Legal
Privacy policy
Last updated 7 September 2026
DeckHand is used by service businesses to answer their customers. That means we hold two kinds of information: what a business tells us about itself, and what its customers send it. This explains both, and what we do with them.
Who we are
DeckHand is operated by Caltan Ventures LLC in Texas. For anything in this policy, write to patcad@caltanventures.com.
Where a business uses DeckHand to handle messages from its own customers, that business decides what is collected and why. We process it on their instructions.
What we collect
From the business
- Account details: name, email address, and a password we never see in plain text.
- Business facts you enter yourself — prices, service area, hours — because they are what replies are written from.
- Billing contact details. Card numbers go directly to Stripe and never reach our servers.
Service records and optional app features
- Customer identity and contact details, property service addresses, pool and equipment details, visits, readings, service notes, tasks, photos, files, quotes and invoices entered by the company or authorized household.
- A property service address describes where work takes place. It is not device location tracking; the app does not request location permission for these records.
- Account and session identifiers, device push registrations, notification preferences and delivery/read status. Camera, photo-library and notification access are optional and requested through the device permission controls when needed.
- Questions, feedback and deletion requests you submit to DeckHand support, their replies and handling status.
From prospects and marketing signups
- If you request a Pool Inbox Audit, your name, work email, pool-company name, company website, and approximate weekly customer-message volume so we can qualify, arrange, and follow up on the audit.
- Campaign tags in the page link—source, medium, campaign, search term, and creative—so we can tell which outreach introduced you to DeckHand. If an explicit marketing signup becomes a trial, we associate those tags and any selected plan interest with the new account and company. Plan interest never grants access or changes billing.
- The public demo records anonymous start and completion events with campaign tags. Those events contain no account, cookie, persistent visitor identifier, message content, referrer, user-agent, or network address.
From the business's customers
- The content of messages they send through the customer app or portal, email, and website forms, including any photographs attached. For a business with an existing supported carrier-SMS configuration, this can also include text messages.
- Their email address or app account, and a phone number when an existing supported SMS route is used, so a reply can reach them.
- For website submissions, the page they submitted from and signals used to check they are not a bot.
How messages are used, including by AI
This is the part worth reading carefully. When a message arrives, its text and any photographs are sent to OpenAI to work out what is being asked and to draft a reply. DeckHand first uses OpenAI's Luna model and may make one additional attempt with its Terra model when the first result cannot be used. The business facts described above are sent with the message, which is what makes the reply specific to that business rather than generic.
OpenAI processes this content to return the classification and draft. Under our API agreement with OpenAI, this content is not used to train its models.
No reply is sent automatically unless the business turns that on. By default every draft waits for a person to approve it, and every send records who approved it and when.
What we do not do
- We do not sell personal information, and we never have.
- We do not sell, rent, or share mobile phone numbers or SMS consent information with third parties or affiliates for marketing or promotional purposes. Mobile information is shared only with service providers needed to deliver requested messages.
- We do not share one business's data with another. The database enforces this.
- We do not use your customers' messages to improve a product for anybody else.
- We do not run advertising or third-party analytics on the signed-in application.
Support assistance and product measurement
When AI-assisted support is enabled, the submitted DeckHand support request and approved support facts may be sent to OpenAI for analysis and an editable response draft. Authorized staff review and deliberately send support replies. AI does not grant access, charge or refund, delete accounts, or resolve a request on its own. A support request does not give staff or AI blanket access to the company's homeowner conversations or photographs.
We use first-party company-level counts, outcomes and timing to understand signup, setup, reviewed drafts, meaningful product use, subscription outcomes and operational problems. These event records exclude private message text, photographs, customer contact details and customer-search terms. Internal, demo, test and reviewer companies are excluded from commercial reporting.
Optional notifications
When you enable notifications, Expo and the device platform push service (Apple or Google) process your push token and notification payload. Notifications use generic text and opaque destination identifiers; they do not include private message bodies, customer names, addresses or photographs. Open the authorized app workspace to read the underlying information. You can keep using messages without enabling notifications.
Text-message privacy
DeckHand does not currently offer new carrier-SMS connections. For a business with an existing supported SMS configuration, if you provide a mobile number and expressly agree to receive service-related texts, message frequency varies and message and data rates may apply. Reply STOP to opt out or HELP for help. Consent is not a condition of purchase. See our messaging terms for more information. Messages sent inside the DeckHand customer app or web portal are in-app messages, not carrier SMS.
Who else can see it
The services we use are each listed with what they can see, on the subprocessors page. We may also disclose information where the law requires it.
How long we keep it
- Messages, drafts and photographs are kept for as long as the business's account is open, because they are that business's record of its own conversations.
- Our approved review schedule is 6 months without actual prospect activity for unconverted leads; 12 months after resolution for detailed support requests; and 30 days after replacement or resolution for unused support AI drafts. Documented ongoing follow-up, incident, dispute and required-record holds can change eligibility. Cleanup is reviewed and must complete before a record is described as erased.
- Detailed company analytics have a 90-day retention schedule and non-identifying aggregate totals a 12-month schedule. Routine diagnostic records have a 30-day schedule and minimal security/admin audit metadata a 12-month schedule, with documented holds. Provider-managed logs and backups are subject to their own verified settings; these schedules are not promises of immediate expiry of every provider copy.
- When a business closes and deletes its DeckHand company account, its company data is deleted with it — conversations, drafts, facts and photographs — except records we must retain for legal, security, tax, or accounting reasons. This cannot be undone.
- Deleting an individual login removes that authentication account and stops future push delivery. It does not delete pool-service, conversation, invoice, or audit records owned by the pool company or required for security and legal compliance.
- Billing records are kept as long as tax and accounting rules require, and are held by Stripe.
Archiving a customer keeps company history and revokes homeowner access. Restoring that history does not restore access or send an invitation; an owner must authorize access again. Permanent customer deletion requires archive and an explicit owner confirmation. Archived history is reviewed annually rather than automatically purged.
Encrypted backups can contain earlier records. Recovery must reapply completed deletion and access-removal decisions before the restored environment is released. Those minimal decisions are retained for every backup that can still be restored. The Mac and Time Machine backup plan does not guarantee a fixed historical-copy expiry; deleting a source archive does not prove every older backup copy is erased.
Security
Data is encrypted in transit and at rest by our hosting providers. Access between businesses is separated in the database itself rather than only in application code, so one account cannot read another's. Photographs are stored in a private bucket and are only reachable through short-lived links.
Staff at Caltan Ventures LLC can see account health and billing for every business — whether an account is working and what it costs to run. Privileged support reads and administrative changes are logged. Staff can read requests submitted to DeckHand support. Household conversations and photographs remain restricted to authorized company or household membership; a platform staff grant alone does not provide that access.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, and to object to some processing. Every signed-in role can initiate complete login deletion from Account in the iPhone app or web portal. We disable push and sign out immediately, then complete protected requests within 7 days after any active subscription, privileged access, or required record retention is resolved. Write to patcad@caltanventures.com and we will respond.
If you are a customer of a business that uses DeckHand and you want your information removed, contact that business — it is their record, and we act on their instructions. Tell us and we will pass it on.
Children
DeckHand is a tool for businesses and is not directed at children. We do not knowingly collect information from anyone under 13.
Changes
If this policy changes in a way that matters, we will say so before the change takes effect rather than quietly moving the date at the top.
