Beta notice

This Privacy Policy is written for HAPSecure's private beta and current customer-facing use. Limited-scope counsel review is still required before broad self-serve launch, paid advertising, or live certified-mail spend.

Privacy Policy

Effective date: June 29, 2026

This Privacy Policy explains how UNFETTEREDMIND LLC (“HAPSecure,” “we,” “us”) collects, uses, shares, and protects personal information in connection with the HAPSecure service. HAPSecure is a software-as-a-service compliance ledger for Section 8 and Housing Choice Voucher landlords.

1. Data we collect

  • Account data: name, email, organization details, role, authentication identifiers, MFA status, and session-related information used to create and secure your account.
  • Billing data: subscription status and payment metadata processed through Stripe. We do not store full card numbers.
  • Uploaded documents and proof: PHA correspondence, PDFs, text files, email attachments, photos, GPS metadata where submitted, cure-proof records, certified-mail packet details, portal/email proof notes, and related unit records.
  • Extracted compliance records: document type, inspection or notice dates, deficiency descriptions, severity, cure deadlines, review status, audit-report data, and append-only ledger events derived from customer-provided records.
  • Usage and technical data: log data, device and browser information, analytics limited to public marketing-page paths, attribution fields such as GCLID/UTM where present, and metering of automated extraction used to operate, secure, improve, and bill the service.

2. How we use data

  • provide, maintain, secure, and support the service;
  • classify and extract structured compliance events from PHA documents and maintain the compliance timeline;
  • run cure-countdown timers, email reminders, audit reports, proof-submission workflows, and billing gates you configure or use;
  • process subscriptions, payments, and usage metering;
  • detect abuse, investigate security issues, troubleshoot bugs, and comply with legal obligations.

We do not sell personal information. Uploaded document contents and tenant personal information are processed to provide the service to your organization and are not used to advertise to third parties.

3. Customer and processor roles

For tenant, applicant, household, and PHA-document data submitted by a customer organization, the customer is typically the controller or business responsible for deciding why and how the data is processed. HAPSecure acts as a processor or service provider as described in the Data Processing Addendum. You are responsible for having a lawful basis to submit Customer Data to HAPSecure.

4. Sub-processors

We use sub-processors to deliver the service. Current core providers include:

  • Supabase - managed Postgres database, authentication, and document storage.
  • Stripe - subscription billing and payment processing.
  • Resend - outbound operational email sent by the application.
  • Cloudflare - DNS, email routing, inbound-email Worker processing, and edge security.
  • Vercel - application hosting and content delivery.
  • Anthropic - large language model services used to classify and extract structured data from PHA documents.
  • Lob - certified-mail letter creation when the customer explicitly uses the certified-mail workflow.
  • Google - public-page analytics and advertising attribution where configured.

Supabase Auth currently sends authentication emails unless and until a custom SMTP provider is configured. We will update this list if core providers change.

5. Data retention

Account and billing data are retained for as long as your account is active and as needed for legitimate business and legal purposes. Compliance records and supporting documents may be retained on an immutable, write-once-read-many basis to support HUD/PHA record-retention expectations and auditability. The append-only ledger may persist as the tamper-evident timeline after individual records are no longer actively used, limited to lawful retention purposes.

6. Security measures

We implement technical and organizational measures designed to protect personal information, including:

  • tenant isolation through Postgres Row-Level Security;
  • private document storage with authenticated access checks;
  • encryption in transit and provider-managed encryption at rest;
  • append-only SHA-256 hash-chained compliance events that make tampering with past records detectable;
  • MFA support and AAL2 enforcement for account security;
  • signup abuse throttles, bot trap, and Turnstile integration.

No method of transmission or storage is completely secure. We do not claim SOC 2, ISO 27001, or any other certification or third-party audit; this Policy describes actual controls only.

7. Data subject rights

Depending on your jurisdiction, individuals may have rights to access, correct, delete, or restrict processing of their personal information, to data portability, and to object to certain processing. Because tenant and applicant data is typically controlled by the customer organization, requests concerning that data should be directed to the relevant landlord or property manager. To exercise rights regarding data we control, contact support@hapsecure.app.

8. Children's data

The service is intended for business use by landlords and their staff. Household composition data within uploaded PHA documents may reference minors; such data is processed on the customer's instructions as part of the compliance record and is subject to the protections described here.

9. International transfers

Our providers may process data in the United States or other countries. Where personal information is transferred across borders in a manner subject to data-transfer law, we rely on appropriate safeguards such as contractual data-protection terms and Standard Contractual Clauses where applicable.

10. Breach notification

If we become aware of a personal-data breach affecting Customer Data, we will notify the affected customer organization without undue delay and provide information reasonably available to help the controller meet its own notification obligations, consistent with applicable law.

11. Contact

For privacy questions or requests, contact support@hapsecure.app, UNFETTEREDMIND LLC.