Privacy Policy

Our privacy policy and how we use your data

Draft — not yet legally effective

This document is pending review and has unset details (entityName, entityAddress, privacyEmail, legalEmail, governingLaw, venue, lastUpdated). It does not yet form an agreement. See config/legal.config.ts.

Last updated: TODO: date these documents were approved · Applies to Meconi Labs and its websites

1. Who we are

Meconi Labs is property-management software operated by TODO: registered legal entity name, TODO: registered business address (“we”, “us”). This policy explains what personal information we handle, why, and what choices you have.

It covers our marketing website, the Meconi Labs application, and the resident portal. It does not cover the practices of the property managers, landlords, or agencies who use Meconi Labs to manage their own properties — see section 2.

2. Two different roles, and why the distinction matters

Meconi Labs is business software. Most of the personal information in the system is not ours — it is entered by our customers about their own tenants, owners, and vendors. Data protection law treats those two situations differently, so this policy does too.

Where we are the controller

For the accounts of the people who sign up to use Meconi Labs — account holders, their team members, and visitors to our website — we decide how the information is used and we are responsible for it. Sections 3 to 14 apply.

Where we are a processor acting on instructions

For records a customer creates about their tenants, leases, maintenance, and payments, the customer is the controller and we act on their instructions. We do not decide what tenant data they collect, and we do not use it for our own purposes.

If you are a resident and want to know why your landlord or property manager holds information about you, or you want it corrected or deleted, contact them directly. They control that record. We will help them respond, and if you reach us first we will point you to the right party where we can identify them.

3. What we collect

Information you give us

  • Account and sign-in details — name, email address, and authentication credentials. Passwords are stored only as salted hashes by our authentication provider; we never see them.
  • Workspace details — the name of your portfolio or organisation, the teammates you invite, and the roles you assign them.
  • Billing details — your subscription plan and billing contact. Card numbers are entered directly with our payment processor and never reach our servers (section 5).
  • Support correspondence — messages you send us and our replies.

Information our customers enter about other people

Handled under the processor role in section 2. It typically includes:

  • Resident records — name, email address, phone number, tenancy status, emergency contact name and phone, and free-text notes.
  • Property, unit, and lease records — addresses, rent amounts, lease dates and terms, and uploaded lease documents.
  • Maintenance records — requests, their status history, attached photographs, and vendor and invoice details.
  • Financial records — charges, payments, adjustments, refunds, and balances.
  • Messages — inbound and outbound correspondence with residents, owners, and vendors handled through the platform.

Information collected automatically

  • Usage and device data — pages visited, approximate location derived from IP address, browser, and device type.
  • Security and audit logs — sign-in events, IP addresses, and a record of significant actions taken in an account, which we keep to investigate misuse and to let account owners see who changed what.

Cookies and similar technologies are described in our Cookie Policy.

We do not knowingly collect government identifiers, credit reports, or background-check results, and the product has no field for them. Customers should not put such information into free-text notes.

4. Why we use it, and our legal basis

PurposeLegal basis (UK/EU GDPR)
Providing the service, hosting your data, and keeping accounts workingPerformance of a contract
Taking payment and managing subscriptionsPerformance of a contract
Securing the service, preventing abuse, and keeping audit recordsLegitimate interests
Diagnosing faults and improving reliability and usabilityLegitimate interests
Product and marketing email about features and changesConsent, or legitimate interests for existing customers, with an opt-out in every message
Meeting accounting, tax, and other legal obligationsLegal obligation

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use your data, or your tenants’ data, to train machine-learning models.

5. Payments

Card payments and payment-method setup are handled by Stripe. Card details are entered into fields hosted by Stripe and transmitted directly to them, so full card numbers never pass through or rest on our servers. We store only what is needed to show a payment history and reconcile a ledger: the card brand, last four digits, expiry month and year, and Stripe’s identifiers.

Stripe processes this information as an independent controller for fraud prevention and regulatory compliance, under its own privacy policy.

6. Automated classification of messages

To help property managers respond quickly, inbound messages can be classified automatically. When this runs, the subject line and body of the message are sent to Anthropic’s API, which returns a category, an urgency level, a one-sentence summary, and sometimes a suggested action or draft reply.

  • The message text is sent for classification only. It is not used to train models.
  • The output is a suggestion. A person reviews and approves any action before it takes effect, so this is not automated decision-making producing legal effects.
  • If a message contains sensitive details they are included in what is sent, because the message body is sent as written.

Customers who do not want this processing should contact us at TODO: privacy contact email to have it disabled for their account.

7. Who we share it with

We do not sell personal information. We share it with service providers who process it on our behalf, under contract and only as needed to run the service:

ProviderWhat it handles
SupabaseDatabase, authentication, and file storage for lease documents and maintenance photos
StripePayment processing and stored payment methods
AnthropicAutomated classification of inbound messages (section 6)
VercelHosting and delivery of the web application
RailwayHosting of our backend API
CloudflareTurnstile, the challenge shown on sign-in and sign-up to block automated abuse, where captcha is enabled
SentryError and performance monitoring, where monitoring is enabled for the deployment
Our email providerTransactional email such as invitations, password resets, and notices
UmamiWebsite analytics, in a self-hosted deployment we control

We also disclose information where we must to comply with the law or respond to a valid legal request, to enforce our Terms of Service, or to protect the rights and safety of our users. If we are involved in a merger, acquisition, or sale of assets, data may transfer to the successor, and we will give notice before your information becomes subject to a different privacy policy.

8. International transfers

Our providers may process information in countries other than yours, including the United States. Where information moves out of the UK or European Economic Area we rely on transfer mechanisms recognised under applicable law, such as the European Commission’s Standard Contractual Clauses, together with additional safeguards where they are needed. Contact us for details of the mechanism relied on for a particular provider.

9. How long we keep it

  • Account data — for as long as your account is open. Deleting an account removes it and its records immediately, and the deletion cannot be undone. Copies may persist in backups until those expire.
  • Customer content — for as long as the customer keeps it. Deleting a record removes it from the application. Backups are retained on a rolling basis and expire within 30 days.
  • Financial records — retained as long as tax and accounting law requires, typically six to seven years, even after an account closes. Payment and charge records are append-only: corrections are recorded as new entries rather than by altering history, which is a deliberate integrity property of a rent ledger.
  • Security and audit logs — retained for the life of the account so owners can see who changed what. We do not currently expire them on a fixed schedule.

10. How we protect it

  • Encryption in transit using TLS, and encryption at rest for stored data.
  • Database-level row isolation, so a signed-in user can only read rows belonging to accounts they are a member of. This is enforced by the database rather than only by application code.
  • Role-based permissions, so team members reach only the functions their role grants.
  • Audit logging of significant actions.
  • Internal access to production data limited to staff who need it.

No system is perfectly secure and we cannot guarantee absolute security. If a breach affects your personal information we will notify you and any regulator within the timeframes the law requires. To report a vulnerability, write to TODO: legal contact email.

11. Your rights

Depending on where you live, you may have the right to access a copy of your personal information, correct it, delete it, restrict or object to how we use it, receive it in a portable form, or withdraw consent you previously gave. You will not be treated differently for exercising these rights.

California residents additionally have the right to know what is collected and disclosed, to delete it, to correct it, and to opt out of sale or sharing. As stated above, we do not sell personal information or share it for cross-context behavioural advertising.

To exercise a right, write to TODO: privacy contact email. We will respond within the period the applicable law allows, normally one month under UK/EU GDPR and 45 days under California law. We may need to verify your identity first. If you are a resident asking about information your landlord holds, see section 2 — we will route your request to them.

You may also complain to your data protection authority. In the UK that is the Information Commissioner’s Office; in the EU it is the authority for your country of residence.

12. Children's privacy

Meconi Labs is a tool for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child’s information has been provided to us, contact us and we will delete it. Note that a customer may record a minor as an occupant of a unit; that record is the customer’s to manage under section 2.

13. Changes to this policy

We may update this policy as the service changes. When a change is material we will update the date at the top of this page and give notice in the application or by email before it takes effect. Continuing to use Meconi Labs after a change takes effect means the updated policy applies.

14. Contact us

Privacy questions and requests: TODO: privacy contact email
Other legal matters: TODO: legal contact email
Postal address: TODO: registered legal entity name, TODO: registered business address