Sunshine Apps LLC
Last updated: July 16, 2026
Floater is a field service management platform for pool service companies, operated by Sunshine Apps LLC ("we," "us," "our"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and what choices you have.
Two different relationships, two different roles. Please read this part carefully — it determines who is responsible for your information.
When you are our customer. If you are a pool service business, or someone working for one, that signs up for and uses Floater ("Operator"), we are the business (or controller) with respect to your account information, your billing information, and information about how you use the Service. This Policy describes what we do with it.
When your information is in an Operator's account. If you are a homeowner, property manager, or other customer of a pool service business that uses Floater ("Homeowner"), the Operator uploaded and controls your information. In that relationship, the Operator is the business/controller and we are the service provider/processor. We process that information only under the Operator's instructions and under our agreement with them. Our obligations for that data are set by that agreement, and if that agreement conflicts with this Policy, the agreement governs.
If you are a Homeowner with a privacy question or request, contact the pool service company you do business with. They control your information. See Section 12 below. We will assist them in responding to you as required by law.
This Policy does not cover third-party websites or services we don't control, or an Operator's own privacy practices.
Account information. Name, email address, phone number, company name, and billing address when you create an Operator account.
Payment information. Handled by Stripe, our payment processor. We do not collect or store full card numbers. We may receive limited details such as card brand, last four digits, and expiration date.
Operator Content. Data you enter to run your business, including your customers' names, addresses, email addresses, and phone numbers; service locations and access details; pool and equipment records; chemical readings; service records and notes; photos; routes and schedules; work orders; and invoices. This is the category that includes Homeowner information, and we process it as your service provider.
Usage data. How you interact with the Service — pages visited, features used, timestamps, referring URLs, and error logs — used to operate, secure, and improve the product.
Device and connection data. Browser type, operating system, device identifiers, and IP address, used for security, troubleshooting, and fraud prevention. We may infer general location (such as city or region) from an IP address.
Location data. Where you or your technicians enable it, we may collect device location to support mapping, geocoding, and routing features. You can disable location access in your device settings; some features may not work without it.
Communications with us. Records of your correspondence when you contact support.
Email delivery data. When the Service sends email on your behalf, we process delivery, open, bounce, and unsubscribe events. See Section 5.
We use information to:
We process Operator Content only to provide the Service to you and as otherwise permitted by our agreement with you.
We may use data in aggregated, anonymized, and de-identified form — meaning it can no longer reasonably be linked to you, your business, or any individual — for:
We will never sell individually identifiable customer or homeowner data.
Operator-identifiable business data — your company name, pool count, revenue, or similar — will not be shared with competing pool service operators or competing software platforms.
Once data is de-identified, we do not attempt to re-identify it, and we require recipients not to.
We do not market to your customers. We do not contact Homeowners for our own marketing purposes, and we do not sell, rent, or share Homeowner contact information with anyone for their marketing purposes.
You are the sender. Service reports, invoices, and other messages the Service sends to your customers are sent on your behalf and branded with your company identity. You are responsible for obtaining any consents required before contacting a recipient and for honoring opt-out requests, as set out in our Terms of Service.
Suppression and delivery records. Because we operate the sending infrastructure, we process and retain delivery, bounce, complaint, and unsubscribe records for messages sent through the Service. We maintain suppression records so that a recipient who unsubscribes or reports a message is not contacted again through our infrastructure. You remain responsible for honoring opt-outs you receive outside the Service and for maintaining your own consent records.
We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand how it's used. You can refuse or delete cookies in your browser settings, but parts of the Service may stop working.
We do not use advertising cookies, ad networks, or cross-context behavioral advertising, and we do not allow third parties to collect information about you across other websites through our Service.
Do Not Track and opt-out preference signals. Because we do not sell or share personal information and do not run targeted advertising, there is nothing for a Do Not Track or Global Privacy Control signal to opt you out of. If that ever changes, we will update this Policy and honor legally recognized browser opt-out signals.
We do not sell your personal information. We share it only as follows:
Service providers (subprocessors). Vendors that perform functions on our behalf, under contract, and only as needed to provide the Service. Our current subprocessors are listed at floater.tradestack.studio/privacy/subprocessors and currently include:
| Provider | Function |
|---|---|
| Supabase | Database hosting, authentication, file storage |
| Vercel | Application hosting |
| Stripe | Payment processing |
| Resend | Transactional email delivery |
| Google Maps Platform | Geocoding and mapping |
We will update that list before adding or changing subprocessors that process personal information.
Legal and safety. We may disclose information to comply with a law, regulation, subpoena, court order, or governmental request; to enforce our agreements; or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of Sunshine Apps LLC, our users, or others. Where we are legally permitted to notify you first, we will.
Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. It remains subject to this Policy, and we will notify you of any change in control that affects how your information is handled.
With your direction or consent. Anywhere else you ask or agree.
We use technical and organizational measures designed to protect information, including encryption in transit, access controls, database-level access restrictions, scoped access tokens for shared report links, and secure credential management. Our infrastructure is hosted in the United States.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your credentials confidential and for maintaining your own backups.
If we become aware of a security incident affecting personal information, we will investigate, take reasonable steps to contain and remediate it, and notify affected parties and regulators as required by applicable law. Where the incident involves Operator Content, we will notify the Operator so they can meet their own notification obligations to their customers.
We retain your information for as long as your account is active.
After termination, you have thirty (30) days to export your Operator Content. After that window closes, we delete it within a commercially reasonable time.
We may retain information longer where required by law, for financial and tax records, to resolve disputes, to enforce our agreements, or to prevent fraud or abuse. Data may also persist in routine backups until those backups are deleted on their normal schedule. Retained information remains subject to this Policy.
Depending on where you live, you may have the right to:
These rights are provided now or in the future by state privacy laws including those of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Scope varies by state.
To make a request, email jonrowles939@gmail.com. We may need to verify your identity before responding, and we may be unable to respond if we can't. You may use an authorized agent with written permission. We respond within the timeframe applicable law requires.
Appeals. If we deny your request, you may appeal by emailing jonrowles939@gmail.com with the subject line "Privacy Rights Appeal," your name, the email on your account, and a copy of our denial. We will respond in writing with our decision and reasons. If we deny the appeal, you may contact your state attorney general.
Marketing. You can unsubscribe from our marketing emails using the link in any such email. You cannot opt out of transactional and account messages while your account is active.
If a pool service company uses Floater to manage your service, they uploaded your information and they decide how it's used. They are the controller. We are their service provider.
To access, correct, or delete your information, or to exercise any privacy right, contact the pool service company directly — they can act on your request immediately, and we are required to follow their instructions regarding your data. If you contact us instead, we will forward your request to them and assist as required by law.
Service reports and invoices you receive were sent by that company, not by us. To stop receiving them, contact that company or use the unsubscribe option in the message.
Floater is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 13. If we learn we have, we will delete it. If you believe a child has provided us information, contact jonrowles939@gmail.com.
You must be at least 18 to open an account.
Floater is operated and hosted in the United States and is intended for use by businesses in the United States. We do not currently offer the Service in the European Economic Area, the United Kingdom, or other jurisdictions with separate data protection regimes, and this Policy does not describe rights under those regimes.
If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those where you live. By using the Service you consent to that transfer.
The Service may link to or integrate with third-party websites and services. This Policy does not apply to them. Review their privacy policies before providing information.
We may update this Policy. For material changes, we will notify the Account Owner by email at least thirty (30) days before the change takes effect and update the date at the top. Continued use after the effective date constitutes acceptance. Prior versions are available at floater.tradestack.studio/privacy/archive.
Sunshine Apps LLC
152 Coquina Bay Drive
St. Petersburg, FL 33705