Commonwell

Home · Privacy Policy

Terms of Service · Privacy Policy · Security & PCI · Accessibility · Sub-processors · Data Processing Addendum · Copyright Policy

Privacy Policy

This Privacy Policy explains how Commonwell ("we", "us") collects, uses, and shares personal information when you use the Service. For community data, Commonwell acts as a processor on behalf of each community (the "controller"); the community decides what data to collect and why. Our Data Processing Addendum sets out the terms of that processing.

1. Information we collect

When you submit a contact or other form on a community's public website, the community receives what you submit, and we process it for that community as described in this policy.

2. How we use information

To provide and maintain the Service; process dues and vendor payments; send transactional and community communications; secure the Service and prevent abuse; comply with legal obligations; and improve the product.

3. AI features (Concierge)

Concierge is an optional AI assistant that each community turns on separately for administrators, residents, and vendors. When you use it, your prompts and attachments, and the community records and documents it needs to answer (only those your own access allows), are processed by AI models hosted by our cloud infrastructure provider (Cloudflare Workers AI and AI Search). Community documents are indexed so Concierge can cite them. Concierge conversations are kept for 30 days and then deleted. Commonwell does not use your content to train or fine-tune AI models. Concierge asks you to confirm before it changes records or sends messages. You can simply choose not to use Concierge, and community administrators can turn it off for everyone.

4. How we share information

5. Cookies and local storage

6. Data retention

We retain personal data while your community account is active or held as a recoverable read-only archive. An archive is not automatically purged; an authorized owner can explicitly delete the community, and individual data rights remain available while it is archived. Following a valid deletion, we delete or anonymize operational personal data. We may retain only the minimum records necessary for an applicable financial or tax obligation, signed-consent evidence, communication opt-out, security investigation, or legal claim, and only for the corresponding statutory or claims period. Access to retained records is restricted and they are not reused for marketing.

Short-lived delivery queues, caches, and backups expire under our providers' retention schedules and are not restored to ordinary product access after an erasure request. Encrypted dead-letter delivery payloads are kept for at most 30 days. Terminal delivery, deduplication, and observability records that can contain free text or serialized metadata are normally removed after 90 days; retryable failures remain restricted while they still require remediation. Ballot selections are stored separately from account rows under a keyed pseudonymous voter hash. That design limits ordinary board access but is not full anonymity because Commonwell can recompute the linkage while the voter key exists.

7. Your rights (GDPR / CCPA)

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact privacy@commonwell.app or your community administrator. We will respond within the timeframe required by applicable law. California residents have the rights described in the CCPA, including the right not to be discriminated against for exercising them.

The self-service export is scoped to the active community so one community does not disclose records controlled by another community, organization, vendor, or staff context. It lists shared records attributed to the requester without automatically copying shared bodies that may identify other people. Household occupant rows likewise include relationship and field-presence information, but not the other occupant's name, email address, or phone number. A requester who is the person named in an occupant row, or who needs personal data embedded in a shared record, can ask the community administrator or privacy@commonwell.app for a controller-reviewed response.

8. Security

We use encryption in transit, hashed credentials, scoped access, and audit logging. Payment card data is handled solely by our PCI DSS Level 1 payment processor. See our Security & PCI page for details.

9. International transfers

The Service runs on a global edge network. Where data is transferred across borders, we rely on appropriate safeguards as required by law, as described in our Data Processing Addendum.

10. Children

The Service is not directed to children under 16 and we do not knowingly collect their personal information.

11. Changes

We may update this Policy; material changes will be notified. The "last updated" date above reflects the current version.

12. Contact

privacy@commonwell.app