1. Introduction
This Privacy Policy explains how the Relay maintenance-operations prototype collects, uses, and handles information. In this draft, “Relay,” “we,” and “us” refer to [legal entity name to be added before launch].
Relay is designed to help property managers receive, organize, review, assign, and track maintenance requests.
2. Information We Collect
Depending on how Relay is used, we collect manager account details, property and unit records, vendor records, tenant maintenance-request information, authentication and session information, and information produced by AI-assisted intake.
3. Manager Account Information
Manager accounts may include a manager’s name, company or organization name, email address, and authentication information.
For password accounts, Relay stores a password hash rather than the plaintext password. Google-only accounts do not have a Relay password credential.
4. Tenant Maintenance Request Information
A tenant request may include:
- Tenant name
- Property and unit
- Maintenance problem description
- Selected or AI-classified category and priority
- AI-generated summary and suggested follow-up question
- Tenant follow-up answer, request status, submission time, and vendor assignment
Tenants should avoid including information that is not needed to explain the maintenance issue.
5. Property and Unit Information
Managers may provide property names, addresses, cities, states, postal codes, unit identifiers, and permanent public property-maintenance links. A public link exposes basic information for one property and its configured units so a tenant can submit a request.
6. Vendor Information
Managers may enter vendor company names, contact names, trades, phone numbers, email addresses, active status, and request assignments. Relay does not currently provide vendor accounts or automatically contact vendors.
7. Authentication and Session Information
Relay uses an authentication cookie to keep managers signed in. The cookie is HTTP-only and is used with server-side session records. Temporary cookies may also support Google sign-in and onboarding.
8. Google Sign-In
Managers may choose to authenticate with Google. Relay receives identity information needed to authenticate or link the account, including a verified email address, a stable Google account identifier, and a name when Google provides one.
Relay verifies Google’s response on the server and does not persist Google access or ID tokens. Google separately handles information under the Google Privacy Policy.
9. AI Processing
Relay sends the maintenance problem text to OpenAI together with the tenant-selected fallback category and priority. Relay does not include the tenant name, property name or address, unit, vendor data, manager information, or internal organization/property/unit identifiers in that AI request.
AI output may summarize the issue, classify its category, conservatively estimate priority, and decide whether one follow-up question may help. AI output can be incomplete or incorrect; property managers should review it and use their own judgment.
OpenAI processes API data under its applicable business terms and policies. See OpenAI’s privacy information and API data controls.
10. How We Use Information
We use information to:
- Create and authenticate manager accounts
- Provide organization-scoped property, unit, vendor, and request workflows
- Receive, structure, display, update, and assign maintenance requests
- Provide AI-assisted intake and follow-up
- Protect the service, diagnose problems, and enforce applicable agreements
13. Data Retention
Draft language requiring legal review: We intend to retain information for as long as reasonably necessary to provide and maintain Relay, meet applicable obligations, resolve disputes, and enforce agreements. Specific retention and deletion schedules have not yet been finalized.
14. Data Security
Relay uses technical safeguards that currently include password hashing, HTTP-only authentication cookies, server-side session validation, verified Google identity responses, and server-side organization isolation. No system can guarantee complete security. Relay does not claim SOC 2, ISO, HIPAA, PCI, or end-to-end-encryption certification or compliance.
15. Organization Data Isolation
Manager-facing database operations are scoped to the authenticated manager’s organization. Direct requests for another organization’s records are designed to return a not-found response. Public tenant links expose only one property’s basic intake information and units; they do not expose manager dashboards, vendors, requests, or analytics.
16. Third-Party Services
Relay currently uses Google for optional sign-in and OpenAI for maintenance-intake analysis. These providers process information under their own agreements and policies. No production hosting provider is identified in this local-development prototype.
17. Your Choices
Managers can choose password authentication instead of Google sign-in. Tenants control the information they enter in a maintenance request.
Requests concerning access, correction, or deletion should be directed to [add Relay support/legal email before launch]. Available rights depend on applicable law and require a production process before launch.
18. Children’s Privacy
Relay is property-maintenance and business software and is not specifically directed to children. If a manager believes a child has provided information through Relay, they should contact [add Relay support/legal email before launch].
19. Changes to This Policy
We may update this draft as Relay changes or as legal requirements are reviewed. The “Last updated” date will identify the latest version. A production notification process for material changes must be decided before launch.
20. Contact
Legal entity: [add legal entity name before launch]
Email: [add Relay support/legal email before launch]
Mailing address: [add if required before launch]
You may also review the companion Terms of Service.
