Privacy Policy
Version 1.9 · Effective September 12, 2026
This policy describes what Poolhand (“we”, “us”) actually does with data — written from the software, not from a template. If you find something here that does not match how the product behaves, that is a bug in this document and we want to hear about it.
1. The short version
That is unusual enough to be worth stating plainly rather than burying. It is also checkable: there is no third-party analytics code in the application to find.
This is a summary, not a substitute. Everything below is the full version — there is no separate longer policy held somewhere else, and nothing in this summary narrows what the rest of the page says.
2. Who controls what
There are three kinds of people in this system, and the distinction matters:
- Poolhand (us). We provide the software and host it.
- A pool-service company — our customer. It controls its own business records. We process those records on its instructions.
- A homeowner or property manager whose pool is serviced. They have no account with us. Their name, address, phone and email are in our database because their pool company entered them. If that company switches service reports on, we also email them on its behalf — see section 9, including how to stop it.
In data-protection terms: for a pool company’s own account information we are the controller; for the client records that company stores, the company is the controller and we are its processor. See section 9 if you are a homeowner.
3. What we collect
We collect these categories of information:
- Account and contact details for the people who sign in and for the company, including a password stored in a form that cannot be reversed. While a signup waits to be confirmed, we hold the details submitted with it.
- Your customers’ details — names, service addresses and contact details your company enters.
- Pool, equipment and site-access records you enter, and the routes and schedules you plan.
- Visit records — visit logs, water readings, chemicals added, notes and photos your technicians record, and the alerts worked out from them.
- Billing details — your plan, subscription, seat counts and a label for the card on file. Card numbers and the billing address you give Stripe are held by Stripe, never by us.
- Technical information — IP addresses, used to rate-limit sign-in and other public requests, and error reports that carry identifiers only, never names or email addresses. We do not keep web access logs.
- Support messages you send us, with your account details, the screen you were on and the app version, so we can reply.
- On a technician’s phone — a copy of route data so the app works offline, the sign-in token in the phone’s secure storage, and a few preferences, including your email address if you ask it to remember you. Fingerprint and face unlock are handled by the phone itself; we never receive biometric data.
4. Why we have it
- To run the service — you cannot have route planning without routes, or visit history without visits.
- To sign you in and keep accounts separate — email, password hash and session tokens.
- To bill correctly — seat counts, sign-in timestamps and plan state.
- To keep the service secure — rate limiting, and detecting reuse of a stolen session token.
- To fix what breaks — error reports and support messages.
- To send transactional email — password resets and signup confirmations.
- To send service reports — where a pool company has switched them on, a summary of each visit to the client whose pool it was, sent on that company’s behalf. Every one carries a link to stop them; see section 9.
- We send no marketing email — no newsletter, no promotions, and nothing to anyone except account holders and homeowners whose own pool company has turned service reports on.
We do not profile users, we do not make automated decisions with legal effects, and we do not use your business data to train anything.
7. How long we keep it
- While your account is open: we keep your business records for as long as you keep them, and we do not delete them on your behalf. We may set fair-use storage limits for photos. If we ever do, you will get at least 60 days’ notice and a way to export before anything is removed.
- After an account ends: we retain data for 30 days so it can still be exported, then delete it within 90 days.
- Backups: encrypted backups may hold copies for up to 7 days after deletion before rotating out.
- Signup requests: deleted automatically when the confirmation link expires, 24 hours after the request, whether or not the link was used.
- Imported spreadsheets: we keep the uploaded rows while an import is in progress so you can review them. A row’s copy is cleared as soon as it is imported or skipped; rows that failed keep theirs so you can see why. The whole import is deleted 30 days after upload, or sooner if you delete it.
- Session tokens: expire and are purged automatically.
- Billing records: retained as long as tax and accounting law requires.
- Service reports sent: for each one we keep the address it went to, when it was sent, and a copy of what it said, so it can be re-sent exactly. Once a report has been sent, that record is kept permanently and the visit behind it can no longer be deleted. A report that was never sent is deleted with its visit. The record keeps the address even after that client is purged.
- Removing a client: you can archive a client, which hides them everywhere without changing any record and can be undone. An owner can purge an archived client, which permanently erases their email address, phone number and addresses. The client’s name is kept, and your visit records, reports and readings stay where they are. A purge cannot be undone.
You can ask us to delete sooner — see below — and we will, except where we are legally required to keep something.
8. Your rights and choices
Wherever you are, and regardless of which law applies to you, we will honour these requests. California residents have these rights under the CCPA/CPRA; we extend the same treatment to everyone rather than gate it by geography.
- Know what we hold about you and why. This policy sets it out, and we will answer questions about your own data.
- Access and export — a machine-readable copy of your account’s data. Most of it you can download yourself, at any time, without asking us.
- Correct anything inaccurate. Most of it you can edit yourself.
- Delete your data, subject to legal retention requirements.
- Not be discriminated against for exercising any of these. We will not degrade your service or change your price because you asked.
How to exercise them: email privacy@poolhandhq.com from the address on your account. We may ask you to confirm your identity — for a request about an account, being able to sign in to it is normally enough. We respond within 30 days.
9. If you are a homeowner, not a customer
If your pool is serviced by a company that uses Poolhand, your details are in our system because that company put them there. It decides what to store and for how long; we hold it on their behalf.
Please contact your pool-service company first — they can see, correct and delete your record directly, which is faster than anything we can do. If you cannot reach them, or they will not help, write to privacy@poolhandhq.com and we will help — including passing your request to them and, where the law requires it, acting on it ourselves.
Service reports. If your pool company sends you reports after visits, what they contain is that company’s choice — ask them about it. A report never includes the notes the company keeps for its own internal use.
You can stop these emails at any time, and you do not need an account to do it. Every report has an unsubscribe link at the bottom. Opening it asks you to confirm, so an email scanner or a link preview cannot unsubscribe you by accident. Once you confirm, we stop sending them to you straight away.
For your protection that link can only stop reports, never restart them, so nobody who is forwarded one of your reports can put you back on. If you change your mind, ask your pool company to turn them back on for you.
10. Security
How we protect your data:
- Encrypted in transit.
- Each company’s data is isolated from every other company’s.
- Passwords are never stored in readable form. We cannot recover yours; a reset is the only way back in.
- Photographs are private, reachable only through short-lived links. The one exception is a full data export you generate yourself, whose photo links work for one hour.
- Hosted with the providers named in section 5.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data, we will tell you — promptly, with what we know, what we do not yet know, and what we are doing about it — and we will notify regulators where the law requires. If you believe you have found a vulnerability, please write to support@poolhandhq.com; we will not pursue anyone who reports one in good faith.
11. Children
Poolhand is a tool for businesses and is not directed at children. Accounts require you to be 18 or older, and we do not knowingly collect personal information from children. If you believe a child’s information has reached us, contact privacy@poolhandhq.com and we will delete it.
12. Changes
If we change this policy in a way that materially affects you, we will give account owners at least 30 days’ notice by email and in the app before it takes effect. The version and effective date at the top of this page always tell you which version you are reading.
13. Contact
Poolhand (operated by Tremor Consulting LLC) — privacy questions and data requests: privacy@poolhandhq.com. Anything else: support@poolhandhq.com. See also the Terms of Service.