Property Managementby 8REC

Privacy Policy

Last updated: 2026-08-07.

Draft — pending legal review.

This page accurately describes what the software actually does — what data is collected, where it goes, and what controls exist — but the bracketed fields below (legal entity, jurisdiction, contact) are placeholders. Don't treat this as your finished privacy notice until those are filled in and a lawyer has signed off on it.

Who this is

PMM by 8rec is operated by [Legal entity name], [registered address], [jurisdiction]. For most of the data described here, the company running a property on this platform is the data controller and PMM is their processor — this page describes the platform; each company using it may have its own privacy notice for its own tenants and staff.

Contact for privacy questions or to exercise the rights below: [privacy@8rec.com].

What we collect

Depending on your role, we (or the company you deal with, through this platform) collect:

  • If you sign up to manage properties: your name, email, phone number, and country.
  • If you rent through a landlord using PMM: your full name, contact email and phone, address, date of birth, nationality, an identity document (passport, national ID, or driver's licence — type, number, and a photo), and your payment/lease history.
  • Everyone: messages sent through the app, and basic device preferences (theme, language) stored in your browser.
  • If you turn on notifications (in your browser, or in the Android app): a device token identifying that specific browser or phone, used only to deliver your own notifications to it — never anything about you personally.

Why we collect it

To run the service you asked for: managing a property listing, screening and running a tenancy, processing rent and deposits, and letting you and your landlord (or tenant) message each other. Identity documents are collected for tenancy screening and record-keeping a landlord is typically expected to keep — [state the specific legal basis relied on per jurisdiction: contract necessity, legitimate interest, or legal obligation].

Who else sees it

We use a small number of services to run the platform, each of which processes some data on our behalf:

  • Google Cloud / Firebase — hosts everything: sign-in, the database, file storage, and the server-side code. Data is processed in the United States (region us-central1).
  • Google, Yahoo, and Apple — if you choose to sign in with one of them, they share the profile details their sign-in flow discloses.
  • A transactional email provider — to deliver account and portal-access emails (invite links, sign-in links, payment notices).
  • Google Play Services / Firebase Cloud Messaging — if you use the Android app and turn on notifications, Google delivers them to your device on our behalf, the same way any Android app's notifications work.
  • geojs.io and OpenStreetMap/Nominatim — the public map on our front page uses these free services to guess your country from your IP address and to show/search locations. These requests go directly from your browser; we don't see or store your IP through them.

We do not sell personal data, and we do not run advertising or analytics trackers of any kind on this site.

How long we keep it

While your account or lease is active, and afterward for as long as the landlord you dealt with has a legitimate reason to keep it — typically financial and legal record-keeping. Ended-lease records (the tenancy, its payments, and its messages) are kept as a permanent archive once a lease ends; [state the intended retention period — e.g., 7 years — and the reason: local tax/limitation-period requirements]. You can ask for your own copy or ask that it be erased at any time (see below) — an active lease, or a record still needed for a legal obligation, may need to be resolved first.

Your rights

Depending on where you live, you may have the right to access, correct, export, or request erasure of your personal data, and to object to or restrict some kinds of processing. In the app today:

  • A tenant can download their own data or request account deletion from the portal (account menu → Settings → "Your data").
  • A staff/company user can request account deletion from the profile menu (top right), and a company owner can download or delete their whole company's data from Admin → Danger Zone.
  • For anything else — access, correction, or a request that doesn't fit the buttons above — contact us at the address at the top of this page.

Cookies and local storage

We use your browser's local storage for a handful of preferences and session state — which theme and language you picked, which tab you last had open, and (for tenants) the identity your portal sign-in resolved to. None of it is used for tracking or advertising, and nothing here comes from a third party. We don't use cookies for anything beyond what your browser or Firebase's own sign-in flow sets automatically.

Children

This service is intended for adults entering into rental agreements and is not directed at children.

Changes to this policy

If this policy changes materially, we'll update the date at the top of this page.