Draft — not yet legally effective
This document is pending review and has unset details (entityName, entityAddress, privacyEmail, legalEmail, governingLaw, venue, lastUpdated). It does not yet form an agreement. See config/legal.config.ts.
Last updated: TODO: date these documents were approved · Applies to Meconi Labs and its websites
Meconi Labs is property-management software operated by TODO: registered legal entity name, TODO: registered business address (“we”, “us”). This policy explains what personal information we handle, why, and what choices you have.
It covers our marketing website, the Meconi Labs application, and the resident portal. It does not cover the practices of the property managers, landlords, or agencies who use Meconi Labs to manage their own properties — see section 2.
Meconi Labs is business software. Most of the personal information in the system is not ours — it is entered by our customers about their own tenants, owners, and vendors. Data protection law treats those two situations differently, so this policy does too.
For the accounts of the people who sign up to use Meconi Labs — account holders, their team members, and visitors to our website — we decide how the information is used and we are responsible for it. Sections 3 to 14 apply.
For records a customer creates about their tenants, leases, maintenance, and payments, the customer is the controller and we act on their instructions. We do not decide what tenant data they collect, and we do not use it for our own purposes.
If you are a resident and want to know why your landlord or property manager holds information about you, or you want it corrected or deleted, contact them directly. They control that record. We will help them respond, and if you reach us first we will point you to the right party where we can identify them.
Handled under the processor role in section 2. It typically includes:
Cookies and similar technologies are described in our Cookie Policy.
We do not knowingly collect government identifiers, credit reports, or background-check results, and the product has no field for them. Customers should not put such information into free-text notes.
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Providing the service, hosting your data, and keeping accounts working | Performance of a contract |
| Taking payment and managing subscriptions | Performance of a contract |
| Securing the service, preventing abuse, and keeping audit records | Legitimate interests |
| Diagnosing faults and improving reliability and usability | Legitimate interests |
| Product and marketing email about features and changes | Consent, or legitimate interests for existing customers, with an opt-out in every message |
| Meeting accounting, tax, and other legal obligations | Legal obligation |
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use your data, or your tenants’ data, to train machine-learning models.
Card payments and payment-method setup are handled by Stripe. Card details are entered into fields hosted by Stripe and transmitted directly to them, so full card numbers never pass through or rest on our servers. We store only what is needed to show a payment history and reconcile a ledger: the card brand, last four digits, expiry month and year, and Stripe’s identifiers.
Stripe processes this information as an independent controller for fraud prevention and regulatory compliance, under its own privacy policy.
To help property managers respond quickly, inbound messages can be classified automatically. When this runs, the subject line and body of the message are sent to Anthropic’s API, which returns a category, an urgency level, a one-sentence summary, and sometimes a suggested action or draft reply.
Customers who do not want this processing should contact us at TODO: privacy contact email to have it disabled for their account.
We do not sell personal information. We share it with service providers who process it on our behalf, under contract and only as needed to run the service:
| Provider | What it handles |
|---|---|
| Supabase | Database, authentication, and file storage for lease documents and maintenance photos |
| Stripe | Payment processing and stored payment methods |
| Anthropic | Automated classification of inbound messages (section 6) |
| Vercel | Hosting and delivery of the web application |
| Railway | Hosting of our backend API |
| Cloudflare | Turnstile, the challenge shown on sign-in and sign-up to block automated abuse, where captcha is enabled |
| Sentry | Error and performance monitoring, where monitoring is enabled for the deployment |
| Our email provider | Transactional email such as invitations, password resets, and notices |
| Umami | Website analytics, in a self-hosted deployment we control |
We also disclose information where we must to comply with the law or respond to a valid legal request, to enforce our Terms of Service, or to protect the rights and safety of our users. If we are involved in a merger, acquisition, or sale of assets, data may transfer to the successor, and we will give notice before your information becomes subject to a different privacy policy.
Our providers may process information in countries other than yours, including the United States. Where information moves out of the UK or European Economic Area we rely on transfer mechanisms recognised under applicable law, such as the European Commission’s Standard Contractual Clauses, together with additional safeguards where they are needed. Contact us for details of the mechanism relied on for a particular provider.
No system is perfectly secure and we cannot guarantee absolute security. If a breach affects your personal information we will notify you and any regulator within the timeframes the law requires. To report a vulnerability, write to TODO: legal contact email.
Depending on where you live, you may have the right to access a copy of your personal information, correct it, delete it, restrict or object to how we use it, receive it in a portable form, or withdraw consent you previously gave. You will not be treated differently for exercising these rights.
California residents additionally have the right to know what is collected and disclosed, to delete it, to correct it, and to opt out of sale or sharing. As stated above, we do not sell personal information or share it for cross-context behavioural advertising.
To exercise a right, write to TODO: privacy contact email. We will respond within the period the applicable law allows, normally one month under UK/EU GDPR and 45 days under California law. We may need to verify your identity first. If you are a resident asking about information your landlord holds, see section 2 — we will route your request to them.
You may also complain to your data protection authority. In the UK that is the Information Commissioner’s Office; in the EU it is the authority for your country of residence.
Meconi Labs is a tool for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child’s information has been provided to us, contact us and we will delete it. Note that a customer may record a minor as an occupant of a unit; that record is the customer’s to manage under section 2.
We may update this policy as the service changes. When a change is material we will update the date at the top of this page and give notice in the application or by email before it takes effect. Continuing to use Meconi Labs after a change takes effect means the updated policy applies.
Privacy questions and requests: TODO: privacy contact email
Other legal matters: TODO: legal contact email
Postal address: TODO: registered legal entity name, TODO: registered business address