Legal
Privacy Policy
Last updated: August 10, 2026
In short: we collect only what the Service needs to run, we never sell personal information, card numbers never touch our servers, and your community can download everything it has stored with us at any time. Details below.
1. Who we are, and whose data this is
HostedHOA (“we”, “us”), operating at hostedhoa.com, provides websites, resident portals, and management tools for homeowner associations and similar communities (each, a “Community”).
For member data — rosters, contact details, dues records, posts, requests — your Community is the data controller: it decides what is collected and who may see it. HostedHOA processes that data on the Community’s behalf to provide the Service. For the account you create directly with us, we are the controller of your basic account details.
2. Information we collect
Account information. Your name, email address, and a bcrypt-hashed password (we never store the password itself). If your Community enables SMS alerts and you opt in, your mobile number.
Community content. What your Community creates in the Service: announcements, events and RSVPs, documents, photos, maintenance and architectural requests, forum posts, directory profiles (opt-in), membership details such as your unit or street address, dues assessments, and payment records.
Payment records — not card data. When a Community enables online payments, checkout happens on Stripe’s hosted pages. Card numbers are entered with Stripe and never touch our servers; we store only the amount, date, status, and a confirmation reference.
Technical data. Standard server logs (IP address, browser type, pages requested) used for security — for example rate-limiting abusive traffic — and operations. We do not use them for advertising or profiling.
3. How we use information
Solely to operate and secure the Service: signing you in, showing your Community its own content, delivering the notifications and emails your Community sends, processing payments the Community has enabled, and preventing abuse. We do not sell personal information, we do not run third-party advertising, and we do not use member data to train AI models.
4. Who can see your information
Visibility follows your Community’s settings, and the defaults are conservative: public pages are visible to anyone; residents-only content requires an approved member account; board-only material is restricted to board members and administrators. Additionally: event attendee names are shown to visitors by first name only, event times and calendar files are members-only, gallery photos appear publicly only after an explicit board approval, and directory profiles are opt-in.
Your Community’s administrators and board can see the member information the Community holds — as they would with any membership roster.
5. Service providers (sub-processors)
We share data only with the providers required to run the Service:
- Cloudflare — network delivery, TLS, and abuse protection for all traffic.
- Stripe — payment processing, when your Community enables online payments or donations.
- Resend — transactional and broadcast email delivery, when your Community enables email.
- Twilio — SMS delivery, when your Community enables text alerts and you opt in.
- Anthropic — AI features such as document Q&A, when your Community enables them. Only the content needed to answer the question is sent, and it is not used to train models.
Each provider receives only what its function requires. We may disclose information if required by law, or to protect the Service and its users.
6. Cookies & sessions
We use a single, essential session cookie to keep you signed in. It contains a signed token — not your personal details — is httpOnly, and expires automatically. We use no tracking, analytics, or advertising cookies, so there is no cookie banner to click.
7. Security
Traffic is encrypted in transit, passwords are hashed with bcrypt, sessions can be revoked everywhere at once, two-factor authentication is available to every member, and each Community’s data is isolated from every other’s in all queries. Read more on our Security page.
8. Retention & deletion
We keep data while your account or Community remains active. Nightly database backups are retained for 14 days and then destroyed. When a Community leaves the Service, its administrators can export all data, and we delete the Community’s data after a wind-down period following termination.
To request deletion of your personal account data, contact your Community’s administrator (the controller of member data) or email us at [email protected]. Note that some records — for example dues payment history — may need to be retained by your association to meet its own legal and accounting obligations.
9. Your rights
You can view and update your profile from the portal, opt out of the resident directory, unsubscribe from newsletters, and disable SMS at any time. You may request a copy of your personal data, corrections, or deletion using the contacts above. We respond to all requests, whether or not a specific privacy statute applies to you.
10. Children
The Service is intended for adults managing and living in their communities and is not directed to children under 13. We do not knowingly collect personal information from children.
11. Changes & contact
We will post any changes to this policy here and update the date above; material changes will be announced to Community administrators. Questions? Email [email protected] — and see our Terms of Service.