Privacy Policy

Last updated: May 5, 2026

1. Information We Collect

We collect information you provide directly: name, email address, organization details, property data, financial records, and tenant information you enter into the platform. We also collect usage data: IP address, browser type, pages visited, and feature usage patterns.

2. How We Use Your Information

We use your information to: (a) provide and maintain the Service; (b) process payments via Stripe; (c) send transactional emails (verification, receipts, notifications); (d) improve the Service through aggregated analytics; (e) provide customer support; (f) comply with legal obligations.

3. Data Storage & Security

Your data is stored in PostgreSQL databases with row-level security (RLS) ensuring tenant isolation. Files are stored in Cloudflare R2 with encryption at rest. All data in transit is encrypted via TLS 1.3. We perform regular backups and maintain disaster recovery procedures.

4. Third-Party Services

We share data with the following third parties solely to provide the Service:

  • Stripe — payment processing
  • Resend — transactional email delivery
  • Sentry — error monitoring (no PII included)
  • Cloudflare — CDN, DNS, and file storage
  • Plaid — bank account linking (with your explicit consent)

We do not sell your personal information to third parties.

5. Cookies

We use essential cookies for authentication (session tokens). We use analytics cookies to understand how the platform is used. You can decline non-essential cookies via the consent banner. Essential cookies cannot be disabled as they are required for the Service to function.

6. Data Retention

We retain your data for as long as your account is active. Upon account deletion, we remove personal data within 30 days. Financial records may be retained for up to 7 years as required by tax regulations. Aggregated, anonymized data may be retained indefinitely for benchmarking purposes.

7. Your Rights

You have the right to: (a) access your personal data; (b) correct inaccurate data; (c) request deletion of your data; (d) export your data in a portable format; (e) withdraw consent for non-essential processing. To exercise these rights, contact privacy@foilios.com.

8. California Residents (CCPA)

California residents have additional rights under the CCPA including the right to know what personal information is collected, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information.

9. Children’s Privacy

The Service is not intended for individuals under 18. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or in-app notification at least 14 days before they take effect.

11. Contact

For privacy-related questions or requests, contact us at privacy@foilios.com.