Last updated: 10 May 2026
1. Data We Collect
We collect information you provide: property details, financial data, tenant information, maintenance records, and account credentials (name and email). We also collect usage data to improve the platform.
2. How We Use Your Data
Your data is used exclusively to provide the Property Command service — to display your portfolio, calculate metrics, and generate insights. We do not sell your personal data to third parties.
3. Data Storage & Security
All data is stored securely using Supabase, hosted on SOC 2 Type II compliant infrastructure. Data is encrypted at rest and in transit using TLS 1.2 or higher.
4. Row-Level Security
Your data is protected by row-level security (RLS) policies enforced at the database level. No other user can access your properties, transactions, or tenancy information.
5. Data Stored Locally
Some features (notification preferences, appearance settings, share tokens, multi-loan entries, inspection schedules, and document vault links) are stored in your browser's localStorage and never transmitted to our servers. This data will be lost if you clear your browser cache.
6. Cookies
We use session cookies for authentication only, managed by Supabase. We do not use tracking, advertising, or analytics cookies.
7. Property Sharing
When you enable property sharing, a unique token is stored in the database alongside your property record. Anyone with the share link can view a limited set of overview data (address, value, growth, rent, yield). Tenant details, contacts, loan balances, and personal data are never included in shared views. You can revoke access at any time.
8. Your Rights
You have the right to access, correct, export, or delete your personal data at any time. Use Settings → Security to export your data or request account deletion. Contact us at hello@propertycommand.io for any request we cannot automatically fulfil.
9. Data Portability
You can export all your data in JSON format from Settings → Security → Export my data. The export includes all properties, transactions, and maintenance records associated with your account.
10. Account Deletion
You can request account deletion from Settings → Security → Delete my account. All database records will be deleted immediately. The authentication record will be removed within 30 days. Some residual data may remain in encrypted backups for up to 30 days before permanent deletion.
11. Retention
We retain your data for as long as your account is active. Deleting your account permanently removes all associated data within 30 days, including backups.
12. International Transfers
Your data may be processed in countries outside your jurisdiction. Where data is transferred outside the EEA or UK, we ensure appropriate safeguards are in place under applicable data protection law.
13. Minors
The Service is not directed at persons under 18. We do not knowingly collect data from children under 13 in the US, or under 16 in the EU. If you believe a minor has provided data, contact us immediately.
14. Changes to This Policy
We will notify you of material changes via email or in-app notice at least 30 days before they take effect.
15. Contact
For privacy-related questions, contact us at hello@propertycommand.io. For data subject requests under GDPR, UK GDPR, CCPA, or similar laws, please include your jurisdiction in the subject line.
© 2026 Property Command