Privacy Notice

Version 1.0 · Effective 2026-09-16

Tetrahedron LLC · 3343 Peachtree Rd NE, Ste 145-2732, Atlanta, GA 30326, United States · mailto:privacy@tenantoffice.com

# Tenant Office privacy notice

Version: `1.0`; effective date: `September 16, 2026`.

## Who operates Tenant Office

Tenant Office is operated by Tetrahedron LLC, registered in Georgia, United States, at `3343 Peachtree Rd NE, Ste 145-2732, Atlanta, GA 30326, USA`. Contact `privacy@tenantoffice.com` about privacy or this notice. This notice covers https://tenantoffice.com and https://app.tenantoffice.com.

We handle website inquiries and service administration. When a property organization uses Tenant Office for its residents, staff, owners or vendors, it determines the information it enters and the property purposes for which it uses it. We operate its workspace under the agreed service arrangements. That organization's own privacy notice also matters; contact it about its property records and decisions.

## Information and purposes

| Information                                                                                                                                                                                             | How it is used                                                                                                                                               |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Inquiry name, business email, organization and selected portfolio-size range or “not sure”; request reference, time, permission version and review status                                               | Record and respond to the inquiry, manage follow-up and prevent duplicate or abusive submissions. The form does not request resident records or attachments. |
| Campaign source, medium, campaign and content labels included in a marketing link                                                                                                                       | Understand which campaign led to an inquiry. These limited labels can be stored for the browser tab and attached to the inquiry.                             |
| Account and access information, such as identity, email, organization membership, role and authentication records                                                                                       | Sign users in, restrict access and administer accounts.                                                                                                      |
| Information entered or uploaded for enabled workspace functions, such as resident and lease details, property/unit records, maintenance requests, vendor/owner details, financial records and documents | Provide the customer's chosen workflows and records. The information depends on what the customer and its authorized users provide.                          |
| Activity and technical records, including action identifiers, actor/resource identifiers, changed-field names, request times and browser/network information processed by hosting or security providers | Operate the service, troubleshoot failures, protect access and maintain an activity record.                                                                  |

Inquiry permission allows a reply about your request; it does not subscribe you to unrelated marketing. Tell us through the contact above or in a reply if you want follow-up to stop. Please do not send resident records, credentials or sensitive documents through a sales inquiry or ordinary support email.

## Providers and access

Tenant Office uses Supabase for its database, authentication, stored files and database backups, and Vercel for the hosted website/application. Account email — workspace invitations, sign-in and security messages — is sent through Supabase's own email service; Tenant Office does not use a separate email marketing provider. Authorized customer users see records according to their access. Authorized operators and service providers may process information to operate and support these services. Adding a provider for email, support correspondence, backups or monitoring requires this notice to be reviewed and republished first.

Subscription billing is handled by Stripe. Payment card details and billing address are entered on Stripe's own hosted checkout and billing-management pages; Tenant Office does not receive or store card numbers. The only information Tenant Office sends to Stripe for a subscription is an organization identifier and the subscription and invoice status it returns. It does not send a name, email address, telephone number or any resident, lease or property record. Stripe processes what you enter on its pages as described at https://stripe.com/privacy.

The inquiry form uses Cloudflare Turnstile to help distinguish human visitors from automated traffic. Cloudflare processes signals such as IP address, browser information and the site being visited for that check and to improve its bot detection. See the [Turnstile privacy addendum](https://www.cloudflare.com/turnstile-privacy-policy/). The Tenant Office verification request submits the challenge token; it does not send the inquiry's contact fields to the verification endpoint.

Processing locations and international transfers: Tenant Office is operated from the United States and is offered on a fixed United States and US-dollar operating basis. The database, authentication records and stored files are held in the United States, in Supabase's Amazon Web Services Northern California region (`us-west-1`). The signed-in application's server functions run in Vercel's San Francisco, United States region (`sfo1`). Public pages, static assets and the inquiry bot-challenge check are served over Vercel's and Cloudflare's global networks, so a request made from outside the United States may first be received at a network location in or nearer to your own country before it reaches the United States. Stripe, Cloudflare and — where marketing tags are enabled — Google each operate internationally and process information under their own published terms. We do not offer a processing region outside the United States: if you use the service or contact us from elsewhere, expect your information to be transferred to and stored in the United States. Our providers publish data-processing terms setting out the transfer mechanisms they rely on for the United Kingdom and European Economic Area; write to the contact address above about the arrangements that apply to a particular transfer. This notice does not promise that all processing or support access stays in one country.

## Browser storage and AI

The application uses sign-in cookies. It also stores identifiers and hashes for pending changes in the browser to reconcile retries; those retry records contain account/resource identifiers rather than the change's descriptive field values. Clearing browser storage may sign you out or interrupt recovery of an unresolved change.

The marketing site uses tab storage for the campaign labels described above. Where a Google tag is configured for a deployment, the marketing site — and only the marketing site — loads Google's advertising and measurement tags. These set cookies and send Google the pages viewed, approximate location derived from IP address, device and browser information, and the referring site or advertisement; Google processes this as described at https://policies.google.com/privacy and may use it to measure and target advertising. The conversion event sent on an inquiry records only that a submission happened: it carries no name, email address, telephone number, message, request identifier or click identifier. No advertising or analytics tag runs in the signed-in workspace, and resident or financial records are never sent to an advertising provider. You can refuse or delete cookies in your browser, or use Google's own controls at https://adssettings.google.com and https://tools.google.com/dlpage/gaoptout; the marketing site remains usable with them blocked. Hosting and challenge providers still process technical information. Provider or analytics changes require this notice to be reviewed.

The current Tenant Office product workflows do not send workspace records to an AI inference service. Staff still review imported information, suggested matches and recorded outcomes.

## Retention and requests

Inquiry retention: `90 days from the last substantive exchange, unless a legal hold applies`. Workspace records are retained under the customer's approved schedule, taking account of the service relationship, applicable recordkeeping duties, disputes and legal holds. Audit history and some identifiers can outlast an account or organization. Deleting a live record does not immediately remove an older backup; backup expiry is `35 daily and 12 monthly recovery sets`.

Contact us to ask about your information, request access or correction, request deletion, or raise a privacy concern. Depending on the applicable law and circumstances, you may have additional rights, including objection, restriction, portability or a complaint to a regulator. We may need to verify identity or authority and coordinate with the relevant property organization. Requests are reviewed by a person; a submitted request is not proof that an export or deletion has occurred. Legal holds or recordkeeping duties can limit deletion.

## Updates

An updated notice will identify its version and effective date. Any material new purpose or processing arrangement must be reviewed and communicated as required before it is introduced.

View the current published notice.