerts, claim messages).
- Twilio — delivers text messages, for garden centers and customers who've chosen text over email.
- Stripe — processes billing for a garden center's subscription. RootTend never sees full card numbers.
- Anthropic — generates answers to staff plant-care questions. The question text and retrieved care-guide excerpts are sent; customer lists are not.
- Browser push services (the vendor behind the subscription endpoint — typically Google, Mozilla, or Apple) — deliver the notification payload to a device that opted in. The payload names the plant, not the customer.
- The National Weather Service — provides forecast data for a garden center's zip code. Only the location is sent; no customer information is shared with the NWS.
- Our hosting and database providers (Vercel and its Postgres/Neon integration) — store and run the application. They don't use the data for anything of their own.
We don't share customer data across garden centers — every account's data is isolated, and one garden center can never see another's customers, purchases, or claims.
If you're a garden center's customer
You didn't sign up for RootTend directly — a garden center you bought from uses it to run their guarantee program and send you relevant updates. You can:
- Change or stop optional emails (seasonal announcements, and care or weather tips by plant type) using the preferences link on any of those messages, without affecting an open guarantee claim. Soil, mulch, pots and other merchandise never get care or weather mail.
- If you chose text messages, the SMS Terms and Conditions explain frequency, STOP/HELP, and how to reach support.
- Ask the garden center (or us, at the address below) what information is on file, and request it be corrected or deleted.
- Contact the garden center directly for anything related to your specific purchase or claim — they can see and manage that faster than we can.
Data retention
We keep account and customer data for as long as a garden center's account is active, so guarantee windows, claim history, and marketing rules keep working correctly. Staff push subscriptions last until that person turns notifications off, their login is deactivated, or the account is deleted. Assistant questions stay with the garden center's account. If a garden center closes their account from Settings, we keep that data for 30 days so they can sign back in and restore the account, or request an export. After 30 days we delete customer and staff records. Billing records — Stripe customer and subscription identifiers here, and invoices in Stripe — are kept longer where tax or accounting rules require it.
Cookies and sessions
RootTend uses a single signed session cookie to keep you logged in — no third-party advertising or tracking cookies. The cookie only identifies your session; it doesn't track you across other sites. The staff dashboard also uses first-party local storage so the install prompt can remember a dismissal; that is not a cookie, is not sent to our servers, and is not used on public customer pages. Detail is on the Cookie Policy.
Children's privacy
RootTend isn't directed at children, and we don't knowingly collect information from anyone under 13. If you believe a child's information has ended up in the system, contact us and we'll remove it.
Changes to this policy
If this policy changes in a material way, we'll update the date at the top of this page. Continued use of RootTend after a change means you accept the update.
Contact us
Questions about this policy, or a request to access, correct, or delete information, can go to support@roottend.com.
RootTend is operated by RootTend Ltd., an Illinois limited liability company, which is responsible for the information described above.
Terms of Service · SMS Terms · Cookie Policy · ← Back to FAQ