Legal
Privacy Policy
Stonerow PM holds some of the most sensitive records a household produces: where people live, what they owe, and what they signed. This policy says plainly what we collect, what we do with it, what we will never do with it, and how to get it back or get it deleted.
Effective date: August 7, 2026. Applies to stonerowpm.com and the Stonerow PM application at app.stonerowpm.com.
1. Who this policy covers
Stonerow PM is web-based property management software for independent landlords and small property managers. Three groups of people are described here, and the rules differ for each:
- Website visitors — anyone reading stonerowpm.com or sending the contact form.
- Customers — landlords, owners, property managers, and the staff users they invite into an organization account.
- Residents and applicants — tenants, co-tenants, occupants, guarantors, and rental applicants whose records a landlord keeps in the software.
For website visitors and customers, Stonerow PM decides how the data is used and is the controller of it. For residents and applicants, the landlord is the controller: they choose what to collect, why, and for how long. Stonerow PM is their service provider (a processor), acting on their documented instructions and not for our own purposes. If you are a resident, the fastest route for a privacy request is your landlord or property manager, and section 10 explains what to do if that route fails.
2. What we collect from website visitors
Browsing stonerowpm.com requires no account and sets no Stonerow cookies. The site carries no analytics package, no advertising pixel, no session recorder, and no social-media tracking script. The only third-party code on the site is the Cloudflare Turnstile verification widget on the contact page.
If you submit the contact form, we receive what you type: name and email (required), and optionally company, phone, number of units managed, state, and your message. Cloudflare Turnstile also receives your IP address to confirm the submission came from a person rather than a bot. The submission is delivered to us as an email; it is not written to a marketing database, added to a mailing list, or shared with anyone else. We use it to answer you.
3. What we collect from customers
Creating an organization account collects the information needed to run it: name, email address, and a password (stored only as a salted hash, never in readable form), the users you invite and the role you assign each of them, and organization details such as legal name, authorized representative, tax identification number, primary state, and billing preferences.
The application also keeps an always-on audit log of privileged actions — what changed, on which record, by which user, at what time, and from which IP address. That log exists for your protection: it is how a dispute over who altered a lease or reversed a payment gets settled, and it is part of what makes the records court-ready. It cannot be edited or switched off.
Ordinary server and edge logs (request time, URL, status code, IP address, user agent) are generated by our web server and by Cloudflare for security, abuse prevention, and troubleshooting.
4. What landlords put in, about residents
Most personal information in Stonerow PM is entered by a landlord about their own tenancies. Depending on which features that landlord uses, it can include resident names and contact details; lease terms, rent, and deposit amounts; the rent ledger of every charge, payment, and reversing entry; payment records (method, amount, and date of offline payments such as cash, check, money order, bank transfer, or card taken elsewhere); invoices and receipts; maintenance requests and work-order history; inspection notes and photographs; uploaded documents and attachments; pets, vehicles, and renters-insurance policy details; rental applications and the answers a landlord chose to ask for; and e-signature records, which capture the signer's typed name, timestamp, IP address, consent version, and a cryptographic hash of the signed document.
Stonerow PM does not require or prompt for Social Security numbers, and the product is built on a data-minimization rule: collect nothing beyond what a given workflow genuinely needs. Landlords who nevertheless enter sensitive identifiers into free-text fields are responsible for that choice and for the obligations it creates under state law.
We do not process card or bank payments. Payment processing integrations ship switched off, so no card numbers or bank credentials pass through Stonerow PM today. If you later enable a payment provider, that provider handles the payment credentials under its own terms, and this policy will be updated before the capability goes live.
5. How we use information
We use personal information only to provide, secure, support, and improve the service, specifically to: operate the application and keep your records available and accurate; authenticate users and enforce the role permissions you assign; run the compliance guardrails (deposit caps, deposit-interest accrual, statutory late-fee limits) that require reading your lease and ledger data; generate the documents, statements, receipts, and reports you ask for; send transactional messages such as receipts, invoices, reminders, and password resets; answer your support requests; detect, investigate, and stop abuse, fraud, and security incidents; meet our own legal, tax, and accounting obligations; and understand aggregate, non-identifying usage so we know which parts of the product need work.
We do not use your information for behavioral advertising, we do not build profiles of residents, and we do not enrich your records with data bought from brokers.
6. What we will never do
These are product commitments, not marketing language, and they are why several ordinary industry practices are absent from this policy:
- We do not sell personal information and we do not share it for cross-context behavioral advertising, under any definition used by US state privacy law.
- We do not pool one landlord's data with another's. Every record is isolated to its own account at the database-query level, and the isolation fails closed: a query without a valid account context returns nothing rather than everything.
- We do not run rent-setting algorithms and we do not generate cross-landlord rent or occupancy recommendations. Your building, your rent, your call.
- We do not use customer or resident records to train artificial-intelligence models, ours or anyone else's.
- We do not run advertising or analytics trackers on the marketing site or in the application.
7. Cookies and similar technologies
The marketing site sets no Stonerow cookies at all. Cloudflare, which sits in front of the site, may set strictly necessary security cookies to operate bot protection and the Turnstile verification check on the contact form. Those cookies exist to tell humans from automated abuse; they do not track you across other websites.
The application sets two strictly necessary cookies once you sign in: a session cookie that keeps you logged in, and a cross-site request forgery token that stops a malicious page from acting as you. Both are required for the application to function and cannot be declined while using it. There are no analytics, advertising, or preference cookies to opt out of, which is why you will not find a cookie consent banner on this site.
8. Who we share information with
We share personal information only in these situations:
- Infrastructure providers. Cloudflare, Inc. provides our edge network, DNS, DDoS and bot protection, the Turnstile check, the encrypted tunnel to our origin server, and email routing for contact-form submissions. Vultr Holdings, LLC (The Constant Company, LLC) provides the virtual private server that runs the application and its database, located in the United States.
- Providers a customer chooses to enable. The application supports customer-selected email, SMS, payment, and tenant-screening providers. All of them ship off by default — selecting a vendor stores configuration only, and nothing is sent or charged until that customer supplies credentials and switches it on. When a customer enables one, data flows to that provider on the customer's instruction and under that provider's terms.
- Professional advisers — accountants, auditors, and lawyers bound by confidentiality, where genuinely necessary.
- Legal compulsion. Where we are required to disclose by valid legal process, or where disclosure is necessary to protect the rights, property, or safety of Stonerow PM, our customers, or the public. We will tell the affected customer unless we are legally prohibited from doing so.
- A business transfer. If Stonerow PM is acquired or merged, records may transfer to the successor, which remains bound by this policy until it gives notice of a replacement.
We do not share information with data brokers, advertising networks, or rent-benchmarking consortia.
9. How long we keep it
Contact-form submissions are kept in our support mailbox for as long as the enquiry and any resulting relationship are live, then deleted on request.
Customer and resident records are kept for as long as the account is active. Legal records — the rent ledger, deposits, leases, and the audit trail — are append-only by design: they are never silently edited or hard-deleted while the account exists, and corrections post as visible reversing entries. That is deliberate. A ledger that can be quietly rewritten is worthless in housing court, and landlord-tenant statutes in Connecticut, Rhode Island, and Massachusetts assume the landlord can produce the history.
When an account is closed, we make a full export available, then delete or irreversibly anonymize the account's data within 90 days, except where we must retain specific records to comply with legal, tax, or accounting obligations, or to resolve a live dispute. Backups roll off on their own schedule and are deleted within 12 months of account closure.
10. Your rights and choices
Whichever state you live in, and whether or not a particular statute currently applies to us, we honour the following requests: to know what personal information we hold about you, to receive a copy of it in a portable format, to correct it if it is wrong, to delete it, and to appeal if we say no.
If you are a customer, most of this is self-service. Your account already contains export and reporting tools, and you can add, correct, or remove your own records directly. For anything else, use the contact form.
If you are a resident or applicant, the records are your landlord's, so start with them — they can correct or remove what they entered. If your landlord does not respond, contact us and we will identify the account, notify the landlord, and help route your request. We cannot unilaterally delete a landlord's lease or ledger records, because those are their legal records and deleting them could destroy evidence they are required to keep.
We do not discriminate against anyone for exercising a privacy right. There is no penalty, price change, or service reduction for asking.
11. How we protect information
Security controls that matter to your data, described accurately rather than aspirationally:
- Encrypted in transit. All traffic to the site and the application is TLS-encrypted through Cloudflare's edge, and the link from Cloudflare to our server is a private outbound tunnel.
- No public attack surface on the origin. The server that holds the database accepts no inbound connections from the public internet. It is reachable only through the tunnel, behind Cloudflare's DDoS and bot protections.
- Per-account isolation, fail-closed. Every query is scoped to one account automatically; a missing or invalid account context yields zero rows, never another customer's rows. Automated tests fail the build if any model is added without that protection.
- Role-based access. Customers assign staff to scoped roles, so a bookkeeper does not get maintenance photos and a leasing agent does not get the ledger.
- Strong password policy. Production passwords must be at least 12 characters with mixed case, numbers, and symbols, and are checked against known-breached password corpora.
- Private file storage. Uploads, inspection photos, and documents are stored off the web root and served only to an authorized user on the owning account, with the file type verified from the file's own contents rather than a spoofable header.
- Tamper-evident audit trail. The audit log is hash-chained per account, so a broken link in the chain is detectable.
- Append-only legal records, enforced in the application and again by database-level constraints and triggers, so even direct database access cannot quietly rewrite a posted ledger entry.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal information, we will notify you and the relevant state authorities as the law requires. We operate against the shortest deadline that applies to us — Rhode Island's 45 days from discovery — so that one process satisfies Connecticut, Rhode Island, and Massachusetts alike.
12. Responsibilities of landlord customers
If you are a customer, you decide what resident information to collect and you carry the corresponding legal duties. Practically, that means: collect only what you actually need; tell residents and applicants what you collect and why; give staff the narrowest role that lets them do their job; keep tenant portal invitations and public listing, application, statement, and signing links to the people who should have them (every one of those links is revocable, so rotate a link the moment it leaks); and comply with the screening, adverse-action, and record-keeping rules that apply to you, including the Fair Credit Reporting Act if you run tenant screening. Massachusetts customers should note that 201 CMR 17.00 requires them to maintain their own written information security program; using compliant software is a component of that, not a substitute for it.
13. Children
Stonerow PM is a business tool sold to landlords and property managers. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. Minors do appear in lease records as occupants when a landlord records a household; that information is the landlord's, entered under their responsibility, and we hold it only as their service provider. If you believe a child's information reached us in error, contact us and we will route it for deletion.
14. International visitors
Stonerow PM is built for landlords in the United States, with its deepest coverage in Connecticut, Rhode Island, and Massachusetts. Our servers are in the United States, and any information you send us is stored and processed there under United States law.
15. Changes to this policy
When this policy changes materially — a new category of data, a new sub-processor, a new purpose — we will update the effective date above and notify account holders by email before the change takes effect. Changes that only clarify wording take effect when posted. We will not apply a materially different use to information already collected without asking you first.
16. How to reach us
Email privacy@stonerowpm.com with privacy questions, access requests, correction requests, deletion requests, and appeals. The contact form works too — mention that the message concerns privacy so it is routed correctly. Either way a person reads it. We acknowledge privacy requests within 10 business days and aim to resolve them within 45 days, extending only where the law permits and telling you if we do.
Related: Terms of Service · What makes rental records court-ready · Our product commitments · Team roles and permissions