This Privacy Policy describes how CoopTools LLC ("CoopTools," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the CoopTools platform, website, and Android mobile app (collectively, the "Service"). CoopTools provides field-operations software to electric distribution cooperatives — storm-recovery documentation, joint-use attachment management, inspections, expense tracking, land and easement records, and document e-signature.
Our role. For most data processed through the Service, the cooperative that subscribes to CoopTools (the "Cooperative") is the controller of that data, and CoopTools acts as a processor on the Cooperative's behalf. This means the Cooperative decides what data is entered and how it is used; we process it to provide the Service. If you are a member, employee, or contact of a Cooperative and have questions about your data, please contact that Cooperative directly. For data we collect as a controller — such as information from our website or from people who contact us — this Policy governs our own practices.
1. Information We Collect
1.1 Information Cooperatives Provide
When a Cooperative uses the Service, it and its authorized users submit data that may include:
- Cooperative operational data — pole records, storm-restoration documentation, joint-use attachment records, inspection records, land and easement records, and expense records.
- Personal information of the Cooperative's members, employees, contractors, and joint-use (attacher) contacts — such as names, email addresses, and signature information on electronically signed documents.
- Photographs and documents uploaded to the Service, which may include location metadata.
CoopTools does not decide what personal information a Cooperative submits; the Cooperative is responsible for the data it enters and for having a lawful basis to provide it.
1.2 Account and Authentication Information
To access the Service, authorized users sign in with credentials provisioned by their Cooperative or by CoopTools. Authentication is handled by our infrastructure provider; CoopTools does not store raw passwords. We process account information such as name, email, role, and Cooperative affiliation.
1.3 Location Data and Photos (Mobile App)
With your permission, the mobile app collects precise location (GPS) to tag field records — such as storm damage sites, pole locations, and easement capture — at the point of capture. Photos taken in the field may also carry location and time information (EXIF metadata) used to grade and document evidence. Map features process coordinates and addresses to display basemaps and look up locations. We do not use location for advertising, and we do not track your location in the background.
1.4 Information We Collect Automatically
When you use the Service, we and our infrastructure providers process limited technical information necessary to operate and secure the platform, such as request metadata, IP addresses, and timestamps. Specific examples:
- Document access is logged (actor, IP address, and timestamp) to maintain an audit trail for signed documents.
- When a document is signed through CoopTools, we record the signer's name, email address, signature, IP address, timestamps, and a record of consent, and generate a Certificate of Completion. This is necessary to produce a legally meaningful, auditable signed document.
- Public self-serve forms use a CAPTCHA challenge that processes the submitter's IP address and a browser challenge token to prevent abuse.
- Security and rate-limiting mechanisms process request metadata to protect the Service.
1.5 Information You Provide Directly to Us
If you contact us (for example, by emailing seth@cooptools.io, using the contact form on this website, or submitting feedback through the Service), we process the information you provide so we can respond and improve the Service.
2. How We Use Information
We use information to:
- Provide, maintain, and secure the Service.
- Authenticate users and enforce access controls and tenant (organization) isolation.
- Capture, store, and display field records, maps, photos, and documents.
- Generate exports, FEMA documentation, invoices, and signed documents.
- Deliver transactional communications, such as document signing requests, permit and inspection notifications, and signed-document copies.
- Respond to support requests and feedback.
- Detect, prevent, and address security incidents, fraud, and abuse.
- Improve the Service, using aggregated or de-identified information where practicable.
- Comply with legal obligations.
We do not sell personal information, and we do not use cooperative data or personal information for advertising.
3. The AI Help Assistant
The Service includes an optional in-application AI help assistant. When a user submits a question to the assistant, the text of that question, together with relevant help-article content, is sent to our AI provider (Anthropic) to generate a response. The assistant is designed to answer only from CoopTools help documentation, and our provider does not use these queries to train its models under our commercial terms. Users should not enter sensitive personal information into the help assistant; its purpose is to answer questions about how to use the Service.
4. How We Share Information
We share information only as necessary to operate the Service and as described below. We do not sell personal information.
4.1 With Your Organization
Data entered into a Cooperative's account is accessible to authorized users of that organization according to their roles.
4.2 Service Providers (Sub-processors)
We use trusted third-party providers to deliver the Service. Each processes only the data needed for its function:
| Provider | Purpose and data processed |
|---|---|
| Supabase | Core infrastructure — database, authentication, file storage, and server functions. Processes all application data and personal information. |
| Vercel | Web application hosting and content delivery. Processes request metadata; does not hold the database. |
| Backblaze B2 | Encrypted offsite backups. Receives an encrypted database backup and stored files. |
| GitHub | Source control and backup automation. The encrypted backup transits the automation runner. |
| Railway | Hosting for the optional read-only GIS map feed into a Cooperative's own ArcGIS. Processes pole and land-record coordinates and attributes for Cooperatives that enable it. |
| Resend | Transactional email delivery. Processes recipient names and email addresses and related message metadata. |
| Cloudflare | CAPTCHA protection on public forms. Processes the submitter's IP address and a challenge token. |
| Esri / ArcGIS | Map basemaps and geocoding. Processes pole coordinates and addresses. |
| Google Maps Platform | Street View and map embeds. Processes pole coordinates and addresses. |
| OpenStreetMap | Key-free basemap fallback on mobile. Processes map tile (viewport) requests. |
| Anthropic | AI help assistant. Processes the user's help-question text and help-article context. |
Some static assets (such as fonts and document-rendering scripts) are served from public content-delivery networks (for example, Google Fonts and unpkg), which process standard request metadata to serve those files. A current sub-processor list is maintained and available on request. If we add a sub-processor, we will update this list.
4.3 Legal and Protective Disclosures
We may disclose information if required by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect the rights, property, or safety of CoopTools, our customers, or others.
4.4 Business Transfers
If CoopTools is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction. We will provide notice and require the successor to honor this Policy or provide equivalent protection.
5. Cookies and Tracking
CoopTools does not use third-party advertising or analytics trackers. We do not use cookies or similar technologies to track you across websites or to build advertising profiles.
The Service uses a small amount of functional browser and device storage that is necessary for it to work — for example, to keep you signed in (your authentication session), to remember certain in-application preferences, and to hold field entries offline until they can sync. This functional storage is not used for tracking.
6. Data Retention
Because CoopTools acts as a processor for Cooperative data, we retain that data for as long as the Cooperative maintains its account, except where a specific retention period applies. The following retention practices are implemented and automatically enforced:
- Signed documents. Signed documents and associated personal information are retained for eighty-four (84) months (seven years) by default, after which an automated nightly process removes the document and personal information, leaving a non-personal record for audit purposes. A Cooperative may configure a different period, and may also erase personal information from a signed document on demand.
- Operational records. Storm, FEMA, and other operational records (pole records, permits, inspections, land and easement records, photos, and expense data) are retained for the life of the account. This reflects the multi-year record-retention expectations associated with federal disaster-assistance programs. These records are removed only through full account deletion.
- Audit logs. Document-access and administrative audit logs are retained for twenty-four (24) months and then automatically purged.
- Soft-deleted items. Items placed in a "trash" state (such as removed expense entries) are permanently purged after thirty (30) days.
- Backups. Primary database backups are retained on a rolling basis (approximately seven days). Encrypted offsite backups are retained according to our backup lifecycle policy.
- After account termination. Following termination, we make Cooperative data available for export for thirty (30) days. The Cooperative's data is then scheduled for deletion and permanently removed after a grace period (currently ninety (90) days), covering database records, stored files, and user logins. Account deletion is an explicit, administrator-initiated action and does not occur automatically based on billing status.
7. Security
We implement administrative, technical, and physical safeguards designed to protect information, including database-enforced tenant isolation, encryption in transit and at rest, private file storage with short-lived access links, access logging, and daily encrypted offsite backups. A detailed, regularly re-verified description is available on our Security page. No system can be guaranteed perfectly secure, but we work to protect data using industry-standard practices and to re-verify our core protections on an ongoing basis.
8. Your Choices and Rights
Depending on your jurisdiction and your relationship to a Cooperative, you may have rights regarding your personal information, such as the right to access, correct, export, or delete it.
- If you are a member, employee, or contact of a Cooperative, the Cooperative controls your data. Please direct requests to the Cooperative; we will assist the Cooperative in responding as its processor.
- Deleting your user account. If you hold a CoopTools user account, you can request its deletion from inside the application (Settings → Security → Delete account) or by contacting us at the address in Section 11. Deletion requests are processed within thirty (30) days; until processed, your account keeps working and you can cancel the request. Processing permanently removes your sign-in credentials, authenticator enrollment, and contact details (email address, phone number, employee number). Operational records your Cooperative is legally required to keep — such as storm work entries, signed documents, inspection records, and activity logs, including your name where it appears on them — are retained under the lawful-retention practices described in Section 6.
- You can disable location and camera permissions for the mobile app at any time in your device settings (some features will not work without them).
- If you interacted with CoopTools directly (for example, through our website), you may contact us at the address in Section 11 to exercise your rights.
- The Service also includes an on-demand "erase personal information" capability for signed documents, which a Cooperative administrator can use to honor erasure requests.
9. Children's Privacy
The Service is a business tool intended for use by cooperative staff and authorized partners in a workplace setting. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.
10. International Users
CoopTools is operated in the United States, and information is processed and stored in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
CoopTools LLC
Email: seth@cooptools.io
12. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a revised effective date and, where appropriate, provide additional notice. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.