Privacy Policy
Last updated: April 24, 2026
Privacy Policy content
Introduction
Black Canyon Exteriors (“we,” “our,” or “us”) is a Utah exterior-services contractor providing siding, gutters, windows, concrete bollards, asphalt repairs, crack seal, seal coat maintenance, and striping to commercial and residential properties across the Wasatch Front and statewide Utah.
This Privacy Policy describes how we collect, use, and protect information when you visit blackcanyonexterior.com (the “Site”) or submit a quote request, lead-magnet form, or any other inquiry through it. It applies to all visitors, whether you are a homeowner researching a siding replacement or a property manager requesting a commercial striping estimate.
This policy is effective as of April 24, 2026. By using the Site, you acknowledge the practices described here.
Information we collect
Information you provide directly
When you fill out our contact form, quote-request form, or guide-download form, we collect the information you submit. This may include:
- Your name (first and last)
- Phone number
- Email address
- Type of service you are requesting (e.g., siding, asphalt repairs)
- The city or area of your property
- Project details, scope notes, or questions you include in the message field
- Whether the project is commercial or residential
We collect only what you choose to give us. No form on this Site requires information beyond what is necessary to follow up on your inquiry or deliver the requested resource.
Information collected automatically
When you visit the Site, our server and analytics tools collect certain technical information automatically. This includes:
- IP address (masked): We record the first three octets of your IP address (for example, 192.168.1.x) for rate-limiting and fraud-prevention purposes. We do not store your full IP address in our lead records.
- User agent: Browser type and version, operating system, and device category, as reported by your browser.
- Pages visited: Which pages on this Site you viewed during your session.
- Referrer: The URL of the page you visited immediately before arriving on this Site, if your browser sends that header.
- UTM parameters: If you arrive from a paid ad or tracked link, the campaign source, medium, campaign name, term, and content values embedded in the URL.
- Timestamps: The date and time of your form submission and your first page visit in the session.
This technical data is collected passively and is used primarily to measure marketing effectiveness and to prevent spam and abuse.
Information from third parties
We use Google Analytics 4 (GA4) to understand how visitors find and use the Site. GA4 sets cookies in your browser and sends anonymized usage data to Google’s servers. We have configured GA4 to anonymize IP addresses. Google may combine this data with other information they hold about you per their own privacy policies.
If you arrive from a paid advertisement, your browser may append a click identifier to the URL. We capture these identifiers at the session level and attach the first-touch value to your lead record so we understand which ad led to your inquiry:
- gclid — Google Ads click identifier
- fbclid — Meta (Facebook/Instagram) click identifier
- msclkid — Microsoft Advertising (Bing) click identifier
We do not purchase data from third-party data brokers or append enrichment data to your record from any outside source.
How we use your information
We use the information we collect for the following purposes:
- Follow-up on quote requests: To respond to your inquiry, schedule an on-site estimate, and communicate about your project.
- Service delivery: When a project begins, your contact information is used by our crew supervisors and office staff to coordinate scheduling, access, and completion sign-offs.
- Lead-magnet delivery: If you request a downloadable guide, we send the guide to the email address you provide and may follow up once regarding related services. You can opt out of follow-up emails at any time.
- Analytics and site improvement: To understand which pages are most visited, which services attract the most inquiries, and how our marketing channels perform.
- Fraud and abuse prevention: Rate-limiting form submissions and detecting automated or malicious requests by reference to masked IP data and submission timing.
- Legal compliance: Maintaining accurate business records, responding to lawful requests from government authorities, and preserving information required for tax, warranty, or dispute purposes.
We do not use your personal information to build advertising profiles, sell to lead aggregators, or automate unsolicited outreach beyond the initial follow-up on your request.
Legal basis and consent
We process personal information under the following bases:
- Contractual necessity: When you request a quote, providing your contact information is necessary for us to deliver the estimate you asked for. We cannot prepare an on-site assessment without knowing who to contact and where to go.
- Legitimate interest: We have a legitimate business interest in understanding how visitors find and use our Site (analytics), preventing fraudulent form submissions (rate limiting and honeypot filtering), and maintaining accurate financial and warranty records.
- Consent: For marketing emails beyond the initial follow-up on your request, we rely on your express consent. We only send marketing communications if you opt in, and every such email includes a clear unsubscribe mechanism.
You may withdraw consent for marketing emails at any time without affecting the lawfulness of processing before withdrawal, or your ability to receive quotes and service from us.
How we share information
We do not sell, rent, or trade your personal information. We share it only in the following limited circumstances:
- Employees and crew: Our office staff and, on a strict need-to-know basis, the project supervisor assigned to your job. Crew members on your property receive only the address, scheduled dates, and scope of work.
- Service providers: We use a small number of technology providers to operate the Site and our communications. These include our email delivery provider (SMTP), Google Analytics (analytics), and our cPanel shared-hosting provider (infrastructure). Each provider processes data only as necessary to provide its service to us and under appropriate data-protection agreements.
- Legal disclosures: We may disclose information if required by a valid court order, subpoena, or applicable law, or if we reasonably believe that disclosure is necessary to protect our rights, prevent fraud, or protect the safety of any person.
- Business transfers: In the event that Black Canyon Exteriors is sold, merged, or substantially all of its assets are transferred, your information may be transferred as a business asset. We would notify affected individuals before that information becomes subject to a different privacy policy.
Data retention
We retain personal information for the following periods:
- Lead and contact records: Up to 7 years from the date of your last interaction with us. This period aligns with our warranty obligations (up to 5 years on siding installation) and standard business record-keeping requirements under Utah law.
- Session and rate-limit logs: 90 days, then automatically deleted. These contain only masked IP data and submission timestamps.
- Analytics data: Retained in Google Analytics for 14 months per GA4’s default retention setting. Aggregate, non-identifiable reports may be retained longer.
- Email correspondence: Emails relating to a project or quote are retained for the same 7-year window as the lead record.
When retention periods expire, records are deleted or anonymized so they can no longer be linked to an identifiable individual.
Your rights
You have the following rights with respect to your personal information. To exercise any of them, contact us using the details in the “Contact” section below.
- Access: You may request a summary of the personal information we hold about you. We will respond within 30 days.
- Correction: If your information is inaccurate or incomplete, you may ask us to correct it.
- Deletion: You may ask us to delete your personal information, subject to legal obligations that require us to retain certain records (for example, completed-project records during the warranty period).
- Opt-out of marketing: You may unsubscribe from marketing emails at any time using the unsubscribe link in any email we send, or by contacting us directly.
- Complaints: If you believe we have handled your information improperly, you may file a complaint with the Utah Division of Consumer Protection at consumerprotection.utah.gov or (801) 530-6601.
We will not discriminate against you for exercising any of these rights. Exercising your right to deletion or opt-out will not affect your ability to receive quotes or services from us, except where the information is strictly necessary to complete an active project or warranty obligation.
Security
We take reasonable technical and organizational measures to protect your personal information:
- Encryption in transit: All data transferred between your browser and our server is encrypted via TLS (HTTPS). We enforce HTTPS site-wide and redirect all HTTP requests.
- Password hashing: Admin account passwords are hashed using Argon2id, a memory-hard algorithm recommended by NIST. We never store plaintext passwords.
- Access controls: The admin area of this Site is password-protected and accessible only to authorized personnel. Database access is restricted to our hosting environment.
- Backups: Daily encrypted database backups are retained for 30 days.
- Incident response: In the event of a confirmed data breach that affects your personal information, we will notify affected individuals within 72 hours of discovering the breach, and comply with applicable state notification requirements under the Utah Consumer Privacy Act.
No system is completely secure. While we take these precautions seriously, we cannot guarantee that unauthorized access, disclosure, or loss will never occur.
Children’s privacy
This Site is directed to adults making purchasing or inquiry decisions about property maintenance. We do not knowingly collect personal information from children under the age of 13. If you believe that a child under 13 has submitted information through our Site, please contact us immediately at privacy@blackcanyonexterior.com and we will delete that information promptly.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we will revise the “Last updated” date at the top of this page. For material changes — those that meaningfully affect how we collect or use personal information — we will provide more prominent notice, such as a note on the Site home page for 30 days following the change.
Your continued use of the Site after a policy update constitutes your acknowledgment of the revised policy. If you do not agree with the changes, you should stop using the Site and may request deletion of your information per Section 7 above.
Contact
For questions, concerns, or requests related to this Privacy Policy or your personal information, contact us:
Black Canyon ExteriorsSalt Lake City, Utah
Email: privacy@blackcanyonexterior.com
Phone: (801) 842-8310
You can also reach us through the contact page on this Site. We respond to privacy inquiries within 5 business days.