Privacy Policy

Last updated: January 11, 2026

1. Introduction

How's Your River ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our water monitoring service.

By using our Service, you consent to the data practices described in this policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Password (encrypted)
  • Display name (optional)
  • Phone number (if you opt into SMS alerts)

2.2 Location Data

We may collect location information when:

  • You pin water body locations for alerts
  • You use the "near me" features
  • You submit content with geographic information

We do not continuously track your location. Location data is only collected when you actively use location-based features.

2.3 Usage Data

We automatically collect:

  • IP address
  • Browser type and version
  • Pages visited and time spent
  • Device information
  • Referring website

2.4 User-Submitted Content

When you submit content, we collect:

  • Photos and images
  • Comments and reviews
  • Hazard reports
  • Any other content you choose to share

3. How We Use Your Information

We use collected information to:

  • Provide the Service: Deliver water level alerts, display conditions, and operate features
  • Send Notifications: Email and SMS alerts you've configured
  • Improve the Service: Analyze usage patterns to enhance features
  • Process Payments: Manage subscriptions through Stripe
  • Communicate: Send service updates, respond to inquiries
  • Ensure Security: Detect and prevent fraudulent activity
  • Legal Compliance: Fulfill legal obligations

4. Email & SMS Communications

4.1 Transactional Communications

We will send you essential service communications including:

  • Account verification and password reset emails
  • Water level alerts you've configured
  • Subscription and payment confirmations
  • Important service announcements

4.2 Marketing Communications

We may send occasional promotional emails about new features. You can opt out at any time by:

  • Clicking "Unsubscribe" in any marketing email
  • Updating preferences in your account settings
  • Contacting us directly

4.3 SMS Alerts

SMS alerts are opt-in only. By providing your phone number and enabling SMS alerts, you consent to receive text messages. Standard message rates may apply. You can disable SMS alerts at any time in your account settings.

5. How We Share Your Information

5.1 Third-Party Service Providers

We share data with trusted partners who help operate our Service:

Provider Purpose Data Shared
Stripe Payment processing Email, payment info
Supabase Database hosting Account data
AWS Cloud hosting, image storage User content
Twilio SMS messaging Phone number, message content
Resend Email delivery Email address, message content
Mapbox Map display Location coordinates viewed

5.2 We Do NOT Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

5.3 Legal Requirements

We may disclose information when required by law, court order, or to protect our rights and the safety of others.

6. Data Retention

We retain your data as follows:

  • Account data: Until you delete your account, plus 30 days for backup recovery
  • Alert history: 1 year for your reference
  • Payment records: 7 years for tax/legal compliance
  • User content: Until you or we remove it
  • Server logs: 90 days

You may request deletion of your data by contacting us (see Section 10).

7. Cookies and Tracking

7.1 Essential Cookies

We use essential cookies to:

  • Keep you logged in
  • Remember your preferences
  • Prevent CSRF attacks

7.2 Analytics

We may use analytics tools to understand how visitors use our Service. This data is aggregated and does not personally identify you.

7.3 Managing Cookies

You can disable cookies in your browser settings, but some features may not work properly.

8. Data Security

We implement security measures including:

  • SSL/TLS encryption for all data transmission
  • Encrypted password storage (bcrypt)
  • Secure database connections
  • Rate limiting on authentication endpoints
  • Regular security audits

While we take reasonable precautions, no internet transmission is 100% secure. You provide information at your own risk.

9. Children's Privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

10. Your Rights

Depending on your location, you may have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate information
  • Deletion: Request deletion of your data
  • Portability: Receive your data in a portable format
  • Opt-out: Unsubscribe from marketing communications

To exercise these rights, email us at: privacy@howsyourriver.com

11. California Privacy Rights (CCPA)

California residents have additional rights under the California Consumer Privacy Act:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt-out of the sale of personal information (we do not sell data)
  • Right to non-discrimination for exercising CCPA rights

12. International Users

Our servers are located in the United States. By using our Service from outside the US, you consent to the transfer of your information to the US, where privacy laws may differ from your country.

13. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes by:

  • Posting the new policy on this page
  • Updating the "Last updated" date
  • Sending an email notification for major changes

14. Contact Us

For questions about this Privacy Policy or to exercise your data rights:

Email: privacy@howsyourriver.com
Website: www.howsyourriver.com