Privacy Policy
Effective Date: March 6, 2026 · Last Updated: March 6, 2026
1. Introduction
My HVAC Tech (“we,” “us,” or “our”) is operated by BaaDigi LLC. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit myhvac.tech (the “Site”), use our services, or interact with us in any way.
We are a commercial HVAC contractor directory serving property managers, facility managers, and commercial HVAC contractors across the United States. By using our Site, you consent to the practices described in this Privacy Policy. If you do not agree, please do not use our Site.
2. Information We Collect
2.1 Information You Provide Directly
- Account Registration: Name, email address, phone number, company name, job title
- Contractor Profiles: Business name, address, service areas, licenses, certifications, photos, project portfolios, service agreements, system specialties
- Quote Requests: Building type, system type, tonnage range, project description, budget range, timeline, preferred contact method
- Contact Forms: Name, email, phone, company name, message content
- Reviews: Ratings, written feedback, project details
- Blog Comments or Newsletter Sign-ups: Email address
2.2 Information Collected Automatically
- Device & Browser Data: IP address, browser type and version, operating system, device type, screen resolution
- Usage Data: Pages visited, time spent on pages, click patterns, search queries on our Site, referring URLs
- Location Data: Approximate geographic location derived from your IP address (city/state level only — we do not collect precise geolocation)
- Cookies & Similar Technologies: See Section 4 below
2.3 Information from Third Parties
- Google Places API: Business information for contractor verification
- Analytics Providers: Aggregated usage and traffic data
- Advertising Partners: Ad interaction data (impressions, clicks)
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and Maintain Our Services: Connect property/facility managers with commercial HVAC contractors, process quote requests, manage accounts
- Improve Our Site: Analyze usage patterns, optimize search results, enhance user experience
- Communications: Respond to inquiries, send lead notifications to contractors, deliver service-related updates
- Advertising: Display relevant advertisements through Google AdSense and similar services
- Security & Fraud Prevention: Detect and prevent unauthorized access, abuse, or fraudulent activity
- Legal Compliance: Comply with applicable laws, regulations, and legal processes
- Analytics: Measure Site performance, track traffic, and generate aggregate reports via Google Analytics 4
4. Cookies & Tracking Technologies
We use the following cookies and tracking technologies:
| Technology | Provider | Purpose | Duration |
|---|---|---|---|
| Google Analytics 4 | Google LLC | Site analytics, traffic measurement | Up to 2 years |
| Google AdSense | Google LLC | Personalized advertising | Varies |
| Supabase Auth | Supabase Inc. | Authentication, session management | Session / 7 days |
| Essential Cookies | First-party | Site functionality, preferences | Session / 1 year |
You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect Site functionality.
Google’s Use of Cookies: Google uses cookies to serve ads based on your prior visits to our Site and other websites. You can opt out of personalized advertising by visiting Google’s Ads Settings or the Network Advertising Initiative opt-out page .
5. Advertising (Google AdSense)
We may use Google AdSense to display advertisements on our Site. Google AdSense uses cookies and similar technologies to serve ads based on your interests and browsing behavior. Third-party vendors, including Google, use cookies to serve ads based on your prior visits to our Site and other websites.
Google and its partners may collect and use the following data for advertising purposes:
- Cookies and device identifiers
- IP address (for approximate location targeting)
- Browsing activity on our Site and across the web
- Interaction data with advertisements (views, clicks)
Your choices regarding advertising:
- Opt out of personalized ads: Google Ads Settings
- Opt out via industry tool: Digital Advertising Alliance
- NAI opt-out: Network Advertising Initiative
6. Third-Party Services
Our Site uses the following third-party services that may collect data:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google Analytics 4 | Website analytics | Google Privacy Policy |
| Google AdSense | Display advertising | Google Ads Privacy |
| Supabase | Database, authentication | Supabase Privacy Policy |
| Google Places API | Business data verification | Google Privacy Policy |
| Vercel | Website hosting, CDN | Vercel Privacy Policy |
7. Data Sharing & Disclosure
We may share your personal information in the following circumstances:
- With Contractors: When you submit a quote request or contact form, your inquiry details are shared with the relevant contractor(s) so they can respond to you
- Service Providers: Third-party vendors who assist us in operating the Site (hosting, analytics, email delivery) under contractual data protection obligations
- Advertising Partners: As described in Section 5, for the purpose of serving relevant advertisements
- Legal Requirements: When required by law, subpoena, court order, or government request
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize disclosure
We do not sell your personal information as defined under the California Consumer Privacy Act (CCPA) or any other state privacy law. Sharing data with advertising partners for targeted advertising may constitute “sharing” under the CCPA — see Section 11 for your opt-out rights.
8. Data Retention
- Account Data: Retained for the duration of your account plus 2 years after deletion, unless you request earlier deletion
- Quote Requests & Leads: Retained for 3 years for business record purposes
- Analytics Data: Google Analytics data is retained for 14 months (GA4 default)
- Advertising Data: Governed by Google’s retention policies
- Server Logs: Retained for 90 days
You may request deletion of your data at any time by contacting us at privacy@myhvac.tech.
9. Data Security
We implement industry-standard security measures to protect your personal information, including:
- SSL/TLS encryption for all data in transit
- Encrypted database storage via Supabase (AES-256)
- Role-based access controls for administrative functions
- Regular security monitoring and updates
While we strive to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
10. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
- Right to Know / Access: Request what personal information we have collected about you
- Right to Correct: Request correction of inaccurate personal information
- Right to Delete: Request deletion of your personal information (subject to legal exceptions)
- Right to Data Portability: Receive your data in a structured, commonly used format
- Right to Opt Out: Opt out of the sale or sharing of personal information, targeted advertising, and profiling
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To exercise any of these rights, contact us at privacy@myhvac.tech. We will respond within the timeframe required by your state’s applicable law (typically 45 days).
11. State-by-State Privacy Rights
The following section provides additional disclosures required by individual state privacy laws. These rights apply to residents of each respective state.
California (CCPA / CPRA)
Applies to: California residents. The California Consumer Privacy Act, as amended by the California Privacy Rights Act, provides the most comprehensive consumer privacy protections in the United States.
Your California Rights:
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us and our service providers
- Right to opt out of the sale or sharing of personal information
- Right to correct inaccurate personal information
- Right to limit use and disclosure of sensitive personal information
- Right to non-discrimination for exercising your rights
- Right to data portability
Categories of Personal Information Collected (past 12 months): Identifiers (name, email, phone, IP address); commercial information (quote requests, service inquiries); internet/electronic activity (browsing history, search queries, ad interactions); geolocation data (approximate, city/state level); professional information (job title, company name).
Sale or Sharing: We do not “sell” personal information as traditionally defined. However, our use of Google AdSense and similar advertising technologies may constitute “sharing” under the CCPA for cross-context behavioral advertising purposes. You may opt out of this sharing.
Do Not Sell or Share My Personal Information: To opt out, email privacy@myhvac.tech with the subject line “Do Not Sell or Share.” We also honor the Global Privacy Control (GPC) signal.
Sensitive Personal Information: We do not collect sensitive personal information as defined by the CPRA (e.g., Social Security numbers, financial account numbers, precise geolocation, racial/ethnic origin, biometric data).
Authorized Agents: You may designate an authorized agent to submit requests on your behalf. We may require verification of the agent’s authority.
Response Time: We will acknowledge your request within 10 business days and respond within 45 calendar days (extendable by 45 days with notice).
Colorado (CPA)
Effective: July 1, 2023. The Colorado Privacy Act applies to entities conducting business in Colorado or targeting Colorado residents that process data of 100,000+ consumers or 25,000+ consumers if deriving revenue from data sales.
Your Colorado Rights:
- Right to access, correct, and delete personal data
- Right to data portability
- Right to opt out of targeted advertising, sale of personal data, and profiling
Universal Opt-Out: As of January 2026, Colorado requires recognition of universal opt-out mechanisms (e.g., Global Privacy Control). We honor GPC signals from Colorado residents.
Cure Period: Colorado’s 60-day cure period expired December 31, 2025. Enforcement may proceed without a grace period. Response Time: 45 days.
Connecticut (CTDPA)
Effective: July 1, 2023 (amended mid-2026: threshold lowered from 100,000 to 35,000 consumers). Applies to entities conducting business in Connecticut or targeting Connecticut residents.
Your Connecticut Rights:
- Right to access, correct, and delete personal data
- Right to data portability
- Right to opt out of targeted advertising, data sales, and profiling
Universal Opt-Out: Connecticut requires recognition of universal opt-out mechanisms (GPC) as of January 2026. We honor GPC signals.
Minors: Sale of personal data of minors and targeted advertising to children is prohibited regardless of consent. Response Time: 45 days.
Virginia (VCDPA)
Effective: January 1, 2023. Applies to entities that conduct business in Virginia or target Virginia residents and process data of 100,000+ consumers, or 25,000+ consumers if deriving more than 50% of revenue from data sales.
Your Virginia Rights:
- Right to access, correct, and delete personal data
- Right to data portability
- Right to opt out of targeted advertising, data sales, and profiling
- Right to appeal our decision regarding your request
Sensitive Data: Opt-in consent required for processing sensitive data. Response Time: 45 days. Appeal: If we deny your request, you may appeal within a reasonable time. We will respond to appeals within 60 days.
Texas (TDPSA)
Effective: July 1, 2024. The Texas Data Privacy and Security Act applies to entities that conduct business in Texas or produce goods/services consumed by Texas residents, and are not classified as a small business under the SBA.
Your Texas Rights:
- Right to access, correct, and delete personal data
- Right to data portability
- Right to opt out of targeted advertising, data sales, and profiling
Sensitive Data: Opt-in consent required. Cure Period: 30 days to cure violations. Response Time: 45 days.
Oregon (OCPA)
Effective: July 1, 2024 (amended January 1, 2026). Applies to entities conducting business in Oregon or targeting Oregon residents that process data of 100,000+ consumers, or 25,000+ consumers if deriving 25%+ of revenue from data sales.
Your Oregon Rights:
- Right to access, correct, and delete personal data
- Right to data portability
- Right to opt out of targeted advertising, data sales, and profiling
- Right to obtain a list of third parties to whom data has been disclosed
2026 Amendments: Sale of precise geolocation data (within 1,750 feet) is prohibited. Sale of personal data of consumers under 16 is prohibited. Controllers must honor universal opt-out mechanisms.
Cure Period: Expired January 1, 2026. Response Time: 45 days.
Utah (UCPA)
Effective: December 31, 2023 (amendments effective July 1, 2026). Applies to entities with annual revenue of $25M+ that conduct business in Utah or target Utah residents and process data of 100,000+ consumers, or 25,000+ consumers if deriving 50%+ of revenue from data sales.
Your Utah Rights:
- Right to access and delete personal data
- Right to data portability
- Right to opt out of targeted advertising and data sales
Note: Utah does not include a right to correct data or opt out of profiling. Response Time: 45 days.
Montana (MCDPA)
Effective: October 1, 2024. Applies to entities conducting business in Montana or targeting Montana residents that process data of 50,000+ consumers, or 25,000+ consumers if deriving 25%+ of revenue from data sales.
Your Montana Rights:
- Right to access, correct, and delete personal data
- Right to data portability
- Right to opt out of targeted advertising, data sales, and profiling
- Sensitive data requires opt-in consent
Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Maryland, Minnesota
These states have enacted comprehensive consumer privacy laws effective between 2024–2025, with rights substantially similar to Virginia’s framework.
Common Rights Include:
- Right to access, correct (except Iowa), and delete personal data
- Right to data portability
- Right to opt out of targeted advertising and data sales
- Sensitive data requires opt-in consent
Note: Iowa does not include a right to correction. Delaware, Maryland, Minnesota, and New Jersey have additional protections for minors’ data. Response times are generally 45 days.
Tennessee & Florida
Tennessee (TIPA): Effective July 1, 2025. Follows the Virginia model with standard access, correction, deletion, portability, and opt-out rights. 60-day cure period.
Florida (FDBR): Effective July 1, 2024. Narrower scope — applies to entities with global revenue exceeding $1 billion and meeting additional criteria. Includes standard consumer rights plus specific requirements around biometric data and children’s privacy.
Indiana, Kentucky & Rhode Island (Effective January 1, 2026)
The newest state privacy laws, all effective January 1, 2026. They largely mirror the Virginia framework.
Common Rights Include:
- Right to access, correct, and delete personal data
- Right to data portability
- Right to opt out of targeted advertising, data sales, and profiling
- Sensitive data requires opt-in consent
Indiana & Kentucky: Apply to entities processing data of 100,000+ consumers or deriving 50%+ of revenue from data sales of 25,000+ consumers. 30-day cure period.
Rhode Island: Lower thresholds — 35,000 consumers, or 10,000 consumers if 20%+ of revenue is from data sales. Requires standalone privacy notices on commercial websites operating in Rhode Island, regardless of threshold.
12. Children’s Privacy
Our Site and services are designed for commercial use by business professionals. We do not knowingly collect personal information from children under 13 years of age in accordance with the Children’s Online Privacy Protection Act (COPPA).
For users under 16: Under multiple state laws (including California, Oregon, Connecticut, Delaware, and Maryland), we do not sell personal data of consumers we know to be under 16, nor do we use such data for targeted advertising.
If you believe we have inadvertently collected information from a child under 13, please contact us at privacy@myhvac.tech and we will promptly delete it.
13. Do Not Track / Universal Opt-Out Mechanisms
Do Not Track (DNT): Some browsers transmit a “Do Not Track” signal. There is no industry consensus on how to respond to DNT signals. We currently do not alter our data collection practices in response to DNT browser signals.
Global Privacy Control (GPC): We honor the Global Privacy Control signal as required by the CCPA/CPRA (California), Colorado, Connecticut, Oregon, and other applicable state laws. When we detect a GPC signal, we treat it as a valid opt-out of the sale and sharing of personal information and targeted advertising for residents of applicable states.
14. International Users
Our Site is intended for users within the United States. If you access the Site from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located. By using our Site, you consent to this transfer.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will update the “Last Updated” date at the top of this page. For material changes, we will provide notice through the Site or by email. We encourage you to review this page periodically.
In accordance with the CCPA, this Privacy Policy is reviewed and updated at least once every 12 months.
16. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
BaaDigi LLC
Email: privacy@myhvac.tech
Website: myhvac.tech
We will acknowledge your request within 10 business days and respond substantively within the timeframe required by your state’s applicable law (typically 45 days).
