Privacy Policy
Last updated: August 11, 2026
1. Who this covers
This policy covers facility operators and staff with Cubby accounts, and tenants who use the payment portal or whose records an operator stores in Cubby. Cubby is the “service provider” here; for tenant records, your facility operator decides what is collected.
2. What we collect
Operators and staff: name, email, hashed password, optional two-factor and passkey credentials, subscription status, and audit logs of actions taken in the app.
Tenant records (entered by the operator or by tenants in the portal): name, email, phone, unit and lease details, invoices and payment history, and lien-notice records.
Automatically: standard server logs (IP, user agent, timestamps) and error reports. We do not run advertising trackers.
3. What we never see
Full card numbers go directly to Stripe and never touch Cubby’s servers. Gate codes are treated like passwords: access-restricted, never written to logs, deactivated at move-out, and rotated at the next move-in.
4. How we use data
To run the service: billing, invoicing, payment reminders, lien-deadline alerts, gate-code management, support, and security (rate limiting, bot protection, fraud prevention). We do not sell personal data, run ads, or use your facility’s data to train AI models.
5. Who we share with
Only processors needed to operate the service: Stripe (payments), Resend (transactional email), Vercel (hosting), Neon (database), Upstash (rate limiting), Sentry (error monitoring), and Cloudflare Turnstile (bot protection on forms). Each receives only what its function requires. We disclose data if legally compelled, and we will tell you unless prohibited.
6. Emails
Cubby sends transactional email only: receipts, invoices, payment reminders, late-fee and lien-deadline alerts, and account security messages. There is no marketing list to unsubscribe from.
7. Retention
Account data is retained while your subscription is active and for at least 90 days after cancellation, after which we may delete it; you can request deletion sooner at any time. Financial records the law requires an operator to keep are the operator’s responsibility to export before deletion. Backups age out on a rolling schedule after deletion.
8. Your rights
Operators can export their data (CSV) and delete their account by contacting us. Tenants should direct access or deletion requests to their facility operator first — the operator controls those records; we will assist the operator in fulfilling them. You can reach us anytime at support@cubbytool.com.
9. Security
Passwords are bcrypt-hashed, sessions use signed, httpOnly cookies, two-factor authentication and passkeys are available, gate codes are never logged, and all traffic is TLS. No system is perfectly secure; if a breach affects your data we will notify you promptly as the law requires.
10. Changes
Material changes to this policy will be announced by email at least 14 days before taking effect. This policy is governed by the laws of the State of Maryland, USA.