Hot Rocks
TermsPrivacySign in

Privacy

Privacy Policy

This Policy explains how personal information is collected, used, disclosed, and protected when you use Hot Rocks.

Effective: July 24, 2026

At a glance: Hot Rocks uses account, business, device, and optional location information to provide and secure the Service. It does not use advertising SDKs, sell personal information, or share mobile numbers or SMS consent for third-party marketing.

1. Scope and responsible organizations

Hot Rocks is owned by Headwaters Holdings LLC (“Headwaters”) and licensed to RockTek Inc. (“RockTek”). RockTek operates the customer-facing service and onboards customers. Headwaters provides and maintains the platform for RockTek.

This Policy applies to the Hot Rocks mobile application, administrative application, websites, APIs, and related support (the “Service”). “we” means RockTek and Headwaters as applicable to the activity described. RockTek generally determines how information is used to manage customers and provide the customer-facing Service. Headwaters processes information to host, maintain, secure, support, and improve the platform, and determines certain processing for platform security, legal compliance, and de-identified data.

A business or organization that gives you access to Hot Rocks (your “Customer”) may control account, employment, listing, or operational information submitted through its workspace. That Customer’s policies also apply, and you should contact its administrator about instructions or requests concerning Customer-controlled data.

2. Information we collect

CategoryExamples and collection context
Account and contact informationName, email address, telephone number, organization, role, membership, invitations, account status, and sign-in method.
Authentication and security informationOne-time-code events, session and account identifiers, sign-in timestamps, IP address, user agent, security events, and passkey public-key credential metadata. Device biometric data used to unlock a passkey remains with the device or platform provider; Hot Rocks does not receive a fingerprint or face template.
Customer and listing informationPlant and business names, addresses, telephone numbers, materials and product types, availability, hours, minimums, maximums, preorder terms, notes, and administrative changes. Some listing information is intended to be shown to signed-in mobile users.
Location informationWith device permission, current or recently cached latitude and longitude used to sort and filter nearby listings and estimate distance. Hot Rocks does not request background location.
Device, network, and usage informationDevice and browser type, operating system, app version and build, requested route, request timing, IP address, interaction and diagnostic events, crash or error details, and limited recent navigation breadcrumbs used for troubleshooting.
Communications and supportMessages and requests sent to support, notification delivery status, SMS consent and opt-out records, and transactional communications.
Administrative and audit informationOrganization onboarding, approvals, permissions, changes to listings, actor, target, timestamps, and related audit records.

We collect information directly from you, Customer administrators and users, your device and use of the Service, and service providers that support authentication, communications, hosting, app distribution, and security. We do not intentionally collect payment-card information through the current Service.

3. Location choices

Location access is optional. If you allow it, the mobile app asks for location only while you use the relevant feature. It sends coordinates to the Hot Rocks API to calculate and filter nearby results and stores the most recent coordinates on your device so the list can remain useful between refreshes. The Service does not use location for advertising or background tracking.

You can deny or revoke location permission in device settings. You can also clear the app’s stored data or uninstall it to remove locally cached coordinates. Without location, nearby filtering and distance estimates may be unavailable, but other available features can still work.

4. How we use information

  • provide, operate, personalize, and support the Service;
  • authenticate users, maintain sessions, enroll passkeys, and deliver requested sign-in codes;
  • create and administer organizations, memberships, roles, listings, and access requests;
  • show relevant listings, estimate distance, and open a selected listing in a mapping service;
  • communicate about accounts, security, support, service operations, and legal updates;
  • monitor performance, diagnose errors, maintain audit trails, prevent abuse, and secure systems;
  • comply with law, enforce agreements, and establish, exercise, or defend legal claims;
  • analyze and improve Hot Rocks, Solace, services, business operations, and industry insights, including through Customer-Redacted Data described below.

Depending on applicable law, these activities are based on performing a contract, the Customer’s and our legitimate interests, consent (including device location permission), or legal obligations.

5. How we disclose information

We may disclose relevant information to:

  • your Customer and its administrators, to manage its workspace, users, listings, permissions, security, and support;
  • RockTek and Headwaters, consistent with their operator, licensor, platform, support, security, and compliance roles described above;
  • service providers, including Fly.io for hosting and application infrastructure, Neon for database infrastructure, Upstash for cache infrastructure, Twilio for requested SMS verification, Resend for email delivery, and providers supporting logging, security, and technical operations;
  • platforms you direct us to use, such as Apple or Google for app distribution, device passkeys, push or operating-system functions, and Apple Maps or Google Maps when you open a location;
  • professional advisers and transaction participants, in connection with an audit, financing, insurance, reorganization, merger, acquisition, sale, or similar transaction, subject to appropriate confidentiality protections where required;
  • government authorities and other parties, when reasonably necessary to comply with law or legal process, protect rights or safety, investigate fraud or security incidents, or enforce agreements;
  • others at your direction or with your consent.

We do not use third-party advertising SDKs in Hot Rocks, sell personal information for money, or share personal information for cross-context behavioral advertising. We do not share telephone numbers, SMS consent, or opt-in data with third parties or affiliates for their marketing or promotional purposes. Service providers may use information only to provide contracted services or as permitted by law.

6. Customer-Redacted and de-identified data

We may aggregate, de-identify, or otherwise modify Customer Data and Service usage so the result cannot reasonably identify a Customer, individual, household, or device (“Customer-Redacted Data”). Removing direct identifiers alone is not enough if the remaining data could still reasonably identify its source.

As described in the Terms of Service, Headwaters owns Customer-Redacted Data and may use, disclose, license, and commercialize it for lawful purposes such as analytics, benchmarking, research, business and market analysis, platform and product improvement, service development, and industry insights. Headwaters will maintain this data in de-identified form, will not attempt to re-identify it, and will not disclose it in a form that reasonably identifies a Customer or person. Recipients of Customer-Redacted Data will be contractually required to maintain it in de-identified form and not attempt re-identification. These rights do not give Headwaters ownership of identifiable Customer Data or personal information.

7. Email and SMS verification

When you request a sign-in code, we use the email address or telephone number you provide to send that transactional message. Telephone verification is delivered through Twilio Verify. Message frequency depends on your requests, and message and data rates may apply. Reply STOPto opt out or HELP for help. We retain limited delivery, consent, opt-out, and security records to operate the feature, prevent abuse, and comply with law. We do not use telephone verification consent for third-party marketing.

8. Retention

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including while an account or Customer relationship is active, and afterward as needed for security, backups, audit and transaction records, dispute resolution, enforcement, and legal obligations. Retention depends on the type and sensitivity of information, business and contractual needs, risk of harm, and applicable law.

When information is no longer needed, we delete, anonymize, or isolate it in accordance with applicable processes. Deletion from active systems may not immediately remove encrypted backups; backup copies are protected and expire through ordinary retention cycles. Customer-Redacted Data may be retained indefinitely because it no longer reasonably identifies a Customer or person.

9. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, authentication, encrypted network transport, tenant separation, logging, and vendor controls appropriate to the Service. No method of storage or transmission is completely secure. Protect your device and credentials, do not share one-time codes, and report suspected unauthorized access to support@stonedev.us.

10. Your choices and privacy rights

  • Account details. You or your Customer administrator may be able to review or update account and organization information in the Service.
  • Location. Control location access through device settings and clear locally stored app data as described above.
  • Communications. Use unsubscribe instructions for optional email, reply STOP to SMS, or contact us. Necessary security and service messages may continue while your account is active.
  • Access, correction, deletion, portability, restriction, or objection. Depending on where you live, you may request these rights and may have a right to appeal a denied request.
  • Consent. Where processing relies on consent, you may withdraw it prospectively.

Send a request to support@stonedev.us with the subject “Privacy Request.” We may verify your identity and authority, ask you to use an existing account channel, and retain information necessary to document and honor the request. An authorized agent may submit a request where law permits, subject to proof of authority and identity verification. We will not discriminate against you for exercising applicable rights.

For Customer-controlled information, we may refer the request to the applicable Customer and assist it as required. Certain information may be exempt, such as security records, legal claims, information about another person, or records we must keep by law.

11. Account deletion

In the Hot Rocks mobile app, open the three-dot menu, choose My Account, and select Delete my account to permanently delete the signed-in account. You may also request deletion of your Hot Rocks account and associated personal information by emailing support@stonedev.us with the subject “Hot Rocks Account Deletion.” Include the email address or telephone number used for the account; do not include a password or one-time code. We will verify the request before deletion.

Deleting an account ends access and removes its contact identifiers, credentials, sessions, and other identifiable account information. Historical business, security, and audit records may be retained only where permitted for security, fraud prevention, legal obligations, audit history, dispute resolution, or another disclosed purpose, and identity links are removed or replaced with a non-login tombstone. De-identified lifecycle metrics and Customer-Redacted Data may be retained. Deletion does not require removal of business listings owned by a Customer or records belonging to other users. If a Customer controls the account, we may coordinate with its administrator.

12. Children

Hot Rocks is a business service not directed to children, and users must be at least 18. We do not knowingly collect personal information from children. If you believe a child provided information, contact support@stonedev.us so we can investigate and take appropriate action.

13. United States processing

Hot Rocks is operated in the United States. If you access it from another country, information may be transferred to and processed in the United States and other locations where providers operate, which may have different privacy laws. Where required, we use an appropriate legal mechanism for cross-border transfers.

14. External services

The Service may link to mapping services, app stores, supplier websites, or other external services. Their privacy practices are governed by their own policies. This Policy does not cover information an independent third party collects directly after you leave or direct the Service to open that third party.

15. Changes to this Policy

We may update this Policy as the Service, data practices, providers, or law changes. The effective date above identifies the current version. We will provide additional notice of material changes when required, such as through the Service or by email. Changes apply prospectively unless law permits otherwise.

16. Contact us

Questions, privacy requests, and account-deletion requests may be sent to RockTek and Headwaters’ Hot Rocks support channel at support@stonedev.us. To help us respond, identify the relevant Customer and the email address or telephone number associated with your account, but never send a password or one-time code.

Hot Rocks•support@stonedev.us