Privacy Policy
Effective August 27, 2026
DoorSpan is property-management software for owner-operators. This policy explains what personal information we process, why, who we share it with, how long we keep it, and the rights you have. We designed the product to collect the minimum needed and to keep sensitive documents out of places they don't belong.
Information we process
Account data (name, email); the property, tenant, lease, financial, and maintenance records you enter or import; files you upload; and, where you connect them, data from services like your bank (via Plaid), mailbox, or payment processor. We do not use third-party advertising trackers, and the only cookie we set is the essential sign-in session.
How we use AI with your data — and how we don't
- We use AI to read documents and draft messages — never to make final decisions for you.
- Before any document is sent for reading, we strip identifiers (SSN, EIN, account and card numbers, taxpayer name) on our own servers; a scan or photo is refused rather than transmitted as an image.
- Our AI provider does not train on commercial API inputs or outputs by default. Its standard API retention is up to 30 days; Zero Data Retention applies only when a separate approved agreement is in place.
- Usage metering records only opaque identifiers and token counts — never your names, contents, or documents.
How long we keep it
Financial scans (tax, mortgage, bank) are read for their figures and never stored. Records you may need — leases, W-9s, insurance, screening/applications, photos — are stored privately and encrypted, then automatically deleted on a retention schedule (e.g. screening 24 months, W-9 4 years, leases 7 years). You can delete anything sooner.
Who we share it with
Only the service providers that make the product work (our “subprocessors”), each under contract and only for the purpose shown. The current list is at /legal/subprocessors. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Your rights
- Access & export — download a copy of your organization's data anytime (Settings → Passwords & Security → Data & privacy).
- Deletion — permanently delete your organization and all its data, including stored files.
- Correction — edit any record directly in the app.
- Security transparency — private encrypted storage, role-based access, MFA, an access audit trail, and automated secure disposal.
Depending on where you live (e.g., California's CCPA/CPRA, Colorado's CPA, or the EU's GDPR), you may have rights to access, delete, correct, or port your data, and to appeal a decision. Exercise access, export, and deletion directly in the app (Settings → Passwords & Security → Data & privacy), or contact us.
How we protect it
Private, encrypted file storage; encryption of sensitive tokens at rest and all traffic in transit; role-based access (staff see only what their role allows); multi-factor authentication; an access audit trail; and automated secure disposal on the retention schedule above. If a breach affecting your personal information occurs, we will notify you and any required authorities within the timeframes the law requires.
Contact
Questions or requests: your organization owner, or the support contact provided to your account.