Privacy Policy
Last updated: August 20, 2026
Contents
PoolCures ("we," "us," or "the Platform") is a business-to-business demand aggregation marketplace. This Privacy Policy explains how we collect, use, share, and protect information when you access or use our website and services. By using PoolCures, you agree to the practices described in this policy. If you do not agree, please do not use the Platform.
1. Information We Collect
1.1 Account Information
When you create an account, we collect your name, email address, business name, and any additional profile details you choose to provide. Sellers who connect via Stripe provide additional business verification information directly to Stripe.
1.2 Transaction Data
We record pool participation, demand signals, bid activity, committed quantities, order history, shipping addresses, and transaction amounts. Payment card details are collected and stored exclusively by Stripe—PoolCures never stores, processes, or has access to full card numbers.
1.3 Usage Data
We automatically collect information about how you interact with the Platform, including pages viewed, features used, search queries, referral sources, session duration, and clickstream data.
1.4 Device and Technical Data
We collect your IP address, browser type and version, operating system, device identifiers, screen resolution, and timezone. This data helps us maintain security and optimize the Platform for different devices.
1.5 Cookies and Similar Technologies
We use cookies and similar tracking technologies as described in Section 8 below.
2. How We Use Your Information
- Provide services — operate the marketplace, match demand, facilitate pools, process transactions, and coordinate fulfillment between buyers and sellers
- Process payments — authorize charges, calculate shipping, issue refunds, and collect platform fees via Stripe
- Communicate — send transactional notifications (pool updates, payment confirmations, shipping alerts), respond to inquiries, and deliver service announcements
- Improve the Platform — analyze aggregated and anonymized usage patterns to improve features, user experience, and performance
- Maintain security — detect fraud, prevent abuse, enforce our Terms of Service, and protect the rights and safety of our users
- Comply with law — fulfill legal obligations, respond to lawful requests from public authorities, and maintain records required by applicable regulations
3. Information Sharing
We never sell your personal data. We share information only in the following limited circumstances:
3.1 Service Providers
- Stripe — payment processing, PCI DSS compliance, seller payouts, and fraud prevention. Stripe's privacy policy: stripe.com/privacy
- Resend — transactional email delivery (pool notifications, receipts, account communications)
- Vercel — website hosting, edge network delivery, and serverless function execution
- Analytics providers — anonymized usage data for Platform improvement
3.2 Buyers and Sellers
Sellers see aggregated pool demand (total quantity, tier progress) but never see individual buyer identities before payment. After a pool is funded and payment is captured, your shipping address is shared with the seller exclusively for fulfillment purposes.
3.3 Legal Requirements
We may disclose information if required by law, subpoena, court order, or governmental regulation, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4. Your California Privacy Rights (CCPA/CPRA)
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (Cal. Civ. Code §§ 1798.100–1798.199.100), grants California residents specific rights regarding their personal information. The B2B exemption expired on January 1, 2023, meaning these rights now apply to business contacts and representatives.
As a California resident, you have the right to:
- Know — request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purpose for collecting it, and the categories of third parties with whom we share it
- Delete — request deletion of personal information we have collected, subject to certain legal exceptions (e.g., tax record retention)
- Correct — request correction of inaccurate personal information
- Opt-out — opt out of the sale or sharing of personal information
- Non-discrimination — exercise these rights without receiving discriminatory treatment
Do Not Sell or Share My Personal Information
PoolCures does not sell personal information as defined by the CCPA/CPRA. We do not share personal information for cross-context behavioral advertising. If this practice changes in the future, we will provide a conspicuous opt-out link and update this policy accordingly.
To exercise any of these rights, contact us at support@poolcures.com with the subject line "CCPA Request." We will verify your identity and respond within 45 days.
5. Rights for Users in the European Economic Area (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and applicable local laws provide you with additional rights.
5.1 Lawful Basis for Processing
- Performance of a contract (Art. 6(1)(b)) — processing necessary to provide the marketplace services you have requested (account management, pool participation, payment processing, fulfillment)
- Legitimate interests (Art. 6(1)(f)) — processing for fraud prevention, Platform security, analytics, and business-to-business marketing, where those interests are not overridden by your data protection rights
- Legal obligation (Art. 6(1)(c)) — processing required to comply with tax, accounting, or regulatory obligations
5.2 Your Rights
- Access — obtain confirmation of whether we process your data and request a copy
- Rectification — correct inaccurate or incomplete personal data
- Erasure ("Right to be Forgotten") — request deletion of your data, subject to legal retention requirements
- Restriction — request that we restrict processing in certain circumstances
- Data portability — receive your data in a structured, commonly used, machine-readable format
- Objection — object to processing based on legitimate interests, including profiling
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing
5.3 International Transfers
Your data is processed in the United States. For transfers from the EEA, UK, or Switzerland to the US, we rely on the EU-US Data Privacy Framework where applicable, and Standard Contractual Clauses (SCCs) adopted by the European Commission to ensure adequate data protection safeguards.
6. Data Retention
We retain your information only as long as necessary for the purposes described in this policy:
- Transaction records — 7 years from the date of the transaction, as required for tax, accounting, and legal compliance
- Account data — retained for the duration of your active account, plus 30 days following account deletion to allow for recovery and to process any outstanding obligations
- Usage and analytics data — 2 years, after which it is aggregated or deleted
- Communication records (support inquiries) — 3 years from the date of the last communication
7. Data Security
We implement commercially reasonable technical and organizational measures to protect your personal information:
- Encryption in transit — all data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security)
- Password security — passwords are hashed using bcrypt and are never stored in plaintext
- Payment data isolation — PoolCures never stores, processes, or transmits payment card data. All payment information is handled directly by Stripe, which is certified PCI DSS Level 1
- Access controls — access to personal data is restricted to authorized personnel on a need-to-know basis
No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
9. Children's Privacy
PoolCures is a business-to-business platform and is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have inadvertently collected information from a child under 18, we will take steps to delete it promptly. If you believe a child has provided us with personal information, please contact us at support@poolcures.com.
10. International Data Transfers
PoolCures is based in the United States. If you access the Platform from outside the US, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
For transfers from the European Economic Area, United Kingdom, or Switzerland, we implement appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission. Our service providers (Stripe, Vercel, Resend) each maintain their own data protection measures and transfer mechanisms.
When you purchase from an international seller, your shipping address is transferred to the seller for fulfillment purposes. This may involve transfer of personal data to countries with different privacy standards. By purchasing from international sellers, you acknowledge and consent to this transfer.
11. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' advance notice via email to the address associated with your account or through a prominent notice on the Platform before the changes take effect. Non-material changes (e.g., formatting, clarifications) may be made without advance notice. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the Platform after any changes constitutes acceptance of the updated policy.
12. Contact
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or need to submit a data-related request, please contact us:
- Email: support@poolcures.com
- Subject line guidance: "CCPA Request," "GDPR Request," or "Privacy Inquiry"
- Response time: We aim to respond to all privacy-related requests within 30 days (45 days for CCPA requests, with one 45-day extension if reasonably necessary)