Legal

Privacy Policy

Last updated: August 22, 2026

This is an MVP legal draft and is not legal advice. Relay should obtain qualified legal review and replace all marked placeholders before production launch.

1. Introduction

This Privacy Policy explains how the Relay maintenance-operations prototype collects, uses, and handles information. In this draft, “Relay,” “we,” and “us” refer to [legal entity name to be added before launch].

Relay is designed to help property managers receive, organize, review, assign, and track maintenance requests.

2. Information We Collect

Depending on how Relay is used, we collect manager account details, property and unit records, vendor records, tenant maintenance-request information, authentication and session information, and information produced by AI-assisted intake.

3. Manager Account Information

Manager accounts may include a manager’s name, company or organization name, email address, and authentication information.

For password accounts, Relay stores a password hash rather than the plaintext password. Google-only accounts do not have a Relay password credential.

4. Tenant Maintenance Request Information

A tenant request may include:

  • Tenant name
  • Property and unit
  • Maintenance problem description
  • Selected or AI-classified category and priority
  • AI-generated summary and suggested follow-up question
  • Tenant follow-up answer, request status, submission time, and vendor assignment

Tenants should avoid including information that is not needed to explain the maintenance issue.

5. Property and Unit Information

Managers may provide property names, addresses, cities, states, postal codes, unit identifiers, and permanent public property-maintenance links. A public link exposes basic information for one property and its configured units so a tenant can submit a request.

6. Vendor Information

Managers may enter vendor company names, contact names, trades, phone numbers, email addresses, active status, and request assignments. Relay does not currently provide vendor accounts or automatically contact vendors.

7. Authentication and Session Information

Relay uses an authentication cookie to keep managers signed in. The cookie is HTTP-only and is used with server-side session records. Temporary cookies may also support Google sign-in and onboarding.

8. Google Sign-In

Managers may choose to authenticate with Google. Relay receives identity information needed to authenticate or link the account, including a verified email address, a stable Google account identifier, and a name when Google provides one.

Relay verifies Google’s response on the server and does not persist Google access or ID tokens. Google separately handles information under the Google Privacy Policy.

9. AI Processing

Relay sends the maintenance problem text to OpenAI together with the tenant-selected fallback category and priority. Relay does not include the tenant name, property name or address, unit, vendor data, manager information, or internal organization/property/unit identifiers in that AI request.

AI output may summarize the issue, classify its category, conservatively estimate priority, and decide whether one follow-up question may help. AI output can be incomplete or incorrect; property managers should review it and use their own judgment.

OpenAI processes API data under its applicable business terms and policies. See OpenAI’s privacy information and API data controls.

10. How We Use Information

We use information to:

  • Create and authenticate manager accounts
  • Provide organization-scoped property, unit, vendor, and request workflows
  • Receive, structure, display, update, and assign maintenance requests
  • Provide AI-assisted intake and follow-up
  • Protect the service, diagnose problems, and enforce applicable agreements

11. How Information Is Shared

Information is available to authenticated managers in the organization that owns the relevant records. Tenant intake information is processed by OpenAI only as described above. Google processes information when a manager chooses Google sign-in.

The current prototype does not include advertising networks or a feature for selling personal information. We may disclose information when required by applicable law or to protect rights, safety, and service integrity; this language requires legal review before launch.

12. Cookies and Similar Technologies

Relay currently uses cookies needed for manager authentication, Google OAuth security, and Google onboarding. The codebase does not currently include advertising or analytics cookies.

13. Data Retention

Draft language requiring legal review: We intend to retain information for as long as reasonably necessary to provide and maintain Relay, meet applicable obligations, resolve disputes, and enforce agreements. Specific retention and deletion schedules have not yet been finalized.

14. Data Security

Relay uses technical safeguards that currently include password hashing, HTTP-only authentication cookies, server-side session validation, verified Google identity responses, and server-side organization isolation. No system can guarantee complete security. Relay does not claim SOC 2, ISO, HIPAA, PCI, or end-to-end-encryption certification or compliance.

15. Organization Data Isolation

Manager-facing database operations are scoped to the authenticated manager’s organization. Direct requests for another organization’s records are designed to return a not-found response. Public tenant links expose only one property’s basic intake information and units; they do not expose manager dashboards, vendors, requests, or analytics.

16. Third-Party Services

Relay currently uses Google for optional sign-in and OpenAI for maintenance-intake analysis. These providers process information under their own agreements and policies. No production hosting provider is identified in this local-development prototype.

17. Your Choices

Managers can choose password authentication instead of Google sign-in. Tenants control the information they enter in a maintenance request.

Requests concerning access, correction, or deletion should be directed to [add Relay support/legal email before launch]. Available rights depend on applicable law and require a production process before launch.

18. Children’s Privacy

Relay is property-maintenance and business software and is not specifically directed to children. If a manager believes a child has provided information through Relay, they should contact [add Relay support/legal email before launch].

19. Changes to This Policy

We may update this draft as Relay changes or as legal requirements are reviewed. The “Last updated” date will identify the latest version. A production notification process for material changes must be decided before launch.

20. Contact

Legal entity: [add legal entity name before launch]

Email: [add Relay support/legal email before launch]

Mailing address: [add if required before launch]

You may also review the companion Terms of Service.