Privacy Policy

Effective date: February 26, 2026  ·  Last updated: February 26, 2026

Summary: Proppify collects the information you provide to run your property management operations. We do not sell your data. We share it only with the sub-processors needed to deliver the service (email, payments, push notifications). You can request deletion of your data at any time.

1. Who We Are

Proppify ("we", "us", or "our") is a software-as-a-service (SaaS) property management platform available on the web at proppify.io, including mobile web access. We may also provide selected customers with access to a private pilot mobile application. Our registered contact address is support@proppify.io.

This Privacy Policy explains what personal data we collect from users of our web platform, mobile web experience, and any pilot mobile app, how we use it, with whom we share it, and what rights you have over it.

2. Data We Collect

2.1 Account & Profile Data

  • Full name
  • Email address
  • Phone number (optional)
  • Password (stored as a bcrypt hash — we never store plain-text passwords)
  • Role within a company (Company Admin, Property Owner, Worker)
  • Hourly rate (for workers, used to generate payroll reports)

2.2 Company & Business Data

  • Company name and subscription plan
  • Property names, addresses, and GPS coordinates
  • Property descriptions and custom rating questions
  • Task titles, descriptions, priorities, due dates, and status
  • Expense descriptions, amounts, and currency
  • Time log entries (start time, end time, duration, notes)
  • Payment records generated from time logs

2.3 Uploaded Files

  • Task images (photos uploaded from mobile web, web, or pilot mobile app access)
  • Expense invoice images or documents

Files are stored securely on our servers. You may delete uploaded files at any time through the platform.

2.4 Device & Technical Data

  • Expo push notification token (mobile app users who grant notification permission)
  • Device name (used to label API access tokens)
  • IP address (collected automatically for security and fraud prevention)
  • Browser or app version and operating system
  • Log data including pages visited, timestamps, and API requests

2.5 Billing Data

Subscription and payment processing is handled by Paddle (paddle.com). Paddle acts as the Merchant of Record for all transactions, meaning Paddle collects your billing name, card or PayPal details, and billing address directly. We do not store your full payment card number on our servers. Please review Paddle's Privacy Policy.

2.6 Property Ratings & Feedback

  • Ratings submitted via QR code feedback links (name, answers to custom questions, star ratings)

2.7 Contact Form Data

  • Name, email address, subject, and message submitted through our website contact form

3. How We Use Your Data

Purpose Legal Basis (GDPR)
Providing and operating the platformContract performance
Processing payments and managing subscriptionsContract performance
Sending transactional emails (invitations, task notifications, expense updates, verification)Contract performance
Sending push notifications about task and expense activityLegitimate interest / Consent
Generating payroll and expense reportsContract performance
Security monitoring and fraud preventionLegitimate interest
Responding to contact form enquiriesLegitimate interest
Improving the platform (aggregated, anonymised analytics)Legitimate interest
Complying with legal obligationsLegal obligation

4. Data Sharing & Sub-Processors

We do not sell, rent, or trade your personal data. We share data only with the following trusted service providers who help us operate the platform:

Provider Purpose Data Shared
PaddlePayment processing & subscription management (Merchant of Record)Billing name, email, payment details
Email Provider (SMTP)Transactional email deliveryRecipient email, name, email content
Expo (Expo Application Services)Mobile push notification deliveryExpo push token, notification content
Hosting / Cloud ProviderInfrastructure, database, and file storageAll platform data (encrypted at rest)

We may also disclose your information where required by law, court order, or to protect the rights, property, or safety of Proppify, our users, or others.

5. Push Notifications

If you use a pilot mobile app and grant notification permission, Proppify may send push notifications about task assignments, status changes, expense approvals, and other platform activity. You can disable push notifications at any time through your device's notification settings. We use Expo's push notification service to deliver these messages; your push token is transmitted to Expo solely for this purpose.

6. Location Data

Property GPS coordinates (latitude and longitude) are entered manually by company administrators when creating or editing a property. We do not collect your device's real-time location. The coordinates are used solely for property information and mapping display within the platform.

7. Cookies & Tracking

The Proppify web platform uses the following cookies:

  • Session cookie – Required for authentication. Expires when you close your browser or log out.
  • CSRF token cookie – Protects against cross-site request forgery. Required for security.
  • Remember-me cookie – Optional. Stores an encrypted token to keep you logged in across sessions. Expires after 30 days.

We do not use advertising, analytics, or third-party tracking cookies. The pilot mobile app uses local secure storage (Expo SecureStore) to persist your authentication token — this is not a cookie and is not accessible to third parties.

8. Data Retention

  • Account data – Retained for as long as your account is active. Deleted accounts are soft-deleted and permanently purged after 90 days.
  • Company data (properties, tasks, expenses, time logs) – Retained for as long as the company subscription is active, plus 30 days after cancellation to allow data export.
  • Uploaded files – Deleted when you remove them from the platform or when your account is purged.
  • Billing records – Retained for 7 years to comply with tax and accounting obligations.
  • Server logs – Retained for 30 days for security monitoring, then automatically deleted.
  • Contact form submissions – Retained for 12 months, then deleted.

9. Data Security

We implement appropriate technical and organisational measures to protect your data, including:

  • HTTPS/TLS encryption for all data in transit
  • Passwords hashed using bcrypt with a strong cost factor
  • API authentication via short-lived bearer tokens (Laravel Sanctum)
  • Role-based access control — users only access data their role permits
  • Database encryption at rest on our hosting provider
  • Regular security updates and dependency audits

No method of transmission over the internet is 100% secure. If you become aware of any security vulnerability, please notify us immediately at support@proppify.io.

10. Your Rights

Depending on your location, you may have the following rights over your personal data:

Access

Request a copy of the personal data we hold about you.

Rectification

Correct inaccurate or incomplete data — you can update most data directly in your profile settings.

Erasure

Request deletion of your account and personal data (subject to legal retention obligations).

Restriction

Ask us to limit how we process your data in certain circumstances.

Portability

Receive your data in a machine-readable format (where technically feasible).

Objection

Object to processing based on legitimate interests.

Withdraw Consent

Withdraw consent for push notifications at any time through your device settings.

Lodge a Complaint

File a complaint with your national data protection authority.

To exercise any of these rights, email us at support@proppify.io. We will respond within 30 days.

11. California Privacy Rights (CCPA)

If you are a California resident, you have the right to know what personal information we collect, disclose, or sell; to request deletion of your personal information; and to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at support@proppify.io.

12. Children's Privacy

Proppify is a business platform intended for users aged 18 and over. We do not knowingly collect personal data from children under 13 (or under 16 in the EEA). If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

13. International Data Transfers

Your data may be processed in countries other than your own, including the United States. Where we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) to protect your data in accordance with applicable law.

14. Third-Party Links

Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the "Last updated" date at the top of this page. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

16. Contact Us

For any privacy-related questions, requests, or complaints, please contact us at:

Proppify

Email: support@proppify.io

Website: https://proppify.io