Legal

Privacy Policy

Last updated 24 July 2026. Plain-language explanation of what we collect, why, and what you can ask us to do about it.

The short version. We collect the minimum needed to run turf intelligence for your organization: who you are, the measurements your TOMi devices take, and where on your site they were taken. We do not sell personal data, we do not run advertising trackers, and the only cookie we set is the one that keeps you signed in.

1. Who is responsible

[Legal entity name] ("PURE Insight", "we") of [registered address] is the controller for personal data described here. Contact us at privacy@getpureinsight.app.

Where your employer subscribes to the Service, we generally act as a processor for the data your organization puts into it, and your employer is the controller. For account and billing records we act as controller.

2. What we collect

Account information — name, work email, organization, role, and a securely hashed password. We never store your password in a readable form.

Turf and sensor data — soil moisture, electro-conductivity, canopy temperature, firmness and derived scores, together with the GPS coordinates, accuracy and timestamp of each sampling point. These coordinates describe ground you manage, not the movements of an identified person; note that on a small crew they could indirectly indicate where an operator walked, so we treat them with the same care as other work records.

Device telemetry — handheld battery and charge state, mobile signal strength and network type, free storage, app version, uptime and sync queue depth. We do not collect your Wi-Fi network name, contacts, photos, or any content unrelated to sampling.

Service logs — request metadata such as timestamp, path, response status, a request identifier, and IP address, kept for security, debugging and abuse prevention.

Audit records — significant actions in the product (sign-ins, device pairing, data syncs, configuration and plan changes) with the acting user, so your organization has an accountable history.

If you contact us or join the waitlist — the email address, name and any message you choose to send.

3. Why we use it, and our legal basis

Under the UK/EU GDPR we rely on:

Performance of a contract — to create and secure accounts, run sampling, sync and analysis, and provide support.
Legitimate interests — to keep the Service secure and available, prevent abuse, fix faults, and improve the product using aggregated, de-identified information. We balance these against your rights and use the least intrusive option available.
Legal obligation — to keep records we are required to keep, and to respond to lawful requests.
Consent — only where we ask for it explicitly, such as sending you waitlist or product updates. You can withdraw consent at any time.

We do not use your data for automated decisions that have a legal or similarly significant effect on you, and we do not sell personal data.

4. Cookies and similar technology

We keep this deliberately minimal:

Strictly necessary cookies only. When you sign in to the TOMi application we set a single httpOnly session cookie so the app knows who you are, plus a paired token used to protect against cross-site request forgery. These are essential to deliver a service you have asked for, so under the ePrivacy rules they do not require consent — but you should know they exist, which is why we show a notice.

No advertising or analytics trackers. We run no third-party analytics, advertising pixels, session recording, or cross-site tracking on the application or this website. There is no "reject non-essential cookies" choice to offer, because there are none to reject.

The application also uses your browser's local storage to remember interface preferences (for example, the area you last viewed and that you have seen the cookie notice). That data stays on your device.

Clearing cookies or local storage will sign you out and reset those preferences.

5. Who we share it with

We share personal data only with service providers who help us run the Service, under contract and only for that purpose:

Cloudflare, Inc. — hosting, application delivery, database and edge security for the platform.

We may also disclose data where required by law, to protect our rights or the safety of others, or in connection with a merger or acquisition (in which case we will tell you). We never sell or rent personal data, and we do not share it with advertisers.

6. International transfers

We are based in the United States and our infrastructure provider operates a global network, so your data may be processed outside your country. Where data is transferred out of the UK/EEA we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses. Ask us and we will describe the safeguards that apply to you.

7. How long we keep it

Account records — for as long as your organization's account is active, then deleted or anonymised within a reasonable period unless we must keep them longer.
Turf and sensor data — for the life of the account, since agronomic value comes from multi-season history. Your organization can request export or deletion.
Service logs — a short operational window, typically 30–90 days.
Audit records — retained longer for accountability and security investigation.

8. How we protect it

Encryption in transit (HTTPS/TLS). Passwords stored using salted PBKDF2 hashing, never in plain text. Device credentials held only as hashes, and revoked immediately when a device is removed. Strict separation between customer organizations, enforced in code and covered by automated tests. Role-based access within each organization. Rate limiting and account lockout against credential-guessing. Access by our own staff is limited, read-only for cross-organization support views, and recorded in the audit log.

No system is perfectly secure. If a breach affects your personal data we will notify you and any relevant regulator as the law requires.

9. Your rights

Depending on where you live you may have the right to: access a copy of your personal data; correct inaccuracies; delete it; restrict or object to processing; receive it in a portable format; and withdraw consent where processing relies on consent. You will not be treated differently for exercising these rights.

If your account was provided by your employer, please raise requests with them first — we will support them in responding.

To make a request, email privacy@getpureinsight.app. We will respond within the time the law allows (usually one month). If you are in the UK/EEA and unhappy with our response you may complain to your local supervisory authority. California residents may also exercise rights under the CCPA/CPRA, including the right to know and to delete; we do not sell or share personal information as those terms are defined.

10. Children

The Service is for professional use and is not directed at children. We do not knowingly collect personal data from anyone under 18.

11. Changes to this policy

We may update this policy. If a change materially affects how we use personal data we will give notice — by email or an in-product notice — before it takes effect. The "last updated" date above always reflects the current version.

12. Contact

Privacy questions or requests: privacy@getpureinsight.app.