Plain-language summary. OnlyHOA provides software that management companies and associations use to run their communities. For most information about residents and communities, your association or management company decides how it is used, and we process it on their behalf. We do not sell personal information, do not use it for targeted advertising, and do not use advertising or cross-site tracking technologies. This notice describes what we actually do; where a statement is limited by how our system works, we say so.
1. Who we are and what this policy covers
OnlyHOA LLC operates a business-to-business software-as-a-service platform (the "Platform") that homeowners/community associations, community-management companies, boards, community managers and staff, residents/homeowners, and vendors use to administer community operations. The Platform, and the personal information it handles, are hosted and processed in the United States, and this policy is written for U.S. users.
This policy applies to the Platform's web application and mobile applications. It does not govern the independent privacy practices of the third-party services described in Section 7, or of an association or management company that uses the Platform. Your use of the Platform is also subject to our Terms of Service; where we process payments, our Payment Terms; and, for our management-company customers, our Data Processing Addendum.
This Privacy Policy is a notice. Reading or acknowledging it does not, by itself, create consent for processing that the law requires us to obtain separately. Where separate affirmative consent is legally required (for example, certain text-message programs), we obtain it through a distinct mechanism.
2. Our role: controller/business vs. processor/service provider
Because the Platform is used by organizations to manage their own communities, our role depends on the information:
When we act on your association's instructions (processor / service provider)
For information that an association or management company (a "Community Organization") places into its community on the Platform — such as resident and homeowner records, property/unit records, board and committee records, community documents, violation and architectural-review records, dues and assessment records, and community communications — the Community Organization determines why and how the information is processed. We process it on their behalf and under their instructions as a service provider/processor. If you are a resident and want to access, correct, or delete this kind of information, your association or management company is generally the right party to direct your request to; we will help route it (Section 12). Our processing of this information is governed by our Data Processing Addendum with the Community Organization.
When we determine the purposes (controller / business)
For information we decide how to use for our own purposes, we act as a controller/business. This includes: your account and login identity; security and authentication information (such as sign-in IP address, device, and activity we log to protect the Platform); records of privacy requests and consents; our billing relationship with management-company and association customers; and marketing or demonstration inquiries you submit to us directly.
3. Information we collect
Depending on your role and how the Platform is configured by your Community Organization, we may handle the following categories:
- Account & identity: name, email address, phone number, mailing address, and password (stored only as a strong one-way hash). Two-factor authentication secrets are stored encrypted.
- Resident/homeowner records: name, contact details, property/mailing address, and — where a Community Organization records them — emergency-contact details, date of birth, vehicle and parking details (including license plate), pet information, and account notes.
- Property/unit records: address, unit/parcel identifiers, and property attributes (including approximate map coordinates derived from the property address).
- Board, committee, staff, and vendor records: names and business contact details, roles, and — for vendors — business license, insurance, and tax-identification information used for payments and compliance.
- Financial and payment information: assessment/dues balances and charges. When you make an electronic payment, your card or bank details are collected and processed by our third-party payment providers; we store only limited tokens/identifiers (for example, the last four digits and a provider reference), not full card or bank-account numbers.
- Documents, photos, and files that you or your Community Organization upload (for example, governing documents, insurance pages, inspection or violation photos, and attachments).
- Communications you send or receive through the Platform (email, text messages, in-app messages, notices) and related delivery records.
- Technical, security, and usage information: IP address, device and browser information, sign-in history and location approximated at the city level from your IP address, and activity logs we keep to operate and secure the Platform.
Sensitive information
The Platform is not designed to collect sensitive categories of personal information, and we have confirmed the following against our system:
- We do not collect biometric data. If you use a passkey or your device's biometric unlock, the biometric stays on your device; we receive only a cryptographic public key.
- We do not collect health information, and we do not collect precise device geolocation, or information about race, ethnicity, religion, or sexual orientation.
- We do not store resident Social Security numbers. Where an electronic-payment provider requires identity verification, information such as the last digits of an SSN and a date of birth is transmitted directly to that provider and is not retained by us. A vendor's tax-identification number (EIN or sole-proprietor identifier), where provided for tax reporting, is stored encrypted.
4. Sources of information
We obtain information: from you (for example, when you register, sign in, communicate, or make a payment); from your Community Organization (for example, when it imports or enters resident, property, board, or vendor records); automatically from your use of the Platform (technical, security, and usage information); and from service providers that help us operate the Platform (for example, a bank-verification provider that confirms a linked account, or an authentication provider you choose to sign in with).
5. How we use information
- To provide and operate the Platform and the features your Community Organization enables.
- To authenticate you, secure the Platform, detect and prevent fraud and abuse, and maintain audit and activity logs.
- To process payments you initiate, through our third-party payment providers.
- To send communications — service, account, transactional, and (where you have opted in) text-message notifications — and to deliver notices your Community Organization sends.
- To support you and respond to requests, including privacy requests.
- To maintain and improve the Platform, including through aggregated and de-identified analysis.
- To comply with law and enforce our agreements.
For information we process on a Community Organization's behalf, we use it only to provide the Platform to that organization and as its instructions and our Data Processing Addendum permit.
6. Artificial-intelligence features
Some Platform features use artificial intelligence to help staff draft, summarize, categorize, and answer questions. These are assistive features that produce drafts and suggestions for a person to review — AI outputs do not take actions on their own. What we can accurately tell you:
- Text AI features (drafting, summarizing, triage, and question-answering) route through a governed pathway that removes or replaces personal identifiers before the request leaves our servers — names, emails, phone numbers, account numbers, and a linked resident's identity are converted to placeholders, and Social Security and payment-card numbers are blocked outright. The AI provider receives only placeholders; real values are restored only in memory to assemble your result and are not stored by the provider for that purpose.
- We do not store the raw text of AI prompts. We keep usage/metering records and a redacted audit preview. Some features save the AI's output (for example, a document summary or a suggested reply) as part of your community's records.
- Certain non-text AI features process content that cannot be redacted as text and are disclosed separately: optional meeting-audio transcription, optional scanning/parsing of an uploaded insurance certificate (document OCR), and AI image generation from a description you type. For these, the file or audio you provide is sent to the applicable AI/OCR provider to perform the task.
- Some financial figures (such as dollar amounts in a budget or financial summary) may be included in AI requests to produce the requested output; identities associated with them are still replaced with placeholders.
- Our AI providers are engaged as service providers. We rely on their standard application-programming-interface terms, under which data submitted through the interface is not used to train their models. We currently use one AI provider by default and may use another as a fallback or configured alternative; the current providers are listed on our Subprocessor List.
- Administrators can disable AI for a community (by setting its AI budget to zero) or for specific features.
7. How we share information
We share personal information only as needed to operate the Platform, and only with the following categories of recipients:
- Your Community Organization and its authorized users (for community-scoped information).
- Service providers / subprocessors that perform functions on our behalf — including cloud hosting and storage, email and text-message delivery, push notifications, payment and bank-verification providers, physical-mail delivery, tax-form filing, address geocoding, artificial-intelligence and document-processing providers, and authentication providers. A current, itemized list is maintained on our Subprocessor List, which we keep current as our infrastructure evolves.
- Authorities and advisors where required by law, to enforce our agreements, or to protect rights, safety, and the security of the Platform.
- A successor in a merger, acquisition, financing, or sale of assets, subject to this policy.
We do not sell personal information, and we do not share it for cross-context behavioral (targeted) advertising. We do not use advertising networks, advertising pixels, or cross-site tracking. Our geolocation lookups run against a database on our own servers, so your IP address is not sent to a geolocation vendor.
8. Cookies and similar technologies
We use a small number of strictly functional, first-party cookies and browser-storage mechanisms: an authentication cookie to keep you signed in, a session cookie, and an anti-forgery token to protect against cross-site request forgery. Our applications also use local browser storage for functional purposes such as offline drafting. We do not use analytics, advertising, or cross-site tracking cookies or tags, and we do not deploy third-party advertising or analytics SDKs in our mobile applications.
9. Data retention
Retention varies by the type of information and the purpose — including the instructions of your Community Organization, our contracts, applicable recordkeeping and legal requirements, and security needs. There is no single, uniform retention period for all information. As examples of how our system currently operates:
- Sign-in/security audit logs are retained on the order of two years; general request telemetry on the order of ninety days; text-message conversation records for shorter, purpose-based windows.
- When an individual's information is deleted under a valid request, we generally anonymize it rather than remove every record, so that financial and statutory records a Community Organization must keep remain intact without continuing to identify you.
- Community records are retained for as long as the Community Organization maintains its account and per its instructions and legal obligations.
Because routine, encrypted backups exist for disaster recovery and are overwritten on an ordinary cycle, we cannot guarantee immediate deletion of a specific item from backups; backup copies age out on that cycle and remain protected in the meantime.
10. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, appropriate to its nature. These include:
- Encryption in transit (HTTPS/TLS) for connections to the Platform.
- Application-level encryption at rest of sensitive resident personal information using per-association encryption keys (AES-256-GCM), and encryption of authentication secrets.
- Strong, memory-hard password hashing (Argon2) — we never store passwords in readable form.
- Role-based access controls and least-privilege access, with multi-factor authentication required for privileged accounts (managers, administrators, and board members).
- A tamper-evident audit trail of security-relevant actions, activity monitoring, and incident-response processes.
- Routine backups for recovery.
No method of transmission or storage is completely secure, and we do not represent that the Platform is impenetrable. We describe the controls we actually implement; we do not claim any specific security certification or audit (such as SOC 2) that we have not obtained.
11. Your privacy rights
Depending on where you live and to the extent applicable law grants them, you may have rights to: access/know the personal information we hold about you; correct inaccurate information; delete your information; obtain a portable copy; and, where applicable, opt out of sale, of targeted advertising, or of certain profiling, limit the use of sensitive information, withdraw consent, use an authorized agent, and appeal a decision on your request. Because we do not sell personal information, do not conduct targeted advertising, and do not perform the kind of automated decision-making that produces legal or similarly significant effects, some of these rights may not apply to how we process your information.
For information we process on behalf of a Community Organization, that organization is the appropriate party to decide your request; we will route or support the request as described below. We will not discriminate or retaliate against you for exercising your rights.
12. How to exercise your rights
You can submit a privacy request through our request center at onlyhoa.com/privacy/dsar, or by emailing legal@onlyhoa.com. We will confirm receipt and respond within the timeframe required by applicable law. We may need to verify your identity before acting, and — where the request concerns information we process for a Community Organization — we will coordinate with that organization. You may use an authorized agent where the law permits, and we may ask the agent to provide proof of authorization. If we decline a request, we will explain why, and where the law provides one, you may submit an appeal to the same contacts.
13. Nevada
OnlyHOA LLC is organized in Nevada. Consistent with Nevada Revised Statutes Chapter 603A:
- Categories of covered information we may collect include name together with contact details and, in limited cases, payment-related identifiers and (for vendors) an encrypted tax-identification number. As noted above, we do not store resident Social Security numbers, driver's-license numbers, or full financial-account numbers.
- Categories of third parties with whom covered information may be shared are the service-provider categories in Section 7 and on our Subprocessor List.
- Review and correction: Nevada consumers may request review or correction of covered information through Section 12; for community-scoped information, we will route the request to the responsible Community Organization.
- Notice of changes to this policy is provided as described in Section 17, and the effective date appears at the top.
- Designated request address: legal@onlyhoa.com (see Section 18).
- Sale of covered information: Nevada consumers have a right to submit a verified request directing a covered operator not to sell their covered information. OnlyHOA does not sell covered information, and honors verified requests consistent with that practice.
14. California (to the extent applicable)
This section applies to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), applies to a given individual's information.
- Categories collected in the preceding 12 months: identifiers and contact information; account and role data; property/community-membership records; commercial/transaction information (dues, payments — tokenized); internet/network activity (technical, security, and usage information); approximate geolocation (city-level, from IP); and content you upload. We do not collect the special categories described in Section 3.
- Sources, purposes, and disclosures are described in Sections 4, 5, and 7.
- Sale/sharing: we do not sell personal information and do not share it for cross-context behavioral advertising. Because there is no sale or sharing to opt out of, we do not offer a "Do Not Sell or Share" mechanism; if our practices ever change, we will implement the required mechanism.
- Sensitive personal information: we do not use or disclose sensitive personal information for purposes that would trigger the right to limit its use.
- Consumer rights (know/access, correct, delete, portability, and non-discrimination) may be exercised through Section 12, including via an authorized agent. Because we do not sell/share or conduct targeted advertising, we do not currently act on opt-out preference signals such as Global Privacy Control; if our practices change to involve sale/share, we will honor a valid signal as required.
- Retention is described in Section 9.
15. Other U.S. state privacy laws (to the extent applicable)
Several U.S. states have enacted comprehensive consumer-privacy laws. To the extent one of these laws applies to a given individual's information, that individual may have rights to confirm and access, correct, delete, and obtain a portable copy of personal information; to opt out of sale, targeted advertising, and certain profiling; to consent to or limit the processing of sensitive data; to withdraw consent; to use an authorized agent; to appeal a denied request; and to be free from retaliation for exercising these rights. Because OnlyHOA does not sell personal information, does not conduct targeted advertising, and does not carry out profiling that produces legal or similarly significant effects, the opt-out rights specific to those activities generally do not arise from our processing.
You can exercise any applicable right through Section 12; where the information is processed on a Community Organization's behalf, we will route your request to that organization. Whether a particular state law applies depends on the law's own scope and thresholds; this policy does not assert that every such law applies to OnlyHOA.
16. Children and minors
OnlyHOA is an adult-focused platform for community administration. Account registration is intended for individuals who are at least eighteen (18) years old, consistent with our Terms of Service, and the Platform does not knowingly solicit or allow account creation by children. The Platform does not implement a children's-account or parental-consent program. A Community Organization may, in the course of maintaining its records, enter limited information about a household that could relate to a minor; we process that information on the Community Organization's behalf under Section 2. If you believe a child has created an account or that we hold a child's information improperly, contact us at legal@onlyhoa.com and we will take appropriate action.
17. Changes to this policy
We may update this Privacy Policy. When we make a material change, we will revise the "Last updated" date above and provide notice through the Platform and, where appropriate, by email, and — where we require you to re-acknowledge — we will ask you to do so. We retain prior versions of this policy for our records.