Privacy and Cookies Policy

1. INTRODUCTION AND KEY INFORMATION

This Privacy and Cookies Policy ("Policy") explains how Pool Guy Technologies Limited (“Owner”, "We", "Us") collects, uses, stores, and protects information when You use the Pool Guy mobile applications (iOS/Android) ("Pool Guy", "Pool Guy App", "App") and www.getpoolguy.com. This Policy complies with privacy laws in New Zealand, the European Union, United States and Australia.

1.1 About Pool Guy

Company: Pool Guy Technologies Limited, a New Zealand company
Registered Office: 10 Madeira Close, Whitby, Porirua 5024, New Zealand
Company Number/NZBN: 9429053049094

Important B2B Notice

Pool Guy is exclusively a business to business service for pool service companies and sole traders. Individual consumers and pool owners cannot register or access the App. End Customers never log in and have no direct relationship with Us.

Our Services

Digital tools helping pool service businesses manage:

  • Pool information and service history;
  • Chemical usage and maintenance records;
  • Team reporting;
  • Repair records and billing data.
Policy Availability

This Policy is available at https://getpoolguy.com/privacy, in-App under More > Privacy Policy, or via privacy@getpoolguy.com.

1.2 Scope and Application

This Policy covers:

  • User data (your business and team members);
  • End Customer Data You upload to Pool Guy;
  • Data collected through our App, WebApp, Website, and Services;
  • Cookie, Tracker and other similar technology usage on our Website, WebApp and App;

This Policy applies to all B2B customers using Pool Guy, including Free Trial users and their Authorised Users (Owners, Admins, Technicians). The Policy also covers Casual Users to the extent that anonymised data is collected on the usage of the Platforms.

1.3 Data Controller and Data Processor Roles

For User Data
  • We are the Data Controller;
  • We determine how this data is processed to operate our Service.
For End Customer Data
  • You are the Data Controller;
  • We are your Data Processor (service provider);
  • We process this data only following your instructions and our Terms of Service.
Your Responsibilities as Controller
  • Establishing lawful basis for collecting End Customer Data;
  • Providing privacy notices to End Customers;
  • Obtaining required consents;
  • Handling End Customer privacy requests.

1.4 Relationship with Other Documents

This Policy should be read in conjunction with Our Terms of Service ("ToS").

Our ToS Section 6.7 constitutes our Data Processing Agreement (DPA) and includes:

  • Article 28 GDPR contractual clauses;
  • Standard Contractual Clauses for international transfers;
  • Sub-processor obligations and notifications;
  • Data subject rights assistance procedures;
  • Security and breach notification requirements.

For privacy matters, this Policy takes precedence over the ToS if any conflict arises.

1.5 Definitions

The definitions applied in our ToS apply in this Policy.

1.6 U.S. "Notice at Collection" (California and Other State Laws)

For residents of California and other U.S. states with comprehensive privacy laws, this Policy also serves as our "Notice at Collection" of personal information. It describes:

  • The categories of personal information we collect (Section 2 and Section 6.6);
  • The purposes for which we collect and use each category (Sections 3 and 6.6);
  • Whether we sell or share personal information or use it for targeted advertising (Sections 4 and 6.6);
  • The categories of third parties to whom we disclose personal information (Sections 4 and 6.6); and
  • Our retention periods for each category of information (Section 5).

We provide a link to this Policy at or before the point where You submit personal information to us online.

2. INFORMATION WE COLLECT AND HOW

2.1 User Information (Data We Control)

What We Collect:
  • Account: Business name, registration/tax numbers, address, contacts;
  • Team Members: Names, emails, roles, hashed login credentials;
  • Usage: Login times, features used, device/browser data, IP addresses, crash logs;
  • Communications: Support tickets, emails, feedback, surveys;
  • Payment: Subscription tier, billing frequency, payment processor IDs (no card details stored).

Collection Methods: Direct input during registration or use; automatic via Firebase Analytics, PostHog and Sentry; payment confirmations from Stripe, RevenueCat or App Stores.

2.2 End Customer Information (Data We Process for You)

What You Store
  • Contact: Names, addresses, emails, phone numbers;
  • Service: Pool specs, equipment, visit history, water testing, chemicals, repairs, notes, photos;
  • Business: Pricing, payment status, revenue.

Collection: You input this data directly. We process it only following your instructions. We never contact End Customers or use their data for our purposes.

2.3 Technical Information

Automatically Collected
  • Mobile: Device type/model, OS/App versions, Firebase IDs, network info, crash reports;
  • Web: Browser type, IP address, pages visited, cookies (see Section 8).
Permission-Based:
  • Camera/Photos: For documenting pool conditions and repairs (uploaded to customer records);

For EU/UK personal data, we process camera/photos where this is necessary to perform our contractual obligations with You, and based on our legitimate interests in operating and improving the service in a secure and efficient way. For Australian personal information, we collect this information where it is reasonably necessary for our functions and activities. We will request the relevant app or device level permissions before accessing camera/photos.

Not Collected (Special / Sensitive Categories)

We do not intentionally collect the following types of information:

  • Special category data such as health information, racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic data, biometric identifiers, sexual orientation;
  • Government identification numbers (except business registration and tax numbers for compliance);
  • Payment card numbers (these are handled directly by payment processors);
  • Social media login credentials;
  • Biometric templates used for identification.

For U.S. law purposes (including under the California Consumer Privacy Act as amended by the CPRA and similar state laws), we may process limited "sensitive personal information" in the form of:

  • Account login credentials (email and hashed password or equivalent authentication data)

We do not use this sensitive personal information to infer characteristics about You, and we only use or disclose it for purposes that are permitted as "necessary" or "expected" under applicable U.S. privacy laws.

2.4 Collection Standards and Notifications

Our Principles
  • Lawful collection only (NZ IPP 4);
  • Direct collection preferred (NZ IPP 3);
  • Government identifiers never used as system IDs (NZ IPP 13).
Third-Party Collection Notification (IPP 2/APP 5)

When collecting from third parties, we notify You of: source, purpose, recipients, your access or correction rights, and consequences of non-provision. Notification occurs at collection or as soon as practicable after.

Your Warranty

You confirm End Customers are informed about data sources, processing purposes, and recipients (including Pool Guy as processor).

2.5 Data Accuracy (NZ IPP 8)

User Data

We maintain accuracy through App editing tools, record updates on notification, and periodic verification of critical data.

End Customer Data

You are responsible for accuracy. We provide correction and deletion tools and act only on your instructions.

Correction Requests

Contact us in accordance with Section 13. New Zealand requests handled within 20 working days.

2.6 Unique Identifiers (NZ IPP 13)

Our System

We use internally-generated Pool Guy IDs only. We never use government or third-party identifiers as system IDs.

Government IDs

Collected only if legally required (tax/GST compliance, verification). Stored separately with restricted access, enhanced encryption, and audit logging.

Your Obligations

Do not use government IDs as primary customer identifiers. Ensure your End Customer identifier practices comply with IPP 13.

2.7 Obligation to Provide Data (GDPR Article 13(2)(e))

Contractual Requirement

Information marked as required during registration (user name, user email, business/company name and registration number) is necessary to create your Account and provide the Service.

Consequences of Non-Provision
  • We cannot create or maintain your Account;
  • We cannot process subscriptions or payments;
  • We cannot provide customer support;
  • Certain features may be unavailable.
Voluntary Information

Non-provision of any voluntary information will not affect core Service access.

2.8 Unsolicited Personal Information (APP 4)

If we receive personal information we did not solicit, we will assess whether we could have collected it under APP 3 and lawfully retain it. If not, We will destroy or de-identify it as soon as practicable unless retention is legally required.

3. HOW WE USE INFORMATION

3.1 User Data (We Are Controller)

Purposes and Legal Bases
PurposeLegal Basis
Service Provision: Account management, authentication, role-based access, core features, billing, synchronisation, backupsContract Performance
Service Improvement: Usage analytics, bug fixes, performance optimisation, feature development (using aggregated data where possible)Legitimate Interests and Contract Performance
Communications: Service alerts, security notices, policy updates, support responsesContract Performance and Legal Obligation for security notices
Marketing: Product updates, offers, surveys (B2B only, with opt-out)Legitimate Interests or Consent
Business Operations: Fraud prevention, Terms enforcement, security, tax compliance, legal obligationsLegitimate Interests or Legal Obligation

Note: You can opt out of marketing but not essential service communications.

3.2 End Customer Data (We Are Your Processor)

We process End Customer Data solely following your instructions to:

  • Store and display pool/service information;
  • Support service workflows (water testing, chemicals, equipment);
  • Track repairs and service history;
  • Generate your requested reports;
  • Provide role-based team access.
We Never

Use End Customer Data for our marketing, sell or rent it to third parties, contact End Customers directly, profile them for commercial purposes or make automated decisions about them.

3.3 Legitimate Interests Assessment

When relying on legitimate interests (Article 6(1)(f) GDPR), we conduct documented assessments balancing our interests against your rights.

Our Interests

Service operation or improvement, B2B marketing to existing customers, fraud prevention, ToS enforcement and security monitoring.

Your Right to Object (Article 21)

You may object to processing based on legitimate interests. We will stop unless we demonstrate compelling grounds overriding your interests or need processing for legal claims. Contact privacy@getpoolguy.com.

3.4 Automated Decision Making (Article 22 GDPR)

Current

No automated decision-making with legal or significant effects. All Account affecting decisions involve human review.

Semi-Automated

Fraud alerts, usage monitoring, and performance optimisation include human oversight without automatic decisions.

Future

Any implementation will include 30 days notice, logic explanation, human intervention rights, and ability to contest decisions.

3.5 Use and Disclosure Limits (NZ IPPs 10-11)

We use or disclose personal information only for stated purposes or as permitted by law.

Additional Uses

Any additional uses require your authorisation, direct relation to original purpose with reasonable expectation, or legal exception (serious threat to health or safety, law enforcement or legal requirement).

Disclosures Limited To

Service providers (Section 4), business successors, your authorised integrations and exports, expected related purposes or legal requirements.

Exceptions are documented and limited to what is reasonably necessary.

4. HOW WE SHARE INFORMATION

We do not sell personal information or share it for third-party advertising agencies. Sharing is limited to the following circumstances:

4.1 User Data Sharing

Service Providers

We share only the minimum necessary data with:

  • Google Firebase (hosting, databases, storage, authentication);
  • RevenueCat (mobile subscriptions);
  • Stripe (web payments);
  • Sentry (error tracking);
  • PostHog (product analytics and session replay);
  • App Stores (distribution/billing).

All our service providers are bound by data protection agreements meeting GDPR/APP/IPP standards.

Other Sharing
  • Business Transfers: In mergers/acquisitions, with advance notice where possible;
  • Legal Requirements: When required by law, court orders, or to protect rights or safety (with notice unless prohibited);
  • Your Consent: For authorised integrations or exports (your consent withdrawable anytime);
  • Aggregated Data: Non-identifiable anonymised data for our business analytics/research.

4.2 End Customer Data Sharing

Shared only:

  • With our sub-processors to enable us to provide the Service;
  • according to your authorised integrations/exports;
  • When legally required.

We never use End Customer data for third-party marketing, profiling, or advertising.

4.3 International Data Transfers

Pool Guy operates from New Zealand using global service providers. Data may be processed in multiple countries.

Primary Locations:
  • United States (Google Firebase/Cloud, Stripe, RevenueCat, Sentry, PostHog);
  • Singapore, Belgium, UK (Google Cloud regions);
  • Ireland (Stripe European operations).
Transfer Safeguards
Data OriginProtection Mechanism
EUAdequacy Decisions or Standard Contractual Clauses
AustraliaData Processing Agreements + consent in accordance with APP 8.1
New ZealandComparable safeguards in accordance with IPP 12
Australian Users (APP 8.1)

You acknowledge that if You consent to this cross-border disclosure, Pool Guy will not be accountable under the Australian Privacy Act if an overseas recipient handles your personal information in breach of the Australian Privacy Principles. Overseas recipients may be subject to foreign laws that could compel disclosure (e.g., US CLOUD Act). We take reasonable steps to ensure overseas recipients handle information consistently with the APPs through binding contractual obligations.

EU Users

We implement reasonable safeguards via:

  • Binding Data Processing Agreements with all sub-processors;
  • Security certifications review (SOC2/ISO 27001);
  • Standard Contractual Clauses where applicable.
Withdrawal

To withdraw consent, cease use of the Service and request account deletion. Withdrawal will not affect lawfulness of prior disclosures

New Zealand IPP 12 Compliance

For NZ data, we ensure overseas recipients either:

  • Are subject to comparable privacy laws;
  • Are bound by contracts providing comparable safeguards;
  • Fall under permitted IPP 12 exceptions (your express authorisation, contract performance, legal requirements).

Users remain responsible for their own IPP 12 compliance when initiating exports or integrations.

Updates

We will provide 30 days notice before transfers to new countries not listed above.

5. DATA RETENTION

We retain data only as long as needed for stated purposes, subject to tier limits, legal requirements, and our DPA.

5.1 User Account Data

Active Accounts:

We retain all Account, usage, and billing data while your subscription is active (billing records kept minimum 7 years for tax compliance).

Cancelled/Expired Accounts
  • Account are deactivated at billing period end;
  • Your core data remains exportable for 90 days;
  • Then permanently deleted or anonymised (except those legally required records);
  • Backup copies of your data may persist up to 6 months (inactive).

5.2 End Customer Data

Retention by Tier (While Active):
  • Starter: 18 months;
  • Professional: 36 months;
  • Business: Unlimited (until You delete).
Deletion
  • Manual deletion: Removed from active systems within 30 days, backups within 90 days;
  • Account termination: 90 day export window, then deleted or anonymised;
  • Expedited deletion is available via privacy@getpoolguy.com.

Note: Export data before subscription ends if needed for your business or legal requirements.

5.3 Cookies and Analytics

  • Session cookies: Current browser session only;
  • Persistent cookies: 1-24 months depending on purpose;
  • Analytics data (Firebase Analytics): Up to 14 months (typically aggregated);
  • Product analytics and session replay data (PostHog): Up to 90 days.

5.4 Legal and Compliance Records

Regardless of subscription status:

  • Financial/tax records: Minimum 7 years (NZ law);
  • Dispute resolution or agreement enforcement records;
  • Security incident/complaint records.

5.5 Right to Restriction (GDPR Article 18)

You may request processing restriction when:

  • Contesting data accuracy (restricted during verification);
  • Processing is unlawful but You oppose erasure;
  • We no longer need data but You need it for legal claims;
  • You have objected to legitimate interests processing (restricted during assessment).

During Restriction: Data will be stored but not processed (except with consent, for legal claims, or protecting rights).

To Request: Email privacy@getpoolguy.com with "Restriction Request" in subject line, specify data and grounds. Response is within 30 days unless expedited action is requested..

6. YOUR PRIVACY RIGHTS

6.1 User Rights

Depending on your location, You have the following privacy rights:

RightHow to ExerciseDetails
AccessVia privacy@getpoolguy.comCopy of your data and how we use it
CorrectionIn App settings or emailFix inaccurate or incomplete information
DeletionDownload request form from https://forms.gle/9FQaodPvaRxM5TwH9 or email to privacy@getpoolguy.comDeletes all team and End Customer Data after retention period
Portability (EU)Email requestStructured, machine readable format
Objection (EU)Email requestObject to legitimate interests processing or marketing
Restriction (EU)See Section 5.5Temporary processing halt
Withdraw ConsentUnsubscribe with a single click via unsubscribe linksFor marketing communications, Withdrawal as easy as giving consent. Single click unsubscribe or settings update. Processed within 48 hours.
Response Times

EU: 1 month (extendable to 3 months with notice); NZ: 20 working days; Australia: 30 days.

Extension Notification (EU)

If we require additional time (up to 2 additional months), we will inform You within the first month, explaining the reasons for the delay.

Verification

We may request identity verification to prevent fraud.

Fee

Generally free. Reasonable fees may apply for manifestly unfounded or excessive requests.

If Access is Refused (Australia)

If we refuse an access request (in whole or in part), we will provide written notice of refusal, reasons for refusal (unless unreasonable to do so), and complaint mechanisms available.

Appeals: Email privacy@getpoolguy.com. If unsatisfied, contact the relevant privacy authority (see 6.3).

6.2 End Customer Rights

End Customers contact You (their service provider) directly. We support You by providing:

  • Data export, access, and deletion tools;
  • Prompt assistance with requests;
  • Timely implementation of corrections and deletions.

6.3 Complaints Process

Internal Process:
  1. Contact: privacy@getpoolguy.com | +64 21 229 4045 | Pool Guy Technologies Limited, 10 Madeira Close, Whitby, Porirua 5024, New Zealand;
  2. Timeline: Acknowledgment within 2 working days; response within 20 days (NZ) or 30 days (AU);
  3. Escalation: Chief Privacy Officer review will be within 10 working days.
External Authorities

You may complain directly to the Privacy Commissioner at any time. You do not need to wait for us to complete our internal process.

  • New Zealand: Privacy Commissioner | 0800 803 909 | enquiries@privacy.org.nz | www.privacy.org.nz;
  • Australia: OAIC | enquiries@oaic.gov.au | www.oaic.gov.au;
  • EU: Your local Data Protection Authority.

6.4 Privacy by Design (GDPR Article 25)

Built-in Protections
  • Data minimisation in system architecture;
  • Purpose limitation controls;
  • Privacy protective defaults (op in marketing, minimal retention);
  • Security first design (encryption, role-based access);
  • Annual privacy reviews and pre-release testing.

6.5 Anonymity (APP 2)

Users cannot use Pool Guy anonymously due to:

  • Tax and regulatory compliance requirements;
  • Subscription billing needs;
  • B2B contract requirements;
  • Account security and support.
Limited anonymous interactions

Website browsing, general inquiries, reviewing public policies

End Customers

Are not allowed to create Accounts with us. Any anonymity is between You and your End Customers. We process only data You provide to us.

By creating an Account, You acknowledge anonymous use is not possible for this B2B Service.

6.6 Additional Rights for United States Residents

This Section applies to Users who are residents of US states with comprehensive privacy laws, including but not limited to California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Tennessee, Indiana, New Jersey, New Hampshire, Kentucky, Nebraska, Maryland, Minnesota, and any other state that enacts comprehensive consumer privacy legislation. As new state privacy laws take effect, we will update this Policy accordingly. These rights supplement those described in Section 6.

Right to Know:

You have the right to request that We disclose:

  • Categories of personal information collected about You;
  • Categories of sources from which personal information is collected;
  • Business or commercial purposes for collecting, selling, or sharing personal information;
  • Categories of third parties to whom We disclose personal information;
  • Specific pieces of personal information collected about You.
Right to Delete:

You have the right to request deletion of personal information We have collected, subject to certain exceptions (e.g., completing transactions, security, legal compliance, internal uses compatible with context of collection).

Right to Correct:

You have the right to request correction of inaccurate personal information We maintain about You.

Portability:

You have the right to obtain a copy of your personal data in a portable format;

Right to Opt-Out of Sale/Sharing:

You have the right to opt out of the "sale" or "sharing" of your personal information for cross-context behavioral or targeted advertising. We do not sell personal information or share it for cross-context behavioral advertising purposes.

Right to Limit Use of Sensitive Personal Information:

Under the CCPA/CPRA and some other state laws, You may have the right to limit the use and disclosure of "sensitive personal information" to purposes that are necessary to provide the Services and as otherwise permitted by law.

Our Practice: As described in Sections 2.3 and 8, we process a very limited set of data that may be considered "sensitive personal information" under U.S. state laws (for example account login credentials and precise geolocation when You enable devicelevel permissions). We use and disclose this information only:

  • To provide and secure the Service (such as authentication, route optimisation, and visit verification);
  • To detect security incidents, protect against malicious or illegal activity, and maintain service integrity; and
  • For other purposes that are expressly permitted without a right to limit under applicable law.

We do not use sensitive personal information to infer characteristics about You, and we do not sell or share sensitive personal information for crosscontext behavioral or targeted advertising. Because we currently only use sensitive personal information for permitted purposes, there is no separate "Limit the Use of My Sensitive Personal Information" mechanism. If our practices change in a way that would give rise to a right to limit, we will update this Policy and provide a dedicated link and mechanism before any such change takes effect.

Right to Non-Discrimination:

We will not discriminate against You for exercising any of your CCPA rights. We will not:

  • Deny goods or services;
  • Charge different prices or rates;
  • Provide a different level or quality of services;
  • Suggest You will receive different prices, rates, or quality.
Right to Opt-Out of Profiling:

You have the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning You. Profiling means any form of automated processing of personal data to evaluate, analyze, or predict personal aspects concerning an identified or identifiable individual.

Current Status: As stated in Section 3.4, we do not engage in automated decision-making that produces legal or similarly significant effects. If we implement profiling that could result in such effects, we will provide prior notice and an opt-out mechanism.

Consent for Sensitive Personal Information:

We are required to obtain your affirmative opt-in consent before processing sensitive personal information. Sensitive personal information under these laws may include:

  • Racial or ethnic origin;
  • Religious beliefs;
  • Mental or physical health diagnosis;
  • Sexual orientation;
  • Citizenship or immigration status;
  • Genetic or biometric data processed for identification purposes;
  • Personal data of a known child;
  • Precise geolocation data (within 1,750 feet or 500 meters).
Financial Incentive Disclosure (California):

Under the CCPA/CPRA, we are required to disclose any financial incentive programs We offer in exchange for the collection, retention, sale, or sharing of personal information.

Current Status: We do not offer any financial incentives, price or service differences, or other benefits in exchange for the retention, sale, sharing, or deletion of your personal information. If We implement any such programs in the future, We will update this Policy with the material terms, describe how You can opt in, explain how You may withdraw, and explain how the incentive is reasonably related to the value of your data.

Categories of Personal Information Collected

In the preceding 12 months, We have collected the following categories of personal information:

CategoryExamplesCollectSourceBusiness PurposeRetention Period
IdentifiersName, email, phone, IP address, account nameYesDirect from You; Automatic collectionService provision, authentication, communicationsActive account duration + 90 days post-termination (except billing records: 7 years)
Commercial InformationSubscription records, purchase historyYesDirect from You; Payment processorsBilling, service delivery7 years (tax compliance)
Internet/Network ActivityBrowsing history, App usage, interactionsYesAutomatic collectionService improvement, security, analyticsUp to 14 months (typically aggregated)
Geolocation DataApproximate location from IPYesAutomatic collectionService improvement, security, analyticsActive account duration + 90 days post-termination
Professional/Employment InformationBusiness name, role, job titleYesDirect from YouEnable/disable app features, service and repair visit identificationActive account duration + 90 days post-termination
InferencesPreferences, characteristics derived from aboveYesDerived from collected dataService personalisationActive account duration + 90 days post-termination

Categories Not Collected: Protected characteristics, biometric information, sensory data, health information, financial account numbers, government IDs (except business registration/tax numbers), sensitive personal information.

Disclosure for Business Purposes

We disclose personal information to the following categories of third parties for business purposes:

  • Service providers (hosting, payment processing, analytics, error tracking);
  • Business partners (only as directed by You through integrations);
  • Legal/regulatory authorities (when required by law).

No Sale or Sharing: We have not sold personal information in the preceding 12 months. We do not share personal information for cross-context behavioral advertising.

Retention: We retain personal information as described in Section 5 of this Policy.

Verification:

To exercise your rights, we will verify your identity by matching information You provide with information we have on file. For requests submitted by authorised agents, we require:

  • Written authorisation signed by You; or
  • Power of attorney; and
  • Verification of your identity.
Oregon-Specific Disclosures:

Under the Oregon Consumer Privacy Act (OCPA), Oregon residents have the right to request a list of the specific third parties to whom we have disclosed their personal data (not just categories). To exercise this right, submit a request to privacy@getpoolguy.com with "Oregon Third Party Disclosure Request" in the subject line. We will respond within 45 days.

Response Timeline

We will respond to verifiable requests within 45 days. We may extend this period by an additional 45 days where reasonably necessary, with notice to You.

How to Submit Requests
  • Email: privacy@getpoolguy.com (subject line: "US Privacy Request")
  • Mail: Pool Guy Technologies Limited, [Address], Wellington, New Zealand
California "Shine the Light"

California Civil Code Section 1798.83 permits California residents to request information regarding disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

Appeals: If we decline your request, You may appeal by emailing privacy@getpoolguy.com with "(Your State) Privacy Appeal" in the subject line. We will respond within 45 days. If your appeal is denied, You may contact your State authority.

Do Not Track:

Our Website does not currently respond to "Do Not Track" browser signals.

Global Privacy Control (GPC):

We honour GPC signals as valid opt-out requests under applicable state laws. When we detect a GPC signal, we will treat it as a request to opt out of any sale or sharing of personal information.

6.7 "Do Not Sell or Share" and "Limit" Notices (U.S. Residents)

Sale or Sharing of Personal Information:

We do not sell personal information and we do not share personal information for crosscontext behavioral or targeted advertising purposes, as those terms are defined under the CCPA/CPRA and similar U.S. state privacy laws.

If we ever decide to sell personal information or share it for targeted advertising in the future, we will update this Policy, provide a clear "Do Not Sell or Share My Personal Information" mechanism, and honour any optout choices You make before such changes take effect.

Use of Sensitive Personal Information:

We process only limited types of "sensitive personal information" (such as account login credentials and precise geolocation, where enabled) and only for purposes that are necessary to provide and secure the Services or otherwise permitted by law.

Because we do not use sensitive personal information for additional purposes that trigger a right to limit under applicable U.S. state laws, we do not currently provide a separate "Limit the Use of My Sensitive Personal Information" link. If our practices change in a way that would give rise to a right to limit, we will update this Policy and provide a dedicated link and mechanism before any such change takes effect.

7. DATA SECURITY

7.1 Security Measures

Technical

Encryption (TLS/SSL in transit, at rest), Firebase Authentication, API protection (Firebase App Check), Google Cloud infrastructure, security patching, password hashing, activity monitoring and use of certified sub-processors.

Organisational

Limited access on need-to-know basis, staff confidentiality and security training, incident response policies and vendor assessments.

Physical

Google Cloud data centers with 24/7 security and environmental controls and restricted access.

7.2 Data Breach Procedures

Notifiable Breaches (NZ Privacy Act 2020)

"Serious harm" threshold includes but is not limited to significant humiliation or dignity loss, financial loss, adverse effect on rights and identity theft exposure.

Our Process
  • Immediate investigation on discovery;
  • Assessment using NZ Privacy Commissioner's "NotifyUs" tool and equivalent frameworks;
  • Notify relevant authorities and affected individuals per jurisdiction requirements below.
New Zealand (Privacy Act 2020)
  • Notify Privacy Commissioner as soon as practicable after becoming aware a breach is notifiable;
  • Notify affected individuals as soon as practicable with: description of breach, information involved, steps taken, steps individuals can take, our contact details, and Privacy Commissioner contact details.
EU (GDPR Articles 33-34)
  • Notify relevant supervisory authority within 72 hours of becoming aware of a breach likely to risk individuals' rights and freedoms;
  • Provide reasons for delay if notification exceeds 72 hours;
  • Notify affected data subjects without undue delay where breach likely results in high risk;
  • Data subject notification not required where: data rendered unintelligible (e.g., encryption); subsequent measures eliminate high risk; or disproportionate effort required (public communication made instead).
Australia (Privacy Act Part IIIC)
  • Notify OAIC as soon as practicable after reasonable grounds exist to believe an eligible data breach occurred;
  • Notify affected individuals as soon as practicable;
  • Include: our identity and contact details, breach description, information types involved, and recommended steps.

An eligible data breach occurs when: unauthorised access, disclosure, or loss occurs; serious harm is likely; and remedial action has not prevented the risk.

Your Responsibilities
  • Compliance with NZ, EU and AU laws and regulations as a Data Controller;
  • Report suspected breaches to privacy@getpoolguy.com immediately;
  • Notify your End Customers and regulators as required;
  • Cooperate with investigation;
  • Implement additional measures (e.g., password resets).

7.3 Shared Security Responsibilities

You Must
  • Use strong and unique passwords;
  • Enable MFA where available;
  • Manage user access or deprovisioning;
  • Secure access devices;
  • Avoid untrusted networks;
  • Report unauthorised access immediately.
Limitation

No system is completely secure. You use Pool Guy at your own risk in accordance with ToS limitations.

United States State Breach Notification

All 50 US states, the District of Columbia, and US territories have data breach notification laws. In the event of a data breach affecting US residents, we will:

  • Assess the breach to determine if notification is required under applicable state laws;
  • Notify affected individuals within the timeframes required by applicable law (ranging from "most expedient time possible" to specific deadlines such as 30, 45, 60, or 72 hours depending on the state and type of data);
  • Notify the State Attorney General or other designated state agency where required (e.g., California requires AG notification if breach affects more than 500 residents; many states have similar thresholds);
  • Provide notice content as required by each applicable state law, which typically includes: description of the incident, types of information involved, steps we have taken, steps individuals can take, and contact information.
State-Specific Requirements:

Some states have unique requirements:

  • California: Notice must include specific categories of breached information and be provided in the "most expedient time possible."
  • New York: Notice to AG within 24 hours if more than 500 NY residents affected.
  • Texas: Notice within 60 days; AG notification if 250+ residents affected.
  • Colorado: Notice within 30 days; AG notification if 500+ residents affected.
  • Florida: Notice within 30 days; AG notification if 500+ residents affected.

8. COOKIES AND TRACKING

8.1 Cookie Types

CategoryPurposeControl
EssentialLogin, security, core functionalityAlways active (required)
FunctionalPreferences (language, display)Can disable (reduces convenience)
AnalyticsUsage patterns, performance (Firebase)Opt-out available
MarketingB2B campaign tracking onlyConsent required

Consent: Cookie banner obtains consent for non-essential cookies before setting. Update preferences via "Cookie Settings" in footer.

Prior Consent (EU)

For EU/EEA Users, no analytics or marketing cookies are placed until You affirmatively consent via our cookie banner. Pre-ticked boxes are not used. Continued browsing or scrolling does not constitute consent.

Legal Bases

Essential cookies are used to provide services You have requested and they are processed on the basis of contract performance and/or our legitimate interests. These cookies are required for the Website and App to function correctly and do not require consent.

If You access our Website from the EU:

  • We will not set analytics or marketing cookies until You have provided consent via the cookie banner;
  • Any later use of "Cookie Settings" to turn off analytics or marketing cookies will be treated as a withdrawal of your consent, and we will stop using those cookies from that point onwards;
  • Essential cookies will continue to operate as they are strictly necessary for the Service.

8.2 Third-Party Technologies

Providers

Firebase/Google, Stripe, App Stores, Sentry (see their privacy policies).

Mobile

Firebase Installation IDs for App instances. No cross App advertising identifiers (IDFA/GAID) currently used.

Your Controls
  • Browser: Settings > Privacy to block/delete cookies;
  • Mobile: Device settings for App permissions;
  • Marketing: Op out anytime via unsubscribe links.

Note: Disabling cookies may affect login, preferences, and features. We do not currently respond to Do Not Track signals.

8.3 Specific Cookies and Trackers

The following are the current cookies and trackers in use. They are subject to change.

Cookie/ Tracker NameProviderCategoryPurposeDuration
_ga, _gidGoogle/FirebaseAnalyticsUsage statistics, user distinction2 years / 24 hours
_gcl_auGoogle/FirebaseAnalyticsConversion tracking3 months
firebase-installation-idFirebaseEssentialApp instance identificationUntil App deletion
auth-tokenPool Guy/FirebaseEssentialAuthentication sessionSession/30 days
pool-guy-sessionPool GuyEssentialSession managementBrowser session
preferencesPool GuyFunctionalUser settings (language, display)1 year
stripe_mid, stripe_sidStripeEssentialPayment fraud prevention1 year / 30 minutes
rc_attributionRevenueCatEssentialSubscription management90 days
sentry-sessionSentryAnalyticsError tracking sessionSession
consent-statusPool GuyEssentialCookie consent preferences1 year

In the EU, analytics and marketing cookies from this list are only activated after You have granted consent via the cookie banner. If You withdraw your consent using "Cookie Settings", we will disable these cookies and stop further processing based on them.

9. CHILDREN'S PRIVACY

Pool Guy is exclusively a B2B only App and Service. To register a valid Account, Users must be 18+ or age of majority in your jurisdiction and operate a pool services business. We do not knowingly collect children's information.

United States (COPPA): Pool Guy complies with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13 years of age. If we discover we have inadvertently collected information from a child under 13, we will promptly delete it. If You believe a child under 13 has provided us with personal information, contact privacy@getpoolguy.com immediately.

10. MARKETING COMMUNICATIONS

10.1 Communication Types

TypeContentOpt-Out
Service (Required)Account confirmations, security alerts, billing, policy changes, password resetsCannot opt out (necessary for operation)
Marketing (Optional)Product updates, features, tips, promotions, surveys, beta invitesUnsubscribe link, Account settings or email request

B2B Context: We may rely on legitimate interests or soft opt in where permitted. Opt outs will be processed within 14 days (5 working days for NZ/AU compliance).

Source Disclosure (Australia): On request, we will notify You of the source of personal information used for direct marketing. Email privacy@getpoolguy.com.

10.2 Spam Law Compliance

NZ Unsolicited Electronic Messages Act 2007 and Australian Spam Act 2003:

  • Clear sender identification (Pool Guy/Owner);
  • Valid contact information in all messages;
  • Functional, free unsubscribe mechanism;
  • Express consent records maintained;
  • B2B messages kept relevant and proportionate.

US CAN-SPAM Act Compliance:

  • All commercial emails include clear identification as advertisements where required;
  • "From," "To," and routing information is accurate;
  • Subject lines accurately reflect message content;
  • Valid physical postal address included in all emails;
  • Opt-out requests honoured within 10 business days;
  • We do not use deceptive subject lines or false header information;
  • We do not sell or transfer email addresses to third parties for their marketing.

State Email Marketing Laws: In addition to CAN-SPAM, we comply with state-specific email marketing requirements, including:

  • California (CalOPPA and Business & Professions Code Section 17529.5): We do not send emails with falsified or misrepresented header information and do not use third-party domain names without permission.
  • Utah, Colorado, and other states with supplementary requirements: We maintain compliance with state consumer protection laws applicable to commercial electronic messaging.

Telephone Consumer Protection Act (TCPA): We do not make telemarketing calls or send marketing SMS messages without prior express consent. Any service related communications via phone or SMS are transactional in nature.

11. THIRD-PARTY SERVICES AND LINKS

11.1 Essential Third Parties

Core Services (acting as Data Processors)
  • Google Firebase/Cloud Platform (infrastructure, databases, storage, authentication);
  • RevenueCat (mobile subscriptions);
  • Stripe (web payments);
  • Sentry (error tracking);
  • Firebase Analytics (usage analysis).
  • PostHog (product analytics and session replay).

Each has contractual data protection obligations. See their privacy policies for details.

11.2 External Links

Our platforms may link to third-party sites (support, documentation, payment providers). We are not responsible for their privacy practices. You follow the third party links at your own risk. You should review their policies before providing information.

Note: We do not currently use any embedded social plugins or behavioral advertising networks. We will give notice to you should this change.

12. AUTOMATIC COLLECTION NOTIFICATION (NZ IPP 3)

New Zealand law (Information Privacy Principle 3 of the Privacy Act 2020) requires notification when automatically collecting personal information.

We Automatically Collect:
  • Device/browser information on App or Website access;
  • Usage analytics via Firebase Analytics;
  • Error/crash data via Sentry;
  • Session data via cookies (see Section 8).
Notification Methods:
  • This Policy serves as a permanent notification;
  • Cookie banner provides real-time notification;
  • In App notices for new automatic collection features.
Your Controls

Disable automatic collection via device settings, cookie preferences, or by not using the Service.

13. RECORDS OF PROCESSING (GDPR ARTICLE 30)

We maintain the following records available to supervisory authorities on lawful request:

Record TypeDetails Maintained
Processing ActivitiesPurposes, categories, recipients and retention periods
Legal BasesDocumented basis for each processing activity
International TransfersCountries, mechanisms and safeguards
Security MeasuresTechnical and organisational measures according to activity
Sub-processorsNames, locations and processing scope
Data Subject RequestsRequests received, actions taken and response times

Review Frequency: Quarterly or on material changes.

14. DATA PROTECTION IMPACT ASSESSMENTS (GDPR ARTICLE 35)

When Conducted
  • New features processing personal data at scale;
  • Implementation of systematic monitoring;
  • Introduction of new technologies affecting privacy;
  • Changes creating high risk to data subjects.
DPIA Process
  1. Describe processing and purposes;
  2. Assess necessity and proportionality;
  3. Identify and assess risks;
  4. Determine mitigation measures;
  5. Document decisions and obtain approvals.

Consultation: We will consult supervisory authorities where DPIAs indicate high residual risk that cannot be mitigated.

15. LEGITIMATE INTERESTS REGISTER

We document all processing based on legitimate interests:

Processing ActivityInterestBalancing Test DateReview Date
Service improvement analyticsBusiness developmentDateAnnually
B2B direct marketingCustomer retentionDateAnnually
Fraud preventionSecurity/financial protectionDateAnnually
Network security monitoringInfrastructure protectionDateAnnually

Access: Summary available on reasonable request to privacy@getpoolguy.com. Full assessments available to supervisory authorities.

16. SUB-PROCESSOR LIST

Current Sub-processors
NameLocationServiceData Processed
Google (Firebase)US/Multi-regionInfrastructureAll platform data
StripeUS/IrelandPaymentsBilling information
RevenueCatUSSubscriptionsPurchase data
SentryUSError trackingTechnical/diagnostic
PostHogUSProduct analytics and session replayProduct-analytics events; session replay of user interactions across app flows
Changes

We provide 30 days advance notice of sub-processor changes via email and in the table above.

Objection Rights

Users may object to new sub-processors within 14 days of notification. Process:

  1. Object in writing within 14 days;
  2. We will discuss concerns and explore alternatives;
  3. If we cannot accommodate your objection, You may terminate your Subscription with pro-rata refund for prepaid unused period;
  4. No objection within 14 days constitutes acceptance.

17. GOVERNING LAW AND JURISDICTION

Primary Law

New Zealand law governs this Policy and our activities as a data controller and data processor.

Additional Compliance
  • EU Users: GDPR applies regardless of NZ law;
  • Australian Users: Australian Privacy Act applies;
  • USA: Applicable US federal and state privacy laws apply, including CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), and other state laws based on your residence.
  • Other Jurisdictions: Local mandatory privacy laws apply where applicable.
Conflict of Laws

Where this Policy conflicts with mandatory privacy laws applicable to You based on your location, mandatory local law prevails to the extent of inconsistency:

  • EU data subjects: GDPR applies;
  • Australian individuals: Australian Privacy Act applies;
  • US residents: Applicable state privacy law applies to the extent it provides greater protection than this Policy.
  • New Zealand individuals: Privacy Act 2020 applies;
  • All other matters: New Zealand law governs.
Dispute Resolution Order
  1. Internal resolution (Section 6.3);
  2. Relevant privacy authority (NZ Privacy Commissioner, OAIC, ICO, etc.);
  3. Courts of New Zealand (subject to your local mandatory consumer protection laws).
Regulatory Enforcement:

Maximum penalties vary by jurisdiction (NZ: NZD$10,000 for individuals/No statutory limit for entities; GDPR: €20M or 4% global turnover; Australia: the greater of: For most serious breaches (Tier 3) AUD $50 Million; Three times the value of the benefit obtained; or 30% of the company's adjusted turnover).

Regulatory Enforcement:

United States: Penalties vary by state. Examples include:

  • California: Up to $2,500 per unintentional violation; up to $7,500 per intentional violation or violations involving minors under CCPA/CPRA; private right of action for data breaches (statutory damages of $100-$750 per consumer per incident).
  • Virginia/Colorado/Connecticut/Other States: Up to $7,500 per violation, typically enforced by the State Attorney General following a cure period (where applicable).
  • Texas: Up to $7,500 per violation; no private right of action.
  • Oregon: Up to $7,500 per violation; 30-day cure period expires January 1, 2026.

18. REGULATORY COOPERATION

We commit to:

  • Respond to supervisory authority inquiries within required timeframes;
  • Cooperate with investigations and audits;
  • Implement binding decisions and compliance notices;
  • Maintain open communication channels with all relevant privacy authorities.

Lead Authority (GDPR): For EU matters, our lead supervisory authority is determined by our main establishment (currently N/A as we are based in New Zealand without an EU establishment).

19. POLICY CHANGES

Material Changes

30 days advance notice via email and in App or on-site notice.

Minor Changes

Updated on website and App with revised "Last Updated" date.

Your Options

Discuss concerns, export data, or cancel your Account before changes take effect. Continued use after the effective date will constitute acceptance.

Data Protection Officer Assessment (GDPR Article 37)

Current Status: DPO appointment not mandatory as we do not:

  • Conduct large scale systematic monitoring as core activity;
  • Process special categories data at large scale;
  • Operate as public authority.

Voluntary Designation: A Privacy Officer is appointed to handle data protection matters, monitor compliance, and liaise with authorities.

Assessment reviewed annually. Documentation available to supervisory authorities on request.

20. CONTACT US

20.1 Privacy Contact

Email: privacy@getpoolguy.com

Mail: Pool Guy Technologies Limited, 10 Madeira Close, Whitby, Porirua 5024, New Zealand

20.2 EU Representative

We are based in New Zealand and do not have a physical establishment in the European Union. If You are located in the EU and wish to contact us regarding your personal data, You may contact us directly:

Email: privacy@getpoolguy.com

Mail: Pool Guy Technologies Limited, 10 Madeira Close, Whitby, Porirua 5024, New Zealand

20.3 US Privacy Requests

For US/State specific privacy requests:

Email: privacy@getpoolguy.com

Include:

  • Your state of residence;
  • The specific right(s) You wish to exercise;
  • Sufficient information to verify your identity and locate your records.

Authorised Agents: Residents of California, Virginia, Colorado, Connecticut, and other applicable states may designate an authorized agent to submit requests on their behalf. Authorized agents must provide:

  • Signed written authorization from the consumer; or
  • A valid power of attorney under applicable state law.

We may require verification of both the agent's authority and the consumer's identity before processing the request.

20.4 Rights Requests

To exercise rights (access, correction, deletion, etc.), email us with:

  • Your full name and business name;
  • Account email;
  • Clear description of request;
  • Identity verification information.

End Customers: Contact your pool service company directly.

20.5 Complaints

See Section 6.3 for complete complaints process and escalation to privacy authorities.

21. ACCEPTANCE

By creating an Account, using Pool Guy, or clicking "I Accept," You confirm:

  • You have read and understood this Policy;
  • You understand Pool Guy is B2B-only and You are responsible for privacy compliance in relation to your End Customers;
  • You consent to data processing by us as described;
  • You agree to comply with this Policy, ToS, and DPA.

22. Annual Policy Review

To ensure ongoing compliance with privacy laws and regulations, We will review Our Privacy and Cookies Policy on an annual basis, including US State laws.

If You do not agree to the above, please do not use Pool Guy.

Last Updated: 10/09/2026

Effective Date: 17/09/2026