Privacy Policy

How we protect your commercial account data, privacy rights, and operational confidentiality.

Privacy & Data Protection Policy

Effective Date: September 6, 2026

Last Updated: September 6, 2026

Operator: Core Durability, LLC (an Arizona limited liability company) doing business as WaterShield

Physical Address: 4814 E Mabel St., Tucson, AZ 85712, Pima County

Privacy Officer Contact: privacy@watershield.app

This Master Privacy Policy details how Core Durability, LLC ("Company", "WaterShield", "we", "us", or "our") collects, processes, and protects information across our platform websites, applications, and services. We strictly bifurcate data into two distinct categories:

  • Commercial Account Data: Business contact details, billing records, and authentication credentials collected from Customer representatives, governed by this Privacy Policy.
  • Operational Facility Telemetry: Physical building parameters, sensor metrics, water test results, and compliance logs, which are governed by our Master Data Processing Agreement (DPA).

1. Scope & Demarcation of Data

WaterShield provides Business-to-Business (B2B) water management, environmental risk management, and regulatory compliance software. We collect Commercial Account Data strictly to provision accounts, process subscription transactions, authenticate authorized personnel, and deliver real-time operational compliance notifications. Facility operational telemetry is processed in accordance with documented Customer instructions under our Master Data Processing Agreement.

2. Information We Collect

2.1 Identity & Contact Information

To provision and manage your account, we collect full names, business email addresses, professional titles, facility affiliations, telephone numbers, and physical facility mailing addresses.

2.2 Authentication & Credential Metadata

We store salted and cryptographically hashed passwords, session tokens, multi-factor authentication (MFA) metadata, and OAuth identifiers to safeguard system access.

2.3 Billing & Commercial Transaction Data

We collect payment transaction metadata, credit card brand and last four digits, billing addresses, tax ID/EIN, and subscription purchase histories. All payment transactions are securely processed via our PCI-DSS Level 1 compliant payment processor, Stripe, Inc. We never store raw credit card numbers or security codes on our servers.

2.4 Technical Network Telemetry & Device Tokens

To maintain forensic security and enforce legal agreements, we log IP addresses, browser User-Agent strings, and access timestamps for all administrative and user sessions. For users who opt in to browser-based alerts, device push notification tokens are stored strictly to deliver real-time excursion notifications.

3. Authorized Sub-Processors & Infrastructure

We transmit Commercial Account Data strictly to verified enterprise sub-processors operating under binding data protection and confidentiality agreements:

  • Supabase, Inc.: Cloud database and authentication infrastructure. User account records, session authentication, and access control policies are managed under PostgreSQL Row-Level Security (RLS).
  • Vercel, Inc.: Cloud hosting and serverless edge compute runtime for web applications and API endpoints.
  • Stripe, Inc.: Payment processing, PCI-compliant billing tokenization, and recurring merchant billing services.
  • Resend, Inc.: Transactional email infrastructure delivering team invitations, password resets, and critical compliance excursion alert notifications.
  • Twilio, Inc.: Critical SMS compliance excursion alerts and emergency notification dispatch.

4. Audit Log Data Retention & Purging Schedules

We enforce precise data retention and disposal schedules aligned with regulatory defensibility:

  • Commercial Account Records: Retained for the active duration of your subscription plus seven (7) years following termination to satisfy federal, state, and corporate statutory audit and tax obligations.
  • Push Notification Device Tokens: Immediately revoked and purged upon user sign-out, session invalidation, or browser permission removal.
  • Cryptographic Audit Trails: In compliance with CMS, Joint Commission, and 21 CFR Part 11 requirements, compliance event hashes, SHA-256 Merkle chains, electronic signature manifests, and executed Business Associate Agreements (BAAs) are permanently preserved in immutable storage unless expungement is ordered by a court of competent jurisdiction.

5. Statutory Privacy Rights (CPRA, GDPR & State Statutes)

Depending on your jurisdiction (including under the California Consumer Privacy Act / California Privacy Rights Act and European General Data Protection Regulation), you possess enforceable legal rights regarding your personal information:

  • Right to Access: The right to request confirmation of data processing and a portable copy of your personal data.
  • Right to Correction: The right to request correction of inaccurate or incomplete personal information.
  • Right to Deletion: The right to request erasure of your personal data, subject to mandatory 7-year statutory and regulatory audit retention exceptions.
  • Right to Opt-Out: We do not sell, rent, or trade personal data, nor do we share personal data for cross-context behavioral advertising. You may opt out of promotional communications at any time; critical operational compliance alert emails cannot be unsubscribed while an active monitoring subscription is maintained.

To exercise any statutory privacy rights, please contact our Privacy Officer at privacy@watershield.app. We verify and respond to all authenticated statutory requests within forty-five (45) days.