Effective date: Dec 13, 2023
Last updated: July 25, 2026

1. Who we are

This Privacy Policy is issued by Rayshobby LLC, a Massachusetts limited liability company doing business as OpenSprinkler, OpenThings, and OpenGarage (“we”, “us”, “our”), of 5 Valley Lane, Amherst, MA 01002.

For users in the United Kingdom and the European Economic Area, Rayshobby LLC is the data controller for the processing described here.

Privacy contact: [email protected]

2. What this policy covers

This policy applies to:

  • OpenSprinkler.com, OpenThings.io, and OpenGarage.io, including the online store and community forum
  • OpenSprinkler, OpenThings, and OpenGarage applications for mobile and web
  • OpenSprinkler accounts
  • Optional cloud synchronization
  • OpenThings Cloud (OTC) remote access
  • Weather and location-selection features
  • Customer support channels

It does not apply to configuration and data that remain on your controller and are never transmitted to us, or to third-party websites and services we link to or integrate with, which have their own privacy policies. It does apply to requests your controller or app makes to services we host, including weather lookups and firmware update checks.

3. Information we collect

Account information. Email address, username, and password. Passwords are stored only as a cryptographic hash. We also generate and store password-reset tokens and session identifiers.

Order and payment information. Name, billing and shipping addresses, email address, telephone number, order contents and history, and order identifiers. Card payments are processed by Stripe. Full card numbers and security codes are entered directly into Stripe’s payment interface and are not transmitted to or stored on our systems. If you choose to save a card for future purchases, we store a payment token together with the card brand, the last four digits, and the expiry date, so that we can display your saved payment methods and process future orders you authorize.

Forum and support content. Content you submit, your account identifier, timestamps, and support ticket identifiers. Forum posts are publicly visible. If a post is removed from our site, copies quoted by other users, or retained by search engines and third-party archives, may remain available.

Cloud-synchronized controller settings. If you enable cloud synchronization, we store an encrypted bundle of your controller connection settings. Depending on your configuration this may include:

  • Controller names or labels
  • Controller addresses, hostnames, URLs, paths, and query strings
  • Saved controller authentication credentials, which may be a password or a password-derived value that can itself be used to authenticate to the controller
  • OpenThings Cloud tokens
  • HTTP authentication usernames and passwords

Section 6 describes the protection and its limits.

OpenThings Cloud (OTC) data. When you use OTC remote access, we store a device registration and an associated token. Our proxy relays traffic between your app and your controller, which necessarily involves transmitting the commands you send and the responses your controller returns. The relay does not retain the contents of that traffic.

Location and weather data. If you configure a location for weather-based watering, we receive that location and use it to obtain forecast and observation data. Depending on your settings this may involve:

  • Our hosted weather service
  • Third-party weather service providers you select (the list includes: Apple Weather, AccuWeather, Pirate Weather, OpenWeatherMap, Open-Meteo, and Weather Underground)
  • Personal weather station (PWS) identifiers, where configured
  • Weather provider API keys you supply

Location selection. If you use map-based location selection, map tiles and place data are loaded from Google Maps directly by your browser or app, and that provider receives the coordinates being displayed under its own privacy policy.

Technical and log data. IP address, user-agent string, requested URLs, timestamps, referring pages, and security events, recorded by our servers and by our content delivery and security provider.

Sensitive values in URLs. Some requests made by our applications or controllers include authentication tokens, passwords, or password-derived values in a URL path or query string. These values may be recorded in server, proxy, or security logs used to deliver, secure, and troubleshoot the service. We restrict access to those logs and retain them according to Section 10. You should treat controller URLs and connection details as sensitive and avoid sharing them.

Cookies and similar technologies. See Section 9.

4. Where the information comes from

Directly from you — when you create an account, place an order, post in the forum, contact support, or configure our applications.

Automatically — when you interact with our websites, applications, and hosted services.

From third parties, including:

  • Our payment processor, for limited transaction information
  • Our content delivery, security, and bot-protection provider, for security and traffic information
  • Weather and mapping providers, for data returned in response to requests
  • Shipping carriers and delivery-status providers, for fulfillment and tracking
  • App stores, for aggregate installation and usage reporting
  • Our support platform, for correspondence and metadata
  • Our WordPress and e-commerce extensions, when they generate or return account, order, payment-status, shipping, fraud-prevention, security, or support information through our sites

5. Why we process information, and our legal basis

Legal bases below are those under Article 6 UK/EU GDPR, for users in those jurisdictions.

Purpose Basis
Creating and administering your account Contract
Processing and fulfilling orders Contract
Providing cloud synchronization and OTC remote access Contract
Providing weather-based watering features Contract
Responding to support requests Contract; legitimate interests
Protecting accounts against unauthorized access and credential attacks Legitimate interests
Detecting, preventing, and investigating fraud and abuse Legitimate interests
Maintaining service reliability, capacity, and fault diagnosis Legitimate interests
Securing our infrastructure and investigating security incidents Legitimate interests
Sending service and transactional messages Contract
Sending marketing messages Consent
Website analytics Consent (EEA/UK); legitimate interests (elsewhere)
Meeting tax, accounting, and other legal obligations Legal obligation

Where processing is necessary for a contract, not providing the information means we cannot provide the corresponding feature — we cannot ship an order without a delivery address, or provide cloud synchronization without an account.

We do not ourselves make decisions based solely on automated processing that produce legal or similarly significant effects concerning you.

You may object to processing based on legitimate interests, and withdraw consent at any time, as described in Section 11.

6. Cloud synchronization: how it is protected, and the limits

Cloud-synchronized controller settings are encrypted in the OpenSprinkler app or browser before they are uploaded to our cloud service. The encryption key is derived from the account password in use when the synchronized copy was last encrypted. Our cloud service stores and transmits the encrypted bundle; decryption ordinarily occurs in the app or browser.

We do not store your account password in readable form. We receive it over an encrypted connection when you sign in, and validate it against a stored password hash.

Anyone who obtains an encrypted bundle can attempt password guesses offline. The protection this encryption provides therefore depends materially on the strength and confidentiality of the password used to encrypt it. A weak, guessable, previously compromised, or reused password may allow the synchronized controller information to be recovered.

This protection applies to the copy stored in our cloud service. Controller settings and key material may also exist on your own devices or in browser storage, where they are protected by the security of those devices and browsers.

Changing your OpenSprinkler.com account password does not automatically re-encrypt an existing cloud-synchronized bundle.

  • The bundle remains encrypted with the password-derived key used when that copy was last saved. After a password change, the app may ask for the previous password to decrypt the existing copy.
  • Logging out or disabling synchronization stops further synchronization on that device but does not by itself delete the server-side copy. To request deletion of the cloud-synchronized copy, contact [email protected].

7. Third-party controllers and services

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

Providers acting on our behalf. These process personal information under contract, on our instructions, for the purposes described in this policy:

Category Provider Purpose
Hosting and infrastructure DigitalOcean LLC Running our servers
Content delivery, DNS, security, bot protection Cloudflare (incl. Turnstile) Delivering and protecting our sites
Support tooling Freshworks Inc. Handling support requests
Analytics Google LLC Understanding site usage

Third parties to whom we disclose information. These determine their own purposes for at least part of what they do, and their own privacy policies apply:

Recipient What we disclose
Stripe Transaction and customer information necessary to process payments
Shipping carriers Recipient name, address, and contact details for delivery

Third parties that collect information directly from you. We do not disclose your information to these; they receive it because your browser, app, or controller communicates with them:

Party When
Google Maps When map-based location selection is used
Weather providers you select When weather data is requested for your location
Apple App Store, Google Play When you download or update our applications; they may also provide us with aggregate reporting

We use WordPress and WooCommerce extensions to operate account, forum, order, security, and support functions. We configure those extensions to transmit personal information only to the providers or recipients identified above, when necessary for a feature you choose, or as otherwise described in this policy. Current provider information is available from [email protected].

We may also disclose information where we reasonably believe it is required to comply with law, enforce our terms, or protect the rights, property, or safety of our users or others; and in connection with a merger, acquisition, financing, reorganization, or asset sale. We will provide notice where required by law.

8. International transfers

We are based in the United States. Our servers are operated by DigitalOcean and located in New York, United States. Our other service providers process personal information in the United States unless stated otherwise. If you use our services from outside the United States, your information is transferred to and processed in those locations.

Our service providers’ data processing agreements incorporate the European Commission’s Standard Contractual Clauses for transfers of personal data from the EEA and the UK. Copies are available on request.

9. Cookies and similar technologies

Strictly necessary cookies. We use cookies to keep you signed in, remember your cart and preferences, and secure our sites. These are required for the site to function and are set without consent.

Analytics cookies. We use Google Analytics to understand how visitors use our sites. This sets cookies that collect information about pages viewed, session duration, and approximate location derived from IP address. For visitors in the EEA and UK, these are set only with your consent, which you can give or withdraw at any time using the cookie settings link in our footer.

Do Not Track and Global Privacy Control. We treat recognized Do Not Track and Global Privacy Control signals as a request to decline non-essential cookies. We do not sell personal information or share it for cross-context behavioral advertising.

Full cookie list. A complete list of the cookies we use, including their names, purposes, and durations, is available in our Cookie Policy.

10. How long we keep information

Data Retention
Account records Until you ask us to delete your account, then deleted within 30 days
Order and transaction records 7 years from the date of the order, to meet tax, accounting, and warranty obligations. After that period we delete or anonymize them.
Forum posts Until you ask us to delete your account, at which point posts are deleted with it
Cloud-synchronized bundles Until the synchronized cloud data or associated account is deleted following a verified request. Logging out or disabling synchronization does not by itself delete the server-side copy.
OTC tokens and device registrations Until the device registration or token is revoked or replaced, or the associated OTC service record is deleted.
OTC connection metadata For as long as reasonably necessary to operate, secure, and troubleshoot OTC, then deleted or de-identified in accordance with our operational retention schedule.
Server and security logs For the shortest period reasonably necessary to operate and secure the services, diagnose failures, prevent abuse, and investigate incidents; longer when a record is subject to a security investigation, legal obligation, dispute, or legal hold.
Password-reset and session tokens Until used, revoked, or expired under the configured security timeout.
Failed authentication records For as long as reasonably necessary to detect and investigate abuse, protect accounts, and satisfy legal or incident-response obligations.
Support correspondence While needed to provide support and maintain service history, and longer where necessary for warranty, legal, security, or dispute-resolution purposes.
Saved card details (brand, last four, expiry) Until the customer removes the saved card or deletes their account.

Where we delete information, residual copies may persist in encrypted backups until those backups expire in the ordinary course, currently 30 days.

We may retain information for longer where required by law, to resolve disputes, to enforce agreements, or where it is subject to a legal hold or forms part of the evidence of a security incident.

11. Your rights

Depending on where you live, you may have the right to:

  • Confirm whether we are processing personal information about you
  • Access that information and obtain a copy
  • Correct inaccurate information
  • Delete your information
  • Obtain a portable copy of information you provided to us
  • Object to processing based on our legitimate interests
  • Object to direct marketing at any time, without needing to give a reason — we will stop
  • Restrict certain processing
  • Withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal
  • Opt out of the sale or sharing of personal information, of targeted advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects
  • Limit the use and disclosure of sensitive personal information, where it is used or disclosed beyond the purposes permitted under applicable law
  • Not be treated differently for exercising any of these rights

To exercise a right, contact [email protected]. We verify identity before acting, and respond within the time applicable law requires. You may use an authorized agent.

If we decline a request, you may appeal by replying to the denial or emailing [email protected] with the subject “Privacy Appeal.” We will review the appeal and respond within the period required by applicable law. If we deny the appeal, we will explain any additional complaint options available to you.

Complaints. UK users may complain to the Information Commissioner’s Office (ico.org.uk). EEA users may complain to their national supervisory authority.

12. Children

Our products and services are intended for adults and are not directed to children. We do not knowingly collect personal information from children under 13. If we learn that we have, we will delete it. If you believe a child has provided us with personal information, contact us at [email protected].

13. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, security monitoring, encryption in transit for connections to our hosted services, and encryption of cloud-synchronized controller settings as described in Section 6.

Direct connections between your app and a controller on your own network, or to endpoints you configure yourself, may not be encrypted unless you have configured TLS for them.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Protecting your account also depends on your use of a strong, unique password and on keeping your credentials confidential.

If we become aware of a security incident affecting your personal information, we will notify you and any applicable regulators as required by law.

14. Changes to this policy

We may update this policy. We will update the effective date and post the revised policy. Where required by law, we will provide additional notice of material changes through an appropriate channel, such as email, an in-app notice, or a prominent notice on our sites.