1. Scope and who we are
This Privacy Policy describes the privacy framework for Triton’s websites, pool service software, related mobile applications, communications, and support services (collectively, the Services). References to Triton, we, us, or our mean Splash App LLC DBA Triton, located at 4046 Ponderosa Way, Las Vegas, NV 89118. Contact us at hello@triton.co for privacy questions.
This policy applies to website visitors, prospective customers, business account administrators, authorized techs and other users, and individuals whose information is processed in connection with pool service operations. It does not govern independent websites, app stores, payment providers, or other services merely linked to or integrated with Triton; their own notices apply to their independent activities.
The website collection described below reflects the demo and analytics functions currently present. Provisions covering mobile permissions, payments, customer communications, and connected services apply only to features actually enabled. Before app distribution, Triton must verify these provisions against the released app, its software development kits, and its store disclosures.
2. Business customers and customer data
For our own website, sales inquiries, subscription administration, and business relationship records, Triton determines the purposes of processing. For records a pool service business uploads or creates about its customers and workforce, that business generally determines the purposes of processing, and Triton processes the records on its behalf to provide the Services, subject to applicable agreements and law.
A pool service business is responsible for providing its customers and personnel with appropriate privacy notices, establishing a lawful basis for processing, obtaining required consent, and responding to requests about its records. If your information was entered by such a business, contact that business first. Triton should assist the business as required by its processing agreement and applicable law; it should not independently disclose or delete another business’s records without appropriate authorization.
3. Information you provide
You may provide information when you request a demo, complete a questionnaire, book a call, communicate with us, create or manage an account, or use an enabled feature. Questionnaire answers and partial form information can be saved as you progress, even if you do not complete the final submission. Please do not provide sensitive information that is not necessary for the relevant activity.
- Identity and business information: name, business name, role, email address, telephone number, service area, and information about your pool service business.
- Demo and questionnaire responses: growth goals, current software, route size, answers about business needs and operations, form progress, submission status, and information used to arrange a demonstration.
- Booking information: selected appointment time, time zone, attendance status, and communications needed to manage a booked call.
- Account and support information, where applicable: account identifiers, authentication information handled by the authentication provider, preferences, support requests, and correspondence.
- Business records, where enabled: customer contact details, service addresses, body-of-water records, routes, assigned techs, quotes, jobs, billing records, service notes, photos, and communications.
- Subscription or transaction information, where enabled: plan details, billing contact, transaction status, and payment-provider identifiers. Any statement about payment-card handling must be verified against the payment integration before publication.
4. Website activity and automatically collected information
The website uses first-party identifiers stored in the browser to associate activity with a visitor and session. It records page views, interactions with links and buttons, browser user-agent information, screen width, time zone, and language. The demo form records progress and partial answers so we can understand how far visitors get and whether they submit or book a call. Returning visits may be associated with the same browser identifier; this identifier is not a guarantee that a visitor is a unique person.
Traffic attribution can include the referring website, landing page, UTM campaign parameters, and advertising click identifiers such as gclid or fbclid when present in a link. These records help us understand which sources bring visitors and leads to the Services. Source information may be associated with a submitted lead and sent to an enabled customer relationship management integration.
Hosting and service providers may process technical request information, such as IP addresses, browser and device characteristics, request times, and error details, to deliver and protect the Services. The exact technical fields, providers, and retention periods must be confirmed in the production configuration. We do not intentionally ask you to put passwords, financial details, or sensitive personal information into page URLs or campaign tags.
5. Mobile applications and device permissions
A mobile application may request device access only when needed for an enabled feature. The application must provide permission prompts and, where required, a clear disclosure before collection begins. This policy alone does not authorize access to a device permission or replace a just-in-time disclosure. The final list of permissions and app data collection must match the released application.
You can generally change permissions in device settings. Declining an optional permission should not prevent unrelated functions from working, but the feature that needs the permission may be unavailable. Revoking access stops future collection through that permission; it does not automatically remove information already saved. Uninstalling the application does not cancel a subscription or delete a business account.
- Location: if route, attendance, or real-time GPS features use location, disclose whether access is approximate or precise, foreground or background, who can view it, and when tracking starts and stops. Background tracking requires a separate prominent explanation and appropriate permission before it begins; it must not be represented as active unless implemented.
- Camera and photos: where service-photo uploads are enabled, access should be limited to taking a photo or selecting the specific photos you choose. Uploaded photos can reveal people, addresses, timestamps, and embedded location metadata.
- Notifications: where push notifications are enabled, a device token and notification preferences may be used for service alerts and messages. Notification permissions can be disabled in device settings.
- Microphone, contacts, and files: these must not be collected merely because the device supports them. If an enabled calling, contact-selection, or upload feature needs them, explain the purpose and obtain the necessary access first.
- Diagnostics: disclose any mobile crash-reporting, analytics, advertising, or other third-party SDK collection in this policy and in the store’s privacy disclosures before release.
6. How information is used
Information is used for specific purposes connected with the Services, rather than merely because it is available. Where a new purpose is materially incompatible with the original purpose, appropriate notice and any required consent should be obtained before the new processing begins.
- Deliver requested pages and features, maintain accounts, and provide authorized access to business records.
- Respond to demo inquiries, manage appointments, answer support requests, and communicate about a requested service.
- Operate enabled scheduling, routes, quotes, billing, messaging, reviews, and reporting features on a business customer’s instructions.
- Understand website traffic, campaign sources, form completion, and booked calls; diagnose errors and improve usability.
- Maintain security, investigate misuse, prevent fraud, enforce agreements, and respond to lawful requests.
- Send marketing communications only where permitted and honor applicable unsubscribe and consent requirements.
- Keep records needed for accounting, compliance, disputes, and the protection of legal rights.
7. Legal bases where required
Where data-protection law requires a legal basis, processing must be supported by an applicable basis. Depending on the relationship and activity, this may include performing a contract or taking requested steps before a contract, complying with legal obligations, pursuing legitimate interests that do not override individual rights, or obtaining consent.
Legitimate interests can include securing the Services, responding to business inquiries, preventing misuse, and improving functionality, subject to the required balancing assessment. Consent must be freely given, specific, informed, and unambiguous when that standard applies. You may withdraw consent for future consent-based processing without affecting processing lawfully carried out before withdrawal. For customer data processed on behalf of a business, that business is responsible for establishing the appropriate basis.
9. Sale, targeted advertising, and tracking
Recording a campaign tag or advertising click identifier is not, by itself, a complete description of advertising data practices. Whether information is sold, shared for cross-context behavioral advertising, or used for targeted advertising depends on the actual recipients, integrations, contractual terms, and applicable legal definitions.
No verified statement that Triton never sells or shares personal information is made in this draft. Before finalization, the operator must audit advertising tools and data flows, state its actual practices, and provide any required opt-out mechanism. Where legally required, recognized opt-out preference signals such as Global Privacy Control must be honored. A policy statement without an implemented opt-out does not satisfy this obligation.
10. Cookies, browser storage, and choices
The current website uses browser storage for visitor and session identifiers and traffic attribution. Service providers may use other cookies or similar technologies depending on the production configuration. Necessary technologies support basic operation and security; analytics and marketing technologies must be classified according to their actual purpose rather than automatically treated as necessary.
You can clear or restrict cookies and browser storage through your browser settings, although this may reset preferences, interrupt sessions, or affect functions. Clearing an identifier does not erase records already held by Triton. Where local law requires consent before non-essential storage or tracking, an appropriate consent mechanism must be implemented before those technologies run. This draft does not represent that a cookie-consent manager or universal opt-out control is already available.
11. Email, texts, calls, and customer consent
Providing contact details for a demo enables us to respond to the inquiry; it must not be treated as blanket consent to unrelated automated marketing texts or calls. Marketing permission, where required, should be collected separately through a clear affirmative choice that identifies the sender, purpose, communication channel, and any use of automation. Consent to marketing must not be a condition of purchase where prohibited by law.
For enabled SMS programs, the enrollment disclosure should identify the program, explain message frequency or that frequency varies, state that message and data rates may apply, provide access to these legal documents, and include STOP and HELP instructions. Consent records should preserve the disclosure shown, affirmative action, timestamp, and relevant source. Marketing consent must not be transferred to independent third parties for their own marketing without a valid legal basis and any required consent.
Use an email’s unsubscribe option to opt out of promotional emails. For a text program that supports these commands, reply STOP to opt out and HELP for assistance. Requests must be honored within applicable legal deadlines. Opting out of marketing does not necessarily stop strictly necessary account or transaction notices delivered by permitted channels. No call should be recorded without the disclosure and consent required in the relevant jurisdiction.
Business customers using Triton to message their own customers are responsible for lawful enrollment, suppression lists, accurate sender identity, permitted sending hours, and honoring revocation. These policy provisions do not create or implement an SMS program, consent checkbox, or automated opt-out workflow.
12. Retention and deletion
Information should be retained only for as long as reasonably necessary for the stated purpose, the business customer’s valid instructions, contractual obligations, legal recordkeeping, security, or the establishment or defense of claims. Different categories may require different periods. The operator must document actual retention periods for website events, incomplete forms, leads, account data, messages, location records, and backups before finalization; this draft does not claim a particular number of days.
When information is no longer required, it should be deleted or appropriately de-identified under the applicable retention process. Deleted records may remain temporarily in restricted backups until those backups expire, and narrowly scoped records may be retained where law or legitimate legal needs require it. Such exceptions should not permit indefinite retention of all account information.
13. Account deletion and app-store requirements
Where the mobile app allows account creation, the released experience must provide the account-deletion mechanisms required by the applicable store. Apple generally requires an in-app way to initiate account deletion; Google Play generally requires an in-app path and an accessible web resource for requesting deletion. Deactivation, signing out, uninstalling the app, or canceling a subscription is not the same as requesting deletion.
This draft does not represent that an in-app deletion control or a public deletion-request workflow has been implemented. Those mechanisms, identity verification, deletion scope, processing time, and legally justified retention exceptions must be established before submission. A Privacy Policy URL alone does not fulfill the account-deletion requirements.
An individual tech’s account and the pool service business’s customer records may be subject to different controls. The operator must explain what is removed, what remains under the business’s lawful control, and why. A deletion request must not require disclosure of a password or complete payment-card information.
14. Information security
Appropriate administrative, technical, and organizational safeguards should be maintained in proportion to the information processed and the risks involved. These include access controls, protection of credentials, restricted administrative access, and secure service configuration. Specific claims about encryption, audits, certifications, or compliance standards must be supported by evidence and are not asserted in this draft.
No network, device, or system is entirely risk-free. Protect your credentials, use available security features, limit access to authorized personnel, and notify support promptly if you suspect misuse. Triton must assess incidents and provide legally required notices to affected businesses, individuals, or authorities as applicable.
15. International processing
Information may be processed in countries where Triton and its enabled providers operate, which may have different privacy laws from your country. The operator must verify and disclose relevant processing locations before finalization.
Where required for a restricted international transfer, appropriate safeguards must be established, such as a valid adequacy decision, applicable standard contractual clauses, or another lawful mechanism, together with any required assessment and supplementary protections. This draft does not claim that a specific transfer mechanism or certification is already in place.
16. Access, correction, and other privacy rights
Depending on your location and applicable law, you may have rights to access information, correct inaccurate information, request deletion, obtain a portable copy, restrict processing, object to certain processing, withdraw consent, or opt out of particular disclosures or uses. These rights are subject to lawful limitations and may differ for employment records, business-contact information, or data processed on a customer’s behalf.
Send privacy requests to hello@triton.co or the mailing address in the Privacy contact and operator details section. We may need proportionate information to verify identity and authority, and should not collect more than necessary for verification. An authorized agent may submit a request where permitted, subject to proof of authorization. Responses must be provided within applicable deadlines, with any lawful extension explained.
If your request relates to a pool service business’s records, contact that business; Triton should assist it where required. You may also have the right to complain to your local data-protection regulator. Exercising a privacy right must not result in unlawful discrimination.
17. United States state and regional disclosures
Where an applicable state privacy law covers Triton, the categories of information, sources, purposes, and recipient categories described above form part of the relevant notice. Rights may include access, correction, deletion, portability, and opt-out of sale, targeted advertising, or specified profiling. The final notice must accurately state whether such activities occur and provide any required request and appeal process.
California residents may have additional rights under applicable California law, including rights concerning sensitive personal information where applicable. Precise location, authentication information, and other categories may receive special treatment. No inference should be drawn from this draft that every state law applies to Triton or that an unimplemented privacy-rights workflow already exists.
If a request is denied and applicable law provides an appeal, the response should explain how to appeal and any subsequent regulator contact available. Finalization requires a verified contact channel, a jurisdiction-specific coverage assessment, and implementation of any required choice mechanisms.
18. Children and age limits
The Services are intended for business use by adults, not directed to children under 13, and are not designed for children to independently create accounts. Authorized users must satisfy the age and authority requirements in the Terms of Service and any applicable local law.
If you believe a child has provided information without appropriate authorization, notify the verified privacy contact so the matter can be investigated and information removed where required. If future functionality is directed to children, the operator must complete a separate assessment and implement all required notices, parental consent, and store disclosures before release.
19. Changes to this policy
The finalized policy may be updated as the Services, providers, or legal requirements change. The revision date should be updated and the current policy made available at this public URL and within any applicable mobile app. For material changes, additional notice and renewed consent must be provided when required by law.
A later policy cannot retroactively authorize an incompatible use of information that required consent or another legal basis. Changes to legal text must be accompanied by corresponding operational changes where needed.
20. Privacy contact and operator details
The Services are operated by Splash App LLC DBA Triton. Mailing address: 4046 Ponderosa Way, Las Vegas, NV 89118, United States. Email: hello@triton.co. Use this email for privacy questions, access or correction requests, deletion requests, and assistance with privacy choices.
For an account-deletion request, email hello@triton.co with the subject Account deletion request and identify the email associated with your account and, if relevant, your business. Do not send passwords, complete financial credentials, or unnecessary sensitive information. We may need to verify your identity and authority before processing a request. This contact method does not confirm that the separate in-app deletion controls required by an app store are implemented; the mobile workflow, deletion timing, and retention exceptions still require verification.
