Home · Privacy Policy
Terms of Service · Privacy Policy · Security & PCI · Accessibility · Sub-processors · Data Processing Addendum · Copyright Policy
Privacy Policy
This Privacy Policy explains how Commonwell ("we", "us") collects, uses, and shares personal information when you use the Service. For community data, Commonwell acts as a processor on behalf of each community (the "controller"); the community decides what data to collect and why. Our Data Processing Addendum sets out the terms of that processing.
1. Information we collect
- Account information: name, email, phone, mailing/unit address, role.
- Community content: documents, announcements, requests, violations, dues and payment records you or your community create.
- Payment metadata: provided by our payment processor (card brand, last four, payout status). We do not store full card or bank account numbers.
- Usage and device data: IP address, user agent, and log/event data used to operate, secure, and debug the Service.
- Concierge (AI assistant) content: the questions you ask, files you attach, and the answers and actions produced when you use Concierge.
- Linked bank account data: when a community links its bank account through our payment processor's bank-linking service, we receive the institution name and account transactions (dates, amounts, and descriptions) for reconciliation. We never receive bank login credentials.
When you submit a contact or other form on a community's public website, the community receives what you submit, and we process it for that community as described in this policy.
2. How we use information
To provide and maintain the Service; process dues and vendor payments; send transactional and community communications; secure the Service and prevent abuse; comply with legal obligations; and improve the product.
3. AI features (Concierge)
Concierge is an optional AI assistant that each community turns on separately for administrators, residents, and vendors. When you use it, your prompts and attachments, and the community records and documents it needs to answer (only those your own access allows), are processed by AI models hosted by our cloud infrastructure provider (Cloudflare Workers AI and AI Search). Community documents are indexed so Concierge can cite them. Concierge conversations are kept for 30 days and then deleted. Commonwell does not use your content to train or fine-tune AI models. Concierge asks you to confirm before it changes records or sends messages. You can simply choose not to use Concierge, and community administrators can turn it off for everyone.
4. How we share information
- Service providers (sub-processors): Cloudflare (hosting, database, storage, email delivery, and AI processing), Stripe (payments, payouts, and bank linking), Google (web font delivery), and, only when enabled, Twilio (SMS) and Intuit QuickBooks (accounting sync). Each processes data only to provide its service. The current list, with purposes and locations, is on our Sub-processors page.
- Your community: administrators of your community can access member data within that community.
- Legal: where required by law or to protect rights and safety.
- We do not sell personal information or share it for cross-context behavioral advertising.
- Mobile numbers and SMS consent: no mobile information will be shared with third parties or affiliates for marketing or promotional purposes. SMS opt-in data and consent are never shared with third parties, except the SMS provider that delivers the messages you asked to receive.
5. Cookies and local storage
- Essential cookie: a secure, httpOnly session cookie keeps you signed in. Our infrastructure provider may also set strictly necessary security cookies that protect the Service from abuse.
- Local storage: your browser keeps preferences on your device, such as theme and layout settings, the community you last selected, unsent drafts, and the accessibility toolbar settings on community websites. You can clear them at any time in your browser settings.
- Fonts: pages load web fonts from Google Fonts, so Google receives your IP address and browser details when the fonts are fetched.
- Payments: when you pay or link a bank account, Stripe's checkout pages and scripts may set cookies Stripe uses to prevent fraud.
- Analytics: we may measure page performance with Cloudflare Web Analytics, which does not use cookies or track you across sites.
- Embedded videos: community websites can embed videos from YouTube or Vimeo. The video provider receives your IP address and browser details when the player loads and may set its own cookies under its own privacy policy.
- Commonwell does not set advertising or cross-site tracking cookies.
6. Data retention
We retain personal data while your community account is active or held as a recoverable read-only archive. An archive is not automatically purged; an authorized owner can explicitly delete the community, and individual data rights remain available while it is archived. Following a valid deletion, we delete or anonymize operational personal data. We may retain only the minimum records necessary for an applicable financial or tax obligation, signed-consent evidence, communication opt-out, security investigation, or legal claim, and only for the corresponding statutory or claims period. Access to retained records is restricted and they are not reused for marketing.
Short-lived delivery queues, caches, and backups expire under our providers' retention schedules and are not restored to ordinary product access after an erasure request. Encrypted dead-letter delivery payloads are kept for at most 30 days. Terminal delivery, deduplication, and observability records that can contain free text or serialized metadata are normally removed after 90 days; retryable failures remain restricted while they still require remediation. Ballot selections are stored separately from account rows under a keyed pseudonymous voter hash. That design limits ordinary board access but is not full anonymity because Commonwell can recompute the linkage while the voter key exists.
7. Your rights (GDPR / CCPA)
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact privacy@commonwell.app or your community administrator. We will respond within the timeframe required by applicable law. California residents have the rights described in the CCPA, including the right not to be discriminated against for exercising them.
The self-service export is scoped to the active community so one community does not disclose records controlled by another community, organization, vendor, or staff context. It lists shared records attributed to the requester without automatically copying shared bodies that may identify other people. Household occupant rows likewise include relationship and field-presence information, but not the other occupant's name, email address, or phone number. A requester who is the person named in an occupant row, or who needs personal data embedded in a shared record, can ask the community administrator or privacy@commonwell.app for a controller-reviewed response.
8. Security
We use encryption in transit, hashed credentials, scoped access, and audit logging. Payment card data is handled solely by our PCI DSS Level 1 payment processor. See our Security & PCI page for details.
9. International transfers
The Service runs on a global edge network. Where data is transferred across borders, we rely on appropriate safeguards as required by law, as described in our Data Processing Addendum.
10. Children
The Service is not directed to children under 16 and we do not knowingly collect their personal information.
11. Changes
We may update this Policy; material changes will be notified. The "last updated" date above reflects the current version.
12. Contact
privacy@commonwell.app