Skip to main content

Trust

Privacy

How Parc & Portfolio collects, uses, and shares personal information for owners and residents.

Privacy policy

Parc & Portfolio (“we”, “us”) provides software for property organizations, prospective renters, and residents. The service supports property and unit records, tour scheduling, rental-interest pre-screening, household setup, move-in, payments, maintenance, documents, and related communications.

This Privacy Policy describes the personal information we process when you visit or use the product, create an account, submit or participate in a rental-interest pre-screen, schedule a tour, join a household, upload or receive documents, make a payment, or use resident features. It applies to the product at this website.

We process account and authentication information such as name, email address, verified-email status, and sign-in session data created by our authentication provider (Clerk), including cookies and similar session tokens needed to keep signed-in users authenticated.

For prospective renters and rental-interest participants, we may process contact information, desired move-in timing, household composition, residence history, employment and resource information, rental-assistance information, pet, vehicle, smoking and viewing information, and answers or certifications submitted through the pre-screen flow. Depending on participant role, we may also process date of birth, Social Security number, and government-issued identification.

A primary adult may provide limited information about children who are expected to live in the home, including legal name, date of birth, and relationship to the primary adult. Children do not create accounts, receive pre-screen invitations, provide Social Security numbers or government identification, or independently complete the pre-screen. We use child household-member information to represent proposed occupancy and determine which household members must complete adult steps.

Rental-interest information is a pre-screening workflow for the property organization. It is not itself a consumer report, automated housing decision, approval, denial, or official third-party rental application. When an organization chooses to proceed to an official application, the service may send eligible adults a link configured by that organization; we do not represent that the third-party destination is operated by us unless it says so.

When an organization uses the product we process organization, property, and unit records the organization enters, including names, addresses, unit identifiers, operational settings, availability, and related records.

When an owner records a household we process household contact details, role information, lease relationships, and, after a person accepts an invitation with a matching verified email, the link between that person and the lease.

Owners may upload signed lease and related documents. We store files in private object storage (Amazon S3) and use automated malware-verification controls before making supported documents available for download. We do not treat an upload as creating or changing a contract between the people named on the document.

Restricted identity information is handled with additional controls. Social Security numbers are encrypted using application encryption backed by AWS Key Management Service (KMS) in configured environments and are not displayed back in full. Government-identification files and other restricted documents use private storage and role-based access controls. Invitation and verification tokens are stored only as hashes where the workflow supports hash-only storage.

We process tenancy and move-in records created in the product, including lease term, rent and deposit amounts, payment obligations, task completion, and related household status.

We process maintenance requests residents submit, including category, description, status, communications, and related property or unit context, so the organization can respond and maintain a service history.

When someone pays rent or another lease charge through the product, payment card and bank-account credentials are handled by Stripe. We receive payment metadata such as amount, currency, status, payment method category, identifiers, and the connected account used to route funds to the organization. We do not store card primary account numbers or online-banking credentials.

We process transactional communications associated with the relationship, including tour confirmations, pre-screen invitations, household invitations, payment messages, move-in messages, and maintenance or account communications. We may retain communication history and delivery identifiers so the organization has a durable record of the relationship.

We may use ordinary contact information to send optional marketing or promotional communications where permitted by law and, where required, with consent. We do not use Social Security numbers, government-identification information, payment credentials, or child household-member information for advertising or marketing, and we do not sell personal information to advertisers.

We use infrastructure processors to operate the service, including Clerk for authentication and sessions; Stripe Connect for payments; Amazon Web Services for private file storage and KMS-backed encryption controls; our hosting and managed database providers for application data; transactional email providers such as Postmark or another configured SMTP provider; document-scanning infrastructure; and configured error-monitoring services for limited diagnostic information. We configure monitoring so restricted identity values, payment credentials, and document contents are not intentionally included in error reports.

We use information to authenticate users, provide requested property and household workflows, evaluate workflow completeness, send transactional messages, secure the service, prevent abuse, maintain audit and communication records, support the organization operating the property, and meet legal, accounting, and security obligations.

We share information with service providers that process data for us, with authorized members of the relevant property organization, and with household participants only to the extent their role permits. Financial information is restricted to roles that are permitted to view household financials. We may disclose information if required by law, to protect the service or users, or as part of a merger, acquisition, financing, or sale of assets subject to appropriate notice or contractual protections.

Our service providers may store or process information in the United States and other countries where they operate. If you access the service from another country, your information may be transferred to those locations.

We keep account, organization, prospect, tour, rental-interest, household, lease, payment-metadata, communication, audit, and document records for as long as reasonably needed to operate the relationship, resolve disputes, meet legal or accounting duties, prevent fraud, and maintain security controls. We delete or de-identify information when we no longer have a legitimate need to retain it, subject to backup, audit-integrity, legal-hold, and other lawful retention requirements.

You may request access, correction, or deletion of personal information we hold about you, or ask a question about this policy, by emailing support@novelassembly.io or using the Contact page. We may need to verify your identity. When information was supplied or controlled by a property organization, we may coordinate with or direct the request to that organization where appropriate.

We use administrative, technical, and physical safeguards appropriate to a hosted software service, including role-based access controls, encryption in transit, private object storage, restricted-identity encryption, hashed invitation tokens, audit records, and environment-specific security controls. No method of transmission or storage is completely secure, and we do not promise that unauthorized access cannot occur.

Accounts and independent pre-screen participation are for adults. A person must be at least 18 years old to create an account or independently accept an adult household or pre-screen invitation. The service may process the limited child household-member information described above when an adult provides it for proposed or actual occupancy. If you believe child information was provided improperly, contact support@novelassembly.io.

If you are a resident of a U.S. state that provides additional privacy rights, including rights to know, delete, correct, or opt out of certain processing where applicable, we will honor those rights when they apply to this service. Submit requests through the Contact page or support@novelassembly.io. We will not discriminate against you for exercising rights provided by law.

We may update this policy as the product or law changes. The version identifier on this page shows the current text. If you have an account, a material change to a legal document that requires renewed acceptance may be presented before continued product use.

Privacy and data questions may be sent to support@novelassembly.io. General company inquiries may be sent to hello@novelassembly.io.