Privacy Policy

Bluewater Residential Group LLC · Last updated September 6, 2026

1. What we collect

Account data (email, hashed password), billing data (handled by Stripe — we never see your card number), usage data (features used, searches run, usage counters for plan limits), technical data (IP address and a device cookie, used for security and to prevent repeat free trials), and any content you save in the app (deals, notes, connected email settings for outreach).

On public marketing pages and the signup page, we also measure page views, selected call-to-action clicks and whether someone makes a valid change in the free calculator. These first-party events include a random session identifier, the page path and limited source, medium and campaign labels. A referring page may be classified in memory as a recognized search or social provider, or a general external referral; its URL is not retained. We do not include calculator inputs, form contents, full URLs, full referrers, email addresses or IP addresses in these analytics records. Successful signup, trial starts and checkout attempts may be linked to the session and an internal account identifier; a checkout attempt is not a payment.

To exclude explicitly identified crawlers from marketing totals, we inspect a few crawler product tokens in the current User-Agent header in memory. A matching telemetry event retains only a fixed crawler category, its random event and session identifiers, and receipt time within the same 30-day event window. The crawler record contains no raw user-agent, IP address or account identifier. These self-declared tokens do not verify who sent a request or identify all automation.

For a newly created account, when measurement context is available and your browser does not communicate a privacy opt-out, we may save a one-time acquisition snapshot: a recorded time, entry page, limited registered source/campaign labels and whether the browser selected a URL tag, coarse referrer, older saved label or resource fallback. This account-linked snapshot has no analytics session identifier or full referrer. We use it to group later qualifying paid accounts; it does not prove a person, referring channel or that a source caused a purchase. We do not reconstruct this snapshot for older accounts or infer past privacy preferences.

A demo request includes the email and market you provide, your optional name and question, a random retry identifier, and the version of the contact-permission notice. Unless your browser communicates a privacy opt-out, it may also include limited source, medium, campaign and entry-page labels. We do not store an IP address or analytics session identifier with the request. These contact details are stored separately from aggregate analytics and are available only to administrators handling requests.

2. How we use it

To operate the Service, enforce plan limits and trial rules, process payments through Stripe, send account emails (verification, password reset) through our email provider, prevent abuse, and improve features. We do not sell your personal information.

We use demo-request details to review and respond to that request. Submitting the form does not subscribe you to a marketing list, create an account or paid plan, or book an appointment. Browser privacy signals can suppress source attribution without preventing you from explicitly requesting contact.

3. Cookies

We use essential cookies only: a session cookie (keeps you signed in) and a device cookie (security and one-trial-per-device enforcement). No third-party advertising trackers.

Browser session storage keeps the marketing session identifier and its source labels. It expires after 30 minutes without observed activity; browser storage can be cleared at any time. A separate local-storage source label supports signup attribution. We do not use fingerprinting for marketing analytics. Do Not Track and Global Privacy Control signals suppress the new marketing event collection when communicated by your browser.

4. Service providers

We share data only with the processors needed to run the Service: Stripe (payments), our hosting provider (Railway), our email delivery provider, and data APIs used to fulfil your requests. Each receives only what it needs.

5. Your outreach email

If you connect your own email account for outreach, the credentials you provide are stored to send on your behalf at your direction and are never used for anything else. You can disconnect at any time in Settings.

6. Retention and deletion

Account data is kept while the account is active. You can request deletion of your account and its data at any time; we will remove it within 30 days except where retention is legally required (e.g. billing records).

Marketing event reports cover at most the previous 30 days. Older event records are removed in bounded cleanup batches during subsequent analytics activity. The compact acquisition snapshot is retained with its account and removed when that account is deleted. It cannot recover session events after their 30-day retention window; existing backup rotation remains separate. New browser privacy signals suppress new measurement capture, rather than reconstructing or rewriting earlier observations. Access to the aggregate growth dashboard is restricted to administrators.

Demo requests have a 90-day review window. Expired requests are hidden from the private inbox immediately and deleted in bounded cleanup batches during subsequent demo-request or administrator activity. You can request deletion of a demo inquiry by contacting dan@bluewater-residential.com. This cleanup applies to the active database; existing backup rotation remains separate.

7. Security

Passwords are stored hashed (scrypt with per-user salt), sessions use httpOnly cookies, data is encrypted in transit, and nightly encrypted backups protect against data loss. No system is perfectly secure; report concerns through your account.

8. Changes

Material changes will be posted here with a new date.