Privacy Policy
WaveOps (operated by Pool Builder's Services, LLC, "we", "us") provides software-as-a-service for pool service companies. This policy describes what information we collect from the people who use WaveOps, why we collect it, who else sees it, and what choices you have about it.
Two groups of people show up in this document: operators (the pool service company owners and their employees who sign in to WaveOps) and their customers (the homeowners whose pool data the operator stores in WaveOps). Most of this policy is about operators. Where it's about customer data the operator entered, we say so explicitly.
What we collect
- Account information you give us when you create an account: name, email address, password (hashed), company name, phone, business address.
- Operational data you enter while using the product: your customers' names and addresses, their pool size, gate codes, pets, chemistry readings, photos taken by your techs, invoices, estimates, payments, route schedules, and service notes.
- Photos and files uploaded through the app — typically pool, equipment, and proof-of-service photos taken by techs in the field.
- Payment information when you pay for a WaveOps subscription. We don't store card numbers ourselves — Stripe does (see Sub-processors below).
- Communication metadata when WaveOps sends an email on your behalf (recipient, timestamp, delivery status). We do not retain the body of automated messages beyond what's needed to show you a delivery history.
- Usage data such as login times, which pages you visit inside the app, and basic device/browser info. We do not use third-party advertising trackers.
How we use it
- To operate the service — log you in, save your work, sync changes between your devices and your team.
- To send transactional emails you've initiated through the product (invoices, estimates, arrival notifications to your customers).
- To bill you for your subscription.
- To respond to support requests.
- To diagnose bugs and improve the product. Aggregated usage data may inform what we build next.
- To detect and prevent abuse (e.g., unusual sign-in patterns, brute-force attempts).
We do not sell, rent, or trade your data. We do not use your operational data to train AI models.
Sub-processors
WaveOps relies on a small number of trusted vendors to deliver the service. Each one only sees the information they need to do their job:
- Supabase (data hosting + authentication). All operator and customer data you enter is stored in a Supabase project we operate.
- Stripe (subscription billing + customer card payments). When you or your customer pays a card through WaveOps, the card details go straight to Stripe; we receive only the result and a payment reference.
- Twilio (phone line). WaveOps does not send text messages. Twilio carries the voice line for our own published phone number — the one you would call to reach us — so when someone calls it Twilio handles the call transport and sees the calling number and call metadata. It is not connected to your customers or to anything in your account.
- Resend (transactional email delivery). When WaveOps sends an invoice email or estimate link, Resend handles transport.
- Anthropic (AI features). When you use AI-powered features — automatic Spanish/English translation of notes, dosing recommendations from chemistry readings — the relevant text is sent to Anthropic's Claude API for processing. Anthropic does not train models on this data. Translated text is cached server-side so the same phrase is never sent twice.
- Cloudflare (CDN + edge delivery for our marketing site and product assets).
- Sentry (error monitoring). When the app hits an unexpected error, a report is sent to Sentry so we can fix it. We configure it not to record sessions and not to attach personal data, and every report is scrubbed of customer names, addresses, email addresses, phone numbers and access links before it leaves your device.
- PostHog (product analytics). If you accept analytics cookies, PostHog records which screens and features get used so we know what to improve. Input values are masked; we do not record your screen. Decline the cookie notice, or turn on Do Not Track in your browser, and nothing is sent. To change that choice later, open any page on gowaveops.com and use the Cookie choices link at the bottom.
If we add or change a sub-processor, we'll update this list before the change takes effect.
Data retention
We keep your account data for as long as your account is active. If you cancel:
- You can export your customer list, invoice history, and stop history at any time from inside the app (Settings → Export).
- After cancellation, your data is retained for 30 days in case you change your mind, then permanently deleted.
- We may keep backups for an additional 30 days, after which they're overwritten on schedule.
- Billing records are retained as long as required by tax law (typically 7 years), separate from your operational data.
Your rights
You have the right to:
- Access the personal information we hold about you. Most of it is visible inside the app; email us for anything else.
- Correct inaccurate information. You can edit account details from Settings.
- Export your data in a portable format (CSV).
- Delete your account and the data associated with it. Email support@gowaveops.com and we'll process the deletion within 14 days.
If you are an operator's customer (a homeowner whose pool data your service company stores in WaveOps) and you want your information corrected or removed, contact your pool service company directly — they're the data controller for that information. If they don't respond, you can write to us and we'll forward the request.
Security
We use industry-standard security practices: encrypted connections (TLS) between your browser and our servers, encrypted storage of passwords (bcrypt hash), row-level security on the database so each company's data is isolated from other companies, and short-lived authentication tokens. We host on Supabase, which inherits enterprise-grade physical and network security from its underlying cloud providers.
No system is 100% secure. If we discover a breach affecting your data, we'll notify you promptly and explain what happened and what you should do.
Children
WaveOps is a tool for businesses. It is not intended for individuals under 18, and we do not knowingly collect information from anyone under that age.
Changes to this policy
If we update this policy, we'll change the "Last updated" date at the top and email account-holders if the change is material.
Governing law and contact
This policy is governed by the laws of the State of Texas, United States. If you have any question about it, email us at support@gowaveops.com.