Skip to content

Privacy

Privacy policy

What we collect, why, and how long we keep it. The free screening collects nothing, and the rest of this page describes what happens once you have an account.

Last updated 2026-07-19

The short version

The free screening collects nothing. It runs in your browser and makes no request, so there is no data for us to receive, log or retain.

If you create an account we store what the product needs to work: your email, the sites you save, the determinations and documents attached to them, the inspection records you write, and a log of API requests made with your keys. We do not sell any of it and we do not use it to train anything.

Information you give us

An email address when you create an account, and the site information you choose to save.

  • Account: email address, and a hashed password or an authentication token, handled by our authentication provider.
  • Sites: the state, acreage, dates and site facts you enter and save, plus the determination produced from them.
  • Records: inspection and corrective action entries you write, and the plan documents generated from your sites.
  • Payment: a customer identifier and subscription status from Stripe. Card details never reach our servers.

Information we collect automatically

For requests to our API we record the endpoint, the timestamp, the response status and the key used, which is what makes the request log in your account useful and what enforces your quota.

We use privacy respecting product analytics on the marketing pages to count page views and referrers in aggregate. We do not run advertising trackers and we do not build profiles of visitors.

How we use it

Only to run the product you are paying for or trialling.

  • To show you your saved sites, records and documents.
  • To enforce plan quotas and rate limits.
  • To take payment and manage your subscription.
  • To answer you when you contact support.
  • To fix faults, using error reports that do not carry your site data.

Who we share it with

Only the providers that run the service: Supabase for the database and authentication, Vercel for hosting, and Stripe for payments. Each receives only what its function requires.

We do not sell personal information, we do not share it with data brokers, and we do not pass it to advertisers.

We will disclose information if we are legally compelled to. If that happens and we are permitted to tell you, we will.

How long we keep it

Account data for as long as your account exists. API request logs are retained for a rolling window sufficient to support billing questions and abuse investigation, then deleted.

One deliberate exception is worth understanding: permit coverage obliges you to retain inspection and corrective action records for three years after coverage ends, and the paid product exists partly to hold them. If you delete your account, that record goes with it. Export it first.

Your choices

You can do all of the following from your account, or by asking us.

  • Export your records as CSV and your plan documents for print.
  • Delete a saved site, which deletes its determination and its records.
  • Close your account, which deletes the data associated with it.
  • Ask what we hold about you, or ask us to correct it, at support@basinwise.com.

Children

This is a professional compliance tool and is not directed at anybody under 18.

Changes

If this policy changes in a way that affects how we handle information we already hold, we will say so on this page and change the date at the top. We will not quietly widen what we collect.

Contact

Privacy questions go to support@basinwise.com.