Legal
Privacy Policy
Effective date: October 1, 2026
This Privacy Policy describes how HavenHOA ("HavenHOA," "we," "us," or "our") collects, uses, discloses, and retains personal information through our websites, applications, communications, and related services (collectively, the "Service"). It applies to website visitors, prospective customers, HOA and property-management customers, administrators, board members, residents, household members, vendors, maintenance personnel, and other people whose information is processed through the Service.
1. Our Role, No Legal Advice, and Customer Responsibility
HavenHOA determines how personal information is processed for our own account administration, billing, marketing, support, security, analytics, and business operations. When an HOA, property manager, or other organizational customer submits or directs us to process resident, household, vendor, financial, governance, document, or communication data ("Customer Data"), HavenHOA generally acts as a service provider or processor on that customer's behalf. The customer controls why the Customer Data is collected, who may access it, and how it is used within the Service.
Customers are responsible for having authority to provide Customer Data, giving legally required notices, obtaining legally required consents, configuring access appropriately, and ensuring that their instructions and use of the Service comply with applicable law. Requests concerning records controlled by an HOA or property manager should ordinarily be directed to that organization. We may refer a request to the relevant customer and assist as required by applicable law or our agreement with that customer.
HavenHOA does not provide legal advice and does not determine which laws, regulations, governing documents, or legal duties apply to a customer, its community, or its use of Customer Data. The availability of a feature, setting, default, template, workflow, notice, consent mechanism, retention option, fee configuration, communication method, report, automation, or support response is not a representation that it is lawful, sufficient, or appropriate in any jurisdiction. Information from HavenHOA, including documentation and support communications, must not be treated as legal advice or a substitute for advice from the customer's own attorney.
Each customer is solely responsible for independently identifying the federal, state, local, and other requirements that apply to it; obtaining advice from its own legal counsel and other professional advisers; and configuring, administering, and using the Service and Customer Data in accordance with those requirements. The customer must reassess its configuration as its operations, governing documents, jurisdictions, or applicable laws change. HavenHOA does not review, approve, monitor, audit, or assume responsibility for a customer's legal compliance.
2. Information We Collect
Depending on how the Service is used, we may collect or process:
- Identity and account information: Names, email addresses, phone numbers, login credentials, authentication records, roles, permissions, language preferences, and account status.
- Community, property, and household information: HOA and property-manager details, subdomains and domains, property and mailing addresses, ownership and occupancy records, household-member information, relationships, vehicle information, notes, and move-in or move-out dates. Customer-provided household records may concern minors.
- Financial and payment information: Assessments, balances, ledgers, journals, invoices, payment and refund history, transaction references, bank-feed institutions, account display information, balances, and transactions. Payment and bank-linking providers generally retain full card numbers, bank credentials, and similar payment credentials.
- Tax and sensitive business records: Association EINs, vendor or owner tax identifiers, tax classifications, withholding information, tax workpapers, information-return records, and related files. Some tax identifiers may be Social Security numbers when supplied for an applicable tax workflow.
- Community operations and governance: Maintenance requests, violations, architectural requests, amenity reservations, visitor information, announcements, acknowledgments, ballots, proxies, election and voting records, approvals, vendor bids, insurance records, and audit history.
- Content and communications: Messages, comments, notification preferences, support communications, email and text delivery records, mailed notices, documents, photographs, attachments, prompts, AI output, summaries, and translations.
- Marketing and lead information: Contact details, HOA or business information, form submissions, meeting or lead status, email engagement, campaign parameters, advertising click identifiers, landing pages, referrers, and conversion milestones.
- Device, usage, and log information: IP address, browser and device information, cookie and similar identifiers, pages and features used, timestamps, approximate location derived from IP address, diagnostic information, and security events.
We receive information directly from individuals; from customers, administrators, property managers, and other users; automatically from browsers and devices; and from providers and integrations such as authentication, payment, banking, accounting, communications, analytics, advertising, and security services.
3. How We Use Information
We may use personal information to:
- Provide, operate, configure, maintain, support, and improve the Service.
- Create accounts, authenticate users, manage permissions, and administer HOA and property-manager portals.
- Provide accounting, payment, bank-reconciliation, tax, document, governance, communication, mailing, and community-management workflows.
- Process transactions, subscriptions, refunds, disputes, and related financial records through our providers.
- Synchronize authorized records with services such as QuickBooks Online and Stripe.
- Deliver transactional, service, marketing, email, text, in-app, and physical-mail communications and manage communication preferences.
- Provide AI-assisted drafting, search, triage, document summaries, and automatic translation; cache derived output where useful to operate the Service.
- Respond to inquiries, provide support, troubleshoot, and communicate about the Service.
- Measure usage, attribute leads and conversions, evaluate advertising effectiveness, and develop or market the Service.
- Detect, investigate, prevent, and respond to fraud, abuse, payment issues, policy violations, technical problems, or security incidents.
- Comply with law, enforce agreements, collect amounts owed, preserve evidence, and establish, exercise, or defend legal rights.
- Fulfill another purpose disclosed when information is collected, a purpose reasonably compatible with the context in which it was provided, or another purpose authorized by the customer or individual.
We may create and use aggregated, statistical, or deidentified information for analytics, benchmarking, research, security, service improvement, and other lawful business purposes. We may retain and use that information as permitted by law and will not attempt to reidentify it except to test our deidentification processes or as otherwise permitted by law.
4. How We Disclose Information
We may disclose personal information in the following circumstances:
- Affiliates and related organizations: We may disclose information to current or future affiliates, subsidiaries, or organizations under common ownership or control, subject to this Policy or protections consistent with it.
- Customers and authorized users: Customer Data may be available to the customer that controls it and to users the customer authorizes, subject to configured roles, permissions, community settings, and public-site choices.
- Infrastructure and technology providers: We use providers for hosting, databases, storage, authentication, monitoring, and performance services. These may include Supabase and Vercel.
- Financial and accounting providers: We exchange information with providers such as Stripe and Intuit when needed for payments, subscriptions, connected accounts, bank feeds, financial records, or QuickBooks Online synchronization. Stripe's independent processing is described in the Stripe Privacy Policy.
- Communications and mailing providers: Providers such as Resend, SendGrid, Twilio, and Lob may process names, contact information, message or notice content, mailing addresses, and delivery metadata to send email, text messages, or physical mail and verify mailing addresses. We do not share text messaging originator opt-in data and consent with third parties or affiliates for their marketing or promotional purposes.
- AI and language providers: Google Gemini may process prompts and relevant Customer Data to provide drafting, search, triage, summaries, and translation. This may include the contents of a selected document or user-authored text. Google's processing is governed by the Gemini API Terms. Customers and users are responsible for ensuring they are authorized to submit information for this processing.
- Analytics, advertising, and security providers: Google Analytics, Google Ads, Vercel Analytics, Meta measurement tools, and Google reCAPTCHA may receive device information, browser identifiers, website activity, attribution information, conversion events, and security signals to provide analytics, advertising measurement, attribution, fraud prevention, and bot detection. Google's services are subject to its Privacy Policy and Terms of Service.
- Professional and business advisers: We may disclose information to attorneys, accountants, auditors, insurers, consultants, financing sources, and other advisers subject to appropriate confidentiality obligations.
- Legal, safety, and enforcement purposes: We may disclose information when we reasonably believe it is necessary to comply with law, legal process, court orders, or government requests; enforce agreements or collect amounts owed; investigate fraud, abuse, payment disputes, or security incidents; preserve evidence; or protect the rights, property, or safety of HavenHOA, customers, users, providers, or the public.
- Business transactions: Information may be reviewed, disclosed, or transferred in connection with financing, due diligence, a merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction or negotiation, subject to customary confidentiality protections and any notice required by law.
- At your direction: We may disclose information when a customer or user directs us to do so, enables an integration, publishes information, or otherwise consents.
We do not sell personal information for monetary consideration. Some laws may define certain analytics or advertising disclosures as a "sale," "sharing," or targeted advertising even when no money is exchanged. Where such laws apply to HavenHOA, eligible individuals may exercise the applicable rights described below.
The Service may contain links to, embed content from, or interoperate with websites and services that HavenHOA does not control. HavenHOA is not responsible for a third party's content, availability, security, or privacy practices. This Policy does not govern information a third party collects independently, and a link or integration does not imply endorsement. Review the third party's privacy notice before providing information or using its service.
5. Cookies and Similar Technologies
We and our providers may use cookies, pixels, local or session storage, and similar technologies for authentication, preferences, security, attribution, analytics, advertising measurement, performance, and conversion reporting. A first-party attribution cookie may retain campaign parameters and advertising identifiers as a visitor moves from a landing page to signup. Analytics and advertising providers may set or read their own identifiers according to their services. Browser and device controls may allow you to delete or block some of these technologies, but blocking essential storage may impair the Service.
The Service does not currently respond to browser “Do Not Track” signals, and HavenHOA does not currently offer an in-Service cookie or advertising preference center. Analytics and advertising providers may collect information about activity over time and across different websites, devices, or services according to their own policies. Certain legally recognized opt-out preference signals, such as Global Privacy Control, are distinct from Do Not Track. HavenHOA will process legally required privacy requests as required by applicable law. You may submit a privacy request to privacy@gethavenhoa.com.
6. Text Messaging
HavenHOA and its communications providers may send recurring automated informational, transactional, and service text messages on behalf of your community association to a mobile number whose user has asked to receive them. Each message begins with the community's name, and messages cover community announcements, maintenance updates, amenity reservations, architectural requests, account notices, violation notices, and statements. That request is what enrolls you: it is made by checking the text-message box at registration or in your resident profile, or by pressing the button to turn on text alerts on a consent link we email you or in the resident portal, and a number provided by you or by your association does not enroll anyone on its own. Marketing text messages are sent only where the number's user has given separate prior express written consent. Message frequency varies, and message and data rates may apply. You can turn off any category, or all of them, in account settings; those settings never turn texting on by themselves. Consent to receive text messages is not a condition of purchasing or using the Service. Reply HELP for help or STOP to opt out; additional opt-out instructions may appear in a message. One HavenHOA toll-free number sends for every community, so replying STOP stops texts from every community you belong to.
We may provide text messaging originator opt-in data and consent to communications providers solely as necessary to deliver messages, maintain consent and opt-out records, prevent abuse, and comply with law. We do not sell text messaging originator opt-in data or consent or share it with third parties or affiliates for their own marketing or promotional purposes. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
7. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Policy, to follow customer instructions, and to satisfy our operational, contractual, accounting, tax, audit, security, dispute-resolution, and legal obligations. Retention varies by record type, customer relationship, feature, provider, and applicable law. Financial, tax, legal, governance, security, and audit records may be retained for extended periods.
Following termination of an HOA portal, we generally make Customer Data available for export for 30 days. After that export period, access may be disabled and data may be deleted, deidentified, or retained as reasonably necessary for the purposes above. Deleting an individual account does not necessarily delete records controlled by an HOA or records concerning transactions involving other people.
Information may remain in backups, archives, logs, provider systems, or records that cannot reasonably be isolated until it is overwritten or deleted through ordinary retention cycles. We may retain aggregated or deidentified information where permitted by law. Disconnecting an integration stops future access through that integration, but previously imported records may remain part of the customer's business records.
8. Data Security
We maintain reasonable administrative, technical, and organizational safeguards designed to protect personal information. Depending on the information and feature, these safeguards may include encryption in transit, authentication controls, tenant-scoped authorization, restricted access, private storage controls, logging, and encryption of selected tax identifiers. Payment card and bank credentials are generally collected and maintained by our payment and bank-linking providers rather than stored by HavenHOA.
No safeguard, system, or transmission method is completely secure. We do not guarantee absolute security. Customers and users are responsible for protecting credentials, maintaining accurate authorized-user access, and promptly notifying us of suspected unauthorized activity. If a security incident occurs, we may investigate, preserve relevant records, take protective action, and provide notices as required by applicable law.
9. Privacy Rights and Choices
Depending on your location, relationship with HavenHOA, and applicable law, you may have rights to access, correct, delete, or obtain a copy of certain personal information; object to or restrict certain processing; opt out of certain sales, sharing, or targeted advertising; limit certain uses of sensitive personal information; appeal a decision; or receive equal service without unlawful discrimination for exercising a privacy right.
These rights are not absolute. They may not apply to Customer Data we process on an HOA's behalf and may be subject to identity and authority verification, legal exemptions, other people's rights, security concerns, confidential information, transaction and recordkeeping requirements, and legally permitted extensions or fees. We may request information needed to verify a request, require proof of an authorized agent's authority, deny or limit a request where permitted by law, or direct the request to the customer that controls the relevant records.
To submit a request, contact privacy@gethavenhoa.com. We will respond within the period required by applicable law. You may unsubscribe from marketing email using the link in the message. Service, security, billing, and legally required communications may continue where appropriate.
10. Sensitive Information and Children
Do not submit Social Security numbers, health information, biometric information, precise geolocation, government identification, or other highly sensitive personal information unless an applicable HavenHOA feature specifically requests it and you are authorized to provide it. Free-text fields, uploads, communications, and AI features should not be used to submit unnecessary sensitive information.
The Service is not directed to children under 13, and children under 13 may not create HavenHOA accounts. Customers and other adults may submit household records concerning minors for community-administration purposes. The customer controls those records and is responsible for having authority to provide and use them. If you believe a child has submitted personal information directly to HavenHOA, contact us so we can review the circumstances and take action required by law.
11. United States Service and Processing
HavenHOA is based in Utah, and the Service is offered for use in the United States. Personal information may be processed and stored in the United States and in other locations where our providers operate, where privacy protections may differ from those in your jurisdiction.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised effective date. When appropriate or required by law, we may provide additional notice through the Service, by email, on our website, or through another reasonable method. Unless otherwise stated, an updated Policy is effective when posted.
13. Contact
HavenHOA is a product of Agentic Software Solutions. Questions, concerns, and privacy requests may be sent to privacy@gethavenhoa.com. Please include enough information for us to understand the request and identify the relevant account, customer, or records. Do not send sensitive identifiers or account credentials by email.