← Property Stride

Property Stride Privacy Policy

Effective Date: [INSERT DATE]
Last Updated: [INSERT DATE]

DRAFT — NOT FOR PUBLICATION. This document is a working draft prepared for attorney review. It has not been reviewed by a licensed attorney and should not be published or relied upon until it has been. See the attached review notes for specific issues flagged for counsel.

Property Stride, LLC, doing business as Property Stride ("Property Stride," "we," "us," or "our") provides a web application that helps residential property management companies coordinate unit turnover and renovation projects, including scoping and pricing work with vendors, managing property owner approvals, and tracking project schedules (the "Service"). This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights available to you.

This Policy applies to:

  • Account Holders — the property management companies (and their employees/users) who subscribe to and log into Property Stride;
  • Vendors — contractors and trade professionals invited by an Account Holder to submit bids or complete work, who interact with Property Stride via emailed invite links without creating an account;
  • Owners — property owners invited by an Account Holder to review and approve project costs, who also interact with Property Stride via emailed invite links without creating an account.

If you are a Vendor or Owner, please note: Property Stride's direct customer is the property management company that invited you (the Account Holder). The Account Holder controls what information about you is entered into Property Stride and decides how your relationship with them is managed. Questions about why your information was submitted, or requests to correct it, should generally start with that company. Property Stride will still honor direct requests to us as described in "Your Rights and Choices" below.


1. Information We Collect

1.1 Account Holder Information

When a property management company signs up for Property Stride, we collect, via our authentication provider (Clerk) and store in our own database:

  • Name and email address of each user
  • Company name and business address
  • Phone number

1.2 Billing Information

Subscription payments are processed by our payment processor, Stripe. Property Stride does not collect or store credit card or bank account numbers. Stripe collects and stores payment method details directly, subject to Stripe's own privacy policy. We retain limited billing metadata from Stripe (e.g., subscription status, invoice history, unit counts billed) needed to administer accounts.

1.3 Property and Project Data

To operate the Service, Account Holders and their invited Vendors input:

  • Property and unit addresses and details
  • Project scope-of-work descriptions and pricing
  • Photographs documenting property conditions
  • Vendor bids and quotes

1.4 Vendor Information

Account Holders may enter, on behalf of their vendors:

  • Vendor name and email address
  • Trade or specialty
  • Self-reported insurance information

This information is provided by the Account Holder, not collected directly from the Vendor, except where a Vendor submits a bid or quote directly through an invite link.

1.5 Owner E-Signature and Approval Records

When a property owner uses an emailed invite link to approve project costs or a change order, we capture:

  • The typed full name entered by the owner
  • The exact text of the approval/consent language presented and agreed to
  • A timestamp of the approval
  • The IP address of the device used
  • The browser user-agent string

We collect this specific combination of data points because it is used to create a durable, auditable record that a property owner reviewed and approved specific costs. This record may be relied upon by the Account Holder (and potentially by Property Stride) as evidence of consent in the event of a later dispute about whether, when, or to what an owner agreed. Because this data can carry legal significance, please see the flag in Section 10 regarding attorney review of this feature.

1.6 Technical and Usage Data

Our error-monitoring tool (Sentry) may automatically capture technical diagnostic information when errors occur — for example, browser type, device information, and application state at the time of an error. This is collected to help us identify and fix bugs, not to build profiles of individuals. Sentry data may incidentally include fragments of personal information (e.g., if a name or email happens to be present in application state when an error occurs).


2. How We Use Information

We use the information described above to:

  • Provide, operate, and maintain the Service (creating accounts, displaying projects, routing invite links, generating documents such as bid PDFs)
  • Process subscription billing and manage accounts
  • Send transactional communications (invite links, approval confirmations, award/decline notices, billing receipts, account notifications)
  • Send product-related communications about the Service you use (e.g., feature updates, service notices)
  • Maintain records of owner approvals and change-order consent for the Account Holder's business and legal recordkeeping purposes
  • Monitor, diagnose, and fix technical errors
  • Enforce our Terms of Service and protect the security and integrity of the Service
  • Comply with legal obligations

We do not:

  • Use your data for advertising or ad targeting
  • Sell personal information to third parties
  • Use your data to train artificial intelligence or machine learning models
  • Send marketing emails unrelated to your use of the Service

3. How We Share Information

We do not sell personal information. We share information only as follows:

3.1 Within the Service, By Design

Because Property Stride is a coordination tool between property managers, vendors, and owners, certain information is necessarily visible across these parties as part of the Service's core function — for example, a Vendor's bid is shared with the Account Holder, and pricing an Owner is asked to approve is shared with that Owner. Account Holders control what property, project, and contact information is entered and shared through the Service.

3.2 Service Providers (Subprocessors)

We share information with third-party service providers who help us operate the Service, under contractual obligations to protect it and use it only to provide services to us. Our current subprocessors are:

SubprocessorPurposeData Involved
ClerkAuthentication and account managementAccount Holder name, email, phone; login credentials
StripePayment processing and billingBilling contact info, subscription/invoice data; Stripe independently collects payment method details
AirtableBackend database / data storageAll application data described in Section 1
VercelApplication hostingAll data transmitted through the Service in the course of hosting
ResendTransactional email deliveryEmail addresses and content of transactional emails (invites, notifications)
SentryError monitoring and diagnosticsTechnical/error data; may incidentally include personal data present in app state

We will update this list if we add or change subprocessors, and where required by law, provide notice of material changes.

3.3 Legal Requirements

We may disclose information if required to do so by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, protect the safety of any person, investigate fraud, or respond to a government request.

3.4 Business Transfers

If Property Stride is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to standard confidentiality protections.


4. Data Storage and Security

Application data is stored using Airtable as our backend database and hosted via Vercel. We rely on industry-standard security practices offered by our service providers, including encryption in transit (TLS/HTTPS) for data transmitted to and from the Service. Payment card data is never transmitted to or stored on our own infrastructure — it is handled entirely by Stripe.

No method of electronic storage or transmission is 100% secure. While we work to protect personal information, we cannot guarantee absolute security.

[Attorney/technical review note: confirm and describe here any additional safeguards actually in place — e.g., access controls, encryption at rest via Airtable, employee access restrictions, incident response plan — once finalized, so this section reflects reality rather than generic language.]


5. Data Retention

  • Account Holder data is retained for as long as the account is active, and for a reasonable period afterward to comply with legal, accounting, and tax obligations, resolve disputes, and enforce agreements.
  • Vendor and Owner data entered by an Account Holder is retained for as long as the associated Account Holder's account remains active, and generally follows the same retention period as the Account Holder's own data, since it is part of the property/project records the Account Holder maintains through the Service.
  • Owner e-signature and approval records are retained for an extended period after project completion, because they may serve as evidence of consent relevant to disputes that can arise well after a project ends. [Attorney review note: recommend counsel specify a defined retention period here — e.g., tied to applicable statutes of limitations for contract/construction disputes in relevant states — rather than "indefinitely" or leaving it undefined.]
  • Billing records are retained as required for tax, accounting, and regulatory purposes.
  • Upon account termination, we will delete or anonymize personal information within a reasonable period, except where retention is required by law or necessary to resolve disputes, unless the Account Holder requests earlier deletion and no legal retention obligation applies.

[This section states intended practice at a policy level; actual technical deletion capabilities should be confirmed before publication — see Section 10.]


6. Your Rights and Choices

Depending on where you live, you may have rights regarding your personal information, including the right to:

  • Access the personal information we hold about you
  • Correct inaccurate personal information
  • Delete your personal information, subject to legal or contractual exceptions
  • Opt out of certain uses (note: since we do not sell data, use it for advertising, or send non-transactional marketing, several rights common under state privacy laws — such as opting out of sale or targeted advertising — are not applicable in the same way, but we still honor access/deletion requests)

How to Exercise Your Rights

You may submit a request by emailing [INSERT PRIVACY CONTACT EMAIL]. We will verify your identity before fulfilling a request. For Vendors and Owners, some information was submitted by the Account Holder rather than by you directly; we may direct you to the relevant Account Holder for certain corrections, but will still process deletion or access requests we receive directly consistent with our legal obligations.

Note that deleting certain information — particularly Owner approval/e-signature records — may not be possible while the underlying Account Holder has a legitimate business or legal need to retain that record (for example, as evidence of an owner's approval of costs already incurred). We will explain any such limitation if it applies to your request.

California and Oregon Residents

Because we operate in Oregon and may have users or data subjects in California, we note the following:

  • California Consumer Privacy Act (CCPA/CPRA): California residents have rights to know, delete, correct, and limit use of their personal information, and the right to non-discrimination for exercising these rights. Property Stride does not sell or share personal information for cross-context behavioral advertising as those terms are defined under the CCPA.
  • Oregon Consumer Privacy Act (OCPA): Oregon residents have similar rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of certain processing (targeted advertising, sale, or profiling) — categories of processing Property Stride does not currently engage in.

[Attorney review note: confirm whether Property Stride currently meets the applicable thresholds for CCPA/OCPA coverage (based on revenue, volume of consumers, or data), and tailor this section accordingly. Also confirm designated-agent and appeal-process requirements under OCPA if Property Stride is subject to it.]


7. Children's Privacy

Property Stride is intended for business use by adults and is not directed to children. We do not knowingly collect personal information from individuals under 18.


8. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice (such as by email to Account Holders or a notice within the Service) before the changes take effect. The "Last Updated" date at the top of this Policy reflects the most recent revision.


9. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

[INSERT LEGAL/BUSINESS NAME]
[INSERT MAILING ADDRESS]
[INSERT PRIVACY CONTACT EMAIL]


10. Notes for Attorney Review

The following items in this draft are flagged as needing specific legal review before publication:

  1. Owner e-signature / IP + user-agent capture (Sections 1.5, 5, 6). This is the highest-priority item. Property Stride is creating what functions as an electronic signature/consent record intended to have legal weight in disputes between owners and property managers (and potentially vendors). Counsel should confirm:
    • Whether this flow satisfies applicable e-signature law (e.g., the federal ESIGN Act and Oregon's adopted UETA) — particularly around consent to do business electronically, retention/reproduction of the signed record, and whether the owner needs a clearer disclosure/consent step before "signing."
    • Whether the disclosures given to the owner at the moment of approval (the "exact text they agreed to") are legally sufficient, and whether a specific e-signature consent disclosure needs to be added to that flow itself (separate from this Privacy Policy).
    • Who owns/controls this record as between Property Stride and the Account Holder, and how it should be retained and produced in the event of a dispute or subpoena.
  2. Data retention specifics (Section 5). The draft intentionally avoids committing to precise retention periods. Counsel should help set defensible, specific retention periods — especially for e-signature records — potentially tied to state contract/construction statutes of limitations.
  3. CCPA/OCPA applicability (Section 6). Whether Property Stride currently meets the thresholds that trigger these laws, and whether additional mechanisms (e.g., a "Do Not Sell/Share" link, a designated request method, appeal rights under OCPA) are legally required even though Property Stride doesn't sell data or run ads.
  4. Data processing agreements with subprocessors. Confirm Property Stride has (or needs) written agreements with Clerk, Stripe, Airtable, Vercel, Resend, and Sentry that appropriately restrict their use of Property Stride's customer data, particularly Airtable given it functions as the primary data store.
  5. Vendor/Owner status as non-users. Confirm the legal framing that Vendors and Owners are third-party data subjects whose information is primarily provided and controlled by the Account Holder, and whether this creates any data-controller/data-processor style obligations between Property Stride and the Account Holder that should be documented in a separate data processing addendum.
  6. Breach notification obligations. This draft does not include a breach notification section; Oregon (and other states, if applicable) have specific breach notification laws that should be addressed, likely in coordination with a security incident response plan.