Privacy Policy
FOUNDER-APPROVED draft — 2026-09-19. Not a substitute for counsel; founder accepts draft-legal risk for product use.
As of: 2026-09-19
This Policy describes how Pool Buildability Report (“we”) collect and use personal information. It matches actual product data flows as of this draft.
1. What we collect
| Data | Purpose | Retention (default) |
|---|---|---|
| Receipts, waitlist, support | Until unsubscribe / order retention ends | |
| Payment metadata (via Stripe when live) | Fulfill orders | Per tax/accounting needs; **card numbers never touch our servers** |
| Street address queried | Produce the report | With order record (~24 months, then purge or anonymize) |
| Waitlist zip + email | Coverage expansion signal | Until covered or you ask to delete |
| Analytics events (Umami or local log) | Improve product | Aggregated; no full street address in event props |
| Support / “bad finding” messages | Fix errors | Case lifetime + short archive |
| Admin session cookie | Authenticate testers | Session / short TTL |
We do not display property owner names in the product UI even when public tax records include them.
2. Why we process data
- Contract: fulfill a purchased report.
- Legitimate interests: security, abuse prevention, product improvement, coverage planning.
- Consent: where required for optional communications.
3. Subprocessors (planned / actual)
| Party | Role | Status |
|---|---|---|
| Hosting provider | Serve site/API | After founder approval |
| Stripe | Payments | After founder approval |
| Email provider (e.g. Resend/Postmark) | Receipts | After founder approval |
| Umami | Privacy-first analytics | Optional; URL empty = local log only |
| Public GIS / Census / FEMA | Regulatory lookups | Live, no personal account |
4. Sale of data
We do not sell personal information and do not share it for cross-context behavioral advertising. California “Do Not Sell or Share” requests: contact us; our answer is that we do not sell or share as defined under CCPA/CPRA.
5. Cookies
We prefer cookieless first-party analytics. Essential cookies may be used for admin sessions and (later) checkout continuity. Marketing pixels / Google Analytics are not used at launch; adding them requires a privacy update and founder approval.
6. Your rights
Subject to applicable law, you may request access, correction, deletion, or export of your personal data. Email the published support address with “Privacy request.” We may need to verify identity.
7. Children
The Service is not directed to children under 16. We do not knowingly collect their data.
8. Security
Secrets stay in environment variables, not git. HTTPS is required for any public deployment. No method of transmission is 100% secure.
9. International users
Primary audience is U.S. (starting North Atlanta, Georgia). If you access from elsewhere, you understand data may be processed in the United States.
10. Changes
We will post updates with a new “As of” date. Material changes to paid processing will be called out before live charges where required.
11. Contact
Update with production privacy contact before public launch.