Privacy Policy
Written from the database rather than from a template — what we actually hold, column by column, and what we do not.
In effect since August 28, 2026
We do not track you, and there is nothing to opt out of. LakeOps runs no analytics, no advertising pixels, no session recording and no third-party tracking scripts of any kind. There is no cookie banner because there are no cookies that would need one. We do not sell data, we do not share it for advertising, and we do not train anything on it.
Two different relationships
This matters more here than on most policies, because LakeOps holds two kinds of information about two kinds of people.
Your business's own information — your company, the people who sign in, what you pay us — is ours to answer for. We decide what to collect and why, and this policy is that answer.
Your customers' information — the lake owners you service — belongs to you. You decide what to record about them; we hold it on your behalf and act on your instructions. If one of your customers asks what you hold about them, the answer is yours to give, and every screen and export you need to give it is in the app. We will help if the export you need is not one of the buttons.
What we actually hold
Written from the database rather than from a template. In full:
The people who sign in. Name, email address, phone number and time zone, plus when they last signed in. Email is how you sign in, so there is no password anywhere in LakeOps to be stolen.
Sign-in security. Each session records the IP address it started from, the IP it was last seen from, and the browser's user-agent string — so an account owner can look at the list of live sessions and recognise their own. Sessions last 90 days and refresh on use. A one-time sign-in code records the address it was sent to and the IP that asked for it, and expires after ten minutes.
Your customers and their properties. Names, company names, email addresses, phone numbers, postal addresses, and the map coordinates of the property and of each item on it. Notes your office writes. Whatever your own business needs to service a shoreline.
Photographs. Reference photographs of equipment on a property, and photographs a crew takes as proof of completed work. Taken by your people, on your instruction, of your customers' property.
Where your crews were, and when. This is the most sensitive thing LakeOps records and it is described here in full rather than buried. When a crew member starts or stops a job timer, the app records the coordinates at that moment along with who they are — so the office can see that somebody was at the property and for how long. That is two points per job, at the start and at the end.
Continuous location is never sent to us. The field app watches the device's position while it is open, to draw the boat on the chart and to rank which stop is nearest — and that stays on the device. It is not transmitted, not stored, and not available to the office or to us. If you are an employer using this: the record you have is arrival and departure at a job, not a movement history.
Money. What you charged, what was paid, by what method, and the tax breakdown on each. Card numbers never reach us — payments run through Stripe and we hold only the last four digits and the card brand, which is what a receipt needs.
An audit trail. Who did what, and when, inside your account. It is the thing that answers "who changed this price" and "who marked that done", and it is deliberately append-only.
Whether a bill was opened. A pay link records how many times it was viewed and when it was first and last opened — so you can tell "they never got it" from "they got it and have not paid". It does not record where it was opened from: no IP, no device, no location.
Mail that failed. When a customer's address bounces or complains, we record that it did, so LakeOps stops mailing it. One shop's bad address list can get sending suspended for every shop on the platform, which is why this is not optional.
What we do not hold. No passwords. No card numbers or bank details. No analytics or behavioural profile. No device identifiers or advertising IDs. No continuous location. Nothing about anybody who is not one of your people or one of your customers.
What stays on your device
The crew app is built to work with no signal, which means some things are held on the phone or tablet rather than sent to us: the day's work, photographs taken out of range and waiting to send, and a queue of changes to sync when the signal returns. All of it lives in the browser's own storage, on that device, and it is cleared as it syncs. Signing out clears it.
Cookies
Three, and none of them track you. A signed session cookie is how the app knows you are signed in. A theme cookie remembers whether you chose light or dark. A returning-visitor flag — a single character, on our own domain, that says nothing except that this browser has signed in before — lets the marketing site show a sign-in link instead of a sign-up one. There is no advertising or analytics cookie, from us or from anybody else.
Who else touches it
Every third party involved, why, and what reaches them:
- Stripe — payments. Card details go directly to Stripe and never through us. Your customers' names, email addresses and the amounts they paid reach Stripe because that is what a payment is.
- Amazon Web Services — where the photographs are stored, and where our email is sent from. Photographs sit in a private bucket in the United States; delivery reports (bounces, complaints) come back to us so we can stop mailing a dead address.
- Honeybadger — error monitoring. When something breaks, it receives the error and enough context to find it: the account, the screen, the request. Not your customer list.
- Map providers — Esri, OpenStreetMap and Protomaps serve the chart's imagery and outlines. Your browser fetches map tiles from them, which means they see the area of a lake being looked at. They are not told whose property it is; we send them no customer data.
- Google — address autocomplete only, and only while somebody is typing an address into the property form. What is typed reaches Google to be completed. Google's map tiles are not used; the chart is not Google's.
That is the whole list. If it changes in a way that matters, the date at the top of this page changes with it and we tell you by email.
How long we keep it
Your records stay while your account does. Seasonal work is only legible across years — last spring's install is what tells a crew where this dock goes — so nothing ages out on its own except one thing.
Completion photographs age out. Once two later seasons have superseded a visit and its photographs are at least 18 months old, they are deleted. Reference photographs of the equipment itself are kept, because they are what a hand who has never seen that shoreline works from.
Sessions expire after 90 days. Sign-in codes expire after ten minutes.
Deleting everything
You can close your account and have your data destroyed, from inside the app, without asking us. Settings → Your LakeOps plan → close the account. You type your shop's name to confirm, and the screen tells you exactly what goes before anything happens.
Thirty days, then it is gone. Nothing is destroyed on the day you ask. Your account closes immediately and the data is deleted thirty days later — and for the whole of that window you can call it off yourself from the same screen. After it, nobody can: there is no backup we can restore you from, which is what deleting your data means.
What is destroyed: every customer, property, item, job, timer, note, price, payment record and report, every photograph your crews ever took — removed from our storage, not merely unlinked — and everybody's sign-in to that account.
What survives, and why. Somebody who also works for another shop on LakeOps keeps that account; only their access to yours goes. Stripe keeps its own record of payments your customers made — you are the merchant on those, so they are Stripe's books under Stripe's retention rules, not ours. And we keep the fact that the account existed and was closed, together with our own billing history for it, because we are required to.
Cancelling your plan is not deletion and never has been. See our refund policy for what cancelling does; cancelling keeps every record readable, which is deliberate.
Seeing it, correcting it, taking it with you
Every report in LakeOps exports to CSV from the screen you read it on, and you do not need to ask us for any of it. You can correct anything about your own business from the settings screens. If you want something we have not built a button for — including a copy of everything at once — write and we will do it.
If you are a customer of a shop that uses LakeOps and you want to know what is held about you, ask the shop. They control it; we hold it for them and act on what they tell us. If you cannot reach them, write to us and we will pass it on.
When we look at your account
We access an account's records to support you, to investigate a fault, or where the law requires it. Every staff sign-in to an account is recorded on that account's own activity log, visible to you, and anything a member of our staff writes while doing it is recorded as theirs and not yours. There is no silent access.
Where it lives
In the United States. The application, the database and the photographs are all hosted there. If you are in a jurisdiction where that matters to you, it matters before you sign up rather than after, which is why it is stated plainly.
How to reach us
Email hello@lakeops.io. A real person answers, within one working day.