Skip to content
SWRainAlert
How it works Features States & thresholds Blog Pricing Sandbox API docs Sign in Start free trial

Legal

Privacy Policy

Last updated 5 September 2026

This is the plain-English version, and it is the only version. If something here is unclear, email [email protected] and we will fix the wording rather than explain it away.

The short version. We collect what is needed to monitor your sites and keep your compliance records. We do not sell your data, we do not run advertising trackers, and this marketing website sets no cookies at all.

1. Who we are

SWRainAlert ("we", "us") provides rainfall monitoring and stormwater inspection recordkeeping for construction sites in the United States. For the data your organisation puts into the service, your organisation is the controller and we are the processor acting on your instructions.

2. What we collect

Account data

  • Name, work email address and organisation name.
  • A password, stored only as an argon2id hash. We never see or store the password itself.
  • Role within your organisation (admin or member), and team invitations you send.
  • Session tokens, including a rotating refresh token held in your device's platform keystore.

Site data

  • Site name, identifier, coordinates, state and timezone.
  • The permit threshold applying to each site, including any value you override.
  • Rainfall readings we retrieve from NOAA for those coordinates, stored per site and per source.

Site coordinates are the core of the service — without them there is nothing to monitor. They identify a construction site, not a person.

Inspection data

  • Completed inspection forms, including the inspector's name and any certification number the state form requires (for example a GSWCC number in Georgia).
  • Photo and video evidence you attach, together with the time it was attached.
  • Corrective actions you open and close, and the signature applied when an inspection is filed.

Photos and video are downscaled on your device before upload. We do not run facial recognition, image classification or any other automated analysis over your evidence.

Technical data

  • Server logs of API requests, including IP address, timestamp and endpoint, kept for security and debugging.
  • Delivery records for the emails we send you (see §4), including the provider's message identifier as proof of send.

What we do not collect

  • Payment card numbers — if and when we take payment, it is handled by a payment processor and card details never reach our servers.
  • Continuous location tracking. The app reads your device location only when you actively use it to place a site pin.
  • Anything at all on this marketing website. No analytics, no cookies, no third-party scripts, no fonts loaded from someone else's server.

3. Why we hold it

PurposeBasis
Monitoring your sites and sending threshold alertsPerformance of our contract with you
Storing inspection records and evidencePerformance of our contract; your own regulatory recordkeeping
Authentication, lockouts and token rotationLegitimate interest in securing accounts
Server logsLegitimate interest in security and reliability
Service email (alerts, password reset, invitations)Performance of our contract

4. Who we share it with

We use a small number of processors, and only these:

  • Brevo — transactional email delivery (alerts, password resets, team invitations). Receives the recipient address and message content.
  • Our hosting provider — stores the database and uploaded evidence in United States regions.
  • NOAA / National Weather Service — the source of rainfall data. This is an outbound request for public grid data; we do not send your site details to NOAA. We download one national grid and sample your coordinates ourselves.

We do not sell personal data, and we do not share it for advertising. We will disclose data if legally compelled, and where we are permitted to tell you, we will.

5. How long we keep it

  • Inspection records and evidence — for the life of your account, and for a further 90 days after closure so a record cannot be lost by accident. Longer if you ask, because permits often require retention for years.
  • Rainfall readings — retained indefinitely. They are the audit trail behind every alert, and deleting them would undermine records that depend on them.
  • Server logs — 90 days.
  • Account data — deleted within 30 days of a deletion request, except where we must keep it for a legal or tax obligation.

6. Your rights

You can ask us to access, correct, export or delete your data, and you can object to processing. Email [email protected]; we respond within 30 days.

You do not need to ask us for an export in the ordinary case: inspections download as PDF from the app, and API keys give scripted access to your sites, readings and records.

If you are in a jurisdiction with specific statutory rights — the CCPA/CPRA in California, the GDPR in the EEA or UK — those rights apply and the address above is the way to exercise them. We do not sell or share personal information as those terms are defined under the CCPA.

7. Security

  • Passwords hashed with argon2id.
  • Short-lived access tokens with single-use rotating refresh tokens. Reusing a rotated token revokes the entire token family, which is how theft of a long-lived credential surfaces at all.
  • Every customer-facing request is scoped to one organisation at a single point in the code, so data cannot leak between organisations by a route we forgot to check.
  • Uploaded evidence is verified by decoding it, not by trusting its file extension.

No system is perfectly secure. If you believe you have found a vulnerability, email [email protected] — we will not pursue good-faith researchers who report responsibly.

8. Children

This is a workplace product. It is not directed at anyone under 16 and we do not knowingly collect their data.

9. Changes

If we change this policy materially we will email account holders before it takes effect, rather than silently updating the date at the top.

10. Contact

[email protected] for anything in this policy. [email protected] for everything else.

Before you deploy this. This policy describes how the product is built, but it is a template, not legal advice. Have a lawyer review it against your actual entity, hosting region and processors before you publish it or take payment.

SWRainAlert

Rainfall monitoring and stormwater inspection alerting for construction sites across the continental United States.

Product

  • How it works
  • Features
  • Pricing
  • Sandbox
  • API & webhooks
  • FAQ

Learn

  • Blog
  • States & thresholds
  • Georgia
  • South Carolina
  • Texas

Legal

  • Privacy policy
  • Terms of service
  • [email protected]
© 2026 SWRainAlert. Data courtesy of NOAA/NWS. A monitoring and recordkeeping aid — not a compliance guarantee.