Start a club →

Privacy Policy

Plain English: what we collect, why, and what we don't do with it.

Last updated: May 9, 2026

Poolside is a software service for neighborhood pool clubs. This policy covers how we handle data that flows through the service — for both the board admins running a club, and the members applying to or belonging to one.

The short version

What we collect

From board admins

From members and applicants

How we use it

Who we share it with

We use a small set of vendors to make Poolside work. Each one is listed below with what they see and why.

VendorWhat they seeWhy
VercelWeb traffic, IP addressesHosts the Poolside web app + handles HTTPS
SupabaseAll stored data (database + uploaded files)Database, file storage, authentication. Encrypted at rest.
StripePayment data (card details, billing address)Processes member dues + Poolside subscription. Card numbers never touch Poolside servers.
ResendEmail recipient address + message bodySends transactional email (sign-in links, receipts, notifications)
TwilioPhone number + SMS message bodySends sign-in codes by text + renewal reminders
GoogleDrive folder + spreadsheet contents you create through Poolside (only if you connect Drive auto-archive); your name + email if you Sign in with GoogleAuto-archives applications to your club's own Drive; OAuth-based sign-in

Data from Google APIs (required disclosure)

Some clubs choose to connect their own Google account so Poolside can auto-archive applications to their Drive and append rows to a roster spreadsheet. When you connect Google Drive:

Limited Use disclosure: Poolside's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

SMS / text messaging (required disclosure)

Some flows on Poolside use SMS — notably one-time sign-in codes (OTP), dues reminders for unpaid renewals, and account-status notifications such as application approvals.

How long we keep it

Your rights

Security

Children's data

Pool clubs naturally handle data about minors (kids who swim there). We collect that data only on behalf of the club, at the direction of the parent/guardian who fills out the membership application. The club, not Poolside, is the controller of that data. Poolside processes it only to run the club's operations — we don't market to kids, profile them, or use their data outside what the club needs.

Cookies and tracking

We use only first-party cookies/localStorage strictly needed for the service: sign-in tokens, theme preferences, dismissed-banner flags. No third-party advertising or analytics trackers.

Changes to this policy

If we make material changes, we'll notify each tenant's primary admin by email with at least 30 days' notice. Smaller clarifications get noted with a date stamp on this page.

Contact

Questions, requests, security reports — email doug@poolsideapp.com. We reply within one business day.