Account and profile. Name, email address, phone number, the building and unit you are associated with, your role, profile photo, language preference, and authentication data (a hashed password, and two-factor secrets if you enable them).
Residency verification. Where a building requires it, the invite code you used, or an identity or residency document you submit. Verification documents are held only as long as needed to complete the check and are then deleted automatically.
Content you create. Maintenance tickets and their photos, community posts and comments, direct and building messages, amenity bookings, guest passes, documents you upload, and governance records such as violations, meeting minutes, and votes.
Building operations. Package deliveries logged for you, service records, meter readings, invoices and expenses associated with your unit, and payment status.
Payments. Card and bank details are entered directly with our payment processor and are never stored on our systems. We retain the transaction record — amount, currency, status, timestamps, and the processor's reference.
Technical and usage data. IP address, device and browser type, app version and platform, push notification tokens, timestamps, and audit records of significant actions (who changed what, and when). We use this to operate the Service, debug it, and investigate abuse.
Marketing-site enquiries. If you use our contact form, we receive the name, email, organisation, topic, and message you send, plus the originating IP address for abuse prevention. That message is delivered to the relevant inbox; it does not create an account.