PRIVACY POLICY

Highs & Lows Reporting Quorra IT LLC

Effective date: September 12, 2026 Last updated: September 12, 2026


1. Two kinds of data, handled differently

This is the most important thing to understand about how Highs & Lows Reporting works.

Utility customer data. Water districts upload meter reading exports containing records about the residents and businesses they serve. We do not own this data and we are not the one deciding what to do with it. The district owns it and directs how it is used. We process it on their instructions to provide the Service. Under the California Consumer Privacy Act, we act as a service provider to the district for this data.

If you are a water customer and want to know what your district holds about you, or want it corrected, contact your water district directly. We cannot act on your request without their instruction, because it is not our data to act on.

Portal user data. People who log in to the Service district staff and our own personnel have accounts with us. We handle that data as described in Section 4.


2. Utility customer data we process

When a district uploads a reading export, it typically contains:

Category Examples
Account identifiers Account number, customer number, route
Equipment identifiers Register ID, meter serial number, MXU
Location Service address
Individual identity Customer name as it appears in district billing records
Consumption Prior read, current read, usage, read date, billing period, meter status

Districts may also connect an optional integration that writes equipment changeout records to a spreadsheet they control.

We do not collect Social Security numbers, payment card data, bank account details, dates of birth, or government identification numbers, and the Service has no use for them. If a district uploads a file containing them, that is outside what the Service is designed for and we ask to be told so it can be removed.

How we use it

Only to provide the Service: normalizing uploaded files, comparing consumption against each register's own history, scoring and ranking accounts for review, generating reports, and supporting the district's staff.

What we do not do with it

  • We do not sell it. We have never sold it and the business model does not depend on selling it.
  • We do not share it with other districts. Each district's data is separated by organization and access is enforced on every request.
  • We do not use one district's data to build products for anyone else. We may use aggregated, de-identified statistics that cannot reasonably be linked back to a district, an individual, or an address, solely to improve detection quality.
  • We do not use it for advertising, and we do not run advertising.

Retention

We retain uploaded reading data for a rolling two years, which is what the year-over-year comparison requires. On termination of a district's agreement, the district has 30 days to export, and we delete their data within 60 days, including from routine backups as those rotate out. We confirm deletion in writing on request.


3. Legal basis and CCPA status

For utility customer data, the district is the business and Quorra IT is a service provider under Cal. Civ. Code § 1798.140. Our contracts prohibit us from retaining, using, or disclosing that data for any purpose other than providing the Service, and from combining it with data from other sources except as permitted for service providers.

Many California water districts are public agencies. Records held by a public agency may be subject to the California Public Records Act, and requests under that Act go to the district, not to us.


4. Portal user data

If you have a login, we collect and process:

Data Why
Name, work email, phone Account identity, support, notifications
Password (hashed, never stored in readable form) Authentication
Two-factor secret and recovery codes Account security
Trusted device records So you are not prompted for a code on every login
IP address, browser user agent, timestamps Security, abuse prevention, troubleshooting
Activity log pages viewed, accounts opened, dispositions entered, uploads performed Audit trail, required for utility recordkeeping
Support messages and bug reports you send To answer you

Your manager can see your activity log for your organization. That is a deliberate feature utilities need to know who reviewed what and you should assume your work in the Service is visible to your organization.

We retain login and security logs for 12 months and activity logs for as long as the district's agreement is active, since they form part of the district's records.


5. Cookies

We use a small number of strictly necessary cookies: a session cookie to keep you logged in, a security token to prevent cross-site request forgery, an optional "remember this device" token if you enable it, and a preference cookie for light or dark theme.

We use no advertising cookies, no third-party analytics, and no cross-site tracking. We do not respond differently to Do Not Track signals because we do not track you across sites in the first place.


6. Service providers we rely on

We use a small number of vendors to run the Service. They are contractually limited to processing data on our instructions.

Vendor What it does Data involved Location
DigitalOcean Hosting and object storage for backups All Service data United States
Cloudflare DNS and network protection Network traffic, IP addresses United States
Resend Transactional email password resets, notifications Recipient name and email address United States
Stripe Invoicing and payment processing District billing contact and payment details; no utility customer data United States
Google (optional) Writes equipment changeout records to a district-controlled spreadsheet, only if the district enables it Equipment and account identifiers the district chooses to sync United States

All data is stored and processed in the United States. We do not transfer data internationally.

We will give districts at least 30 days' notice before adding a vendor that would process their data.


7. Security

  • All traffic is encrypted in transit with TLS.
  • Passwords are stored using a modern one-way hash. We cannot read your password.
  • Two-factor authentication is available and can be required organization-wide.
  • Access is role-based and scoped by organization on every request.
  • Administrative access to production systems is limited to personnel with a business need.
  • Backups run daily, are stored separately from the production system, and are integrity-checked.
  • Failed login attempts are rate-limited and logged.

No system is perfectly secure. If we confirm a breach affecting a district's data, we notify that district within 72 hours with what we know, and we cooperate with any notifications they must make under Cal. Civ. Code § 1798.29.


8. Your choices

District staff with logins: you may access and correct your own account details in the Service. Requests to delete your account go through your organization's manager, since your activity log may be part of the district's records.

Water customers: contact your water district. We will support them in responding, but we cannot act on your data without their instruction.

Anyone: you may email [email protected] with a privacy question. We will respond within 45 days, and will route you to the right party if the data is a district's rather than ours.

We will not discriminate against anyone for exercising privacy rights.


9. Children

The Service is a business tool used by utility staff. It is not directed to children and we do not knowingly collect data from anyone under 18 through the portal. Utility billing records may of course concern households that include children; those records are the district's, handled as described above.


10. Changes

We may update this policy. Material changes will be posted here with a new effective date, and district managers will be notified by email at least 30 days in advance.


11. Contact

Quorra IT LLC Email: [email protected] Phone: (916) 302-7695

Support: [email protected] · (916) 302-7695 · Terms · Privacy