Legal
WaterMark™ Data Processing Addendum
Last updated: July 17, 2026 · Forms part of the Terms of Service
This Addendum describes how WaterMark™, operated by Watermark App LLC (a New Jersey limited liability company; "we", the processor), handles the personal data of your customers (homeowners) on behalf of your company (the controller) when you use the service.
Roles
Your company decides what customer data to collect and why: you are the controller. WaterMark only processes that data to provide the service under your instructions, as set out in the Terms and Privacy Policy.
What we process
On your behalf we process your customers' contact details (name, address, phone, email), their pool/service records, photos and videos (including microphone audio recorded with a video), water-chemistry readings, invoices and payment status, and messages you send them. We process it only to operate the features you use.
Sub-processors
We use vetted providers to deliver the service. Each processes data only as needed for its function. The current list of sub-processors includes, but is not limited to, the following:
| Provider | Purpose | Data category |
|---|---|---|
| Stripe | Payment processing, subscription billing + payouts (PCI-compliant) | Payer name and email, invoice amounts, card data (sent directly to Stripe) |
| Twilio | SMS you choose to send, and optional AI-receptionist phone calls, when enabled | Customer phone numbers and message or call content |
| Resend / SendGrid | Transactional email delivery, depending on configuration | Recipient email addresses and message content |
| Cloudinary | Durable photo and video storage and delivery | Job and pool photos and videos (including their audio) |
| Render | Application hosting + database | All service data, at rest and in transit |
| Backblaze | Encrypted off-site backups of the service database | All service data, as backup snapshots |
| Anthropic | Optional AI features (photo analysis, recommendations, translations), when enabled; not used to train models | The photos, readings and text submitted to the feature |
| Apple | Geocoding service addresses to map coordinates (tried first), and drawing the map in the iPhone and iPad app | Service addresses and coordinates |
| Drawing the map in the Android app; optional Google Business Profile connection when you link it | Service coordinates; for Business Profile, the review and listing data you authorize | |
| US Census Bureau (Geocoder) | Geocoding service addresses to map coordinates, as part of the fallback chain behind Apple | Service addresses and coordinates |
| OpenStreetMap services (Nominatim / OSRM) | Geocoding service addresses to map coordinates and computing road routes | Service addresses and stop coordinates |
| Mapbox | Computing and drawing road routes when our own routing server is unavailable | The coordinates of the stops on a route |
| Expo | Delivering push notifications to technicians' devices | Device push tokens, notification title and body |
| Sentry | Application error monitoring | Error reports tagged with a company id and request id; no customer records |
| PostHog | Product analytics processor: counts setup milestones, used to find where the product stalls | Limited to a WaterMark-generated company identifier, a fixed list of milestone events, and coarse product state such as plan and surface; no names, email addresses, phone numbers, street addresses, notes, or customer records. No IP-based location will be sent. |
| Intuit QuickBooks | Optional accounting sync, when you connect it | Customer names, invoices and payments |
| Xero | Optional accounting sync, when you connect it | Customer names, invoices and payments |
We will give notice of material changes to this list, including before engaging a new sub-processor that processes personal data.
Security
Each company's data is logically isolated so one company can never see another's. Access is authenticated; payment card data is handled by Stripe, not stored by us; data in transit is encrypted. We restrict internal access to what is needed to operate and support the service.
Your customers' rights
You can export or delete a customer's data at any time from the app, which also revokes their public links. If a customer contacts us directly, we will refer them to your company as the controller.
Text-message consent
You are responsible for obtaining consent before texting your customers. WaterMark honors opt-outs automatically: a customer who replies STOP is added to a do-not-text list and will not receive further messages until they reply START.
Data retention & deletion
We retain data for as long as your account is active. On account closure, or on your request, we delete or return your data within 30 days, except where retention is required by law (e.g. financial records) and for residual copies held in encrypted off-site backup snapshots, which are purged on a rolling 30-day cycle and are never used to reconstitute deleted data.
Breach notification
If we become aware of a personal-data breach affecting your data, we will notify you without undue delay and share what we know to help you meet your obligations.
Contact
Watermark App LLC · 151 Ledgewood Ave., Netcong, NJ 07857 · support@watermarkapp.online