Privacy Policy
Effective Date: April 1, 2026 · Last updated: August 4, 2026
1. Introduction
AquaFlow Pro ("we," "us," or "our") operates a software-as-a-service (SaaS) platform that helps pool service companies manage routes, log water chemistry, bill customers, and communicate with technicians and homeowners. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
If you have any questions about this policy, contact us at support@getaquaflowpro.com.
2. Information We Collect
From pool companies who sign up
- Business name, owner name, email address, and phone number
- Billing information processed through Stripe — we never store card numbers, CVV, or full card details
- Company branding, including logo and color selections
- QuickBooks Online authorization tokens, when the owner connects their accounting — see Section 5, QuickBooks Online
From pool company customers
- Name, email address, phone number, and service address
- Pool specifications (volume, equipment, chemistry readings)
- Payment information processed through Stripe
- Service history and visit logs
- Messages sent through the customer portal
From technicians
- Name, email address, and role
- Visit logs and route data
- Location data only while the route feature is actively in use
Automatically collected
- Browser type and device information
- IP address
- Pages visited and features used
- Error logs for platform stability
3. How We Use Your Information
- To provide and operate the AquaFlow Pro platform
- To process payments through Stripe
- To sync data with QuickBooks when authorized by the company owner
- To send invoices and payment reminders on behalf of pool companies
- To send trial expiry and subscription emails
- To provide AI chemistry assistance through a third-party AI service provider
- To improve platform features and fix bugs
- To communicate important updates about the service
We never sell your data to third parties. We never use your data to train AI models.
4. How We Share Your Information
We share data with the following service providers only as necessary to operate the platform:
We may also disclose data if required by law or to protect the rights, property, or safety of AquaFlow Pro, our users, or others.
5. QuickBooks Online Integration
Connecting QuickBooks Online is optional. Nothing described in this section happens unless a pool company owner explicitly authorizes it, and it stops the moment they disconnect.
How the connection is authorized
The owner connects through Intuit's OAuth 2.0 flow. They sign in on Intuit's own website and approve the connection there. We never see, receive, or store an Intuit username or password. Intuit returns an authorization token instead.
We request a single permission scope, com.intuit.quickbooks.accounting. We do not request QuickBooks Payroll or QuickBooks Payments permissions.
What we read from QuickBooks
- The QuickBooks company name, so we can show which company file is connected
- Existing customer records, to match them against AquaFlow Pro customers and avoid creating duplicates
- The income and accounts-receivable account references and the service item needed to post an invoice correctly
What we write to QuickBooks
- Customers — name, email, phone, and service address
- Invoices — amount, description, and due date
- Payments recorded against those invoices
We do not access, read, or modify payroll records, bank feeds, tax filings, or any part of the QuickBooks file outside the customers, invoices, payments, and account references listed above.
How the authorization tokens are stored
- Tokens are held in a restricted server-side location in our Google Cloud (Firebase) database that our own web and mobile apps cannot read. Only our backend services, running with administrator credentials, can access them.
- They are encrypted in transit using TLS and encrypted at rest by Google Cloud.
- They are never sent to a browser, never written to a page, and never included in an email or a log file.
Disconnecting
An owner can disconnect at any time from Account → QuickBooks Online. When they do, we revoke the authorization directly with Intuit and then delete the stored tokens from our database. Revocation invalidates the authorization at Intuit's end, so the credentials cannot be used again even if a copy existed somewhere.
If Intuit cannot be reached at that moment, we still delete our copy of the tokens and tell the owner to also remove AquaFlow Pro under QuickBooks → Settings → Manage Users → Connected Apps, so the authorization is closed on both sides.
Data already written into QuickBooks stays in QuickBooks — it belongs to the company's accounting records and is theirs to keep or delete within QuickBooks.
We never sell QuickBooks data, never share it with other pool companies on the platform, and never use it to train AI models.
6. Data Retention
- Active accounts: Data is retained while your account is active.
- After cancellation: Data is retained for 90 days, then permanently deleted on request.
- Payment records: Retained as required by law — typically seven (7) years.
- Error logs: Retained for 30 days.
You can request deletion of your data at any time by emailing support@getaquaflowpro.com.
7. Data Security
- All data is transmitted over HTTPS encryption.
- Firebase security rules restrict data access by company and user role.
- Payment data is handled exclusively by Stripe. We never store card numbers, CVV, or full card details.
- QuickBooks authorization tokens are held in a restricted server-side location that client applications cannot read, encrypted in transit and at rest, and revoked with Intuit on disconnect — see Section 5.
- Access is limited to authenticated users only.
- Regular security audits are performed.
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Export your data in a standard format
- Opt out of non-essential emails
- Withdraw consent at any time
To exercise any of these rights, email support@getaquaflowpro.com.
9. Cookies
We use minimal cookies:
- Firebase Authentication session cookies — required for login
- Google Analytics cookies — can be opted out in your browser settings
- reCAPTCHA cookies by Google — required for form security
We do not use advertising cookies and we do not sell cookie data.
10. Children’s Privacy
AquaFlow Pro is a business platform and is not intended for children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
11. California Privacy Rights (CCPA)
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt out of the sale of personal information
- Right to non-discrimination for exercising CCPA rights
We do not sell personal information. To exercise any CCPA rights, contact support@getaquaflowpro.com.
12. Changes to This Policy
We may update this policy from time to time. We will notify active users by email at least 30 days before material changes take effect. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
13. Contact Us