Rainbase Privacy Policy

Rainbase LLC (“Rainbase,” “we,” “us,” or “our”) provides a business operations application and related website for contractor, exterior, roofing, restoration, and similar service businesses. This Privacy Policy explains how Rainbase collects, uses, stores, discloses, protects, and deletes personal information in connection with the Rainbase mobile application, website, support communications, AI-assisted features, voice transcription, customer-management features, file and report features, and related services.

Rainbase is currently designed primarily as a United States business-to-business service. Rainbase customers are businesses. Those businesses may invite or authorize their owners, administrators, employees, contractors, sales representatives, field users, crew users, or other authorized users to use Rainbase.

This Privacy Policy is written to describe Rainbase’s current data practices. If Rainbase later adds material new systems, such as expanded cloud storage, payment processing, SMS messaging, external calendar integrations, OCR providers, additional analytics tools, or additional third-party integrations, Rainbase will update this Privacy Policy as appropriate.

1. Summary

This summary is provided for convenience. The full Privacy Policy below controls.

Rainbase is a B2B operations application. Business customers use Rainbase to manage customers, homeowners, properties, jobs, files, photos, inspection records, reports, calendar items, communications, production workflows, and related operational records.

The current Rainbase mobile app stores much of its workspace data locally on the user’s device using app storage and local file storage. Local data may include customer records, property addresses, files, photos, PDFs, report files, technical file metadata, saved transcript records, calendar entries, communications, notifications, assistant history, and app settings.

Rainbase also uses certain service providers. Current or conditionally used providers include Squarespace for the Rainbase website and contact form, Firebase/Google services for authentication and limited database access, Google Places/Google Maps for address autocomplete and map directions when used, and OpenAI or another configured AI/transcription provider for AI assistant routing and voice transcription when those features are enabled or used.

Rainbase does not sell personal information. Rainbase does not use personal information for cross-context behavioral advertising or targeted advertising. Rainbase does not currently use advertising SDKs inside the mobile app.

Rainbase does not currently process payment card information inside the mobile app. If payments are later accepted through Squarespace, an invoice provider, a payment processor, or another billing provider, that provider may process payment and billing information under its own terms and privacy policy.

Rainbase is not intended for healthcare, HIPAA-regulated use, legal services, education, children, government benefit decisions, credit decisions, employment decisions, or the storage of Social Security numbers, government IDs, full payment card numbers, protected health information, passwords, API keys, secrets, biometric templates, or other highly sensitive information unless Rainbase expressly enables and documents support for that category.

Privacy questions and requests may be sent to support@rainbase.io.

2. Scope

This Privacy Policy applies to:

the Rainbase mobile application;

the Rainbase website hosted through Squarespace;

Rainbase support and onboarding communications;

Rainbase AI-assisted, voice, transcription, file, document, report, calendar, customer-management, and operations features; and

related services that link to this Privacy Policy.

This Privacy Policy does not replace a Rainbase business customer’s own privacy policy or legal obligations. Rainbase customers are responsible for providing legally required notices and obtaining legally required permissions from their own employees, contractors, customers, homeowners, clients, property owners, and other individuals whose information they enter into or process through Rainbase.

3. Definitions

Customer means the business, contractor, exterior company, roofing company, restoration company, or organization that creates, receives, pays for, or is authorized to use a Rainbase workspace or account.

Authorized User means an individual who is invited, created, approved, or permitted by a Customer or Rainbase to use Rainbase, such as an owner, administrator, employee, contractor, salesperson, office user, field user, crew user, or internal testing user.

Customer Content means files, photos, PDFs, reports, notes, inspection records, job records, communications, calendar entries, technical metadata, transcripts, customer records, homeowner records, property records, and other content submitted to, generated in, stored in, or managed through Rainbase.

End Customer Data means information about a Customer’s own customers, homeowners, clients, prospects, properties, jobs, inspections, projects, communications, claims, estimates, reports, appointments, or related business records.

Personal information means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual, household, account, or device, depending on applicable law.

4. Rainbase’s Role

Rainbase may act in different roles depending on the context.

For Rainbase website visitors, prospective customers, support contacts, authentication data, account administration, internal operations, service security, diagnostics, and Rainbase business records, Rainbase generally determines the purposes and means of processing.

For Customer Content and End Customer Data entered, stored, managed, or generated by a Customer or its Authorized Users, Rainbase generally processes that information to provide the Rainbase service to that Customer. Customers control what business records they enter into Rainbase and are responsible for their own notices, permissions, and legal obligations.

Because the current Rainbase mobile app stores much workspace data locally on user devices, some Customer Content may remain only on the user’s device unless the user chooses to send it to a provider, share it, export it, use a connected feature, or otherwise transmit it.

5. Information Rainbase Collects or Processes

Not every category applies to every user, Customer, device, feature, or account.

5.1 Website and contact-form information

Rainbase’s website is currently hosted through Squarespace. If a visitor uses the Rainbase website or submits a contact form, Rainbase may collect:

first name;

last name;

email address;

optional phone number;

company or business information if provided;

message content;

requested service or inquiry details; and

related communication metadata.

Squarespace may also process website visitor information needed to provide, secure, analyze, and operate the website. Depending on the website settings and cookies used, this may include browser, network, device, IP address, pages visited, referral information, clicks, timestamps, searches, scrolling, cookie identifiers, and similar website analytics or performance information.

Rainbase uses website and contact-form information to respond to inquiries, manage leads, provide support, schedule onboarding, communicate with prospective customers, and operate the Rainbase website.

5.2 Account, authentication, and membership information

Rainbase currently uses Firebase/Google services for authentication and limited database access.

Rainbase may process:

email address;

password submitted to Firebase for sign-in;

Firebase user ID;

Rainbase user ID;

company or workspace ID;

role ID;

membership status;

authentication session information;

local session information;

sign-in/sign-out state;

account and access metadata; and

related security or diagnostic information.

Rainbase does not intend to store plaintext passwords in its own app code. Password authentication is handled through Firebase Auth or related authentication services.

The current app primarily supports sign-in to existing Firebase-backed accounts rather than open public self-service account creation inside the app.

5.3 Company, workspace, team, role, and permission information

Rainbase may process business and workspace information, including:

company name;

company ID;

workspace or organization information;

admin name and email;

business role;

user display name;

first and last name;

email address;

phone number;

role;

permissions;

company lifecycle status;

local billing or plan-status fields;

folder templates;

pipeline templates;

tags;

job-code templates;

settings; and

related configuration records.

Some of this information is currently stored locally on the device in Rainbase app storage, especially for local workspace configuration, roles, permissions, company users, and administrative or testing records.

5.4 Customer, homeowner, lead, job, and property records

Customers and Authorized Users may enter, import, create, edit, store, display, search, archive, restore, or delete records about their own customers, homeowners, leads, clients, properties, and jobs.

This information may include:

first and last name;

phone number;

email address;

street address;

city;

state;

ZIP code;

property address;

job code;

lead type;

customer type, such as Retail or Insurance;

storm date;

owner or assigned user;

pipeline stage;

job status;

archive status;

archive reason;

created and updated timestamps;

production workflow status;

assigned users;

completion or return history;

notes; and

related operational records.

Customer records currently exist primarily in local app storage on the user’s device. Limited cloud database customer exact-read functionality may exist for specific customer records where Firebase membership and database security rules permit that read.

5.5 Calendar, scheduling, communications, and notifications

Rainbase may process local calendar and scheduling information, including:

calendar names;

calendar colors;

calendar access lists;

event titles;

start and end times;

all-day status;

addresses;

contact names;

phone numbers;

notes;

attendees;

invite status;

accepted or declined status;

calendar preferences; and

related local notifications.

Rainbase may also process local customer communication records, including:

communication log titles;

message bodies;

author name;

author user ID;

author type;

attachments;

mentions;

message previews;

timestamps; and

notification previews.

Current calendar, communication, and notification features are local-app features. Rainbase does not currently have active external Google Calendar, Outlook Calendar, Apple Calendar, external email, external SMS, or push-notification provider integrations in the audited mobile app.

5.6 Files, photos, PDFs, documents, reports, and file metadata

Rainbase allows users to create, capture, import, view, preview, organize, delete, and share business files, photos, PDFs, documents, report files, and related records.

This information may include:

inspection photos;

uploaded files;

uploaded documents;

PDFs;

generated report PDFs;

file names;

folder names;

file type;

MIME type;

file size;

created and updated timestamps;

source information;

tags;

inspection context;

report linkage;

selected report photos;

voice-note previews;

transcript references; and

related file-management information.

The current app stores these files primarily in the device’s local Rainbase file storage. Rainbase may also create additional technical records associated with user files so the app can manage file organization, previews, reports, inspection context, voice notes, transcription references, cleanup, deletion, and related functionality.

These technical records may contain personal information if the related file, photo, customer, property, report, note, or transcript contains personal information. Rainbase does not disclose the internal structure of these records in this Privacy Policy, but they are treated as part of Customer Content when they relate to a Customer’s workspace records.

Rainbase may generate reports from selected customer, inspection, photo, and report-template information. Generated PDFs may be stored as customer files and may be previewed or shared by the user.

5.7 Voice, transcripts, and audio

Rainbase may provide voice features for assistant input, inspection notes, photo notes, or related workflow actions.

When a user uses voice transcription, Rainbase may process:

temporary audio recordings;

audio bytes;

transcribed text;

transcription provider or model metadata;

duration or file-size metadata;

voice-note preview text;

full transcript text;

transcript references; and

related status information.

Temporary audio is intended to be used to create the transcript and then deleted on a best-effort basis. Transcripts may be retained locally when the user saves them as part of a customer file, inspection note, photo note, assistant message, or other Rainbase record.

When voice transcription is enabled, audio or transcript-related data may be sent to OpenAI or another configured AI/transcription provider through Rainbase’s configured proxy or backend service to provide transcription. Users should not record or submit highly sensitive information through voice features.

5.8 AI assistant, prompts, messages, and tool-routing information

Rainbase may provide AI-assisted features, including assistant routing, navigation, workflow help, voice-to-text submission, tool selection, and text generation or refinement.

Rainbase may process:

user-entered assistant messages;

voice transcripts submitted as assistant messages;

assistant responses;

local assistant message history;

tool-routing signals;

limited app context needed to perform a requested action;

request IDs;

tool IDs;

validation status;

diagnostic category;

latency;

input length indicators;

routing outcome;

error status; and

related local diagnostic information.

The current Rainbase assistant history may be stored locally by company and user and is designed to retain only recent messages, currently capped to the most recent 50 messages in the audited app behavior. Rainbase provides a local control to clear assistant history for the current workspace and user.

Rainbase does not intend to store a user’s natural-language prompt solely for general analytics. However, user prompts, assistant messages, and voice transcripts may be stored locally as feature history, customer records, note records, file metadata, or other user-selected records when needed for the feature to function.

When AI routing or transcription is enabled, Rainbase may send the relevant user text, voice audio, transcript, or limited app context to OpenAI or another configured AI/transcription provider to perform the requested AI or transcription function. Rainbase is designed to limit what is sent for AI routing and transcription to what is needed for the requested feature.

Rainbase does not intentionally send full customer databases, broad file folders, full workspace exports, or internal file-management records to AI providers unless Rainbase later builds and discloses a specific feature that requires that processing.

Rainbase does not use Customer Content to train Rainbase or third-party AI models unless Rainbase separately discloses that use and obtains any required permission or consent.

5.9 OCR and extracted text

Rainbase’s current code contains fields and planning boundaries for OCR, extracted text, document intelligence, search, and insurance-document extraction. However, based on the audited current mobile app code, active document OCR provider processing is not currently implemented.

If Rainbase later enables active OCR, document extraction, document search, or document intelligence features, Rainbase will update this Privacy Policy as appropriate before materially expanding those practices.

5.10 Device permissions and device features

Rainbase may request device permissions needed for app features, including:

camera access for inspection photos and related capture workflows;

microphone access for voice notes, assistant voice input, and transcription;

file or document picker access for user-selected uploads;

photo or image-library access where the user chooses to select an image or file;

local file storage access through the app sandbox;

native sharing or opening features when the user chooses to export, open, preview, or share a file; and

phone dialer access when the user taps a customer phone number.

Rainbase does not currently use device GPS location in the audited mobile app code. Rainbase currently uses typed property addresses and Google Places/Maps features rather than device geolocation.

Rainbase does not currently use operating-system push notification APIs in the audited mobile app code. Rainbase notifications are currently local in-app records.

5.11 Google Places and Google Maps information

If Google Places address autocomplete is enabled and the user types into an address field, typed address text, autocomplete session information, place IDs, and selected place details may be sent to Google to provide address suggestions and address details.

If a user taps a Google Maps directions link or map-related action, the selected address or destination may be sent to Google Maps or opened through the device or browser.

Users may enter addresses manually if address autocomplete is unavailable or not used.

5.12 Billing and payment information

Rainbase does not currently process payment card information inside the mobile app. The audited app code does not show an active payment processor integration inside the mobile app.

Rainbase may maintain local business plan, billing-status, trial, or access-status fields for administrative or onboarding purposes. These fields do not currently mean that Rainbase is processing payment card information in the mobile app.

If Rainbase later accepts payments through Squarespace, an invoice provider, a payment processor, or another billing provider, that provider may process payment and billing information under its own terms and privacy policy. Rainbase will update this Privacy Policy as appropriate if payment processing becomes active in a way that materially changes these practices.

5.13 Support and business communications

If a user, Customer, prospect, or website visitor contacts Rainbase, Rainbase may process:

name;

email address;

phone number;

company name;

role;

message content;

support issue details;

attachments voluntarily provided;

account or workspace identifiers;

communication history; and

related support records.

Rainbase uses this information to respond to inquiries, provide support, troubleshoot issues, onboard customers, manage business relationships, and operate Rainbase.

5.14 Technical, diagnostic, and security information

Rainbase and its providers may process technical and diagnostic information needed to operate, secure, debug, and improve the service, including:

IP address;

device type;

browser or app information;

operating system;

authentication events;

session information;

local diagnostic logs;

error information;

request status;

latency;

input length indicators;

routing status;

feature status;

provider status; and

similar technical data.

The audited mobile app does not show active third-party analytics SDKs such as Google Analytics or Sentry in the app. Rainbase may use local development diagnostic logs and provider-level diagnostics through Firebase, Squarespace, OpenAI, Google, Apple, or other infrastructure used to provide the service.

6. How Rainbase Uses Information

Rainbase may use personal information for the following purposes:

to provide, operate, maintain, and improve Rainbase;

to authenticate users and manage sign-in;

to verify Firebase membership and workspace access;

to manage companies, users, roles, permissions, and local workspaces;

to allow Customers to create and manage customer, homeowner, job, property, calendar, communication, file, photo, inspection, and report records;

to save files, metadata, reports, transcripts, and related records locally on the user’s device;

to provide address autocomplete and map directions where enabled;

to provide AI assistant routing, voice transcription, and assistant interactions where enabled;

to generate, preview, save, open, export, or share user-selected reports and files;

to provide customer support, onboarding, troubleshooting, and account administration;

to respond to website contact forms and business inquiries;

to maintain service security, detect errors, prevent abuse, and debug issues;

to enforce agreements and protect Rainbase, Customers, users, homeowners, and others;

to comply with applicable law, legal process, disputes, tax/accounting obligations, or business-record requirements; and

to create aggregated, de-identified, or statistical information that is not intended to identify a specific individual.

Rainbase does not use personal information for targeted advertising or cross-context behavioral advertising. Rainbase does not sell personal information.

7. Local Device Storage

A major part of Rainbase’s current design is local device storage.

The current mobile app may store the following locally on the user’s device:

active session state;

company/workspace information;

local users, roles, permissions, and templates;

customer, homeowner, lead, contact, job, and property records;

phone numbers, email addresses, and property addresses entered by users;

job codes, pipeline stages, and production workflow records;

calendar events, attendees, notes, and local notifications;

customer communication logs and message previews;

uploaded documents, photos, PDFs, and generated reports;

technical file metadata and related file-management records;

voice-note previews, saved transcript records, and transcript references;

assistant message history;

local development diagnostic logs;

report-template data and local test exports; and

app settings or preferences.

Local data may remain on the device until it is deleted through Rainbase app controls, removed through a hard-delete or cleanup flow, cleared by deleting or resetting the app, removed by uninstalling the app, removed through device settings, or otherwise removed by the operating system or user.

Because local device data is controlled by the device and operating system, copies may also exist in device-level backups depending on the user’s device settings, backup settings, iCloud or platform backup configuration, mobile-device management tools, or other user-controlled backup systems.

8. When Information Leaves the Device

Although much Rainbase workspace data is currently local-first, information may leave the device in several situations.

8.1 Firebase and Firestore

Rainbase may send authentication and membership-related information to Firebase/Google services, including email/password sign-in information, Firebase user ID, email address, authentication session information, membership documents, company membership checks, and limited exact customer reads where configured and permitted by database security rules.

8.2 Squarespace website

Rainbase website visitor data and contact-form submissions may be processed by Squarespace to host the website, operate website features, store form submissions, provide analytics, protect the site, and support website functionality.

8.3 Google Places and Google Maps

Typed address information, autocomplete session information, place IDs, and selected address details may be sent to Google when address autocomplete is enabled or used. Address or destination information may be sent to Google Maps when the user opens directions or a map action.

8.4 OpenAI and AI/transcription providers

When AI routing, assistant voice, or transcription features are enabled or used, Rainbase may send relevant user text, voice audio, transcripts, limited app context, request information, and related metadata to OpenAI or another configured AI/transcription provider to perform the requested function.

For example, a user may speak a command or voice note, and Rainbase may send the audio for transcription so the app can convert it into text, help navigate the app, or save the user-approved note.

Rainbase is designed to limit what is sent for AI routing and transcription to what is needed for the requested feature. Rainbase does not intentionally send full customer databases, broad file folders, full workspace exports, or internal file-management records to AI providers unless Rainbase later builds and discloses a specific feature that requires that processing.

AI and transcription providers may process and retain submitted content according to their own terms, security controls, abuse-monitoring practices, and legal obligations. Rainbase does not intentionally use Customer Content to train AI models unless Rainbase separately discloses that use and obtains any required permission or consent.

8.5 User-directed sharing, exporting, opening, or dialing

When a user chooses to share, export, open, preview, download, or send a file, photo, PDF, report, or other record using the device’s share sheet, file viewer, browser, or another app, the selected information may be provided to the operating system or third-party app selected by the user.

When a user taps a phone number, the customer phone number may be provided to the device dialer or phone app.

8.6 App stores and platform providers

Apple, Google, device manufacturers, operating systems, app stores, and platform services may process technical, crash, diagnostic, purchase, distribution, device, and account information under their own terms and privacy policies.

9. AI, Voice, and Transcription

Rainbase may use OpenAI or similar providers to support AI assistant routing, voice transcription, and related features.

Rainbase may send user-provided text, voice audio, transcripts, and limited app context to the AI or transcription provider to perform the requested action. For example, a user may speak a command, and Rainbase may transcribe it so the assistant can help navigate the app or prepare text for the user.

Rainbase is designed to avoid intentionally sending full customer databases, broad file folders, full workspace exports, or internal file-management records to the AI router unless Rainbase later builds and discloses a specific feature that requires such data.

AI and transcription providers may process and retain submitted content according to their own terms, security controls, abuse-monitoring practices, and legal obligations. Rainbase does not intentionally use Customer Content to train Rainbase or third-party AI models unless Rainbase separately discloses that use and obtains any required permission or consent.

AI-assisted output may be incomplete, inaccurate, or inappropriate. Users are responsible for reviewing AI-assisted outputs before relying on them, sending them, saving them, or using them in business decisions.

Rainbase does not provide legal, medical, financial, insurance, engineering, safety, employment, credit, housing, or government-benefit advice.

Users should not submit Social Security numbers, government IDs, protected health information, full payment card numbers, passwords, secrets, API keys, biometric data, or other highly sensitive information through AI, voice, transcription, or assistant features.

10. Files, Reports, File Metadata, and Transcripts

Rainbase may store user-selected files, inspection photos, documents, PDFs, generated reports, and related local file metadata on the device.

Rainbase may maintain technical information associated with files and reports, such as file name, file type, file size, timestamps, tags, source information, inspection context, report linkage, voice-note preview information, transcription references, and cleanup status. This information helps Rainbase organize files, connect files to customer records, support report generation, manage voice-note features, and delete related records when deletion controls are used.

Saved transcripts or voice-note text may be retained locally when a user chooses to save them as part of a customer file, inspection note, photo note, assistant message, report workflow, or other Rainbase record.

Voice-note text or previews may also be used in report workflows, captions, or related customer records when the user chooses to save or use that content.

When users delete files or customers through available hard-delete controls, Rainbase attempts to delete related local files, technical file metadata, transcript references, saved transcript records, and associated local records where technically feasible. Some cleanup may be best-effort and may depend on app state, device storage, file availability, and operating-system behavior.

When users share or export files or reports, they are responsible for choosing appropriate recipients and destinations. Shared files may leave Rainbase and be processed by the selected app, operating system, service, or recipient.

11. Internal Access, Support, and Administrative Tools

Rainbase personnel and internal tools are intended to access Customer Content only when reasonably necessary for permitted purposes, such as:

providing, maintaining, testing, securing, or troubleshooting Rainbase;

responding to a Customer or Authorized User support request;

helping with onboarding, account administration, or data recovery;

investigating suspected abuse, security incidents, unauthorized access, fraud, or policy violations;

complying with law, legal process, or enforceable government requests;

enforcing Rainbase’s agreements; or

protecting the rights, safety, property, or security of Rainbase, Customers, users, homeowners, or others.

Current internal administrative and debug tooling in the audited app is primarily local and development-oriented. If Rainbase later expands production support or administrative access to hosted Customer Content, Rainbase intends to implement appropriate controls, such as role-based access, authorization checks, support-purpose limits, and auditability.

Rainbase does not intend to browse, mine, review, or use Customer workspace content for unrelated purposes.

12. How Rainbase Discloses Information

Rainbase may disclose personal information as described below.

12.1 Service providers

Rainbase may disclose information to providers that help operate Rainbase, including website hosting, contact forms, authentication, database, address autocomplete, maps, AI, transcription, app distribution, security, diagnostics, hosting, support, legal, and business operations providers.

Current or conditionally used providers may include Squarespace, Firebase/Google services, Google Places/Google Maps, OpenAI or another configured AI/transcription provider, Apple, Google, and other providers selected by Rainbase.

12.2 Customer owners, administrators, and authorized users

Customer owners and administrators may access, manage, archive, delete, export, or restrict workspace information according to roles, permissions, app controls, and business decisions. Team-member activity, customer records, job records, files, reports, communications, calendar events, or other workspace records may be visible to other Authorized Users depending on the Customer’s configuration and permissions.

12.3 User-directed sharing

If a user shares, exports, opens, previews, sends, or downloads a file, report, photo, PDF, address, phone number, or other record, Rainbase may provide that information to the operating system, device app, external app, recipient, or destination selected by the user.

12.4 Legal, safety, and compliance

Rainbase may disclose information if Rainbase believes disclosure is required or appropriate to comply with law, legal process, court orders, subpoenas, government requests, regulatory obligations, security incident response, fraud prevention, abuse investigation, rights enforcement, dispute resolution, or protection of the rights, property, safety, or security of Rainbase, Customers, users, homeowners, or others.

12.5 Business transactions

Rainbase may disclose, transfer, or make available information in connection with an actual or potential merger, acquisition, financing, investment, due diligence, reorganization, bankruptcy, receivership, asset sale, corporate transaction, or similar business transaction, subject to appropriate confidentiality and legal protections where applicable.

12.6 Aggregated or de-identified information

Rainbase may disclose aggregated, de-identified, or statistical information that is not intended to identify a specific individual, such as product usage trends, performance summaries, operational metrics, or business analytics.

12.7 No sale or targeted advertising

Rainbase does not sell personal information. Rainbase does not share personal information for cross-context behavioral advertising or targeted advertising. Rainbase does not currently use advertising SDKs inside the mobile app.

13. Cookies and Website Analytics

Rainbase’s website is hosted by Squarespace. Squarespace may use cookies and similar technologies to provide, secure, operate, analyze, improve, and protect the website.

These technologies may include necessary cookies required for the website to function and analytics or performance cookies that help understand website traffic and activity, depending on Rainbase’s website settings and any cookie banner or consent settings.

Website visitors may be able to control cookies through browser settings, device settings, or website cookie controls where available. Blocking necessary cookies may affect website functionality.

Rainbase does not currently use advertising pixels or cross-context behavioral advertising technologies on the Rainbase website or in the mobile app based on the current information available to Rainbase. If Rainbase later adds advertising pixels or targeted advertising tools, Rainbase will update this Privacy Policy and provide legally required choices before doing so.

14. Retention, Deletion, and Backups

Rainbase retains personal information only as long as reasonably necessary to provide Rainbase, maintain Customer-selected records, support app functionality, comply with legal obligations, resolve disputes, prevent fraud or abuse, maintain security, preserve necessary business records, and support legitimate business operations.

14.1 Local device data

Because the current Rainbase mobile app stores much workspace data locally on the user’s device, local customer records, files, photos, PDFs, reports, metadata, transcripts, calendar entries, communications, notifications, assistant history, app settings, and related records generally remain on that device until:

deleted by the user through app controls;

hard-deleted where a hard-delete flow is available;

removed through a Customer or Rainbase deletion process;

cleared by app reset or app data deletion;

removed by uninstalling the app;

removed by the device or operating system; or

removed through future retention controls implemented by Rainbase.

Archiving is not deletion. Archived records may remain stored and may be visible to authorized users until restored or hard-deleted.

14.2 Customer records and files

Customers and Authorized Users may archive, restore, delete, or hard-delete certain records where app controls allow.

Archiving is not deletion. Archived records may remain stored and may be visible to authorized users until restored or hard-deleted.

Hard-delete flows are intended to delete the relevant local customer records, files, photos, PDFs, reports, technical file metadata, transcript references, saved transcript records, communications, and related local state where technically feasible.

Some cleanup may be best-effort and subject to device storage behavior, operating-system behavior, file availability, app state, errors, backups, provider retention, or legal exceptions.

14.3 Company/account deletion

If a Customer requests cancellation and deletion of its Rainbase company/workspace account, Rainbase generally aims to delete or de-identify Rainbase-controlled account, company, membership, and related business records within 30 days after Rainbase verifies the requester’s authority, confirms the requested deletion scope, and confirms that deletion is appropriate, unless retention is required or reasonably necessary for legal, security, fraud-prevention, dispute, tax, accounting, compliance, contractual, or business-record purposes.

Because Rainbase currently stores much workspace data locally on user devices, company deletion by Rainbase may not automatically remove every local copy from every Authorized User’s device unless the app provides and completes a local deletion or reset flow on that device. Rainbase may provide instructions or app controls to help Customers and Authorized Users remove local data.

14.4 Firebase and provider data

Firebase, Google, Squarespace, OpenAI, Apple, device platforms, app stores, and other providers may retain information according to their own terms, privacy policies, security practices, and legal obligations. Rainbase may need to coordinate with providers or use provider tools to delete, disable, or de-identify certain provider-hosted data.

14.5 AI and diagnostic data

Local assistant message history is designed to retain only recent messages, currently capped to the most recent 50 messages in the audited app behavior. Rainbase provides a local control to clear assistant history for the current workspace and user.

Local development diagnostic logs for AI routing are intended to be short-lived and limited, currently designed around a 14-day retention window and daily event cap in development tooling. Rainbase also provides a Super Admin development control to clear local diagnostic logs from the device.

Rainbase does not intentionally store raw prompts solely for general analytics. Prompts, transcripts, and assistant messages may still be retained locally as feature history or user-selected records.

14.6 Website contact forms and support records

Rainbase may retain website contact-form submissions, support communications, onboarding communications, and related business records for as long as reasonably necessary to respond to the request, manage the business relationship, maintain records, resolve disputes, comply with law, or support business operations.

14.7 Backups

Rainbase does not currently claim a production Rainbase cloud backup retention schedule for Customer Content in the audited mobile app. Local device data may be included in device-level, iCloud, platform, mobile-device-management, or operating-system backups depending on the user’s device settings and platform behavior. Those backups may be controlled by the user, device administrator, operating system, or platform provider rather than Rainbase.

15. Customer and User Controls

Depending on role, permissions, account type, device, and feature availability, Customers and Authorized Users may be able to:

sign in and sign out;

manage local session state;

manage company users, roles, permissions, and templates;

create, edit, archive, restore, or delete customer records;

create, edit, delete, or share files, photos, PDFs, and reports;

create, edit, delete, or manage local calendar events;

create, edit, or delete communications;

clear assistant history for the current workspace and user;

clear local notifications for the current workspace and user;

use or avoid voice transcription;

use or avoid Google Places address autocomplete;

enter addresses manually;

control camera and microphone permissions through device settings;

control photo-library access through device settings where supported;

share or not share files through the native share sheet;

delete app data or uninstall the app; and

contact Rainbase for account deletion, workspace deletion, or privacy requests.

Rainbase provides app-facing privacy, support, and deletion-request controls and may add or improve additional privacy controls as the product matures.

16. Privacy Requests

Privacy requests may be sent to support@rainbase.io.

Depending on applicable law and the nature of the relationship with Rainbase, individuals may request access, correction, deletion, portability, restriction, opt-out of certain processing, appeal of certain decisions, or other privacy rights.

Rainbase may verify the requester’s identity before responding, such as by requiring the requester to confirm access to an email address, authenticate into an account, provide information matching Rainbase records, confirm company authority, or complete another reasonable verification step.

Rainbase may deny, limit, or delay a request where permitted by law, including if Rainbase cannot verify the requester, if the request conflicts with legal obligations, if the information is controlled by a Customer rather than Rainbase, if the information is necessary for security or fraud prevention, if the request is excessive or fraudulent, if retention is legally required, or if compliance is technically infeasible.

If a request relates to Customer Content or End Customer Data controlled by a Rainbase business Customer, Rainbase may direct the requester to the Customer. For example, a homeowner whose information was entered into Rainbase by a contractor may need to contact that contractor because the contractor controls the underlying business record.

Where legally required, Rainbase generally intends to respond to verified privacy requests within 45 days. If additional time is reasonably necessary, Rainbase may extend the response period where permitted by law and provide notice where required.

17. Account Deletion

Rainbase currently supports sign-in to existing Firebase-backed accounts. If a Customer or Authorized User wants to delete an account, company workspace, or associated Rainbase-controlled data, the request may be sent through the app’s Privacy & Support section or to support@rainbase.io.

Rainbase provides an in-app request path for account or workspace deletion through the app’s Privacy & Support section. This request path does not automatically delete data. Rainbase may require verification from the Customer owner or an authorized administrator before deleting account, company, workspace, or business records. Customers and Authorized Users may also request deletion by contacting support@rainbase.io.

Rainbase generally aims to delete or de-identify Rainbase-controlled account, company, membership, and related business records within 30 days after Rainbase verifies the requester’s authority, confirms the requested deletion scope, and confirms that deletion is appropriate, unless retention is required or reasonably necessary for legal, security, fraud-prevention, dispute, tax, accounting, compliance, contractual, or business-record purposes.

Rainbase may require confirmation from the Customer owner or authorized administrator before deleting a company workspace or business records. Deleting a company workspace may be permanent and may remove customer records, files, reports, metadata, transcripts, calendar entries, communications, settings, and related local or provider-controlled records where technically feasible.

18. Security

Rainbase uses reasonable administrative, technical, and organizational safeguards designed to protect personal information and Customer Content.

Current safeguards may include Firebase authentication, database security rules, role-based access controls, local permission checks, local file path restrictions, app sandboxing, HTTPS/TLS for supported provider connections, provider security controls, limited cloud reads, internal access limits, development/testing boundaries, diagnostic controls, and deletion/cleanup flows.

No method of transmission, processing, or storage is perfectly secure. Rainbase cannot guarantee absolute security.

Customers and Authorized Users are responsible for maintaining the security of their own devices, accounts, passwords, authentication factors, app access, roles, permissions, local files, exports, share-sheet actions, and connected services.

Rainbase does not currently claim SOC 2, ISO 27001, HIPAA, PCI DSS, or similar formal security certifications unless Rainbase expressly states otherwise in writing.

19. Sensitive Data and Prohibited Uses

Rainbase is intended for contractor, exterior company, roofing, restoration, CRM, operations, inspection, document, workflow, and related business use.

Rainbase is not intended for medical, healthcare, HIPAA-regulated, legal, education, child-directed, government-benefit, employment, credit, housing, high-risk, or regulated decision-making use cases.

Customers and users must not submit, upload, store, dictate, or process the following through Rainbase unless Rainbase has expressly enabled and documented support for that specific category:

Social Security numbers;

government IDs;

driver’s license numbers;

passport numbers;

protected health information;

HIPAA-regulated data;

full payment card numbers;

payment card security codes;

bank account numbers;

passwords;

secrets;

API keys;

private keys;

biometric templates;

sensitive authentication data;

children’s personal information; or

other highly sensitive information.

Rainbase may delete, restrict, quarantine, or require removal of prohibited or unsupported sensitive information if Rainbase becomes aware of it.

20. Children and Age Restrictions

Rainbase is not directed to children under 13 and does not knowingly collect personal information directly from children under 13.

Rainbase is designed for business use. Business account owners and administrators must be at least 18. Employee, contractor, field, or crew users must be at least 16 and must be authorized by the Customer, employer, parent or guardian where required, or another legally appropriate party to use Rainbase in connection with their work.

Customers must not invite or permit children under 13 to use Rainbase.

If Rainbase learns that it has collected personal information directly from a child under 13 without required consent, Rainbase will take reasonable steps to delete the information or otherwise comply with applicable law.

21. U.S.-Only Intended Use and International Processing

Rainbase is currently intended for use in the United States.

Rainbase does not currently target users in the European Union, United Kingdom, or other non-U.S. jurisdictions. If Rainbase later expands outside the United States, Rainbase may update this Privacy Policy and implement additional privacy notices, data-transfer terms, consent flows, or legal mechanisms where required.

Even though Rainbase is intended for U.S. use, Rainbase and its providers may process information in the United States or other locations where they operate. Those locations may have privacy laws different from the laws where an individual lives.

22. State Privacy Notices

Residents of states with comprehensive privacy laws, such as California, Texas, Minnesota, and other states, may have certain rights depending on the law, the person’s relationship with Rainbase, Rainbase’s size and activities, and whether a particular law applies.

Rainbase provides this Privacy Policy to describe:

categories of personal information processed;

sources of personal information;

purposes for processing;

categories of service providers and third parties;

retention approach;

privacy request methods; and

choices available to Customers and users.

Rainbase does not sell personal information. Rainbase does not share personal information for cross-context behavioral advertising or targeted advertising. Rainbase does not intentionally process sensitive personal information for purposes other than providing, securing, debugging, supporting, or improving Rainbase, complying with law, or fulfilling Customer-requested features.

Rainbase will not discriminate against individuals for exercising privacy rights where applicable law prohibits discrimination. Some information is necessary to provide Rainbase, and deleting or restricting that information may affect access to or functionality of the service.

23. Communications

Rainbase may send transactional or relationship communications, including account notices, support responses, onboarding communications, security notices, product updates, service notices, deletion confirmations, and administrative messages.

Rainbase may send marketing communications where permitted by law. Users may opt out of marketing emails by following the unsubscribe instructions in those emails or by contacting Rainbase.

Rainbase does not currently operate an external SMS marketing provider or push-notification provider in the audited mobile app. If Rainbase later adds SMS, push notifications, or email marketing tools, Rainbase will update disclosures and provide legally required choices where applicable.

24. Third-Party Services

Rainbase may link to, integrate with, or rely on third-party services. Current or conditionally used examples include Squarespace, Firebase/Google services, Google Places, Google Maps, OpenAI or another configured AI/transcription provider, Apple, Google app/platform services, device operating systems, and user-selected share-sheet destinations.

Third-party services may collect, use, store, disclose, or retain information under their own terms and privacy policies. Rainbase is not responsible for third-party privacy practices except where required by applicable law or Rainbase’s contracts with those providers.

If a user chooses to share or export content to another app or service, that destination’s privacy practices apply to the shared or exported content.

25. Changes to this Privacy Policy

Rainbase may update this Privacy Policy from time to time.

If Rainbase makes material changes, Rainbase will provide notice as required by law, such as by updating the “Last Updated” date, posting the updated policy on the website, providing an in-app notice, sending an email, or using another appropriate notice method.

Continued use of Rainbase after an updated Privacy Policy becomes effective means the updated Privacy Policy applies to personal information processed after the effective date, subject to applicable law and Customer agreements.

26. Contact

For privacy questions, requests, or concerns, contact Rainbase at:

Rainbase LLC
Minnesota, United States
Email: support@rainbase.io

Rainbase may update this contact information before publication or after obtaining a dedicated privacy email address, mailing address, PO box, commercial mailbox, or support portal.