Imovly is a property portfolio management platform operated as a SaaS service. When this policy refers to “we”, “us”, or “our”, it means Imovly. When it refers to “you”, it means the landlord or tenant using the platform.
Full name, email address, phone number, and company name.
Password — stored encrypted and managed by Supabase Auth. We never see your plaintext password.
Preferences: timezone and currency.
Property and portfolio data
Property addresses: the address, city, postal code, and country of properties you manage. This is the address of the managed property, not your personal home address.
Financial records: rental income, expenses by category (maintenance, insurance, taxes, cleaning, etc.), repair costs, deposit amounts, and monthly rent figures. This is rental portfolio data — we do not collect or store bank account numbers or banking credentials.
Lease data: lease start and end dates, rent amounts.
Maintenance tickets: issue descriptions, categories, priorities, photos, and repair notes.
Service bookings: booked service type, scheduled date, and quoted price.
Tenant information (entered by landlords)
Landlords may enter the following personal data about their tenants: full name, email address, and phone number. See Section 3 below for how this data is handled and your responsibilities as the data controller for your tenants.
Billing information
Subscription plan and payment status.
We do not store card numbers, CVV codes, or banking details — these are handled exclusively by Stripe. See Section 5.
Technical data
Activity inside the platform: when you use a feature (for example creating a property, adding a transaction, importing a CSV, or reaching your plan’s property limit), we record the action, whether it succeeded, and the time. We do not record the content you type — only which action took place. We use this to see what works, what fails, and what needs improving.
Emails and notifications we send you: we keep a record of each email and push notification sent to you (type, subject, time, and delivery status).
Analytics (only with your consent): if you accept analytics cookies, PostHog records the pages you visit and how you move through the platform, linked to your account. If you decline, nothing is collected and nothing is stored in your browser.
Our hosting provider (Vercel) collects standard server logs — including IP addresses, request timestamps, and browser/device type — for infrastructure and security purposes. This data is not used by us for profiling.
Authentication session cookies are used. Analytics cookies are set only if you accept them. We do not set advertising cookies.
3. Tenant data — your responsibilities as a landlord
When you add a tenant’s name, email, or phone number to Imovly, you are acting as the data controller for that personal data under the GDPR. Imovly acts as your data processor — we store and process that data solely on your instruction, to operate the platform on your behalf.
This means:
You are responsible for having a lawful basis to enter your tenants’ personal data into Imovly (for example, a legitimate interest in managing your rental or a contractual necessity under the tenancy agreement).
If a tenant contacts you to exercise their GDPR rights (access, correction, deletion), you are responsible for responding. You can delete a tenant’s data from within the platform, or contact us if you need assistance.
We will not use your tenants’ data for any purpose other than operating the platform features you use.
Tenant invites sent via Imovly include a link that allows tenants to create their own account. Once they do, they become data subjects in their own right and this policy applies to them directly.
4. How we use your data
To provide and operate the Imovly platform.
To process your subscription and send billing-related emails.
To send transactional emails: lease expiry reminders, maintenance alerts, booking confirmations, tenant invites, and monthly portfolio digests.
To understand how the platform is used, find what is broken, and decide what to improve, using the activity records described in Section 2.
To comply with legal and regulatory obligations.
We do not sell your data to third parties. We do not use your data for advertising.
5. Legal basis for processing (GDPR)
We process your personal data on the following legal bases:
Contract (Art. 6(1)(b)): processing your account information and portfolio data is necessary to deliver the service you signed up for.
Legitimate interests (Art. 6(1)(f)): server logs, security monitoring, error reports, the record of actions inside the platform, and the record of emails and notifications sent are processed in our legitimate interest to keep the platform secure, working, and improving.
Legal obligation (Art. 6(1)(c)): retaining financial records may be required by applicable tax or accounting law.
Consent (Art. 6(1)(a)): analytics cookies (PostHog) and any optional communications are used only with your consent, which you can withdraw at any time.
6. Third-party sub-processors
We use the following sub-processors to operate the platform. Each receives only the data necessary for their function:
Supabase — database storage and user authentication. All your account and portfolio data is stored here. Privacy policy
Stripe — payment processing. Stripe handles all card and billing data. We only receive subscription status from Stripe; we never see your card number or CVV. Privacy policy
Resend — transactional email delivery. Resend receives your name and email address (and your tenants’ where applicable) to deliver emails triggered by platform events. Privacy policy
PostHog (EU hosting, Frankfurt) — product analytics, only if you accept analytics cookies. Receives the pages you visit, your interactions, and your account email. Privacy policy
Sentry (EU hosting, Germany) — error reporting. When something fails, Sentry receives technical details of the error, which may include your IP address and browser type. Privacy policy
Cloudflare Turnstile — protection against automated sign-ups and abuse on our forms. Receives technical browser signals to tell people from bots. Privacy policy
Vercel — application hosting and deployment. Vercel processes request metadata (IP address, browser type, URL) as part of serving the application. Privacy policy
7. International data transfers
Supabase, Stripe, Resend, Vercel, and Cloudflare are US-based companies. PostHog and Sentry process our data in the EU. When your data is processed by these sub-processors, it may be transferred to and stored in the United States or other countries outside the European Economic Area (EEA).
Where such transfers occur, we rely on appropriate safeguards including the EU Standard Contractual Clauses (SCCs) as approved by the European Commission, and/or the EU-US Data Privacy Framework where applicable. Each sub-processor linked above maintains their own transfer mechanisms described in their privacy policies.
8. Data retention
We retain your data for as long as your account is active and your subscription is valid.
Account deletion: if you delete your account (available in Account settings), your personal data and all associated records are permanently deleted immediately from our database. This action is irreversible.
Legal retention: where applicable law requires it (for example, tax or accounting regulations), financial transaction records may be retained for up to 7 years even after account deletion. In such cases, only the minimum data necessary is kept.
Activity and email records: kept for 12 months, then deleted automatically. When you delete your account, the record of emails sent to you is deleted immediately; the activity record keeps only an internal identifier that no longer links to any person.
Backups: deleted data may persist in encrypted database backups for up to 30 days before being purged from backup storage.
9. Your rights (GDPR)
If you are based in the EU or EEA, you have the following rights under the GDPR:
Access: request a copy of the personal data we hold about you.
Rectification: correct inaccurate or incomplete data. You can update your name and email directly in Account settings.
Erasure: request deletion of your data. You can delete your entire account immediately in Account settings, or contact us if you need partial deletion.
Restriction: request that we restrict processing of your data in certain circumstances.
Portability: request a copy of your data in a structured, machine-readable format.
Objection: object to processing based on legitimate interests.
Withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any right not covered by self-service settings, email us at support@imovly.fyi. We will respond within 30 days. If you believe we have not handled your data correctly, you have the right to lodge a complaint with your local data protection authority — in Luxembourg, this is the CNPD (Commission nationale pour la protection des données).
10. Cookies
We use essential session cookies, which are required for authentication and security — without them, you cannot stay logged in. With your consent, we also use analytics cookies from PostHog to understand how the platform is used. We do not use advertising cookies or tracking pixels.
Analytics cookies are off until you accept them in the cookie notice, and you can change your choice at any time with the button below. A summary of our cookie use is also included in our Terms of Service (Section 13).
11. Changes to this policy
We may update this policy from time to time. For material changes, we will notify you by email at least 14 days before they take effect. The date at the top of this page always reflects the most recent version. Continued use of the platform after the effective date of any changes constitutes acceptance of the updated policy.