Privacy Policy
Last updated: 15 August 2026
This Privacy Policy explains how WellSenseOS (“WellSenseOS”, “we”, “us”, or “our”) collects, uses, stores, and shares information when you visit www.wellsenseos.com, use the customer portal at portal.wellsenseos.com, or connect edge devices that send readings to our ingest API.
We do not sell personal data. By using the Service, you agree to this Policy. If you do not agree, please do not use the Service. See also our Terms of Service and Refund Policy.
1. Who we are
WellSenseOS provides cloud software for monitoring wells and water tanks, together with a software agent that customers run on their own Raspberry Pi (or similar) hardware. Hardware is purchased and maintained by you; we provide the cloud platform and agent software.
Privacy contact: [email protected]
General contact: [email protected]
2. Scope
This Policy covers:
- The public marketing website
- The authenticated portal (dashboard, wells, devices, analytics, alerts, settings)
- The device ingest API and data sent by the WellSense edge agent
- Related support and sales communications
It does not cover third-party websites or hardware vendors you buy sensors or Raspberry Pis from.
3. Information we collect
3.1 Account and organization data
When you register or administer an organization, we may collect:
- Name, email address, and password (stored hashed)
- Organization / tenant name
- Optional profile or contact details you provide
- Authentication and security events (e.g. login, password reset, token rotation)
3.2 Well, device, and operational data
To operate the Service we process:
- Well metadata (name, geometry, units, location if you enter it, catchment notes)
- Device identifiers, names, agent version, update channel, and configuration (e.g. reading interval)
- Sensor readings (distance/level-related measurements, timestamps, idempotency keys)
- Derived metrics we compute (volume, percent full, consumption, projections, scores)
- Device diagnostics you choose to send (e.g. CPU temperature, memory, signal strength)
- Alert rules, notification provider settings, and event history
- Water provider / pricing data you configure for cost comparisons
- Exports you generate (e.g. CSV usage reports)
3.3 Marketing site and technical logs
- Standard server and CDN logs (IP address, user agent, referring URL, timestamps)
- Google Analytics 4 on the marketing site (page views, approximate location, device/browser information) to understand traffic and improve the site
We do not use third-party advertising trackers on the marketing site for selling ads. Analytics is processed by Google under their terms; see Google’s Privacy Policy.
3.4 Support and sales
If you email us or request Enterprise sales contact, we process the content of that correspondence and your contact details to respond.
3.5 Payment data
Paid subscriptions are processed by our payment partner (currently Paddle). Card and wallet details are handled by that provider under their terms; we typically receive limited billing metadata (plan, status, invoices), not full card numbers. See also our Refund Policy.
4. How we use information
We use information to:
- Provide, maintain, and improve the Service (ingest, storage, dashboards, analytics, alerts, OTA/config features)
- Authenticate users and protect accounts and device tokens
- Enforce plan limits and administer trials or subscriptions when enabled
- Communicate about the Service (security notices, product updates, support)
- Respond to sales and support requests
- Monitor reliability, prevent abuse, and comply with law
We do not use your well readings to train public AI models or sell datasets to third parties.
5. Legal bases (EEA/UK users)
Where GDPR (or UK GDPR) applies, we rely on:
- Contract — to provide the Service you request
- Legitimate interests — security, product improvement, and basic site operations, balanced against your rights
- Consent — where we ask for it (e.g. optional marketing email)
- Legal obligation — when we must retain or disclose information by law
6. Sharing
We may share information with:
- Infrastructure providers that host the Service (e.g. cloud hosting, databases, CDN, email delivery), under contracts that require appropriate protection
- Organization members you invite — users in your tenant can see operational data for that organization according to product permissions
- Professional advisers or authorities when required by law or to protect rights and safety
- Successors in a merger, acquisition, or asset transfer (you will be notified where required)
We do not sell personal information.
7. International transfers
Our hosting and subprocessors may process data in the EU, UK, United States, or other countries. Where required, we use appropriate safeguards (such as standard contractual clauses) for transfers of personal data from the EEA/UK.
8. Retention
We retain account and organization data for as long as your account is active and as needed to provide the Service. Reading history retention may vary by plan (for example shorter retention on Free than Home). We may retain backups, security logs, and billing records for a limited period after deletion for integrity, dispute resolution, and legal compliance, then delete or anonymize them when no longer needed.
9. Security
We use industry-standard measures appropriate to a multi-tenant SaaS product, including encrypted transport (HTTPS), hashed passwords, device bearer tokens, and access controls. No method of transmission or storage is 100% secure. You are responsible for keeping portal credentials and device tokens confidential and for securing your own Raspberry Pi and local network.
10. Your rights
Depending on your location, you may have rights to:
- Access, correct, or delete personal data
- Export or receive a copy of data you provided (portability)
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
To exercise these rights, email [email protected]. We may need to verify your identity. Organization owners can also manage much of their operational data directly in the portal (wells, devices, exports).
11. Children
The Service is directed at businesses and adults. We do not knowingly collect personal data from children under 16. If you believe we have, contact us and we will delete it.
12. Cookies
The portal uses cookies or similar technologies necessary for authentication and session security. The marketing site may use cookies or similar technologies set by Google Analytics to measure visits and usage. We do not run third-party ad networks on the marketing site.
13. Changes
We may update this Policy from time to time. The “Last updated” date will change, and material updates may be notified via the portal or email where appropriate. Continued use after the effective date constitutes acceptance of the updated Policy.
14. Contact
Privacy questions: [email protected]