Well Ops

by Wellreports.io

Legal

Privacy Policy

How Well Ops collects, uses, stores, and protects information across the platform, its portals, and related services.

Effective July 12, 2026 · Provided by Wellreports LLC

This Privacy Policy describes how Wellreports LLC handles information across the Well Ops platform. For operational data our customers submit, the customer is the controller and we act as a processor on their behalf.


Contents
  1. 1.Scope & Our Role
  2. 2.Information We Collect
  3. 3.How We Use Information
  4. 4.AI Processing
  5. 5.How We Share Information
  6. 6.Subprocessors
  7. 7.Cookies & Tracking
  8. 8.Data Security
  9. 9.Data Retention
  10. 10.Your Rights & Choices
  11. 11.Owner & Vendor Portal Users
  12. 12.Data Location & International Transfers
  13. 13.Children’s Privacy
  14. 14.Changes to This Policy
  15. 15.Contact Us
1. Scope & Our Role

This Privacy Policy explains how Wellreports LLC, doing business as Well Ops and Wellreports.io (“we,” “us,” or “our”), collects, uses, discloses, and protects information in connection with our platform, websites, applications, and portals (the “Services”). It works together with our Terms of Service.

Our role. For most operational data our customers (oil and gas operators) submit through the Services (“Customer Data”), the customer is the controller (or “business”) and we act as a processor (or “service provider”) that processes such data on the customer’s behalf, under its instructions and our agreement. For information about our customers’ administrators and visitors to our websites, we act as a controller. If you are an Authorized User, mineral or royalty owner, or vendor interacting with a customer’s account, please also review that customer’s own privacy notice.

2. Information We Collect
Information you provide
  • Account and contact information — name, email address, phone number, company name, and job title.
  • Credentials — passwords are stored using industry-standard hashing; we do not store them in plain text.
  • Billing information — plan selection and billing contact. Payment-card details are handled by our payment processor, not stored by us.
  • Communications — messages, support requests, and feedback you send us.
Operational data (Customer Data)

When you use the Services, you and your Authorized Users submit, or the Services generate, operational data that may include: well and production data; financial and accounting records; land and lease records; vendor records (including W-9s and taxpayer identification numbers); mineral and royalty owner records (including bank/ACH details and 1099 tax information); documents and uploaded files; field photographs; electronic signatures; geological and well-log data; and SCADA/telemetry readings.

Information collected automatically
  • Usage and device data — IP address, device and browser identifiers, operating system, pages viewed, actions taken, and timestamps.
  • Diagnostic and log data — error reports and performance metrics used to operate and secure the Services.
  • Messaging engagement — email delivery, open, and click events, and SMS delivery status.
  • Cookies and similar technologies — see the Cookies section below.
3. How We Use Information
  • Provide, operate, maintain, secure, and improve the Services;
  • Process AI Features and meter and bill usage;
  • Authenticate users and administer accounts and portals;
  • Communicate with you, including service and security notices, support, and — where permitted — product updates;
  • Monitor, analyze, and improve performance, reliability, and features;
  • Detect, prevent, and investigate fraud, abuse, and security incidents; and
  • Comply with legal obligations and enforce our agreements.
4. AI Processing

Certain features use artificial intelligence provided by third-party model providers (currently Anthropic) to process documents, images, records, and queries and to generate outputs for the customer. Content is transmitted to the provider only to produce those outputs. We do not use Customer Data to train our own foundation models, and our AI provider does not use Customer Data transmitted through its commercial API to train its models. AI usage is metered, as described in our Terms of Service. See our Subprocessors list for more.

5. How We Share Information

We do not sell your personal information. We may share information with:

  • Service providers and subprocessors — for hosting, storage, email, SMS, payment processing, AI, mapping, and error monitoring, under contracts that require them to protect the data (see Subprocessors).
  • Within a customer’s account — for example, with the customer’s administrators and with owners or vendors the customer invites to its Portals.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
  • Legal and safety — to comply with law, respond to lawful requests, or protect the rights, property, and safety of our users, the public, or us.
  • With your consent — when you direct or permit us to share.
6. Subprocessors

We engage third-party subprocessors to help deliver the Services. A current list of subprocessors — including what each does and where data is processed — is available on our Subprocessors page. We require subprocessors to protect information consistent with this Privacy Policy.

7. Cookies & Tracking

We use cookies and similar technologies for authentication and sessions, to remember preferences, and for analytics and error monitoring. We do not use them for third-party advertising. You can control cookies through your browser settings; disabling some cookies may affect functionality. See our Cookie Notice for details.

8. Data Security

We maintain technical and organizational measures designed to protect information, including encryption in transit and at rest, access controls, monitoring, and internal security practices. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If you believe your account or information has been compromised, contact us at security@wellreports.io.

9. Data Retention

We retain personal and operational data for as long as needed to provide the Services and for legitimate business or legal purposes. After an account is terminated, we delete or anonymize Customer Data within 90 days, unless we are required to retain it by law or for the establishment or defense of legal claims. Customers can export Customer Data during the subscription, as described in the Terms of Service.

10. Your Rights & Choices

Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal data, and to object to or restrict certain processing. Because we often process Customer Data on behalf of a customer, requests relating to a customer’s account should be directed to that customer, and we will assist as a processor.

California (CCPA/CPRA). California residents have rights to know, delete, and correct personal information, and to opt out of its sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising.

EEA/UK (GDPR), where applicable. You have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. We rely on legal bases such as performance of a contract, legitimate interests, consent, and legal obligation.

Communications. You can unsubscribe from marketing emails using the link in those emails, and reply STOP to opt out of SMS messages (reply HELP for help). We may still send you service, security, and transactional messages.

To exercise your rights, contact us at privacy@wellreports.io. We will not discriminate against you for exercising your rights.

11. Owner & Vendor Portal Users

If you access an Owner Portal or Vendor Portal, you are interacting with the Services on behalf of the customer (operator) that invited you, and that customer controls the data you provide. We process that data as a processor on the customer’s behalf. Please direct requests about your data to the relevant customer; we will support them in responding.

12. Data Location & International Transfers

The Services are hosted in the United States (Amazon Web Services, US East / Ohio, us-east-2). If you access the Services from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your location.

13. Children’s Privacy

The Services are intended for business use and are not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected such information, contact us and we will delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will post the updated policy and update the “Effective” date, and provide additional notice where appropriate. We encourage you to review this policy periodically.

15. Contact Us

Questions about this Privacy Policy or our data practices may be sent to privacy@wellreports.io, or by mail to Wellreports LLC, [Registered Mailing Address].


More legal documents