1. Information We Collect
Account and registration data: name, email address, business name, phone number, and password (hashed — never stored in plaintext).
Workspace operational data (processed on behalf of workspace operators): tenant and resident records, applicant data, property and lease records, payment histories, maintenance records, and documents stored in Supabase Storage.
Technical data: session tokens managed by Clerk, IP address (used for rate limiting only — not retained for profiling), request timestamps, error reports captured anonymously by Sentry, and browser or device type.
Communications: messages submitted via contact forms, support requests, newsletter subscriptions, and in-platform communications.
2. How We Use Personal Information
To provide, operate, and improve the Service: account management, workspace provisioning, billing, feature delivery, and onboarding.
Security and fraud prevention: rate limiting, anomaly detection, Cloudflare Turnstile CAPTCHA verification, and platform abuse prevention.
Communications: transactional service emails (essential), responses to support enquiries, and newsletters where you have given consent.
Legal compliance: retaining records as required by applicable law and responding to lawful requests from regulatory authorities.
3. Legal Basis for Processing
Contract performance (GDPR Art. 6(1)(b)): processing required to deliver the subscription service you have signed up for.
Legitimate interests (GDPR Art. 6(1)(f)): platform security, rate limiting, error monitoring, and product improvement using aggregate anonymised analytics.
Legal obligation (GDPR Art. 6(1)(c)): financial record-keeping, tax compliance, and responses to lawful authority requests.
Consent (GDPR Art. 6(1)(a)): newsletter subscriptions and optional analytics. You may withdraw consent at any time without affecting the lawfulness of prior processing.
4. Data Sharing & Sub-Processors
We do not sell personal data. We share it only as necessary to run the Service, with these sub-processors: Supabase (database and file storage), Clerk (authentication), Stripe (subscription billing), Resend and Brevo (email delivery), OpenAI (the in-product assistant — do not enter sensitive personal data in chat), Sentry (error monitoring), and Vercel (hosting).
Each sub-processor publishes its own security and compliance documentation. Contact us for the current list and the data-processing terms that apply.
5. Your Rights
Depending on where you live, you may have rights over your personal data — to access it, correct it, delete it, restrict or object to how it is used, receive a copy, or withdraw consent you have given. We do not sell personal data.
To ask about any of these, contact us at propflowhq.com/contact. We handle requests within the timeframes required by the law that applies to you.
6. Retention & Children's Privacy
Workspace data is retained while the subscription is active. PropFlow does not automatically delete your data when a subscription lapses. The retention schedule that will apply afterwards is being finalised and will be published here before it takes effect; in the meantime, contact us to ask about deletion or export.
The Service is not directed to persons under 18. We do not knowingly collect data from children. Contact us immediately if you believe a child has submitted data.
7. Changes & Contact
We may update this policy to reflect changes in the Service or in the law. Material changes will be notified in advance. Continued use of the Service after the effective date constitutes acceptance.
For privacy enquiries, contact us at propflowhq.com/contact. If you are unsatisfied with our response, you may be able to complain to the data protection authority for your country.