Privacy Policy

Last updated August 26, 2026

Your reports stay on your device unless you choose to sign in.

Florida Wind Mit works completely without an account: every report, every photo and the finished PDF are created and kept in your own browser, and we never see them. Signing in is optional, and adds one thing — a backup copy of your reports, held for you so you can reach them from another device. Section 3 sets out exactly what changes when you do.

1. Who this policy covers

This policy explains how Florida Wind Mit (“we”, “us”) handles information in connection with Florida Wind Mit, the web application at floridawindmit.com for completing the Florida Uniform Mitigation Verification Inspection Form (OIR-B1-1802).

We are established in Poland, which means the EU General Data Protection Regulation applies to our processing — even though the Service is built for a Florida form and used almost entirely in the United States. You can reach us at support@floridawindmit.com.

Our role depends on the data. We are the controller for your account: your email address, the inspector details you save, your subscription status, and any rejection feedback you send us. For the contents of reports you sync — which are mostly about a homeowner, not about you — you are the controller and we are your processor, holding a copy on your instruction and doing nothing else with it. Section 6 explains what that means in practice.

It applies to the website and the application. It does not apply to what you do with a PDF after you export it, or to any insurer, employer or third party you send it to.

2. What is stored on your device

The application stores your work in your browser using IndexedDB, in a database named windmit. It holds your reports, your photo metadata, the raw image bytes, a record of what has been backed up, and your saved inspector details. Depending on what you enter, that data can include:

  • About the property and its owner: owner name, contact person, street address, city, ZIP code, county, home, work and mobile telephone numbers, email address, insurance company name, insurance policy number, year of construction and number of storeys.
  • About you, the inspector: name, licence type, licence number, company, telephone number, initials, the statutory basis for your licence, and — where a contractor or professional engineer has delegated the inspection — the name of the employee who performed it.
  • Signature blocks: the typed inspector and homeowner signature entries and their dates.
  • Inspection content: your answers to questions 1 through 9, the property type, any validation warnings you explicitly acknowledged, and the photographs you take or attach for each question.

If you are not signed in, all of it stays on the device and none of it is transmitted to us or to anyone else by the application. If you are signed in, a copy of it is backed up to your account, as section 3 describes.

3. What we collect

If you do not sign in

Nothing. There is no analytics, no error reporting and no telemetry, and your inspection data is never transmitted. The only network requests the application makes are for the pages themselves and for the blank government form, both served from this site.

If you sign in

Signing in is optional and reversible. When you do, we hold:

  • Your email address, used to send you a sign-in link and to identify your account. There is no password.
  • Your saved inspector details — the same licence and contact fields listed in section 2 — so they can be filled into each new report instead of retyped.
  • A backup copy of your reports and photographs, including the homeowner and property information they contain. This is the point of signing in; it is what lets a lost or replaced phone not cost you your work.
  • Your subscription status, if you subscribe: whether the subscription is active, which plan it is, and when the period ends. Card numbers are handled by Stripe and never reach us.
  • Rejection feedback you choose to send, if you use the “this form was rejected” report — the reason you type, the insurer if you name one, and which report it concerned.

Our legal basis for the account data is performance of the contract between us (Article 6(1)(b)) — you asked for an account and a backup, and this is what providing them requires. For rejection feedback the basis is our legitimate interest (Article 6(1)(f)) in finding out why real forms get refused so the tool can stop producing them; it is entirely voluntary and you can decline to send it.

Server logs, either way

The pages have to be delivered to you over the internet, so our hosting provider necessarily processes your IP address, the page you requested, your browser user-agent string and a timestamp, in ordinary server logs. That is the same information every website receives, it is used to serve and secure the site, and it contains none of your inspection data. Our legal basis is legitimate interest (Article 6(1)(f)) in delivering the site, keeping it available and protecting it from abuse. Logs are retained only as long as our hosting provider keeps them for those purposes, and we do not use them to build a profile of you, combine them with anything else, or identify individual visitors.

4. Cookies, tracking and why you see no cookie banner

We use:

  • No cookies.
  • No analytics of any kind, including Google Analytics.
  • No advertising, no advertising identifiers and no remarketing pixels.
  • No third-party trackers, tag managers, session recorders or chat widgets.

If you sign in, your session is kept in your browser’s localStorage so that you stay signed in between visits. That is the only thing stored there, it exists solely to keep you signed in to a service you explicitly asked for, and it is not used to track you — on this site or anywhere else.

The typefaces are compiled into the site when it is built rather than fetched from Google Fonts at page load, so no font provider receives your IP address either.

This is why the site shows no cookie consent banner: nothing is set that would require your consent. The IndexedDB storage described in section 2 is not tracking — it is the document you are writing, held where you are writing it — and the sign-in session above is strictly necessary for a feature you chose to use.

5. Third parties

Our hosting provider serves the site and processes the server-log data described in section 3.

Supabase provides the authentication, database and file storage behind accounts, and acts as our processor for everything described in section 3. Our Supabase project is hosted in the United States, which is also where the inspections themselves and the insurers receiving them are.

Stripe processes payments if you subscribe. Stripe collects your payment details directly and acts as an independent controller for them under its own privacy policy; we receive only your subscription status and a customer reference, never card numbers.

The PDF is assembled by a software library that runs inside your browser as part of the page; it is not a service and it transmits nothing. Beyond the providers named above, the application shares data with no one.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we have no advertising relationships.

6. Information you record about other people

Most of the personal information in a report is not yours — it belongs to the homeowner or the policyholder. You decide what to record, why, and who to send the finished form to. In the language of privacy law, you are the controller of that information.

If you do not sign in, the application is simply the instrument you use to write it down, in the same way a clipboard and a camera would be. If you do sign in, we additionally hold a copy of it as your processor: we store it so you can get it back, we act on your instructions, we do not use it for any purpose of our own, and we delete it when you delete the report or close your account.

You are responsible for having the authority to collect that information and for handling it in line with your own professional and legal obligations. If a homeowner makes a request to you about their data in a report you have synced, you can satisfy it yourself from within the application — and we will help if you need us to.

7. Photographs and hidden location data

Photographs you capture or attach are stored exactly as your camera produced them. Camera files often carry embedded EXIF metadata, and if location services were enabled for your camera app, that metadata can include the GPS coordinates where the photo was taken.

The application does not currently strip that metadata, photographs are embedded in the exported PDF in their original form, and if you are signed in the backup copy carries the same metadata. This matters because the coordinates would travel with the PDF to whoever you send it to. If that concerns you, disable location tagging in your device’s camera settings before an inspection.

8. The exported PDF

The PDF is generated on your device and saved wherever your browser puts downloads. Its filename and its internal document title both contain the property address and the inspection date, so the address is visible without opening the file.

Once you email, upload or hand over that PDF, it is outside the application and outside our control. Treat it as you would any other document containing a client’s address and policy number.

9. How long data is kept, and how to delete it

Reports stay on your device until you delete them. Deleting a report from the reports list permanently removes the report and every photograph attached to it from your device — and, if you are signed in, deletes the backup copy too.

Without an account there is no backup and no recovery. Because the data lives in browser storage, it will be destroyed — irreversibly, and without warning — if you clear your browsing data or site data, uninstall or reset the browser, use private or incognito browsing, or if the browser evicts stored data because the device is low on space. The application asks the browser to mark its storage as persistent to make eviction less likely, but the browser makes the final decision and may refuse.

Signing in is what changes that: a backed-up report survives the device. It is still worth exporting the PDF of anything that matters and keeping it somewhere you control.

To close your account and have everything we hold for you erased, email us at support@floridawindmit.com from your account address. We will delete your reports, photographs, saved details and account, and confirm when it is done. Billing records that we are required to retain for tax and accounting purposes are the one exception, and they contain no inspection data.

10. Security

The site is served over HTTPS. Sign-in uses a one-time link sent to your email address rather than a password, so there is no password of yours to be guessed or reused. Backed-up reports and photographs are stored in a private, access-controlled location and are readable only by your own account.

Beyond that, the security of your inspection data is the security of your device and your email account: anyone who can unlock your phone and open your browser can read your reports, and anyone who can read your email can request a sign-in link. Use a device passcode or biometric lock, keep the operating system updated, secure your email account, and do not use a shared or public device for inspections.

11. Your privacy rights

Under the GDPR you have rights to access, rectify, erase, restrict and port your personal data, to object to processing carried out on the basis of legitimate interest, and to lodge a complaint with a supervisory authority — in our case the Polish authority, the Prezes Urzędu Ochrony Danych Osobowych (UODO). Privacy laws in Florida, California and other US states give comparable rights.

In practice you exercise most of these directly and immediately: you can view and correct any answer by opening the report, export a full copy as a PDF, and delete a report and its photographs permanently from the reports list. There is no request to submit and no waiting period, because there is no intermediary.

For anything held in your account — your email address, your saved details, your backed-up reports — write to support@floridawindmit.com and we will action it. If you never signed in, we hold nothing about you beyond the server logs in section 3.

12. Children

The application is a professional tool for licensed inspectors. It is not directed to children, and we do not knowingly collect personal information from anyone under 18.

13. Where this service is offered, and where we are

Florida Wind Mit exists to complete a Florida state insurance form, and its users are Florida inspectors. We, however, are established in Poland, in the European Union.

That means the GDPR governs our processing regardless of where you are, because it attaches to where the controller is established rather than to where the user sits.

If you do not sign in, no inspection data is transmitted anywhere, so no transfer of it ever takes place. If you do sign in, your account data and backed-up reports are held in the United States — the country the properties, the inspectors and the insurers are all in. Where that involves an international transfer, it is carried out under the transfer mechanisms our providers maintain for that purpose, including the European Commission’s Standard Contractual Clauses.

Our hosting provider may likewise serve the site from infrastructure in the United States or elsewhere, on the same basis.

14. Changes to this policy

If this policy changes we will update the date at the top of the page. If a change materially affects how information is handled — for example if analytics were ever introduced — we will say so prominently in the application before the change takes effect.

15. Contact

Questions about this policy: support@floridawindmit.com.