Privacy Policy — LocalePM

Privacy Policy

Effective September 3, 2026

A resident directory is sensitive by definition, so this policy tries to be specific rather than reassuring. It explains what LocalePM collects, why, who can see it, how long we keep it, and what you can do about it.

LocalePM is built and hosted in the EU. Your building's data stays in the European Union (Germany), and this policy is written to the GDPR.

1. Who is responsible for your data

LocalePM is used by buildings. That makes the responsibility split matter, so it is worth stating plainly:

  • Your building is the controller of information about its residents. It decides what to collect, what the directory shows, who has which role, and how long to keep things. If you are a resident, questions about why your building holds something go to your property manager or board first.
  • We are the processor for that data. We store and process it to run the Service, on the building's instructions.
  • We are the controller for our own relationship with you: account credentials, billing, support conversations, marketing-site enquiries, and the security logs we keep to protect the platform.

2. Information we collect

Account and profile. Name, email address, phone number, the building and unit you are associated with, your role, profile photo, language preference, and authentication data (a hashed password, and two-factor secrets if you enable them).

Residency verification. Where a building requires it, the invite code you used, or an identity or residency document you submit. Verification documents are held only as long as needed to complete the check and are then deleted automatically.

Content you create. Maintenance tickets and their photos, community posts and comments, direct and building messages, amenity bookings, guest passes, documents you upload, and governance records such as violations, meeting minutes, and votes.

Building operations. Package deliveries logged for you, service records, meter readings, invoices and expenses associated with your unit, and payment status.

Payments. Card and bank details are entered directly with our payment processor and are never stored on our systems. We retain the transaction record — amount, currency, status, timestamps, and the processor's reference.

Technical and usage data. IP address, device and browser type, app version and platform, push notification tokens, timestamps, and audit records of significant actions (who changed what, and when). We use this to operate the Service, debug it, and investigate abuse.

Marketing-site enquiries. If you use our contact form, we receive the name, email, organisation, topic, and message you send, plus the originating IP address for abuse prevention. That message is delivered to the relevant inbox; it does not create an account.

3. Why we use it

  • To provide the Service — running the building's directory, tickets, packages, bookings, messaging, billing, and governance. Lawful basis: performance of a contract, or the legitimate interests of the building in operating the property.
  • To keep it secure — authentication, verifying residency, rate limiting, fraud and abuse prevention, and audit logging. Lawful basis: legitimate interests, and legal obligation.
  • To communicate — service emails, push notifications, and SMS about things that concern you (a package arrived, a ticket was updated, an invoice is due). Lawful basis: performance of a contract, or consent where required.
  • To take payment — processing subscription fees and resident payments. Lawful basis: performance of a contract, and legal obligation for financial records.
  • To improve the Service — aggregate, de-identified usage analysis. Lawful basis: legitimate interests.

We do not sell personal information, and we do not use resident data to train machine-learning models for other customers or to build advertising profiles.

4. Who we share it with

Within your building. Your name and unit are visible to your building's managers and administrators. What other residents can see about you depends on the directory settings your building configures and on the choices you make in your own profile. Content you post to a community channel is visible to the residents of that building.

Never across buildings. Every record is scoped to a single building at the application layer, by database query filters, and by database row-level security. A manager of one building cannot read another building's data.

Service providers. We use a small number of processors, each bound by contract to use data only on our instructions: Stripe (payments), Google Firebase Cloud Messaging (push notifications), our email and SMS delivery providers, and our cloud hosting and S3-compatible object storage providers.

Legal and corporate. We may disclose information where we are legally required to, to protect our rights or someone's safety, or to a successor entity in a merger or acquisition — in which case we will give notice before your information becomes subject to a different policy.

5. How we protect it

Data is encrypted in transit (TLS) and at rest. Sensitive personal fields receive an additional layer of application-level encryption, so they are unreadable even to someone holding the raw database. Access is controlled by role, tenant boundaries are enforced independently at the application and database layers, sessions can be revoked centrally, and significant actions are written to an audit log.

No system is perfectly secure. If a breach affects your personal information, we will notify the affected building and, where the law requires, the relevant supervisory authority and the individuals concerned.

6. How long we keep it

  • Account data — for as long as your account is active, then deleted or anonymised.
  • Identity and residency documents — deleted automatically once verification is complete or has expired.
  • Building content — for as long as your building keeps it. A building on the free tier has a shorter retention window than a paid one.
  • Audit and security logs — for a limited retention period, then purged automatically.
  • Financial records — for the period tax and accounting law requires, regardless of account closure.

Backups are retained on a rolling schedule and overwritten in the ordinary course; deleted data may persist in a backup briefly after deletion from the live system.

7. Your rights

Depending on where you live, you may have the right to access your personal information, correct it, delete it, restrict or object to its processing, receive a portable copy, and withdraw consent you previously gave. You also have the right to complain to your local data protection authority.

You can export your data and request deletion of your account directly in the app and dashboard, without contacting anyone. Where a request concerns data your building controls, we will pass it to your building and support them in answering it.

Some data cannot be deleted on request — financial records the law requires us to keep, and audit entries that exist precisely so that actions cannot be erased. We will tell you when that applies and why.

To exercise a right or ask a question, email privacy@localepm.com.

8. Notifications and communication choices

You control push and email notification categories in your settings, and you can turn off push entirely from your device. Some messages are not optional — security alerts, billing notices, and material changes to these terms — because they concern the account itself rather than marketing. Marketing emails, where we send them, always carry an unsubscribe link.

9. Cookies and local storage

The dashboard uses cookies and browser storage that are necessary to run it: a session cookie holding your refresh token, a cross-site request forgery token, and locally stored preferences such as your selected building, language, and theme. We do not use advertising or cross-site tracking cookies.

10. Where your data is stored

LocalePM is hosted in the European Union (Germany). Resident data, uploaded documents, and backups stay within the EU, so for customers in the EU and EEA there is no international transfer to justify in the first place.

Some of our processors are established outside the EU — notably Stripe (payments) and Google Firebase Cloud Messaging (push notifications). Where personal information reaches them, it is covered by an appropriate transfer mechanism, such as the European Commission's standard contractual clauses or an adequacy decision.

11. Children's privacy

LocalePM is intended for adults responsible for a residence. We do not knowingly collect personal information from children. If a building has added a minor as a household member and you believe information was collected in error, contact privacy@localepm.com and we will remove it.

12. Changes to this policy

We may update this policy as the Service changes. Where a change materially affects how we use your personal information, we will give notice in the product or by email before it takes effect, and will update the effective date above.

13. Contact us

LocalePM is operated by LoftyBits Technologies (loftybits.com), Tagala Street 7-15, Haabersti district, Tallinn, Harju County, Estonia (P.O. Box 13524).

Privacy enquiries: privacy@localepm.com, or use the contact form and choose “Privacy & data”. See also our Terms of Service.

For company information, visit loftybits.com. As we are established in Estonia, we have no separate EU representative under Article 27 GDPR — you can reach us directly at the address above. We have not appointed a Data Protection Officer; privacy enquiries go to the address in this section.