{"version":"2.0","effective":"2026-08-03","text":"# WindTroubleshooter — Privacy Policy\n**Version 2.0 · Effective 2026-08-03**\n\nThis Privacy Policy explains what information WindTroubleshooter LLC (\"Company,\"\n\"we\") collects through the WindTroubleshooter website, applications, and services\n(the \"Service\"), how we use it, and the choices you have. By creating an account,\naccepting this policy, or using the Service, you agree to it. If you do not agree,\ndo not use the Service.\n\n## 1. Information we collect\n\n**Account information.** Email address and a one-way HASH of your password (we\nnever store your password itself), your role, account status, and timestamps.\n\n**Profile information (optional, provided by you).** Name, company,\ncountry/region/city, and work phone, if you choose to enter them.\n\n**Access-voucher information.** If your account was created with an access\nvoucher: the voucher id and the first and last name the voucher was issued to.\n\n**Legal-acceptance records.** When you accept the Terms of Use, this Privacy\nPolicy, or sign a Non-Disclosure Agreement, we record the version, timestamp, your\naccount email, device identifier, IP address, browser user-agent, and (for the\nNDA) the exact name you typed as your electronic signature.\n\n**SMS consent records.** If you enroll for text alerts, we record — **from you\ndirectly** — your mobile number, the timestamp of your consent, the method and\nsource of enrollment, the IP address you consented from, the exact consent\nlanguage displayed to you, and which alert categories you consented to. We record\neach subsequent change, including any withdrawal of consent and the date and\nmethod by which it was received. These records are kept as evidence of consent.\n\n**SMS alert information.** Your name, mobile number, and the sites you subscribed\nto, for the alert categories you consented to.\n\n**Device/seat information.** A device identifier and label for each device you\nregister (this is how paid seats are counted), with first and last-seen\ntimestamps.\n\n**Technical logs.** Standard server logs (IP address, requested path, timestamp,\nstatus) and in-browser error reports, kept for security and reliability.\n\n**What we do NOT collect.** We do not collect your device's GPS location\n(wind-farm coordinates in the Service are business data about sites, not about\nyou); we do not collect payment card numbers (payments, when launched, go directly\nto the payment processor); we do not use advertising identifiers; and we do not\nrun third-party advertising or cross-site tracking of any kind.\n\n## 2. How we use information\n\nTo provide, secure, and operate the Service (authentication, seat licensing,\nfeature access); to send service messages you request or that the Service\nrequires (password resets, sign-in codes, text alerts you consented to,\noperational reports); to enforce our agreements and protect against fraud, abuse,\nand security incidents; to maintain legally required records, including consent\nand acceptance evidence; and to improve reliability. We do NOT sell or rent\npersonal information, and we do not share it for cross-context behavioral\nadvertising.\n\n**Mobile information.** No mobile information will be shared or sold to third\nparties or affiliates for promotional or marketing purposes. Mobile numbers and\nSMS consent are used only to deliver the alerts you consented to, and are shared\nsolely with the SMS carrier service needed to transmit those messages.\n\n## 3. Legal bases for processing (where GDPR or UK GDPR applies)\n\nWhere the EU or UK General Data Protection Regulation applies, we rely on:\n**contract** (Art 6(1)(b)) to provide the Service to you; **legitimate interests**\n(Art 6(1)(f)) for security, abuse prevention, and reliability; **consent**\n(Art 6(1)(a)) for text alerts, which you may withdraw at any time as described in\nSection 6; and **legal obligation** (Art 6(1)(c)) for retention of consent and\nacceptance records.\n\nWhere we process personal data on behalf of an organizational customer — for\nexample the details of that customer's personnel — that customer is the\ncontroller and we act as processor. **We will enter into a data processing\nagreement with any customer who requests one; contact\nadmin@windtroubleshooter.com.**\n\n## 4. Service providers (processors)\n\nWe use a small number of infrastructure providers that process data on our\nbehalf: cloud hosting and database (Render), email delivery (our SMTP provider),\nand — if text alerts are enabled — an SMS carrier service (e.g., Telnyx) that\nreceives the recipient name and phone number needed to deliver the message.\nWeather data requests to our weather-data provider contain WIND-FARM coordinates\nonly, never your personal information. If you sign a Non-Disclosure Agreement, we\nsend the IP address you signed from to an IP-geolocation provider (ip-api.com) to\nrecord an approximate city, region and country on the signature certificate as\nevidence of execution; no other personal information is sent. Providers are bound\nto use data only to provide their service to us.\n\n## 5. Retention\n\n| Category | Retention period |\n|---|---|\n| Account, profile and device data | While your account exists, then deleted within 30 days of account deletion |\n| Legal-acceptance records (Terms, Privacy, NDA) | Six (6) years from the end of the account relationship, as evidence of execution |\n| SMS consent and revocation records | Six (6) years from the date consent ended, as evidence of consent |\n| SMS subscriber entries (active list) | Until you withdraw consent or the feature is discontinued, then removed within ten (10) business days |\n| Server logs | Thirty (30) days |\n| In-browser error reports | Ninety (90) days |\n| Security and incident records | Two (2) years |\n\nWhere a longer period is required by law, by a legal hold, or to establish,\nexercise or defend legal claims, we retain the relevant records for that longer\nperiod and delete them when it ends.\n\n## 6. Text alerts: your consent and how to stop them\n\n**How consent works.** We send text alerts only to a person who has consented\ndirectly to receive them. An administrator at your organization may invite you,\nbut **your consent is given by you, to us, and is recorded as described in\nSection 1.**\n\n**Separate categories.** Where we offer more than one category of message, we ask\nfor and record your consent separately for each. Consent to one category is not\nconsent to another.\n\n**How to stop them.**\n\n- You may withdraw consent **by any reasonable means**, at any time.\n- Replying with **STOP, QUIT, END, REVOKE, OPT OUT, CANCEL or UNSUBSCRIBE** to\n  any message from us withdraws your consent.\n- **Other wording also works.** If you reply in any words a reasonable person\n  would understand as a request to stop, we will treat that as a withdrawal of\n  consent.\n- You may also withdraw consent by emailing **admin@windtroubleshooter.com**, by\n  replying to any message from us, or by telling us by any other reasonable\n  method. **We do not require you to use any particular method, and we do not\n  designate any method as the only way to opt out.**\n- **We will honour any withdrawal within ten (10) business days of receiving it**,\n  and in practice we act sooner.\n- We may send you **one** message confirming that we have stopped, which will\n  contain no promotional content. If you consented to more than one category, that\n  message may ask which categories you meant, and we will stop all of them unless\n  you tell us otherwise.\n\n**If two-way texting is unavailable.** If we ever send from a number that cannot\nreceive replies, we will say so clearly in every message and give you an\nalternative way to opt out in that message.\n\n**You do not need to go through your administrator to stop messages, and we will\nnever refuse a request because it did not come through them.**\n\n## 7. Your rights and choices\n\n**Access and deletion.** You may delete your account at any time in the app\n(Settings → Delete account); this permanently removes your credentials, profile,\ndevices and seats, and active sessions. Legal-acceptance and consent records are\nretained as described in Section 5. You may also contact us at\nadmin@windtroubleshooter.com to exercise rights of access, correction, deletion,\nportability, restriction, and objection, and the right not to be discriminated\nagainst for exercising them, where applicable law grants them.\n\nWe respond to verified requests within the time required by applicable law — 30\ndays under the GDPR and UK GDPR (extendable by two further months for complex\nrequests, with notice), and 45 days under the CCPA/CPRA (extendable once by a\nfurther 45 days, with notice).\n\n**We do not \"sell\" or \"share\" personal information** as those terms are defined\nby the CCPA/CPRA, and we have not done so in the preceding twelve months.\n\n**Complaints.** If you are in the EU or UK you may lodge a complaint with your\nlocal supervisory authority. We ask that you contact us first so we can try to\nresolve the matter.\n\n## 8. Security and incident notification\n\nPasswords are stored only as salted PBKDF2 hashes; access tokens are opaque and\nexpire; privileged functions require elevated roles; and acceptance, consent and\nsecurity events are logged. No method of transmission or storage is completely\nsecure, but we apply administrative and technical safeguards appropriate to the\ndata we hold.\n\n**If a security incident affects your personal information**, we will notify you\nwithout unreasonable delay once we have determined that notification is\nappropriate or required, and in any event within the period required by applicable\nlaw. Where the GDPR or UK GDPR applies and the incident is a reportable personal\ndata breach, we will notify the competent supervisory authority within 72 hours of\nbecoming aware of it. Where we act as processor for an organizational customer, we\nwill notify that customer without undue delay so it can meet its own obligations.\nOur notice will describe, so far as known, what happened, what information was\ninvolved, what we have done, and what you can do.\n\n## 9. International transfers\n\nThe Service is operated from the United States, and your information is processed\nthere.\n\n**Where we transfer personal data from the European Economic Area, the United\nKingdom or Switzerland to the United States, we rely on the European Commission's\nStandard Contractual Clauses (Decision 2021/914), together with the UK\nInternational Data Transfer Addendum where the transfer originates in the United\nKingdom, supplemented by a transfer impact assessment. A copy of the relevant\nsafeguards is available on request from admin@windtroubleshooter.com.**\n\nWe do not claim certification under the EU-U.S. Data Privacy Framework. We are not\nself-certified to it, and we will not state otherwise unless and until that\ncertification is actually completed with the U.S. Department of Commerce.\n\nWe do not currently offer the Service to individuals in the European Union, and we\nhave not appointed a representative under Article 27 GDPR. If we begin offering the\nService to EU data subjects, we will appoint one and name them here before doing so.\n\n## 10. Children\n\nThe Service is a professional tool intended for adults and is not directed to\nanyone under 18. We do not knowingly collect personal information from children.\nIf you believe a child has provided information, contact\nadmin@windtroubleshooter.com and we will delete it.\n\n## 11. Changes to this policy\n\nWe may update this policy; the version and effective date above change when we do.\nMaterial changes are presented in-app for re-acceptance before continued\nsigned-in use, using the same mechanism as our Terms of Use. We keep superseded\nversions, and the version you accepted governs the period during which you\naccepted it.\n\n## 12. Contact\n\nWindTroubleshooter LLC · admin@windtroubleshooter.com ·\n2222 W Grand River Ave STE A, Okemos, MI 48864\n\n==============================================================================\n"}