Effective date: October 2, 2026
OperatorCore and Aqua Tech Resources
OperatorCore is a water and wastewater operations platform provided by Aqua Tech Resources LLC. Aqua Tech Resources LLC is responsible for operating the platform and handling information as described in this policy.
Information we collect
Account information
When you create or use an account, we may collect your name, email address, phone number, state, employer, job title, organization, account status, license information, and password credentials in protected form.
Subscription and billing information
We may collect subscription plan, status, billing contact, organization name, seat count, invoice request, transaction identifiers, and subscription dates. Individual card information is entered directly with Stripe; Aqua Tech Resources does not receive or store full payment-card numbers through OperatorCore.
App and training information
We may collect assigned programs, course progress, practice-test attempts and results, account preferences, demo access, and form-delivery email addresses.
Operational records and files
We collect information entered into asset and component inventories, equipment nameplate records, standard and organization-created forms, work orders, bench sheets, calibration and inspection records, permit-limit settings, organization settings, and other operational tools. Organization form settings may include form names and categories, department access, field identifiers and labels, dropdown choices, required-field rules, engineering units, numeric ranges and decimal precision, conditional logic, layout choices, and parent-to-child field mappings. Asset records may include supported JPG, PNG, WebP, or PDF attachments, filenames, file types, and storage identifiers. Saved and submitted operational records may be stored with an individual account or with the organization to which the record belongs.
Other information you submit
We collect information you enter into contact forms, support requests, account settings, resource-link requests, and other app features. Some form drafts may be stored locally on your device until submitted or cleared.
Technical, usage, and security information
We may collect the requested page or shortened route, approximate time, referring source, device category, browser-generated request information, response status and timing, Core Web Vitals (LCP, INP, and CLS), page-load, document-readiness, and time-to-first-byte measurements, and security or diagnostic logs. Server-side diagnostic events may also include database query count and timing, error count, and aggregate rows read or written; scheduled storage snapshots may include database size and aggregate counts of organizations, users, assets, and maintenance records. These diagnostic events do not include SQL text, query values, completed form contents, names, or email addresses. For login abuse detection, the service may create one-way hashes derived from an email address or network address. The website’s basic traffic reporting is designed not to store visitor names, email addresses, or IP addresses as analytics fields.
How we use information
- Provide, operate, secure, and improve the website and app.
- Create and manage accounts, permissions, organizations, and training records.
- Generate, email, and retain requested forms or records.
- Respond to inquiries, support requests, and password-reset requests.
- Send administrative or service-related communications.
- Diagnose errors, prevent misuse, and protect users and systems.
- Comply with legal obligations and enforce applicable agreements.
How information is shared
We do not sell personal information. Information may be shared with service providers that support hosting, object and database storage, authentication, email delivery, payment processing, security, weather, maps, routing, educational media, and website operations; with an organization administrator when your account belongs to that organization and the feature requires organizational reporting or record management; with authorized Aqua Tech Resources platform administrators who operate, support, secure, or administer the organization and its records; when you direct us to send a form or record to selected recipients; or when disclosure is required to comply with law, protect rights and safety, or complete a business transaction.
Organization accounts
If an account is connected to an employer, municipality, utility, client, or other organization, authorized organization administrators may receive, review, edit, or manage information needed to administer that relationship, including account identity, roles, assignments, progress, completion information, asset inventories, uploaded files, organization settings, work orders, and submitted records. Aqua Tech Resources platform administrators have administrative visibility across organizations for platform ownership, support, security, onboarding, and authorized record management. Organization users remain limited to records made available within their own organization. OperatorCore associates organization records with an organization identifier and applies organization and account ownership checks when records are read, changed, linked, emailed, or generated. Page-context checks are also used to prevent a stale page from saving after an account or organization context changes. Users should not enter sensitive facility, personnel, security, or regulated information unless authorized by their organization and necessary for the intended feature.
Email and form delivery
When you ask the app to email a form, the completed record and associated information are sent through the email-delivery provider to you and the addresses configured for that form category. Verify recipients before submitting. OperatorCore also uses email delivery for sign-in codes, account recovery, welcome messages, reminders, and subscription or demo requests.
Location, weather, maps, and routing
Some tools may request your device location through the browser. Location access occurs only after browser permission, and a manual-entry option may be available. Coordinates may be sent through OperatorCore to the National Weather Service or an OpenStreetMap-based routing service to return weather or route information. OpenStreetMap map tiles may receive ordinary browser request data. Location is not added to an account profile solely because permission was granted, but location information may be retained if you save or submit it as part of a form or record.
Cookies, sign-in, PINs, and local device storage
The website and OperatorCore use secure session cookies for signed-in administrator and operator access. Operator sessions ordinarily expire after eight hours. Operator sign-in uses a password and an emailed verification code; the code expires after a short period. If you choose to trust a device, a secure cookie and a hashed device token may be retained for up to 30 days.
Operators may create a four-digit PIN used to confirm sensitive actions and identify the operator, sampler, or analyst making an entry. OperatorCore stores an encrypted copy of the PIN so it can be recovered by email and a separate one-way fingerprint used to verify entries and prevent duplicate PINs. Answers to three selected recovery questions are stored as protected one-way password hashes. After all three answers are verified, the PIN may be decrypted and sent to the registered account email through the email-delivery provider. Administrators cannot view the PIN through OperatorCore administration pages. PIN and recovery-attempt records are subject to rate limiting and security logging. A PIN is not a substitute for the account password or emailed sign-in code.
The app may also use browser storage, a service worker, and device caches to support installation, offline assets, calculator favorites, a remembered facility selection, saved preferences, in-progress form drafts, and device-local information used to identify unsynced drafts. Clearing browser data or uninstalling the app may remove locally stored information and may sign you out, but it does not by itself delete account information or server-stored records.
Cross-device saving and record history
When an open account-saved form is changed, OperatorCore may compare the version originally opened on the device with the current server record. If another save changed the server record first, the stale save is rejected instead of overwriting the newer record, and the entries on the current device remain available for the user to review or reconcile. For supported records, OperatorCore stores the prior form content and timestamp for the 20 most recent changed saves. That history remains scoped to the record owner and associated organization and is available to the signed-in record owner for selective recovery. Applying selected historical entries does not restore protected identity, confirmation, or locked fields and does not sign or complete the form.
Data retention and account deletion
Information is retained for as long as reasonably necessary to provide OperatorCore, maintain training, asset, work-order, maintenance, calibration, compliance, or business records, resolve disputes, meet legal obligations, and protect the platform. Users may close their account through My Account, and an administrator may permanently delete an account. Closing an account immediately disables sign-in and schedules personal account information for permanent deletion after 30 days unless the account is reactivated first.
Records belonging to an organization—including assets, attachments, work orders, maintenance records, onboarding history, and other operational records—may remain with that organization after an operator account is deleted. When a technical record must remain linked for record integrity, OperatorCore removes or replaces the former operator’s account details and disables all sign-in access rather than deleting the organization-owned record. Independent-account assets and their stored attachments are deleted with the account. Deletion may not remove information that Aqua Tech Resources must retain separately to meet legal, contractual, financial, safety, or regulatory obligations. Security login-attempt records may be retained for approximately 30 days, application diagnostic events for approximately 90 days, and administrator audit records for approximately one year.
Managed WeatherLink and service requests
When an organization enables Managed WeatherLink, its administrator may provide Davis WeatherLink API credentials for a facility. OperatorCore encrypts the key and secret before storing them and uses them to discover stations and request current or historical weather for assigned facilities. Station identifiers, names, coordinates, time zones, facility assignments, and connection status may be stored with the organization. Disabling the add-on retains the encrypted credentials and assignments for later reactivation. WeatherLink receives requests needed to provide station data and applies its own terms and privacy practices.
Service requests record the selected facility, area or equipment, issue, priority, operating impact, safety concern, description, requested completion date, requester name, contact phone, account and organization identifiers, and request status. These records are available within the organization and to authorized platform administrators for operational management.
Permit profiles, monitoring requirements, and comparison flags
An authorized organization administrator may save a permitting state, issuing agency, facility, permit number, issue, effective, and expiration dates, facility address, receiving water and downstream stream network, an optional protected permit-reference PDF, and monitoring requirements. Monitoring requirements may include an outfall or monitoring location, parameter, unit, phase, concentration or loading limits, sampling frequency and type, seasonal months, and instantaneous screening limits. OperatorCore may compare organization-defined instantaneous limits with supported form readings and display a flag when a reading appears outside a configured range. Permit settings and flags remain associated with the organization and are available to authorized organization users and platform administrators. A flag is an operational aid, not an official compliance determination, regulator submission, permit interpretation, or substitute for reviewing the current permit and agency requirements.
Asset QR labels and scanner
Authorized users may generate printable QR labels for asset records. The QR image is rendered by QuickChart and encodes an OperatorCore asset-page URL that contains the asset record identifier. When the label image is generated, QuickChart receives the encoded URL and ordinary request information under its own privacy practices. Scanning a label opens the OperatorCore asset page; a signed-in, authorized account is still required to view the organization-scoped asset and its work history.
The QR Scanner uses the device camera only after browser permission or processes a photo selected by the user. Camera frames and selected QR photos are decoded in the browser with bundled scanner code; OperatorCore does not upload or retain those images as part of the scan. Camera access stops when the scanner closes or the page becomes hidden. Opening a scanned external link may disclose ordinary request information to the destination site.
Organization-created forms and linked records
Authorized organization administrators may create forms and change eligible organization form settings. These settings are stored with the organization and can affect the fields, layout, warnings, calculations, required entries, and choices shown to its users. Shared measurement settings can apply an allowable range and decimal precision to matching units across organization forms; out-of-range readings are flagged but remain recordable.
When a user creates a configured child record, OperatorCore copies only the selected mapped values from the parent at that time and stores a link between the records. Later parent changes do not automatically change the child. Organization-created records retain a snapshot of their configured field definitions so that later template changes do not silently alter the meaning of a closed record. Completing an organization-created form may produce a PDF and send it through the email-delivery provider to the organization’s configured form recipients.
Automatically created, scheduled, and saved records
For organizations using weekly process workflows, OperatorCore may create dated process-round, calibration, plant-inspection, wasting, and related bench-sheet drafts in the organization’s account. The app may save changes to an open form record as fields are entered. These records can contain facility and equipment information, operator, sampler, and analyst identities, sample and test times, operational readings, weather or forecast information, notes, confirmations, and links between related records. Some linked records or work orders are created only when a user chooses the applicable action. A locally saved draft may also remain on the device. Organization administrators and authorized platform administrators may access organization records as described above.
Authorized organization users and eligible paid independent operators may create preventive-maintenance schedules containing task instructions, asset and location references, recurrence settings, advance-creation timing, start and end dates, status, and a snapshot used for generated work orders. OperatorCore may automatically create separate dated work orders from an active schedule. Pausing or canceling a schedule affects future generation and does not by itself remove work orders already created. Completed preventive-maintenance records may be rendered as PDFs and sent through the email-delivery provider.
Deleted operational records
When an authorized user deletes a supported form or work order, OperatorCore may mark it as deleted instead of removing it immediately. Authorized administrators may be able to restore a deleted record for up to 30 days, after which the application may permanently remove it. Related bench, calibration, reminder, or link information may also be removed or updated to preserve record consistency.
Service providers and external services
OperatorCore currently uses Stripe for individual payment checkout, Resend for email delivery, and QuickChart to render asset QR-code images. Certain optional tools use National Weather Service data, Davis WeatherLink, OpenStreetMap maps or routing, and Wikimedia Commons educational media. Hosting, database, object-storage, security, and related infrastructure providers also process information needed to operate the service. Each provider handles information under its own terms and privacy practices.
Preventive-maintenance generation status
For accounts or organizations using preventive-maintenance schedules, OperatorCore may retain the most recent generation-attempt time, successful-generation time, and status so a generation problem can be identified and shown to an authorized user.
Security
We use reasonable administrative and technical safeguards designed to protect information, including protected password storage, two-step operator sign-in, secure session cookies, organization- and account-scoped authorization checks, stale-page context checks, and limited retention of certain operational logs. OperatorCore also performs automated checks for inconsistent organization ownership and record links. No internet transmission, email system, or storage method is completely secure, so absolute security cannot be guaranteed.
Your choices
You may update available account information in the app. You may request correction or deletion of personal information, subject to legal, security, contractual, and record-retention requirements. You can clear locally saved form drafts using the form controls or your browser settings.
Children’s privacy
The website and app are intended for adults and workforce training. They are not directed to children under 13, and Aqua Tech Resources does not knowingly collect personal information from children under 13.
Third-party links
Links to third-party websites, agencies, videos, or resources are governed by their own privacy practices. Review those policies before providing information.
Changes to this policy
This policy may be updated as features or legal requirements change. The effective date will be revised when a new version is posted.
Contact
For privacy questions or requests, email info@aquatechresources.com.