Privacy ยท version 2026-08-20-xt3-v1

Privacy & data handling

Operator / privacy contact

Legal operator:
Privacy contact:
Privacy email/contact:

We collect and use information reasonably necessary to operate QuoteCapture, PropertyWorkHQ and related acquisition surfaces, secure accounts, verify businesses and providers, coordinate work, preserve lawful evidence, prevent abuse and respond to privacy/security requests. We do not operate a behavioural-advertising or data-broker product.

Information we may process

Depending on the role and workflow, this can include business/contact information; property, unit and work-order information; provider credentials, insurance and compliance evidence; PM entity/authority evidence; workforce/technician records; resident contact and access preferences; job-scoped communications and attachment hashes; approvals, offers, assignments, outcomes and commercial provenance; integration identifiers/events; security, device and consent metadata; and encrypted property-access secrets such as lockbox, gate or alarm information when intentionally stored in the secure-access feature.

How information is used and shared

Information is used to provide the requested platform workflow, verify eligibility, route or coordinate work, send transactional notifications, operate integrations, investigate incidents, maintain audit/evidence records and protect the service. PM Customers, Providers, residents and authorized personnel receive only the information appropriate to their role and the relevant property/job. Independent Providers receive information needed for assigned/offered work; they do not receive unrelated PM or resident data. Service vendors acting for the Platform may process information under appropriate contractual/security controls.

Sensitive property-access information

Secure access values are treated separately from ordinary notes: encrypted at rest, scoped to the relevant property/job/authorized assignment, disclosed only when the access policy permits, and audited when revealed. Access secrets are excluded from normal telemetry. Users should not place door, gate, alarm or lockbox codes in ordinary message/notes fields.

Communications and evidence

Job-scoped messages, system events, delivery status, agreement acceptance and workflow evidence may be retained as tamper-evident operational records. Redaction can limit ordinary display without falsifying the historical audit record where retention remains necessary for security, disputes, commercial provenance or legal obligations.

Integrations

Authorized PM Customers can connect external systems using scoped integration credentials. Integration data is limited to the authorized workspace and supported operations. Credentials and webhook secrets are protected separately and revoked as part of offboarding.

Retention and offboarding

Retention depends on record type, active service need, security/audit requirements and applicable law. Unmatched request records are targeted for deletion or de-identification within 90 days unless another legitimate retention basis applies. Offboarding revokes active access/credentials and starts the applicable retention workflow. Where historical commercial, consent, security or evidence records must remain, we prefer minimization/anonymization over retaining unnecessary personal information.

Your requests

Subject to applicable law and identity/authority verification, you may request access, correction, deletion, restriction or withdrawal of future optional sharing/communications. Some records may need to be retained or de-identified rather than deleted when required for security, fraud prevention, contractual evidence, disputes or law.

Open the Data Request Centre

Transactional communications

Operational email, SMS or push messages may be used to deliver work offers, status changes, access coordination and other requested service communications. Marketing consent is handled separately from communications necessary to provide the requested platform service.

Security and incidents

We use role/scope controls, encrypted secrets, hashed access credentials, audit records and other safeguards appropriate to the system design. No system can guarantee absolute security. Suspected privacy/security incidents should be reported to the Privacy Lead promptly.