1. What we collect
Your account. An email address, a password (stored only as a hash, never readable), and a record of sign-ins, password changes and resets with their times.
Your company's records. Whatever you enter to run your buildings: owners, buildings, suites, tenants and their contacts, leases, charges and receipts, work orders, vendors, notices and replies, and the files you upload such as leases and insurance certificates. This includes personal details of tenants, owners, vendors and your staff. You decide what goes in.
Technical logs. The address your requests come from, the page or endpoint asked for, and errors. We use these to keep the service running and to stop abuse. They are kept for a limited time in Google Cloud logging.
Website visits. The marketing site uses Cloudflare Web Analytics, which counts page views without cookies and without following you across sites.
2. What we do not do
We do not sell your data. We do not show ads. We do not use your records to train anything. We do not read your tenants' replies except to deliver them to your inbox and, when you ask for help, to fix a problem.
3. Where it lives
The app and its database run on Google Cloud in the central United States. Data is encrypted on disk and in transit. The database is backed up every day and can be restored to any point in the last seven days. There is no copy outside the United States.
4. Who helps us run it
These companies process data for us, each only for the job named:
- Google Cloud (United States): hosting, database, backups, logs, secret storage.
- Resend: sends the email the app sends, such as notices, sign-in help and codes. It sees the addresses and the message.
- Cloudflare: serves this website and routes replies to notices into the app. It sees the reply email while passing it on.
- Lob or PostGrid: only if your company connects its own account for certified mail. Then the letter and the tenant's address go to the provider you chose, under your own agreement with them.
We add to this list before we use anyone else.
5. Cookies
The app sets two cookies: one that keeps you signed in for up to eight hours, and one that protects forms from forgery. Both are needed for the app to work. The website sets none.
6. How long we keep it
- Your company's records: for as long as the company is open.
- After a company is closed, by cancellation or at your request: fourteen days, so you can export or change your mind, then everything is deleted for good. Backups can hold a copy for up to seven days more.
- Your account: until you ask us to delete it, or it has had no company for a year.
- Technical logs: thirty days.
7. What you can ask
Export your company's records from inside the app at any time. Correct a record by changing it in the app; money is corrected by a reversal, never erased, so the trail stays honest. To delete a company, ask us to close it; fourteen days later it is gone. To delete your account, write to us. If someone whose details are in a company's records asks us about them, we point them to that company, which decides what it holds; we help the company answer.
8. Security
Passwords are at least 12 characters and locked after five wrong tries. Sessions end after eight hours and can be ended early from your account. Roles are enforced on the server for every request. The security page lists what is in place and what is not built yet.
9. Children
TenantLogix is for businesses. It is not for anyone under 18, and we do not knowingly hold data about children.
10. Changes
When this policy changes we post the new version here with its date and, for a change that matters, we email account owners first.
11. Contact
EvolvLabs, LLC · hello@tenantlogix.com