PoolHelm Privacy Policy
Last updated: August 6, 2026
This Privacy Policy explains how BorderLeap LLC ("BorderLeap," "we," "us," or "our"), which operates PoolHelm ("PoolHelm" or the "Service"), collects, uses, and shares personal information. By using the Service or this website, you agree to this Policy.
1. Who This Policy Covers
This Policy applies to:
- Visitors to our website.
- Customers — the pool service businesses and their staff who use PoolHelm.
- Your customers (homeowners) — the people your business serves, whose information you enter into or communicate through PoolHelm.
For information about your business's customers, you (the pool service business) decide what information is collected and how it is used — you act as the controller (or "business"), and we process that information on your behalf as your processor (or "service provider") to provide the Service. If you are a homeowner with questions about how a pool service business uses your information, please contact that business directly; we will refer you to them, or work with them to answer you.
2. Information We Collect
Information you provide.
- Account and business details — name, business name, email address, phone number, mailing or service address, and login credentials.
- Billing information — your subscription plan and payment details. Card payments are processed by our payment provider, Stripe; we do not store full card numbers on our servers.
- Customer and property data you enter — the names, addresses, contact details, service records, chemistry readings, photos, and notes you add about the customers and properties your business serves.
- Communications — messages you send us, and support requests.
Information collected automatically.
- Usage and device data — how you interact with the Service, along with IP address, browser type, and device information, collected through cookies and similar technologies and through analytics providers.
- Session analytics. Our website uses Microsoft Clarity, which records page interactions such as clicks, scrolling, and mouse movement in order to produce heatmaps and session replays. This is used to improve the site. Clarity's recordings are of our marketing website.
- Location data — property addresses are used to provide mapping, routing, geocoding, and hyperlocal weather features. We do not collect continuous background location from technicians' devices.
We do not knowingly collect sensitive personal information — such as government identifiers, precise real-time geolocation, health information, biometric data, racial or ethnic origin, religious beliefs, or the contents of your private communications — and we ask that you not enter it into the Service.
3. How We Use Information
We use personal information to:
- provide, operate, secure, and improve the Service;
- set up and manage accounts, process your subscription, and handle billing;
- send service-related messages, and — on your behalf — deliver the customer communications you configure (such as service reports, invoices, weather notices, and referral messages);
- provide mapping, routing, geocoding, and weather features;
- respond to support requests;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- comply with legal obligations and enforce our agreements; and
- send you product and marketing updates, which you can opt out of at any time.
We do not use your data, or your customers' data, to train machine-learning models for other customers, and we do not sell it. Where the Service uses artificial intelligence — for example the morning briefing and route narration — it processes your organization's own data to produce output for you.
No automated decisions with legal effects. PoolHelm produces recommendations that a person reviews and acts on. It does not make decisions about individuals that produce legal or similarly significant effects without human involvement.
Legal bases (for individuals in the UK/EEA). Where the UK GDPR or EU GDPR applies to our processing, we rely on: performance of a contract (providing the Service and billing); our legitimate interests (securing and improving the Service, preventing fraud, and limited direct marketing to business contacts); consent (non-essential cookies and analytics, where required); and compliance with legal obligations.
4. How We Share Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information with:
- Service providers ("subprocessors") that help us run the Service, under contracts that limit their use of the information. These currently include:
- Supabase — application database and hosting of your account and business data.
- Stripe — subscription billing, and the payment links you send your own customers.
- Resend — sending service and transactional emails.
- Beehiiv — sending marketing and onboarding emails to subscribers.
- Google Maps Platform, Google Weather, and Google Route Optimization — mapping, geocoding, weather, and route features.
- Anthropic — the AI provider behind the morning briefing and related generated text.
- Twilio — text-message delivery, where a business has enabled messaging.
- Vercel — website and application hosting.
- Google Analytics and Microsoft Clarity — website usage analytics and session replay.
- Professional advisors and authorities where required by law, to protect our rights, or to investigate fraud or abuse.
- In a business transfer — if BorderLeap is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
We will maintain a current list of subprocessors and will use commercially reasonable efforts to give notice before adding a new one that processes customer data.
5. Cookies and Analytics
We use cookies and similar technologies to keep you signed in, remember your preferences, understand how the site and Service are used, and improve them. Essential cookies are required for the Service to function. You can control cookies through your browser settings; disabling some cookies may affect how the Service works.
Do Not Track. Browsers may send a "Do Not Track" signal. There is no common industry standard for responding to it, and we do not currently respond to it. Where required by law, we honor recognized opt-out preference signals such as Global Privacy Control for the purposes those signals cover.
6. Data Retention
We keep personal information for as long as your account is active and as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. In general:
- Account and business data — kept while your subscription is active. After termination, we make your data available for export for at least 30 days, then delete it in the ordinary course.
- Billing records — retained as long as required for tax, accounting, and audit purposes.
- Support communications — retained while needed to handle your request and for a reasonable period afterward.
- Website analytics — retained per the provider's default retention period.
Residual copies may persist in encrypted backups for a limited period before being overwritten. When information is no longer needed, we take reasonable steps to delete or de-identify it.
7. Security
We use reasonable administrative, technical, and organizational safeguards to protect personal information. These include encryption in transit, access controls, and row-level database isolation so that each customer organization can access only its own records. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a security breach affecting your personal information, we will notify you without undue delay and as required by applicable law.
8. Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal information, to opt out of marketing messages, and to appeal a decision we make about your request. To exercise these rights, contact us at hello@poolhelm.com. We will verify your request using the information already associated with your account, and we will respond within the time required by applicable law. We will not discriminate against you for exercising these rights.
You may use an authorized agent to submit a request on your behalf; we may ask for proof of the agent's authority.
If your request concerns information a pool service business entered about you as their customer, that business is the controller of that information — we will refer you to them, or work with them to fulfil your request.
United States — state privacy rights. Residents of California, Texas, Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have the rights described above, including the right to know what personal information we collect and how it is used and shared, the right to delete or correct it, the right to a portable copy, and the right to opt out of the sale or sharing of personal information and of targeted advertising. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for targeted advertising or profiling in furtherance of decisions producing legal or similarly significant effects. If we deny your request, you may appeal by replying to our decision or writing to hello@poolhelm.com; we will respond to an appeal within the period required by your state's law.
UK/EEA. If the UK or EU GDPR applies, you additionally have the right to object to or restrict certain processing, to withdraw consent where we rely on it, and to lodge a complaint with your local supervisory authority. Where we transfer personal information outside the UK or EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), together with additional measures where needed. BorderLeap LLC operates from the United States, and information you provide is processed there.
Marketing. You can opt out of marketing emails at any time using the unsubscribe link in those emails. Service and billing messages are not marketing and are necessary to operate your account.
9. Children's Privacy
The Service is intended for businesses and is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us at hello@poolhelm.com and we will delete it.
10. Third-Party Links
The Service may link to third-party websites and services. We are not responsible for their privacy practices, and we encourage you to review their policies.
11. Changes to This Policy
We may update this Policy from time to time. If we make material changes, we will take reasonable steps to notify you (for example, by email or in-app notice) before they take effect. The "Last updated" date above shows when this Policy was last revised.
Material change — August 6, 2026. We clarified our processor role and added detail on session-replay analytics, AI processing and the Anthropic and Twilio subprocessors, retention periods, security and breach notification, automated decision-making, U.S. state privacy rights and appeals, GDPR legal bases and international transfers, and opt-out preference signals.
12. Contact Us
BorderLeap LLC 1100 Lovers Ln, Longview, TX 75604 Email: hello@poolhelm.com
For privacy requests, please use hello@poolhelm.com with "Privacy request" in the subject line.