Pool Command — Privacy Policy
Last updated: August 9, 2026 Effective: August 9, 2026
Pool Command LLC ("Pool Command," "we," "us") operates business management software for pool service companies. This Privacy Policy explains what personal information we collect, why, who we share it with, and the choices you have.
Read this first: two different roles
This matters, because it determines who you should talk to about your data.
1. When a pool service company uses Pool Command, we act on their behalf. The customer records, addresses, pool details, service photos, and payment history inside an account belong to that pool service company. They decide what to collect and how long to keep it. We only process it under their instructions. Under California law, they are the business and we are their service provider.
If you are a homeowner and you want your information corrected or deleted, contact your pool service company. They control it. We will help them act on your request, but we cannot make those decisions for them. If you don't know who to contact, email us at privacy@poolcommand.app and we will route you.
2. When you sign up for a Pool Command account, we act for ourselves. Your account details, billing information, and how you use our product are ours to manage, and we are the business for that information. The rest of this policy tells you which rules apply where.
1. Information We Collect
1.1 Account information (we are the business)
When you create a Pool Command account: name, business name, email address, phone number, business address, password (stored only as a salted hash — we never see it), plan and billing details, and support correspondence.
1.2 Customer Data uploaded by our subscribers (we are a service provider)
Pool service companies upload information about their own customers and properties, which typically includes:
- homeowner name, service address, email address, and phone number
- property and pool details — size, surface, equipment, gate codes and access notes
- service visit records, including chemical readings, dosing, work performed, and technician notes
- photographs of the property, pool, and equipment taken by technicians
- location and route data associated with service visits
- invoices, service history, and payment records
1.3 Payment information
Payments run through Stripe. Card numbers go directly to Stripe and we never receive or store full card numbers. We receive limited confirmation data — last four digits, card brand, expiration, transaction status, and amounts.
1.4 Information collected automatically
IP address, browser and device type, operating system, pages viewed, features used, timestamps, referring page, and — where a technician grants permission in the mobile app — device location while performing a service route. We also collect diagnostic and crash data.
1.5 Communications
Emails, support tickets, feedback, and beta-program correspondence.
1.6 What we do NOT collect
We do not knowingly collect Social Security numbers, driver's license numbers, government ID numbers, precise health information, biometric identifiers, or information from anyone under 18. The Service is not directed to children and we do not knowingly collect information from anyone under 13. If you believe a child has provided information, contact us and we will delete it.
2. How We Use Information
| Purpose | What we use | Legal basis (where applicable) |
|---|---|---|
| Provide and operate the Service | Account info, Customer Data, usage data | Contract |
| Process payments and payouts | Billing info, transaction data | Contract |
| Send transactional messages — receipts, service reports, notifications | Account info, Customer Data | Contract / subscriber instruction |
| Provide support and respond to inquiries | Account info, communications | Contract / legitimate interest |
| Secure the Service, detect fraud and abuse, enforce rate limits | Usage data, IP address, device data | Legitimate interest |
| Diagnose errors and improve reliability | Diagnostic and crash data | Legitimate interest |
| Improve and develop features | Aggregated and de-identified usage data | Legitimate interest |
| Send product announcements and marketing | Account info | Consent / legitimate interest — you can opt out anytime |
| Comply with law and legal process | As required | Legal obligation |
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act. We have not done so in the preceding twelve months.
We do not use Customer Data to train AI models. See Section 4.
3. Who We Share Information With
We share personal information only as described here.
3.1 Subprocessors and service providers
| Provider | What it does | Data it may access |
|---|---|---|
| Supabase | Database, authentication, file storage, edge functions | All Customer Data and account data |
| Netlify | Application hosting and delivery | Request data, IP addresses |
| Stripe | Payment processing, Stripe Connect payouts | Billing and transaction data, payer contact details |
| Resend | Transactional email delivery | Recipient email addresses, message content |
| Sentry | Error monitoring and crash reporting | Diagnostic data; may incidentally include identifiers appearing in error context |
| Upstash | Rate limiting and caching | IP addresses, request metadata |
| Google Maps Platform | Geocoding, mapping, route optimization | Service addresses and location coordinates |
| Anthropic | AI-assisted features — service summaries, drafted communications, document parsing, in-app assistant | Only the specific content submitted to that feature — see Section 4 |
| OpenAI | Text embeddings used for in-app help search | The text of help questions you type, and our own help article content |
Each provider is contractually bound to use the information only to provide services to us. We will post an updated list here when we add or change a subprocessor.
3.2 Between subscribers and their customers
Information a pool service company enters is visible to that company's authorized users, and — where the company enables the homeowner portal — to the homeowner whose property it concerns. Accounts are isolated from one another; one subscriber cannot see another subscriber's data.
3.3 Legal and safety
We may disclose information if required by law, subpoena, or court order, or where we believe in good faith it is necessary to protect the rights, property, or safety of Pool Command, our subscribers, or the public. Where legally permitted, we will notify the affected subscriber before disclosing their data, so they can seek protective relief.
3.4 Business transfers
If Pool Command is involved in a merger, acquisition, conversion to a corporation, financing, or sale of assets, personal information may be transferred as part of that transaction. We will give notice before your information becomes subject to a materially different privacy policy.
3.5 With your direction
Where you connect a third-party integration or ask us to share information, we will do so as you direct.
4. Artificial Intelligence Features
Some features use third-party AI models to summarize service history, draft customer communications, parse uploaded documents, or assist with chemical analysis. The providers we use for this are named in Section 3.1.
- Only the specific content needed for the feature is sent to the model provider — not your whole database.
- We do not use Customer Data to train AI models, and we do not authorize any AI provider to use it for model training. We select providers whose business terms are consistent with that, and we will update this section if our providers change.
- AI output is informational only. Any chemical recommendation must be independently verified against manufacturer instructions, applicable health codes, and professional judgment before you act on it. Do not rely on AI output for health or safety decisions.
5. Cookies and Tracking
We use cookies and similar technologies for strictly necessary purposes — keeping you signed in, maintaining session security, and preventing abuse — and for basic analytics to understand feature usage.
We do not use advertising cookies, and we do not permit third-party advertising trackers on the Service. Because we do not sell or share personal information for cross-context behavioral advertising, we do not act on Global Privacy Control signals for advertising purposes, but we honor them where applicable.
You can block cookies in your browser, but strictly necessary cookies are required for the Service to function.
6. Data Retention
| Data | How long we keep it |
|---|---|
| Account information | For the life of the account, then 30 days after closure |
| Customer Data | For the life of the account; exportable for 30 days after termination, then deleted from active systems |
| Backups | Deleted in the ordinary course of backup rotation, generally within 30 days |
| Payment and transaction records | As required by tax and financial recordkeeping law, generally 7 years |
| Diagnostic and error logs | Up to 90 days |
| Marketing preferences and suppression lists | Until you ask us to delete them, or indefinitely where needed to honor an opt-out |
Subscribers may configure shorter retention for their own Customer Data where the Service supports it.
7. Security
We maintain administrative, technical, and physical safeguards, including:
- encryption in transit (TLS) and at rest
- row-level security policies enforcing tenant isolation at the database layer
- password hashing; we never store plaintext passwords
- role-based access control — our personnel access production data only when necessary for support or operations
- rate limiting on sign-in and password-reset requests, applied per source address and per account identifier
- separate staging and production environments
- credentials held in a managed password manager, with second-factor generators kept in a separate application
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for safeguarding your credentials and controlling who in your organization has access.
Breach notification. If we become aware of a security breach affecting personal information, we will notify affected subscribers without undue delay and consistent with California Civil Code § 1798.82 and other applicable law.
8. Your Privacy Rights
8.1 California residents (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and the categories of sources and recipients
- Access a copy of your personal information, in a portable format
- Delete your personal information, subject to legal exceptions
- Correct inaccurate personal information
- Opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of
- Limit use of sensitive personal information — we do not collect sensitive personal information as defined by the CPRA
- Non-discrimination — we will not deny service, charge different prices, or provide a different quality of service because you exercised a right
How to exercise: email privacy@poolcommand.app. We will verify your identity before acting, typically by confirming control of the account email. We respond within 45 days, extendable by another 45 with notice. You may use an authorized agent with written permission.
Homeowners: contact your pool service company. Where we hold your information as a service provider, we will forward your request to the pool service company that controls it and assist them in responding.
8.2 Other U.S. states
Residents of states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana — have comparable rights of access, correction, deletion, portability, and appeal. Contact us at the address below and we will honor them.
8.3 Everyone
Regardless of where you live, you may access and update your account information in the Service, export your data, opt out of marketing email using the unsubscribe link in any message, and close your account. Transactional messages about your account cannot be opted out of while the account is active.
9. International Users
Pool Command is operated from the United States and intended for use in the United States. If you access it from elsewhere, your information will be transferred to and processed in the U.S., which may have different data protection laws than your country. We do not currently offer the Service to individuals in the European Economic Area or the United Kingdom, and this policy is not designed to satisfy the GDPR.
10. Changes to This Policy
We may update this policy. We will update the "Last updated" date, and for material changes we will give at least thirty (30) days' notice by email or in-app notice before they take effect. Your continued use after the effective date constitutes acceptance.
11. Contact Us
Pool Command LLC 2108 N ST, STE N Sacramento, CA 95816 Privacy: privacy@poolcommand.app Security: security@poolcommand.app
If you have a concern we haven't resolved, you may contact the California Attorney General at oag.ca.gov or the California Privacy Protection Agency at cppa.ca.gov.