washlistBack to Washlist

Privacy Policy

Effective date: July 14, 2026 · Version 1.0

This Privacy Policy (this "Policy") describes how Washlist collects, uses, stores, discloses, and protects information in connection with the Washlist mobile application (the "App"), the website located at washlistapp.com (the "Site"), and the application programming interfaces, databases, and related services that power them (together, the "Service"). Please read it carefully before using the Service.

This Policy is incorporated into, and forms part of, the Washlist Terms of Service (the "Terms"). Capitalized terms used but not defined in this Policy have the meanings given to them in the Terms. By creating an account or otherwise using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, you must not use the Service.

1. Introduction and Scope

The Service is operated by Washlist, a sole proprietorship organized and operating under the laws of the United States ("Washlist," "we," "us," or "our"). This Policy applies to every visitor to the Site, every user of the App, and every holder of a Washlist account (an "Account"), in each case with respect to information processed in connection with the Service.

A design principle worth stating at the outset: the Service points at areas, not people. Opportunity scores describe neighborhoods and other aggregate geographic areas, and they are computed from public, aggregate, statistical sources. The Service does not display the name, home address, or telephone number of any individual, and Washlist does not compile or maintain profiles of the people who live in scored areas. Section 5 of this Policy explains where the numbers come from in detail.

This Policy does not apply to information practices of third parties that Washlist does not control, including the payment processor, mapping providers, and any website you reach by following a link from the Service. Those parties process information under their own privacy policies, which we encourage you to review.

2. Information You Provide to Us

Account information. When you register, we collect your email address and a password. Authentication is operated through our infrastructure provider, and only a salted cryptographic hash of your password is ever stored. Washlist does not store, and cannot view, your plaintext password.

Business profile information. You may optionally provide information about your business, such as a business name and a booking or website link. Providing this information is not required to use the Service.

Saved areas, notes, and preferences. When you save a favorite area, rename it, attach a note to it, set a default metro, configure filters or alerts, or adjust appearance settings, we store those inputs so the Service can function as you configured it.

Correspondence. If you contact us by email, submit a privacy request, deliver a notice under the Terms (including an arbitration opt-out notice), or otherwise correspond with us, we retain that correspondence and the information it contains, including your email address and the content of the message.

Payment information. Payments are processed by Stripe, Inc. ("Stripe"). Your full card number, card verification value, and equivalent payment credentials are transmitted directly to Stripe and never touch Washlist systems. We receive and store only what is needed to administer your subscription: your subscription status and tier, Stripe customer and subscription identifiers, and general billing state such as whether a payment succeeded or failed. Section 4 describes this in more detail.

3. Information Collected Automatically

Usage records. The Service records the actions needed to operate your Account: the metros you scan, the filters applied, timestamps of scans, quota counters, and your favorites and history activity. These records are what make plan limits, scan history, and cached results work, and they are also used to detect abuse as described in Section 6.

Log data. When your device communicates with the Service, the infrastructure providers that host it (described in Section 7) generate standard server logs, which may include your IP address, device and browser user agent, request timestamps, and the endpoints requested. We use log data for security, rate limiting, abuse prevention, and debugging. Log data is subject to the short, rolling retention schedules of the providers that generate it.

What we deliberately do not collect. The App contains no third-party analytics software development kit, no advertising SDK, no session-replay tooling, and no device-fingerprinting library. The App does not request or access your device's GPS or precise location; when the map moves, it moves to a metro you selected, not to where your device is. The App does not access your contacts, photos, camera, microphone, or files. The Site does not set advertising or cross-site tracking cookies; the only cookies and local storage used are those strictly necessary for authentication and session integrity.

Notifications. Opportunity alerts and scan notifications are generated locally on your device. If a future version of the App registers a push notification token in order to deliver alerts you have enabled, that token will be stored solely to deliver those notifications and will be deleted when you disable notifications or delete your Account.

4. Information Received From Third Parties

Payment processor. Stripe sends us subscription lifecycle information: for example, that a checkout was completed, a trial started, an invoice was paid or failed, or a subscription was updated or canceled. This is how your Account reflects your billing state. We never receive your full payment card details from Stripe.

Sign-in providers. If third-party sign-in options (such as Google or Facebook) become active in the App, and you choose to use one, we would receive the name and email address associated with the account you authorize, and this Policy would govern that information once received. As of the Effective Date, no third-party sign-in option is active.

No data brokers. We do not purchase information about you from data brokers, and we do not enrich Accounts with third-party marketing or demographic data about you.

5. Where Scores Come From; No Consumer Profiles; No FCRA Use

Opportunity scores are computed from aggregate, area-level statistical sources, including: estimates published by the United States Census Bureau through the American Community Survey; climate normals and weather data obtained at the metro level; and open map and construction data. Every input is statistical information about a geographic area. None of it is information about an identifiable individual.

Because the underlying sources are survey-based estimates with published margins of error, every score is itself an estimate. Scores describe places, not people, and Washlist does not create, hold, or sell dossiers, profiles, or contact lists concerning the residents of any scored area.

Canadian metros are offered as a preview and rely in part on modeled demographic estimates alongside real weather and map data. Section 13 addresses Canadian data and Canadian users specifically.

Washlist is not a consumer reporting agency within the meaning of the Fair Credit Reporting Act, 15 U.S.C. section 1681 et seq. ("FCRA"), and nothing in the Service constitutes a consumer report. You must not use the Service, or any score or data obtained from it, in whole or in part, to establish any individual's eligibility for credit, insurance, employment, housing, or any other purpose that would subject Washlist to the FCRA. The Terms prohibit such use, and any such use is entirely at your own risk.

6. How We Use Information

We use the information described in this Policy to: (a) provide, operate, and maintain the Service, including running scans you request, storing your favorites and history, and remembering your preferences; (b) enforce plan quotas, rate limits, and feature gates; (c) administer subscriptions, trials, and purchases through Stripe; (d) secure the Service, including detecting and preventing fraud, scraping, quota circumvention, unauthorized access, and other conduct prohibited by the Terms; (e) send transactional communications concerning your Account, billing, security, and legal notices; (f) send product news and opportunity alerts, subject to the preferences described in Section 15; (g) comply with legal obligations and enforce our agreements; and (h) create aggregated and de-identified data as described in Section 16.

We do not use your information to serve third-party advertising, and we do not sell your personal information or share it for cross-context behavioral advertising. We have never done either.

We do not use your personal information to make automated decisions that produce legal or similarly significant effects concerning you.

7. How We Share Information

Service providers. We share information with service providers that process it on our behalf and on our instructions, in each case only to the extent their function requires: Supabase (database, authentication, and realtime infrastructure), Stripe (payment processing), Vercel (application hosting and serverless compute), Cloudflare (network proxying, DNS, and email routing), Expo (application tooling and, in store builds, notification delivery), Google Maps Platform (maps and geocoding), and the weather data providers used to compute weather factors. Each provider is bound by its own contractual and legal obligations with respect to the data it processes.

Mapping providers. Map tiles and related mapping features displayed in the App and on the Site are served by third-party mapping platforms, which may collect information (such as IP address and map interactions) directly from your device under their own privacy policies when tiles are requested.

Legal requirements. We may disclose information if we believe in good faith that disclosure is required by law, subpoena, or court order, or is reasonably necessary to protect the rights, property, or safety of Washlist, our users, or the public, to enforce the Terms, or to detect and prevent fraud or abuse.

Business transfers. If the Service or substantially all of its assets are acquired by, or reorganized into, another entity (including a successor entity formed to operate the Service), information may be transferred as part of that transaction. Any successor will be bound by this Policy or will provide notice and choices before materially changing how your information is handled.

With your consent. We share information for any other purpose only with your consent.

For clarity: we do not sell personal information, we have not sold personal information in the twelve months preceding the Effective Date, we do not share personal information for cross-context behavioral advertising, and we do not process sensitive personal information other than account credentials used for authentication.

8. Data Retention

Account data. We retain your Account information for as long as your Account exists. When your Account is deleted, whether through the in-App deletion flow or a verified request under Section 10, we delete or de-identify the personal information associated with it within thirty (30) days, and residual copies are purged from encrypted backups within ninety (90) days, except as stated below.

Scan history and quota records. Monthly scan allowances are calculated from your scan history. For that reason, using "Clear history" in the App hides cleared entries from your view but does not immediately delete the underlying records; they are retained (a) so that the current period's quota is calculated accurately and cannot be reset by clearing history, and (b) for security and abuse investigation. History records are permanently deleted when your Account is deleted.

Log data. Server logs are retained on the short, rolling schedules of the infrastructure providers that generate them and are not kept longer than needed for security and operations.

Cached area scores. Scores and the aggregate inputs behind them describe geographic areas, not individuals. They are not personal information, and they are retained and refreshed on the caching schedules of the Service.

Legal holds. We may retain specific information longer where reasonably necessary to comply with a legal obligation, resolve a dispute, enforce our agreements, or maintain records of privacy requests, arbitration opt-outs, and similar notices.

9. Security

We use technical and organizational measures appropriate to the nature of the data we handle, including: row-level security policies at the database layer, so that each Account can read only its own rows; encryption of data in transit using TLS; encryption at rest provided by our infrastructure providers; server-side confinement of all secret keys; and the structural decision not to collect payment card data, precise location data, or analytics identifiers in the first place. The most effective protection in this Policy is the data the Service never collects.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach of security affecting your personal information occurs, we will notify you and the relevant authorities as required by applicable law.

10. Your Privacy Rights

Washlist extends the following rights to every user, regardless of where you live: (a) the right to access and receive a copy of the personal information we hold about you; (b) the right to correct inaccurate personal information; (c) the right to delete your personal information; (d) the right to receive your personal information in a portable, machine-readable format; and (e) the right to opt out of non-transactional communications as described in Section 15.

How to exercise these rights. You may delete your Account directly in the App from the Profile screen, which initiates the deletion described in Section 8. For any other request, or if you cannot access the App, email [email protected] from the email address associated with your Account. We will acknowledge requests within ten (10) days and complete them within forty-five (45) days, extendable once by a further forty-five (45) days where reasonably necessary, in which case we will tell you.

Verification and authorized agents. Because Account data is sensitive, we verify requests before acting on them, ordinarily by confirming control of the Account email address. An authorized agent may submit a request on your behalf with proof of written authorization; we may still require you to verify your identity directly.

No discrimination. We will not deny you the Service, charge you a different price, or provide a different level of quality because you exercised any of these rights.

Exceptions. Deletion requests do not reach: (a) history records retained for the remainder of the current quota period as described in Section 8; (b) information we must retain to comply with law, resolve disputes, or enforce agreements, including records of the request itself; and (c) aggregated or de-identified data described in Section 16, which is no longer personal information.

United States state privacy laws. For users in states with comprehensive privacy statutes: the categories of personal information we collect are identifiers (email address, IP address), commercial information (subscription and purchase records), and internet activity (the usage and log records described in Section 3); the sources are you, your devices, and our payment processor; the purposes are those listed in Section 6; and the categories of recipients are the service providers listed in Section 7. We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use or disclose sensitive personal information beyond authentication. If we decline a request, you may appeal by replying to our response, and we will answer your appeal within forty-five (45) days; residents of some states may also contact their state Attorney General.

11. Do Not Track and Global Privacy Control

Some browsers transmit "Do Not Track" signals, and some transmit the Global Privacy Control ("GPC") signal, to websites. Because the Service does not sell personal information, does not share it for cross-context behavioral advertising, and does not engage in the tracking those signals are designed to limit, there is no tracking or sale for such signals to switch off. The Service treats every user the way those signals request by default.

12. Children

The Service is not directed to children under thirteen (13), and we do not knowingly collect personal information from any child under thirteen. If we learn that a child under thirteen has provided personal information through the Service, we will delete that information and terminate any associated Account.

Individuals aged thirteen (13) to seventeen (17) may use the Service only under the account of, and with the supervision of, a parent or legal guardian who has accepted the Terms, as described in Section 2 of the Terms. In that case, the Account and all information associated with it belong to the parent or guardian, who is responsible for it.

13. Users in Canada

Canadian data note. Canadian metros are offered as a preview. Scores for Canadian areas are computed from modeled demographic estimates combined with real weather and map data, pending integration of Statistics Canada sources, and are therefore rougher than scores for United States areas. Treat Canadian scores accordingly.

Cross-border processing. The Service is hosted and operated in the United States. If you use the Service from Canada, your information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those of Canada. By using the Service, you consent to that transfer and processing.

Canadian privacy rights. The rights described in Section 10 are available to Canadian users in full. If you have a question or complaint concerning our handling of personal information under the Personal Information Protection and Electronic Documents Act, contact [email protected]; you also have the right to complain to the Office of the Privacy Commissioner of Canada.

14. Users Outside the United States and Canada

The Service is directed to users in the United States, with a preview offering for Canada. It is not directed to, marketed in, or intended for use in the European Economic Area, the United Kingdom, or Switzerland, and we do not monitor the behavior of individuals located there. If you nonetheless access the Service from outside the United States and Canada, you do so on your own initiative, you are responsible for compliance with local law, and you acknowledge that your information will be processed in the United States as described in this Policy.

15. Communications and Notification Preferences

Transactional communications. We send communications that are necessary to operate your Account, including registration and security emails, billing and renewal notices, legal notices, and responses to your requests. You cannot opt out of transactional communications while you hold an Account, because they are how the Service tells you things you need to know.

Product news and alerts. We may send occasional product updates, feature announcements, and opportunity alerts. Every such message includes a working unsubscribe mechanism, and you can also control alerts from within the App. Opt-outs are honored within ten (10) business days and do not affect transactional communications.

Push notifications. Notifications delivered by the App can be disabled at any time in the App's settings or through your device's operating system settings.

16. Aggregated and De-Identified Data

We may create and use aggregated or de-identified data, such as usage patterns, scan statistics, and score distributions, for any lawful purpose, including operating, analyzing, and improving the Service and its scoring. Where we maintain de-identified data, we maintain it in de-identified form, we commit not to attempt to re-identify it except as permitted by law to test the effectiveness of de-identification, and we require any recipient to commit to the same. Aggregated and de-identified data are not personal information and are not subject to access or deletion requests.

Area scores themselves, being aggregate statistics about geographic areas derived from public sources, are the property of Washlist and are not personal information about any user or any resident.

17. Changes to This Policy

We may revise this Policy from time to time. If a revision materially changes how we handle personal information already collected, we will provide at least fifteen (15) days' advance notice by email to your Account address or by prominent notice in the App before the revision takes effect. Non-material revisions take effect when posted with an updated date. Your continued use of the Service after a revision's effective date constitutes acceptance of the revised Policy; if you do not agree, you must stop using the Service and may delete your Account.

18. Contact

Privacy questions and requests: [email protected]. General support: [email protected]. A mailing address for formal correspondence will be provided upon written request sent to [email protected].

Privacy Policy v1.0 · Effective July 14, 2026