1. Who We Are
Tu Comunidad ("we," "us," or "the Company") operates the Portal condominium management platform at tucomunidad.ai. This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our platform.
2. Information We Collect
Information you provide:
- Account information: name, email address, phone number
- Financial information: bank account number, routing number (for ACH payment processing)
- Property information: apartment or house unit, ownership or occupancy records
- Guest authorization data: guest names, phone numbers, vehicle information
Information collected automatically:
- IP address and browser information (for security and audit logging)
- Session data (encrypted cookies)
- Usage data (pages visited, actions taken, timestamps)
Information from third parties:
- Bank account verification data from Plaid (routing number, account number, account type, institution name)
- OAuth profile data from Google or Apple (name, email) if you choose to sign in with these providers
3. How We Use Your Information
- Process condominium fee payments via ACH debit transactions
- Generate financial statements and payment records
- Manage guest access authorizations and security check-ins
- Send notifications about payments, guest arrivals, and community events
- Maintain audit logs for legal and regulatory compliance
- Verify your identity and prevent fraud
- Improve and maintain the platform
4. How We Protect Your Information
- Bank account and routing numbers are encrypted at rest using AES-256-GCM encryption
- All data in transit is protected by TLS 1.2 or higher
- Passwords are hashed using bcrypt with a cost factor of 12
- Sessions use encrypted httpOnly cookies with automatic expiration
- Rate limiting protects against brute-force attacks
- Role-based access control ensures users only see data relevant to their units and communities
5. Information Sharing
We do not sell your personal information. We share data only in these limited circumstances:
- Your condominium association (HOA): Financial records, payment status, and ownership information are visible to community administrators as needed for property management.
- Plaid: When you connect a bank account, Plaid processes your bank credentials to verify your account. Plaid does not share your bank login with us.
- Your HOA's bank: Bank account and routing numbers are included in ACH debit files generated for your HOA to process payments through their bank.
- Legal requirements: We may disclose information if required by law, court order, or governmental regulation.
6. Data Retention
- ACH authorization records: 2 years after revocation (per NACHA rules)
- Transaction records: 6 years (per NACHA rules)
- Audit logs: 6 years
- Account data: lifetime of account plus 2 years after closure
- Guest authorization records: 2 years after expiration
When data passes its retention period, it is securely deleted or anonymized. Encrypted data is disposed of by deleting the ciphertext, rendering the original data unrecoverable.
7. Your Rights
You have the right to:
- Access the personal information we hold about you
- Correct inaccurate information in your profile
- Request deletion of your account and personal data (subject to legal retention requirements)
- Revoke ACH payment authorizations at any time through the platform
- Revoke guest access authorizations at any time
To exercise these rights, contact your community administrator or email us at the address below.
8. Cookies
We use a single encrypted session cookie ("portal_session") to maintain your login state. This cookie is httpOnly (not accessible to JavaScript), secure (only sent over HTTPS), and expires after 24 hours of inactivity. We do not use tracking cookies, analytics cookies, or advertising cookies.
9. Children
Portal is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the platform after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or your personal data, contact us at:
Tu Comunidad
Email: privacy@tucomunidad.ai
© 2026 Tu Comunidad.