IrriFlow
IrriFlow · Privacy Policy

Privacy Policy

What IrriFlow collects, why, who else sees it, how long we keep it, and how to get rid of it.

version 0.2updated 2026-09-12Raff’s Company Limited
Draft — pending counsel reviewThese documents are a draft, not in force yet, and no lawyer has reviewed them — counsel has not signed off and nothing here is legal advice. They are published in the app so you can read what we intend to commit to, and so you can tell us if any of it is wrong.

Who we are

IrriFlow is made by Raff’s Company Limited (“RCL”), of Houston, Texas. We are responsible for the information described here. Our registered address is [REGISTERED ADDRESS — NOT SUPPLIED] and you can reach us at irisupport@raffscompanylimited.com.

IrriFlow has two sides. Homeowners use it free, to describe a problem and find an irrigation technician near them. Technicians pay for it, to run their business — their calendar, their customers, their van, their invoices. This policy covers both, and says which is which wherever it matters.

What we collect

Your email address, because it is how you sign in. There is no password. We email you a six-digit code, and we keep the code — hashed, never in the clear — with the address and the IP address the request came from, for one day. An account created before sign-in moved to email carries the phone number it signed in with, kept the same way.

If you are a homeowner asking for help, we also collect:

  • The zipcode you type, so we can show you technicians who cover it.
  • What is wrong — the category you tap and anything you write.
  • Photographs of the problem, if you attach any.
  • Your first name, if you give it, so a technician knows who they are talking to.
  • The messages you send, and the technician’s replies.
  • A property address, once you choose to share it with a technician you have picked.

If you are a technician, we also collect:

  • Your business name, the business email and phone you put on your invoices, and the area you cover.
  • Your licence and insurance documents, and their expiry dates.
  • A neighbourhood point you nominate for the map. Not your address — see below.
  • Your customers: names, phone numbers, addresses, job history, notes and invoices.
  • Your work: jobs, close-outs, photographs, parts used, prices, estimates and invoices.
  • What is on your van, what you bought to restock it, and what your business spends.

We do not use advertising identifiers, we do not run a third-party analytics SDK, and we do not buy information about you from anybody.

Addresses, and who can see one

A homeowner describing a leak is not inviting a stranger over. So a technician sees your zipcode, your city and your state — and nothing more precise — until you share your address with the technician you have chosen. Where a map has to show your general area, the point is deliberately blunted to about a kilometre, by truncation rather than rounding, so it never lands on your house.

The mirror of that rule protects technicians. Most sole operators work from home, so a technician’s home address is never published. The pin a homeowner sees is a separate neighbourhood point the technician nominates, and the public card the app builds cannot carry a home address — that is enforced in the database, not by a check somebody has to remember.

When an address is saved, we send it to a geocoding service to turn it into a point on a map, so the calendar can judge whether a day’s work is on the way. Whichever service that is receives the address text and nothing else — no name, no phone number, and nothing about the job. Today it is the United States Census Bureau’s public address geocoder, which needs no account and returns a point on the street segment rather than on the building. If we buy a Google Maps key for a more precise answer, Google receives the same address text and we will say so here.

Photographs

Photographs are the most revealing thing this product handles, so they get the most rules.

  • Location data is stripped from a photograph on your phone, before it is uploaded. Every path — camera, library, and every retry — goes through the same strip.
  • The upload goes from your phone straight to storage. Our servers never hold the file.
  • Our servers re-check the uploaded file and refuse one that still carries location data, and delete it.
  • Photographs are private. A photograph of somebody’s property only ever appears on a technician’s public card if the household in it says yes — and the answer is recorded against that exact photograph and that exact household.
  • Nobody at RCL browses your photographs. Support can open one only when there is an open report or warranty claim behind it, and every one of those views is written to a permanent record that we cannot delete.

A homeowner can withdraw permission for a published photograph at any time and it comes down. Photographs held as evidence in an open dispute or warranty claim are the one exception: they survive a deletion request while the claim is open, because a record of what was actually done to somebody’s system protects both sides of it.

Messages and notifications

Messages between a homeowner and a technician are stored so both of you can read the thread later. We do not read them for advertising and we do not sell them. We look at a thread when somebody reports it, and when the law requires it.

Push notifications go through Expo’s push service, which hands them to Apple or Google to reach your phone. What leaves our servers is your device’s push token, a title, a short line of text, and a few identifiers. The title of a message notification is a first name and a zipcode — “Sarah · 77008” — and never a word of what was said. That is a deliberate limit, not a side effect of the design.

We do not send marketing email or text messages. The only email the product sends is a six-digit code — to sign in, or to confirm deleting your account — and it carries no link and no tracking. Text messages are switched off.

Money

We record what a technician charged, what was paid, what they spent on parts, and what the platform charged them. Those records are a permanent double-entry ledger: entries are never edited or deleted, because a book you can rewrite is not a book.

When we add payments, a payment processor will handle the card and we will hold only what they hand back — the last four digits, the brand, whether a charge succeeded. We will update this policy to name the processor before a single card is charged, not afterwards.

An invoice a technician sends is a link the customer opens without an account. Anyone holding that link can see that invoice, so treat it the way you would treat the invoice itself. The link carries instructions telling browsers not to pass it on or cache it, and it is scrubbed out of our own logs.

Your phone’s contacts, and importing your book

A technician can add a customer from their phone’s contacts. The picker is the operating system’s, so the app never reads your address book — you choose one contact and only that contact’s name, phone number and email are handed over.

A technician can also paste a spreadsheet of their existing customers. Those rows are the technician’s own business records. As we write them we check each phone number against IrriFlow accounts, for one purpose only: a customer the technician already had must never be charged for as a new lead.

How we measure whether the app works

We count seventeen things: the app being opened, a side being chosen, sign-in starting and succeeding, onboarding steps finishing, a client being created, a job being booked, started and closed out, an estimate, an invoice, a payment, a message, a review, and two lead events. That is the whole list, it is enforced in three places including the database, and an event with a name that is not on it is refused.

  • The measurements are counts and fixed choices — how many lines were on a close-out, which payment method, which onboarding step. There is no field anywhere in that list that a person typed into.
  • No names, no phone numbers, no addresses, no message text, no review words, no amounts of money.
  • Who did it comes from your signed-in session, never from anything the app claims. Before you sign in, only three of the seventeen can be sent at all.
  • It is stored in our own database. There is no analytics vendor and no advertising network in this product.
  • It is deleted after 180 days, by our clock rather than your phone’s, and the database will not let anyone edit one after the fact.

When the app breaks

Crash reporting is built and switched off. Nothing is sent today. When we turn it on, reports go to Sentry, and everything on the way out is stripped: request bodies and headers are dropped rather than cleaned, sign-in tokens and signed links never travel, and phone numbers, email addresses, street addresses and verification codes are scrubbed by pattern from anything that is left. You are identified in a crash report by a random account identifier and by nothing else.

Our server logs go to Microsoft Azure and are scrubbed by the same rules on the way out, because a log export is a copy of this product’s information with none of its permissions attached.

Who else sees it

The complete list of companies that touch your information today:

  • Microsoft Azure — hosting. Our servers, our database and our logs run there, in the United States. The database has no public address and is encrypted at rest and in transit.
  • Cloudflare R2 — private photograph storage. Your phone uploads straight to it and every view is a link we sign for one file, for a few minutes. It is the only company that holds a photograph other than us.
  • Expo — the app’s over-the-air updates and its push notifications. Expo receives an update check from the app and, for a notification, a push token and the short line of text described above.
  • Apple and Google — they carry a push notification the last step to your phone, and they distribute the app itself.
  • The United States Census Bureau’s public geocoder — an address, to turn it into a point on a map. Nothing else about you goes with it.
  • Every company on this list is held to the same protection you have here: it may use what it receives only to do the job named beside it, never for its own purposes, and never to sell.

And when the features that need them ship:

  • Postmark — delivers your sign-in code by email. It receives your email address and the message with the code in it, and nothing else. Built; switched on when our sending domain is verified.
  • A text-message provider, only if sign-in by phone comes back. Built and switched off.
  • Sentry — crash reports, as described above. Built, switched off.
  • A payment processor, when payments ship. Nothing is connected and no card reaches us.
  • A bank-connection provider, if we build the accounting import a technician has asked for. Not started. It would be optional and a technician would connect it themselves.

We will hand over information when the law requires it — a subpoena, a court order, a genuine emergency involving somebody’s safety. If we are ever bought, the information moves with the business and this policy moves with it until we tell you otherwise.

How long we keep it

  • Sign-in codes and the addresses or numbers they were sent to: one day. A sweep runs every six hours and deletes them in batches.
  • The stored copy of a request’s response, which we keep so a retried tap cannot file the same job twice: one day, deleted by the same sweep.
  • Product measurements: 180 days.
  • Signed-in devices: a session ends after 30 days, or after 14 days without being used, and you can end one yourself from Account. The address and device description on it are erased the moment it ends; the record that it existed is deleted 30 days after that.
  • Photographs that were started and never finished uploading: about a day, then the bytes are deleted.
  • On your phone: a photograph you take for a close-out, and the close-out draft itself, stay on the handset only until the photograph has reached us and the close-out is filed, or until you sign out — and are deleted from the phone then. They are never written into the phone’s camera roll.
  • Messages, jobs, close-outs, invoices and the ledger: kept while your account is open, and kept afterwards where tax and accounting law requires it.
  • Server logs: as long as our hosting keeps them, scrubbed of personal information on the way in.

What you can ask us to do

Texas has no general consumer-privacy statute of the kind California and several other states have, and we are not going to make you find out which state you are in before you can ask us something. These apply to everybody:

  • Get a copy. Ask and we will send you what we hold about you in a format another program can read.
  • Correct it. Most of it you can edit in the app; for anything you cannot, ask us.
  • Delete it. See the next section for exactly what deletion does and what it cannot touch.
  • Take your business with you, if you are a technician. Your client book, your job history and your invoices are yours, exportable, including after you cancel. We do not hold a business hostage to keep it paying.
  • Complain, and be answered by a person.

Ask at irisupport@raffscompanylimited.com. We answer within 30 days. Today an export is something we run for you when you ask; a self-service export button is on the list and is not built.

IrriFlow is not for children. It is a tool for running an irrigation business and for hiring one, and we do not knowingly collect anything from anyone under 18.

Deleting your account

Settings → Account → Delete my account. It takes two taps and the second one is a real confirmation rather than an alert nobody reads. Here is exactly what happens.

  • Your email address and phone number are erased, which also releases them so you can sign up again later.
  • Your name goes. For a technician, so do the business name, the biography, the business email and the business phone — a sole trader’s business name is usually their own name.
  • Your photographs are deleted from storage — the files themselves, not a flag on a record. That includes photographs of your property that a technician took, as well as ones you took yourself.
  • Every session is ended, on every device, in the same instant.
  • Every phone registered for notifications is switched off, so nothing arrives afterwards.
  • Your account is closed and stops working immediately.

Photographs are removed by the delete button — the files themselves, deleted from storage, not a flag on a record. There is one exception written into the code and it is deliberate: a photograph attached to an open warranty or dispute claim is evidence, and it stays while that claim is open. It is a homeowner’s proof of what was done to their system, so a technician leaving must not be able to erase it either. Today that exception cannot apply to anybody, because no job is covered by work protection yet — see below. Ask at irisupport@raffscompanylimited.com if you want to know whether anything of yours is being kept.

If your phone is lost or stolen, you do not have to delete your account. Settings → Account → Sign out of all devices ends every session everywhere, including the one on the phone you no longer have.

How it is protected

  • The database sits on a private network with no public address. Nobody connects to it from a laptop.
  • Everything in transit is encrypted, and everything at rest is encrypted.
  • Your sign-in token lives in the phone’s keychain, marked so it never leaves that device and never enters a backup.
  • A session lasts 30 days and does not extend itself. You can end them all at once.
  • The account our servers use cannot drop a table and can only delete from a short, listed set. A break-in cannot erase the evidence of itself.
  • Records of who viewed a private photograph, of every job transition, and of every ledger entry are append-only and cannot be edited or removed by the application at all.

No system is perfect and we are not going to claim ours is. If we ever have a breach that affects you, we will tell you what happened, what was in it, and what we did about it — plainly, and quickly.

Changes to this policy

When we change something that matters, we will tell you in the app before it takes effect, and the version and date at the top of this document will change. We keep every version.