Skip to main content

Privacy Policy

Last updated: June 30, 2026. This policy explains how BoroDesk (“we”) collects, uses, and protects the personal information of building residents, owners, and board members who use the Unified Resident & Board Portal (the “Portal”). We operate the Portal on behalf of your property-management company (the “Manager”), who is the controller of your data; we are the processor. For processor terms, see our Data Processing Addendum.

1. Information we collect

  • Account & contact: name, unit, email, phone, preferred language, household members, emergency contact, vehicles, pets.
  • Financial (ledger): your account balance, charges, payments, and credits, read live from the general ledger. We do not store card or bank numbers — payments are processed by Stripe, and we retain only Stripe references and payment status.
  • Service & building activity: maintenance requests (including photos you upload), amenity reservations, package records, pre-authorized visitors, and messages you send.
  • Governance (board members): board role, voting eligibility, ballots (secret ballots are stored unlinkably — see §6), meeting attendance.
  • Consents: your per-channel, per-category communication preferences.
  • Technical: authentication identifiers and security/audit logs (actor, action, timestamp, IP) needed to keep the Portal safe.

We do not collect protected-class information to make decisions about you, and we do not use your data for discriminatory targeting (see our Fair Housing posture in COMPLIANCE.md).

2. How we use it

  • To show your live balance and let you pay rent, fees, and assessments.
  • To route and track maintenance requests, reservations, packages, and visitors.
  • To deliver building communications on the channels you have consented to.
  • To power the resident assistant — which answers questions using only your own data (see §5).
  • To run auditable governance (elections, minutes) for board members.
  • To secure the Portal, detect abuse, and maintain the audit trail.

3. Per-unit isolation

Your portal data is scoped to your unit. We enforce isolation in the database itself with row-level security — not merely in application code — so another resident cannot read your balance, packages, visitors, reservations, messages, or documents. This is verified by an automated test that gates every release.

4. Sharing & processors

We share data only with the Manager and staff who need it for building operations, and with these sub-processors under data-processing agreements:

  • Supabase — database, authentication, and file storage (hosting).
  • Stripe — payment processing (PCI-DSS; card data never reaches us).
  • Anthropic — the Claude model powering the resident assistant; it receives only the data your permission scope allows and does not train on it.
  • Email / SMS / push providers — to deliver communications you have consented to.

We do not sell your personal information.

4a. SMS / text messaging

We do not share or sell mobile phone numbers or SMS consent with third parties for their marketing or promotional purposes. Mobile information is used solely to deliver the building notifications you have opted into (package alerts, maintenance/work-order updates, payment receipts, amenity and meeting notices, and emergency broadcasts).

Message frequency varies based on your building activity and the categories you opt into. Message and data rates may apply. Reply STOP to any message to opt out of that channel, START to opt back in, and HELP for assistance. Opt-in is per channel and per category and is recorded in your profile; you can change it anytime in Profile & preferences. See our Terms of Service for messaging terms.

5. The resident assistant

The assistant is permission-aware: it retrieves information through the same access-controlled queries you would use, so it can only ever surface your data. It does not move money, cast votes, or take actions on your behalf. When it surfaces financial information, we record an audit entry.

6. Voting privacy

For secret ballots, your selection is stored without any link to your identity. A one-way commitment proves your eligible unit voted exactly once without revealing how you voted; the tally is verifiable via a tamper-evident hash chain that never exposes the voter-to-selection link.

7. Retention

We keep account and service data for as long as you reside in the building and as the Manager’s retention policy and law require. Governance records (minutes, election audit trails) are retained per corporate-records obligations. Payment references are retained for financial-recordkeeping periods. Audit logs are retained as security records.

8. Your NY resident rights

You may request access to, correction of, a portable export of, or deletion of your personal information. Use the export/deletion path in your Profile or contact the Manager; we will act on the Manager’s instruction, subject to legal retention obligations. New York residents are protected by the SHIELD Act’s data-security requirements.

9. Security

We apply a written reasonable-safeguards program: TLS in transit, encryption at rest, least-privilege access, row-level tenant isolation, immutable audit logging, and breach-detection hooks. See SECURITY.md for specifics.

10. Contact

Questions or requests: privacy@borodesk.com. For anything about your building’s operations, contact your Manager.