Legal

Privacy Policy

Version 1.0.0 · Effective 2026-02-01 · Last updated 2026-02-01
Download counsel-ready PDF

0. Template Notice

This document is a good-faith starting-point template drafted for a US-based property-management SaaS with residents in the US, EU, and UK. Before it becomes binding on any real user, your counsel must review and adapt it to your jurisdiction, sub-processor list, and specific data-handling practices. Prestigious provides this text as-is with no warranty of legal sufficiency.

1. What We Collect

Account data (name, email, unit, phone), ledger data (balance, charges, payments), operational data (maintenance tickets, ARC requests, violations, bookings, pets), communication logs (email + SMS metadata, not message bodies unless you sent them through Prestigious), and diagnostic data (IP, user-agent, audit-log actions). We do not collect payment card details — Stripe holds those and returns only a token.

2. How We Use Your Data

To operate the Service: authenticate you, deliver statements, run maintenance workflows, send legally required notices, and prevent abuse. We do not sell your data. We do not use resident data to train third-party AI models.

3. Legal Basis

For EU/UK residents: we rely on (a) contract (to provide the Service), (b) legal obligation (tax, HOA record-keeping), and (c) legitimate interests (fraud prevention, product improvement). You may withdraw consent for optional communications at any time.

4. Data Sharing

We share data only with our sub-processors (Stripe for payments, Resend for email, GoHighLevel for SMS, DocuSign for signatures, Anthropic via Emergent Integrations for AI, MongoDB Atlas for storage) and only what each needs to fulfill the Service. All sub-processors are contractually bound to keep your data confidential.

5. Retention

Active accounts: data retained until you delete it or close the account. Closed accounts: financial and audit data retained for 7 years to satisfy accounting and HOA record-keeping obligations. Other data purged within 30 days of closure.

6. Your Rights (GDPR / CCPA)

You may (a) access all data we hold about you via Resident Portal → Profile → "Export my data" (returns a signed zip), (b) request correction or deletion by emailing privacy@prestigeproperty.os, and (c) request that we stop processing your data for direct marketing. We honor requests within 30 days.

7. Security

Passwords: bcrypt hashed. Sessions: HttpOnly + Secure JWT cookies. Transport: TLS 1.2+. Audit log: append-only with SHA-256 hash chain. Webhooks: signature-verified (HMAC for Stripe / DocuSign, Ed25519 for GoHighLevel). Rate limits: per-IP + per-user on all sensitive endpoints. Rate limit and webhook signature enforcement are on by default in production.

8. Cookies

We use one essential cookie (`access_token`, HttpOnly + SameSite=None + Secure) for authentication. We do not use tracking or advertising cookies.

9. Children

The Service is not directed at children under 16 and we do not knowingly collect their data.

10. Changes to This Policy

Material changes will be announced in-app and by email. Continued use after the effective date constitutes acceptance.

11. Contact

Data protection questions: privacy@prestigeproperty.os