Privacy Policy

Effective date: June 16, 2026

Last updated: June 16, 2026

This Privacy Policy explains how HOA Handled LLC (“HOA Handled LLC, ” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with the HOA Handled platform and related websites and services (the “Service”). It applies to association boards, their authorized representatives, and unit owners or members who use the Service. Our Terms of Service govern your use of the Service.

1.Information We Collect

We collect the following categories of information:

  • Board & owner personal information. Names, mailing addresses, email addresses, phone numbers, unit/lot details, and roles you provide or upload for board members and unit owners.
  • Financial information. Assessment and dues records, ledgers, and payment-related details. Card and bank account details are collected and processed by our payment processor, not stored by us directly.
  • Documents. Governing documents, meeting materials, notices, correspondence, and other files you or your association upload to or generate within the Service.
  • Usage data. Information about how you interact with the Service, such as pages and features used, actions taken, log data, device and browser information, and approximate location derived from IP address.
  • AI conversation history. When you use AI-assisted chat features, your questions and the assistant’s responses are stored to maintain conversation continuity within a session.
  • Electronic signature data. If you use the document-signing feature, we store the signature you draw or apply, together with an audit trail — including your IP address and browser information at the time you consent to electronic signing.
  • Public scanner submissions. If you use our public compliance scanner without an account, we collect the email address and association name you enter and your IP address to return your results and manage usage limits.

2.How We Use Information

We use information to:

  • provide, operate, maintain, and secure the Service;
  • perform core functions you request — compliance tracking, dues and assessment collection, owner communications by email and physical mail, document storage, and AI-assisted drafting and answers;
  • process payments and Connect payouts through our payment processor;
  • communicate with you about your account, transactions, and service updates;
  • analyze usage to understand, troubleshoot, and improve the Service; and
  • comply with legal obligations and enforce our Terms of Service.

When you or the Service uses AI-assisted features — including automated scheduled reports and text extraction from scanned documents — the relevant document text, your query, and the HOA operational context needed to respond (such as owner, lot, and payment records) may be sent to our AI providers to generate output for you. We do not sell personal information.

3.Sub-processors & Third Parties We Share With

We share information with the service providers (“ sub-processors”) below so they can perform functions on our behalf. Each is bound to use the information only to provide its service to us. We may also disclose information to comply with law, to protect rights and safety, or in connection with a business transfer.

ProviderPurposeData involved (typical)
ClerkUser authentication and account/session management.Account identifiers, email, login metadata.
StripePayment processing for subscriptions and dues, Connect payouts to associations, and bank-account verification for ACH payments (via Stripe Financial Connections).Payment and payout details, transaction metadata, and limited bank-account information used to verify ACH payment methods.
ResendSending transactional and notification email.Recipient email addresses, message content.
LobPrinting and mailing physical letters and notices.Recipient mailing addresses, letter content.
AnthropicAI processing of documents and queries (drafting, summarization, and question answering).Document and query text, plus the HOA operational context needed to answer board questions (owner and lot records, dues and payment status), and the content of scanned documents submitted for text extraction.
VercelApplication hosting and content delivery.Request and infrastructure data; data in transit.
SentryApplication error monitoring and diagnostics to detect and fix faults.Error events and technical diagnostics (stack traces, affected route, environment). Configured to exclude request bodies, cookies, and personal data (no default PII collection).
NeonManaged PostgreSQL database hosting.Customer Data stored by the Service.
Cloudflare R2Object storage for uploaded and generated documents.Governing and association documents, attachments.
PostHogProduct analytics to understand and improve feature usage.Usage events, device/browser metadata, pseudonymous identifiers.
Voyage AI / OpenAIGenerating vector embeddings of documents and queries for semantic search (Premier and Complete plans). Voyage AI is primary; OpenAI is a fallback.Extracted document text and search query text.
InngestBackground job orchestration for scheduled reports, document processing, and automated workflows.Job event metadata, including tenant and record identifiers.
SignWellElectronic signature collection for board documents, when an association enables the signing integration.Signer name and email address, and the document submitted for signature.
UpstashRate limiting for AI and API endpoints to protect the Service.Client IP addresses used as short-lived rate-limit identifiers.

This list reflects the providers in use as of the effective date and may change as the Service evolves. Material changes will be reflected in an updated version of this policy.

4.Cookies & Similar Technologies

We and our providers use cookies and similar technologies that are necessary to operate the Service (for example, to keep you signed in and to secure sessions) and, where applicable, to measure product usage through our analytics provider. You can control non-essential cookies through your browser settings; disabling essential cookies may prevent parts of the Service from working.

5.Data Retention

We retain Customer Data for as long as your account is active and as needed to provide the Service. After account termination, on written request we will make reasonable efforts to provide a copy of your Customer Data, and we retain data as needed to meet legal, accounting, or compliance obligations, after which we delete or anonymize it in the ordinary course. Some information may persist in backups for a limited time. Associations remain responsible for keeping their own independent records as their governing documents or applicable law require.

6.Security

We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit, access controls, and tenant isolation so each association’s data is segregated. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your information, we will notify affected parties as required by applicable law.

7.Your Rights & Choices

Depending on where you live, you may have rights regarding your personal information — such as the right to access, correct, delete, or obtain a copy of it, and to object to or restrict certain processing. Washington residents and residents of states with comprehensive privacy laws (for example, California’s CCPA/CPRA) may have additional rights. We do not sell personal information.

Note for finalization: the specific rights, response timelines, verification steps, and the list of applicable state-law (Washington/CCPA-style) provisions in this section are being finalized with legal counsel before this policy takes effect.

To exercise a right or ask a question, contact us at info@hoahandled.com. Much of the personal information in the Service is provided by an association on behalf of its owners; in those cases we may direct your request to the relevant association as the controller of that data.

8.Children's Data

The Service is intended for use by adults acting on behalf of an association and is not directed to children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us personal information, contact us and we will delete it.

9.International Users

The Service is operated from, and intended for use in, the United States, and information is processed and stored in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your jurisdiction.

10.Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice and update the “Last updated” date above. Your continued use of the Service after the changes take effect means you accept the updated policy.

11.Contact

Questions about this Privacy Policy or our data practices? Contact HOA Handled LLC at info@hoahandled.com.

⚠️ DRAFT — pending legal review. Not yet effective. This document contains placeholders to be completed by the founder and reviewed by an attorney before launch.