Privacy Policy
Last updated: April 2026 · Effective: April 2026
1. Introduction
In plain English
This policy explains what data we collect, why we collect it, and how we protect it. We believe in being transparent about your information.
Symple Leases ("we," "us," or "our") operates a multi-sided property management platform (the "Platform"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our website, mobile application, and related services. By using the Platform, you consent to the practices described in this policy.
2. Information We Collect
In plain English
We collect info you give us (like your name and email), info generated when you use the platform (like pages viewed), and limited info from payment and authentication partners.
2.1 Information You Provide
2.2 Information Collected Automatically
2.3 Information from Third Parties
We may receive information from third-party services, including:
- Payment and identity verification data from Stripe.
- Authentication data if you sign in using a third-party provider.
3. How We Use Your Information
In plain English
We use your data to run the platform, process payments, send you notifications, improve the product, and keep things secure. We don't sell your data.
We use the information we collect to:
- Provide, operate, and maintain the Platform and its features.
- Process payments, including rent collection, service payments, and subscription billing through Stripe.
- Send transactional notifications via email (through Resend) and SMS (through Twilio, when you opt in).
- Facilitate communication between users, including hosts, owners, tenants, and service professionals.
- Improve the Platform through analytics, usage patterns, and user feedback.
- Enforce our Terms of Service and protect the security of the Platform and its users.
- Comply with legal obligations and respond to lawful requests from government authorities.
4. Third-Party Service Providers
In plain English
We work with trusted partners (like Stripe for payments and Supabase for hosting) to run the platform. Each has its own privacy policy and we only share what's necessary.
We share your information with the following categories of third-party service providers:
| Provider | Purpose |
|---|---|
| Stripe | Payment processing, subscription billing, and Connect Express accounts |
| Supabase | Database hosting, file storage, and real-time features |
| Resend | Transactional email delivery for notifications and receipts |
| Twilio | SMS delivery for opt-in notifications and alerts |
| Inngest | Background job processing for notifications and scheduled tasks |
| Vercel | Application hosting and content delivery |
We require all service providers to use your information only as necessary to perform services on our behalf and to maintain appropriate security measures.
7. Data Retention
In plain English
We keep your data while your account is active. After you close it, we retain some records for legal and compliance reasons — transaction records for 7 years, communications for 3 years, and anonymized analytics indefinitely.
We retain your personal information for as long as your account is active or as needed to provide you with the Platform. After account closure:
| Data Type | Retention Period |
|---|---|
| Transaction records | 7 years (tax & financial compliance) |
| Communication logs | 3 years (dispute resolution) |
| Usage analytics | Indefinitely (aggregated & anonymized) |
| Legal holds | Until the matter is resolved |
8. Your Rights
In plain English
No matter where you are, you can access, correct, delete, or export your data. Just email us and we'll respond within 30 days.
Regardless of your location, you have the right to:
- Accessthe personal information we hold about you.
- Correctinaccurate or incomplete information.
- Deleteyour personal data, subject to legal retention requirements.
- Exportyour data in a portable, machine-readable format (JSON or CSV).
- Objectto certain processing activities.
To exercise any of these rights, contact us at privacy@sympleleases.com. We will respond within 30 days. We will not charge a fee for making a request unless the request is manifestly unfounded or excessive.
9. California Residents (CCPA/CPRA)
In plain English
California residents have extra privacy rights under state law, including the right to know what data we collect, request deletion, and opt out of any future sale of data. We will never discriminate against you for exercising these rights.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know: You may request details about the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the third parties with whom we share it.
- Right to delete: You may request deletion of your personal information, subject to certain legal exceptions (e.g., completing a transaction, legal obligations, security).
- Right to correct: You may request correction of inaccurate personal information we hold about you.
- Right to opt out of sale/sharing: We do not sell or share your personal information for cross-context behavioral advertising. If this ever changes, we will provide a “Do Not Sell or Share My Personal Information” mechanism.
- Right to limit use of sensitive information: We only use sensitive personal information as necessary to provide the Platform and do not use it for profiling.
- Non-discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights. You will receive equal service and pricing.
To submit a verifiable consumer request, email privacy@sympleleases.com. We will verify your identity before processing and respond within 45 days.
10. EEA & UK Residents (GDPR)
In plain English
If you're in Europe or the UK, you have strong privacy rights under the GDPR. We process your data based on specific legal grounds and you can lodge a complaint with your local supervisory authority if you're unhappy with how we handle it.
If you are located in the European Economic Area or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):
Legal Basis for Processing
Your GDPR Rights
- Right of access, rectification, erasure, and data portability.
- Right to restrict or object to processing.
- Right to withdraw consent at any time where processing is based on consent.
- Right to lodge a complaint with your local supervisory authority.
Data Protection Contact
For GDPR-related inquiries, contact our data protection team at privacy@sympleleases.com. We will respond within 30 days.
11. Children's Privacy
In plain English
Symple Leases is not for anyone under 18. We don't knowingly collect data from minors. If we learn we have, we delete it immediately.
The Platform is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@sympleleases.com.
12. International Data Transfers
In plain English
We're based in the US. If you're using the platform from outside the US, your data will be transferred here. We use Standard Contractual Clauses to protect data from the EU/UK.
Symple Leases is based in the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States. We take appropriate measures to ensure that your data is treated securely and in accordance with this Privacy Policy, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA.
- UK International Data Transfer Agreement or UK Addendum to the EU SCCs for transfers from the UK.
- Contractual data protection obligations with all sub-processors to ensure equivalent safeguards.
13. Security Measures
In plain English
We use encryption, row-level database security, role-based access controls, and multi-factor authentication to keep your data safe. No system is 100% secure, but we take it very seriously.
We implement industry-standard security measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest.
- Row-level security (RLS) policies on our database to ensure users can only access their own data.
- Role-based access controls (RBAC) to limit internal access to personal information.
- Regular security reviews and monitoring.
- Secure, hashed password storage with multi-factor authentication support.
While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
14. Changes to This Policy
In plain English
We may update this policy. For significant changes, we'll give you 30 days' notice via email and an in-app banner.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and by posting a prominent notice on the Platform at least 30 days before the changes take effect. Your continued use of the Platform after the effective date constitutes your acceptance of the revised policy. If you do not agree with the changes, you may close your account before they take effect.
15. Contact
In plain English
Have a privacy question or want to exercise your data rights? Email us and we'll take care of it.
Symple Leases — Privacy Team
3277 S White Rd, Suite 912
San Jose, CA 95148
Privacy inquiries & data rights: privacy@sympleleases.com
General support: support@sympleleases.com