Privacy Policy
Last updated:
1. Who We Are
Brynlock is self-storage management software for independent facility operators. This policy explains what data we collect, how we use it, and your rights.
Brynlock is the data controller for the account data described in Section 2 (“Account and operator data”), and acts as a service provider (processor) on behalf of operators for the tenant data operators enter into the Service. Brynlock operates in the United States and stores data in US regions. For controller-related requests, contact legal@brynlock.com.
2. Data We Collect
Account and operator data:
- Name, email, and phone number of facility operators
- Facility name, address, and billing information
- Payment information (processed and stored by Stripe — we do not store card numbers)
Tenant data (entered by operators):
- Tenant names, email addresses, and phone numbers
- Rental unit assignments and payment history
- Documents uploaded by the operator (lease agreements, etc.)
Usage data:
- Pages visited and features used (via PostHog analytics)
- Error reports (via Sentry)
- IP addresses and browser type for security logging
3. How We Use Data
- To provide and improve the Service
- To process subscription payments via Stripe
- To send transactional emails (receipts, notices) via Resend
- To diagnose and fix errors
- To analyze product usage and improve features
- To comply with legal obligations
4. Third-Party Services
We share data with these service providers only as necessary to operate:
- Supabase — database and authentication hosting
- Stripe — payment processing
- Resend — transactional email
- Vercel — application hosting
- PostHog — product analytics (anonymized)
- Sentry — error monitoring
We do not sell your data or your tenants' data to any third party.
5. Tenant Data
Operators are responsible for informing their tenants about how their data is collected and used through the online rental flow and tenant portal. Operators should maintain their own privacy disclosures as required by applicable law.
6. Data Retention
We retain your data while your account is active and for 30 days after termination. You may request earlier deletion by contacting us.
7. Security
Data is encrypted in transit (HTTPS) and at rest. Access is controlled via Supabase Row Level Security. We conduct regular security reviews.
8. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by emailing us. We will respond within 30 days.
California residents may have additional rights under CCPA. Contact us to exercise any CCPA rights.
9. Cookies, Analytics, and Your Choices
We use strictly necessary session cookies for sign-in — these are required for the Service to function. Product analytics (PostHog) runs by default and stores an identifier in your browser's local storage; it sets no advertising cookies and we do not use session recording. On your first visit, a banner lets you Accept or Decline analytics. Declining stops all analytics events from that browser, and we honor the Global Privacy Control browser signal as a Decline. To change your choice later, clear this site's data in your browser settings and the banner will reappear. We do not sell personal information or share it for cross-context behavioral advertising.
10. Data Breach Notification
If we become aware of a security breach affecting your personal data, we will notify affected operators by email without undue delay and within the timeframes required by applicable US state law, describing what we know about the scope of the breach and the steps we are taking in response.
11. Children's Privacy
The Service is intended for businesses and is not directed to children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.
12. Contact
Privacy questions or requests: privacy@brynlock.com or legal@brynlock.com