OnDeck Display is a companion app for Apple TV made by OnDeck Aquatics ("OnDeck Aquatics", "OnDeck", "we", "us"). It turns an Apple TV into a read-only operations board — showing an aquatics facility's on-duty staff, water-chemistry readings, certification status, and open alerts on a lobby or pool-deck screen. This policy explains how the Apple TV app handles data. It is deliberately narrow because the app is a passive display: it has no sign-in, no camera or microphone, and it collects no personal information from anyone who sees or walks past the screen.
OnDeck Display collects no personal information from viewers, contains no advertising, and uses no analytics or tracking. It stores only a revocable, read-only "display token" on the device so it can show the board of the facility it was paired to. The information shown on the board is your organization's own operational data, delivered securely from OnDeck's servers.
1. Who this policy covers
This policy covers the OnDeck Display app for Apple TV (tvOS). An aquatics organization ("Customer") that already uses OnDeck installs the app on a TV in its facility and pairs it to the organization. For that operational content, the Customer is the data controller and OnDeck is a data processor acting on the Customer's behalf. This policy is specific to the Apple TV app; our full company privacy practices are described in the OnDeck Privacy Policy.
2. Information the app does not collect
The Apple TV app is a one-way display. It does not:
- ask anyone to sign in or create an account on the TV;
- collect names, emails, or any personal information from viewers or passersby;
- use the camera, microphone, or location;
- contain advertising, advertising identifiers (IDFA), or third-party marketing or tracking SDKs;
- track you across other apps or websites; or
- sell or rent any data.
3. What the app stores on the device
After you pair the display (see below), the app saves a small amount of information in the app's local storage on that Apple TV, solely so it can keep showing the right board:
- a read-only display token — a low-privilege credential that lets the TV fetch its board and nothing else;
- the paired organization name, branch/location label, and display mode, used to title the board before content loads.
This information is stored only on the device, is not shared with any third party, and is erased when the display is unpaired, when the token is revoked, or when the app is uninstalled.
4. What the app displays
Once paired, the app shows the operations board published by your organization through OnDeck. Depending on how your organization configures the display, this may include the names of staff currently on duty, certification and compliance status, recent water-chemistry readings, and operational alerts. This content is your organization's own data — the app only reads and displays it and never modifies it. Because it appears on a public screen, your organization controls what a given display is allowed to show.
5. How pairing works
Pairing uses a device-code flow, so no credentials are ever typed on the TV:
- The Apple TV shows a short pairing code and asks an administrator to approve it from OnDeck (Settings → Displays) on a phone or computer.
- When an administrator approves the code, OnDeck's server issues the read-only display token to that TV.
- To authorize and manage the display, OnDeck's servers record standard connection details for the pairing — such as a device label, IP address, and timestamps. This is handled by the OnDeck service under the OnDeck Privacy Policy.
- An administrator can unpair (revoke) a display at any time; the token immediately stops working and the app returns to the pairing screen.
The app also offers a demo board that shows sample, non-real data without pairing, so the app can be evaluated (including by Apple App Review) with no account required.
6. Network and security
The app communicates only with OnDeck's own servers at app.ondeckaquatics.com, over encrypted HTTPS (TLS). The display token is low-privilege — it can retrieve only the assigned board — and is revocable by an administrator at any time. The app makes no connections to advertising or analytics networks.
7. How information is shared
The board content is delivered by the OnDeck service, which relies on a small set of infrastructure providers (for example, Cloudflare for application compute and Neon for the database) that are contractually bound to process data only to provide their service to us. These are listed in the OnDeck Privacy Policy. We do not share display data with advertisers and we do not sell data.
8. Children
OnDeck Display is a business tool intended for aquatics facilities and is not directed to children. The app collects no personal information from anyone viewing the screen. Board content is your organization's confidential operational data; where it may reference facility patrons, it is treated as the Customer's data under the OnDeck Privacy Policy.
9. Data retention
The token and labels stored on the device persist until the display is unpaired, the token is revoked, or the app is uninstalled. Server-side records related to a display and its pairing are retained by the OnDeck service as described in the OnDeck Privacy Policy.
10. Changes to this policy
We may update this policy from time to time. If we make material changes we will update the "Last updated" date at the top of this page. Continued use of the app after an update means you accept the revised policy.
11. Contact us
Email us at [email protected], or use our contact form and select "Privacy" in your message. We respond within one business day.