Privacy Policy

Effective date: April 10, 2026

1. Who we are

AutopilotHOA ("we," "our," or "us") provides a cloud-based homeowners association management platform. This Privacy Policy describes how we collect, use, and protect information about users of our service at autopilothoa.com.

2. Information we collect

Account information: name, email address, hashed password, phone number (optional), and community membership details.

Community data: HOA settings, member rosters, dues configurations, payment records, announcements, documents, violations, maintenance requests, polls, and events — all provided by your community administrators.

Payment data: Subscription billing is handled by Stripe. We store your Stripe customer ID and subscription status; we do not store raw card numbers.

Usage data: login timestamps, IP addresses, and browser/device information collected automatically via server logs and cookies.

3. How we use your information

  • Provide, operate, and improve the AutopilotHOA service
  • Send transactional emails (dues reminders, announcements, notifications)
  • Process subscription payments via Stripe
  • Respond to support requests
  • Comply with legal obligations

We do not sell your personal information to third parties.

4. Data sharing

We share data only with the following third-party service providers, each bound by their own privacy policies:

  • Neon (PostgreSQL) — database hosting
  • Vercel — application hosting and edge infrastructure
  • Stripe — payment processing and subscription billing
  • Resend — transactional email delivery
  • UploadThing — file storage (documents, attachments)

5. Data retention

We retain your data for as long as your account is active or as needed to provide the service. If you cancel your subscription, community data is retained for 30 days before being permanently deleted. You may request earlier deletion by contacting us.

6. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access a copy of the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Object to or restrict certain processing
  • Receive your data in a portable format (GDPR Article 20)

To exercise any of these rights, email us at privacy@autopilothoa.com.

7. Cookies

We use a single authentication session cookie (managed by NextAuth.js) to keep you signed in. We do not use advertising or tracking cookies.

8. Security

All data is transmitted over HTTPS. Passwords are hashed with bcrypt (12 rounds). Access to production data is restricted to authorized personnel. We conduct periodic security reviews and promptly address any vulnerabilities.

9. Changes to this policy

We may update this Privacy Policy periodically. Material changes will be communicated by email to HOA administrators at least 14 days before taking effect.

10. Contact

Questions about this policy? Email us at privacy@autopilothoa.com.