DRAFT — attorney review required before live paid use.

Privacy Policy

FOUNDER-APPROVED draft — 2026-09-19. Not a substitute for counsel; founder accepts draft-legal risk for product use.

As of: 2026-09-19

This Policy describes how Pool Buildability Report (“we”) collect and use personal information. It matches actual product data flows as of this draft.

1. What we collect

DataPurposeRetention (default)
EmailReceipts, waitlist, supportUntil unsubscribe / order retention ends
Payment metadata (via Stripe when live)Fulfill ordersPer tax/accounting needs; **card numbers never touch our servers**
Street address queriedProduce the reportWith order record (~24 months, then purge or anonymize)
Waitlist zip + emailCoverage expansion signalUntil covered or you ask to delete
Analytics events (Umami or local log)Improve productAggregated; no full street address in event props
Support / “bad finding” messagesFix errorsCase lifetime + short archive
Admin session cookieAuthenticate testersSession / short TTL

We do not display property owner names in the product UI even when public tax records include them.

2. Why we process data

3. Subprocessors (planned / actual)

PartyRoleStatus
Hosting providerServe site/APIAfter founder approval
StripePaymentsAfter founder approval
Email provider (e.g. Resend/Postmark)ReceiptsAfter founder approval
UmamiPrivacy-first analyticsOptional; URL empty = local log only
Public GIS / Census / FEMARegulatory lookupsLive, no personal account

4. Sale of data

We do not sell personal information and do not share it for cross-context behavioral advertising. California “Do Not Sell or Share” requests: contact us; our answer is that we do not sell or share as defined under CCPA/CPRA.

5. Cookies

We prefer cookieless first-party analytics. Essential cookies may be used for admin sessions and (later) checkout continuity. Marketing pixels / Google Analytics are not used at launch; adding them requires a privacy update and founder approval.

6. Your rights

Subject to applicable law, you may request access, correction, deletion, or export of your personal data. Email the published support address with “Privacy request.” We may need to verify identity.

7. Children

The Service is not directed to children under 16. We do not knowingly collect their data.

8. Security

Secrets stay in environment variables, not git. HTTPS is required for any public deployment. No method of transmission is 100% secure.

9. International users

Primary audience is U.S. (starting North Atlanta, Georgia). If you access from elsewhere, you understand data may be processed in the United States.

10. Changes

We will post updates with a new “As of” date. Material changes to paid processing will be called out before live charges where required.

11. Contact

Update with production privacy contact before public launch.