Privacy Policy
Last Updated: June 6, 2026
SyncHOA handles homeowner records, board operations, documents, communications, and payment context. This Privacy Policy explains what data we collect, how we use it, who we share it with, how long we keep it, and how to exercise your rights. If you have questions, contact legal@synchoa.com.
1. Who We Are and Our Roles
SyncHOA is operated by Zachary Clark, an individual doing business as SyncHOA, based in West Hartford, CT.
SyncHOA acts in two distinct roles depending on the category of data:
- Controller: account information, billing data, marketing website interactions, platform support conversations, security and audit logs, and legal acceptance records. SyncHOA determines the purpose and means of processing this data.
- Processor / service provider:homeowner records, dues history, violation records, maintenance records, documents, meeting materials, resident communications, and other HOA-operational data. The HOA board is the controller for this data; SyncHOA processes it on their behalf. As the HOA board, you are responsible for your community's compliance with applicable privacy laws for the homeowner data you input and manage through the platform.
2. Data We Collect
We collect the data needed to operate the product, including:
- Account data: name, email address, OAuth provider ID, profile photo.
- Community data: community name, address, unit count, timezone, logo.
- Homeowner records: name, unit/address, email, phone, board role, move-in date, contact preference, mailing address.
- Dues and financial records: payment amounts, dates, methods, check images, receipt numbers, Stripe payment intent IDs, transaction categories, budget lines.
- Violations and maintenance: descriptions, photos, status history, notes, assigned vendor, fine amounts.
- Documents: file metadata, category, upload date, object storage keys.
- Meetings: title, type, agenda, minutes, attendees, motions, votes.
- Communications: announcements, messages, forum threads, comments, polls, votes.
- Support and feedback: support conversations, feature requests, bug reports.
- Audit and security: audit log entries (action, actor, entity, timestamp), terms acceptance records (version, timestamp, IP address, user agent).
- Stripe Connect metadata: connected account ID, charge IDs, payment intent IDs, dispute IDs, charges-enabled status.
- Notification preferences, tutorial state, and UI preferences.
- Technical data: IP address, browser type, device information, and server logs collected automatically when you use the Services.
We do not intentionally collect information from children under 13, or under 16 in the EEA/UK.
3. How We Use Data
We use data to:
- Provide and improve the Services and authenticate users by role;
- Send transactional notifications (dues reminders, violation updates, meeting notices, invite emails);
- Generate PDF reports and CSV exports;
- Process subscription billing via Stripe;
- Facilitate optional resident payments via Stripe Connect;
- Respond to customer support requests;
- Maintain platform security, prevent fraud, and resolve disputes;
- Comply with legal obligations and enforce our Terms of Service.
4. Service Providers and Disclosures
We share data with the following third-party service providers under appropriate agreements:
- Stripe — subscription billing and optional resident payment processing (United States).
- Resend — transactional email delivery (United States).
- Cloudflare R2 — object storage for documents, photos, and generated files (United States / global edge).
- Neon — managed PostgreSQL database hosting (United States).
- Vercel — application hosting and serverless infrastructure (United States / global edge).
- Google OAuth — supported sign-in flow (United States).
We may also disclose information when required by law, to protect rights and safety, to investigate fraud or security issues, or in connection with a business transfer or acquisition. We do not sell personal data or share personal data for cross-context behavioral advertising.
5. Data Breach Notification
If we discover a security breach reasonably likely to result in harm to your personal information, we will notify affected users as required by applicable law. Notification will generally be provided within 30–72 hours of discovery (depending on jurisdiction) by email to the address on file and, where required, by prominent in-product notice. The notification will describe the nature of the breach, the categories of data affected, steps you can take to protect yourself, and our remediation measures.
6. California Privacy Rights (CCPA / CPRA)
California residents may exercise the following rights by submitting a verifiable request to privacy@synchoa.com:
- Right to Know: request disclosure of the categories and specific pieces of personal information we collect, use, disclose, and retain about you.
- Right to Delete: request deletion of personal information we hold about you, subject to legal retention obligations.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt-Out of Sale / Sharing: we do not sell personal information or share it for cross-context behavioral advertising. No opt-out action is required.
- Right to Non-Discrimination: we will not discriminate against you for exercising any of these rights.
We will respond to verifiable requests within 45 days. We may extend the response period by an additional 45 days with notice. We will verify your identity before processing any request. Authorized agents may submit requests on your behalf with written authorization.
7. Legal Bases for Processing (GDPR — EEA / UK Users)
For users in the European Economic Area or United Kingdom, we process personal data under the following legal bases:
- Contract performance (Art. 6(1)(b)): account creation, authentication, service delivery, and subscription billing.
- Legitimate interests (Art. 6(1)(f)):platform security, fraud prevention, product improvement, and dispute resolution — where those interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c)): tax, accounting, chargeback, and other legal compliance records.
- Consent (Art. 6(1)(a)): optional communications you have opted into. You may withdraw consent at any time by contacting legal@synchoa.com.
8. International Data Transfers
The Services are operated from the United States. If you access SyncHOA from outside the United States, your data may be transferred to and processed in the United States and other locations where our service providers operate. Where required by applicable law (including GDPR), we rely on appropriate transfer mechanisms such as Standard Contractual Clauses to safeguard international transfers. You can request a copy of applicable safeguards by contacting legal@synchoa.com.
9. Retention
Active account and community data is retained while the account or subscription is active. After cancellation, community data is available for export for 30 days, then deleted or anonymized within 60 days where technically and legally feasible. Billing records, legal acceptance records, tax and accounting records, fraud-prevention data, security logs, support records, and chargeback and dispute records may be retained longer as required by law or legitimate business need. Subscription consent and auto-renewal authorization records may be retained for at least three years, or for one year after subscription termination, whichever period is longer where required by law.
10. Your Rights
Depending on your location, you may have rights to access, correct, delete, or export personal data; object to or restrict certain processing; withdraw consent; and opt out of non-essential communications. California residents should see Section 6. EEA/UK residents should see Section 7.
Some HOA-operational records (homeowner records, dues history, violation records) are controlled by the HOA board. For requests relating to that data, we may need to direct you to the HOA board as the data controller.
To exercise rights, contact privacy@synchoa.com.
11. Security
We use reasonable technical and organizational measures to protect data, including role-based access controls, HTTPS encryption in transit, hosted infrastructure security controls, audit logging, and third-party payment processing through Stripe. No system is perfectly secure. If you discover a potential security issue, please report it to legal@synchoa.com.
12. Do Not Track
SyncHOA does not currently respond to browser Do Not Track (DNT) signals. There is no industry standard for how DNT signals should be interpreted. In any case, SyncHOA does not use behavioral tracking scripts or advertising cookies. See our Cookie Policy for details.
13. Cookies and Browser Storage
SyncHOA uses authentication cookies and limited browser storage required for sign-in, security, payments, and preferences. We do not use advertising, analytics, or behavioral tracking cookies. See our Cookie Policy for the full list of cookies and storage items, including durations.
14. Changes
We may update this Privacy Policy as our Services, providers, or legal obligations change. For material changes, we will provide advance notice by email or in-product notification before the change takes effect. The “Last Updated” date at the top of this page reflects the most recent version.
Questions or rights requests: privacy@synchoa.com