Privacy Policy
Last Updated: September 10, 2026
Under One Roof Property Manager ("Under One Roof", "we", "us", or "our") is dedicated to protecting the privacy, financial security, and personal boundaries of homeowners association (HOA) members, condo residents, volunteer board officers, property managers, and service providers. This Privacy Policy describes how we collect, process, secure, and retain data across the Under One Roof platform.
1. Information We Collect
To provide an autonomous community operating system, we collect and process the following categories of data:
- Member Directory & Roster Data: Resident names, verified email addresses, telephone numbers, unit designations, ownership status (owner vs. tenant), and designated board roles.
- Governing Documents: Association CC&Rs, bylaws, architectural review guidelines, election rules, and reserve studies uploaded for parsing and retrieval.
- Financial & Transaction Records: Assessment dues amounts, itemized payment ledger histories, pending dues credits, and bank transaction metadata provided via read-only financial feeds.
- Operations & Maintenance Records: Maintenance requests, timestamped inspection photos, contractor quotes, work order completion slips, and architectural alteration submissions.
- Governance & Voting Records: Meeting attendance rosters, quorum verification tallies, and encrypted digital ballot timestamps.
2. Read-Only Banking Integration & Financial Security
We believe financial stewardship requires ironclad protection. Depository bank connections for operating and reserve fund tracking are powered exclusively by Plaid Inc. under end-to-end 256-bit TLS encryption and SOC 2 Type II compliance.
- Read-Only Access: Under One Roof maintains strictly read-only authorization to view bank account balances and incoming/outgoing transaction memos. Under One Roof never stores unmasked bank account numbers or routing credentials on its servers.
- Account Number Masking: All bank account numbers rendered in the user interface or ledger tables are truncated to the last four digits (e.g.,
•••• 4821). - Zero Unauthorized Withdrawal Capability: The platform cannot initiate debit transfers, alter account routing, or withdraw community funds. All treasury disbursements require affirmative authorized officer approval via your depository institution's secure ACH debit protocol.
3. Dual-Tier Data Retention & Privacy Protection
In accordance with our Data Retention & Disposal Policy, we enforce strict tier-based data retention to balance statutory corporate compliance with resident personal privacy:
- 7-Year Statutory Audit Retention: Official board resolutions, certified meeting minutes, quorum voting logs, financial ledgers, contractor invoices, and statutory disciplinary records under California Civil Code § 5855 are securely preserved in encrypted storage for seven (7) years to satisfy state corporate audit and tax regulations.
- 90-Day Ephemeral Neighbor Chat Purge: Informal direct unit-to-unit messages, casual neighbor repair inquiries, and transient amenity hold messages are automatically purged from production storage after ninety (90) days, preventing permanent surveillance of private neighbor interactions.
- 14-Day Notice Board Expiration: Community bulletin announcements automatically expire after fourteen (14) days unless explicitly pinned as official by the Board President.
4. In-App Privacy Masking & Personal Boundary Shield
Volunteer board leaders and residents are entitled to privacy within their own homes:
- Unit-to-Unit Masking: When communicating regarding building matters, phone numbers and personal email addresses remain masked within the platform to prevent harassment or unwanted solicitation.
- After-Hours Boundary Shield: Non-urgent member communications sent outside designated business hours are queued for daytime review, protecting volunteer officers from late-night interruptions while routing true life-safety emergencies to designated building contacts.
5. Statutory Due Process Confidentiality (Civil Code § 5855)
In accordance with California Davis-Stirling Common Interest Development Act standards (and equivalent state statutes), all disciplinary notices, alleged guideline reminders, and executive session hearing records are treated as strictly confidential. Access is restricted exclusively to the subject homeowner and the elected Board of Directors.
6. Data Ownership & Absolute No-Sale Commitment (SMS Privacy Policy)
Your community owns 100% of its data. Under One Roof will never sell, lease, monetize, or share your member roster, email addresses, financial histories, or CC&R documents with third-party advertisers, data brokers, or marketing syndicates. Data is processed exclusively to deliver platform functionality to your community.
Mobile Information & SMS Consent: No mobile information or phone numbers will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with or transferred to any third parties.
7. Corporate Contact & Data Subject Rights
Community administrators and individual members may request an export of their data or submit privacy inquiries by contacting our privacy compliance team:
Under One Roof Property Manager LLC
Privacy & Data Protection Office
455 Market St Ste 1940
San Francisco, CA 94105-2448 US
Email: info@underoneroofpm.com