Legal
Privacy Policy
Effective July 10, 2026
This Privacy Policy explains what personal information Unitly collects, why we collect it, who we share it with, where it is stored, how long we keep it, and the choices and rights you have. Unitly is a property-management service for small and independent landlords and the people connected to their properties: co-managers, tenants, and maintenance helpers. We are a small Canadian team, we aim to handle personal information in line with PIPEDA (Canada's Personal Information Protection and Electronic Documents Act), we do not sell personal information, and we do not use it for advertising. If anything here is unclear, ask us; we would rather explain than hide behind boilerplate.
Unitly is a family-run service operated by Frank Aube, doing business as Unitly. That operator is the organization accountable for personal information under this policy, and all references to "Unitly", "we", "us", and "our" mean that operator.
1. Who we are and what this policy covers
In short
This policy covers the Unitly website, web app, mobile app, and API, operated by a small Canadian team.
This policy covers personal information handled through the Unitly website at unitly.cloud, the Unitly web application, the Unitly mobile applications, and the Unitly API at api.unitly.cloud (together, "the Service").
It does not cover third-party services you use alongside Unitly under their own terms, such as your Stripe account, your Google account, or the app store you download our mobile app from. Those services have their own privacy policies.
2. Our two roles: your account data, and the data landlords store
In short
For your own account information we are responsible directly to you; for tenancy records a landlord stores, the landlord is responsible and we process that data on the landlord's behalf.
Unitly handles personal information in two distinct capacities, and your rights work differently in each:
- Unitly as the responsible organization (controller). For the information we collect about our own users, such as your account profile, sign-in credentials, subscription billing, support conversations, and analytics you have consented to, we decide how and why it is used, and we are accountable to you for it under PIPEDA.
- Unitly as a service provider (processor) for landlords. Landlords use the Service to keep records about their tenancies: leases, rent ledgers, maintenance requests, inspection reports, messages, and similar records that contain tenants' and other individuals' personal information. For that information, the landlord decides what to collect and store, and Unitly processes it on the landlord's behalf, only to provide the Service. The landlord is responsible for having the legal authority to collect it and for responding to requests about it.
If you are a tenant: your landlord invited you and controls the tenancy records about you. For requests about the content of those records, for example to correct something in a lease or an inspection report, contact your landlord first; we will support the landlord in honouring the request. For your own Unitly account profile, contact us directly (see section 15).
If you are a landlord: you are responsible under the privacy laws that apply to you for the tenant information you collect and store in Unitly. Practically, that means collecting only what you need for the tenancy, being honest with your tenants about how you keep records, and responding to their access and correction requests.
3. Information we collect
In short
We collect what you give us (account details, tenancy records, documents, photos, signatures, messages), payment references but never raw card or bank numbers, and limited technical data needed to run the Service.
Account information (all roles). Name, email address, password (stored only as a cryptographic hash), phone number if you add or verify one, profile settings, role and property assignments, and, if you sign in with Google, the basic profile information Google provides (name, email, and identifier). We never see your Google password.
Landlord and co-manager records. Property and unit details, tenancy records, rent schedules and payment history, lease documents, listings you choose to publish, appointment scheduling details, accounting entries, and uploaded receipts.
Tenant information. Contact details entered by the landlord or by you, tenancy details (unit, lease terms, rent amounts), rent payment history, maintenance requests you submit, messages you send, and documents connected to your tenancy.
Uploaded files and rich content. Documents (such as leases), photos (for example maintenance and inspection photos and listing photos), electronic signatures applied to leases and inspection reports, and message attachments.
Payment information. Subscription and rent payments are processed by Stripe. Stripe collects card and bank details directly; raw card numbers and bank credentials never touch Unitly servers. We store payment references and status, such as amounts, dates, the last state of a payment, and Stripe identifiers, so your records stay accurate.
Technical and usage information. IP address, authentication session data, device and browser type, and server logs generated as you use the Service. If you opt in to analytics (section 5), Google Analytics collects usage events on our behalf. If you use the mobile app and enable notifications, we store a push notification token for your device.
Support and correspondence. Messages you send us by email or through the Service.
We do not knowingly collect government identifiers, credit reports, or background-check data, and the Service has no fields designed for them. Landlords should not upload information they do not need for the tenancy.
4. How we use information
In short
We use personal information to run the Service you signed up for, keep it secure, support you, and meet legal obligations, and for nothing resembling ads or data sales.
We use personal information to:
- create and manage accounts, authenticate sign-ins, and scope access by property and role;
- provide the features you use: leases and e-signing, rent tracking and collection, maintenance, messaging, inspections, listings, appointments, and accounting;
- send transactional notifications you would expect, such as invitations, rent reminders, maintenance updates, and security notices, by email, push notification, or SMS depending on your settings;
- process subscription billing and, for landlords who enable it, rent collection through Stripe;
- provide support and respond to your requests;
- secure the Service, prevent abuse and fraud, and debug problems;
- understand aggregate product usage, only where you have opted in to analytics; and
- comply with legal obligations and enforce our Terms of Service.
We do not sell or rent personal information. We do not use it for third-party advertising. We do not use your content or your tenants' personal information to train generative artificial intelligence models.
5. Consent and our legal bases
In short
We rely on your consent, which is usually implied by your choice to use a feature, and we ask explicitly for anything that is not obvious, like analytics cookies.
PIPEDA requires that we collect, use, and disclose personal information only with your knowledge and consent, except in limited circumstances the law allows. In practice:
- Consent through use. When you sign up and use the Service, you consent to the collection and use of the information reasonably needed to deliver the features you are using. Providing an email address to receive an invitation, uploading a lease to store it, or entering payment details with Stripe to pay rent are all examples where the purpose is evident from the action.
- Express consent. We ask for explicit opt-in consent for anything that is not necessary to run the Service, most notably analytics cookies (section 6). Declining never blocks you from using the Service.
- Withdrawal. You can withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent for essential processing may mean we can no longer provide the Service, in which case you can export your data and close your account.
- Landlord-stored records. Where a landlord stores information about tenants and others, the landlord is responsible for the consent or legal authority to do so, as described in section 2.
8. Where your data is stored
In short
Unitly is Canadian, but data is currently hosted in United States cloud regions, which means it can be subject to US law; we tell you this plainly because PIPEDA requires openness about it.
Unitly is operated from Canada, and the product is built for Canadian landlords first. However, the Service is currently hosted in established United States cloud regions, through the providers listed in section 7. That means your personal information, including tenancy records and uploaded documents, is stored and processed in the United States and may be accessible to United States authorities under United States law.
PIPEDA permits transfers of personal information to service providers outside Canada, provided the transferring organization uses contractual and other means to ensure a comparable level of protection, and is transparent about the practice. Our providers are established companies that commit to industry-standard security and confidentiality obligations, and we limit each provider to the specific function described in section 7. By using the Service, you acknowledge this cross-border processing.
We are evaluating Canadian-region hosting as we grow. If data residency changes, we will update this policy and the security page.
9. How long we keep information
In short
We keep your data while your account is active; when you delete your account we remove it from the live service and residual copies age out of backups, and you can export a copy anytime.
We retain personal information for as long as your account is active, so your leases, payment history, and records stay available to you. Rent ledgers and tenancy records often need to be kept for years for tax and legal reasons, and the Service is designed to hold them for you for as long as you keep your account.
When you delete your account, we remove your personal information from the live service. Residual copies persist for a limited period in encrypted database backups and then age out as backups are rotated. We may retain limited records where we have a legal obligation to do so, for example billing and tax records, or where reasonably necessary to resolve disputes or enforce our terms, and we retain them only as long as needed for those purposes.
Because tenancy records belong to the landlord's account, a tenant leaving a tenancy does not by itself delete the landlord's records of that tenancy; retention of those records is the landlord's responsibility under applicable law.
You can export your data at any time from account settings, and we encourage you to keep your own copy.
10. Your rights and choices
In short
You can access, correct, and export your information, withdraw consent, delete your account, and complain to the Privacy Commissioner of Canada if we get it wrong.
Under PIPEDA you have the right to:
- Access. Ask us whether we hold personal information about you, and get access to it. Much of your information is directly visible in your account, and the export feature gives you a machine-readable copy at any time.
- Correction. Ask us to correct inaccurate or incomplete personal information. You can edit your own profile in settings; for tenancy records controlled by your landlord, ask your landlord, as described in section 2.
- Withdraw consent. Withdraw consent to collection, use, or disclosure at any time, subject to legal or contractual restrictions and reasonable notice (section 5). For analytics, you can withdraw consent instantly from the cookie settings.
- Deletion. Request deletion of your account and personal information from account settings, with the retention limits described in section 9.
- Complaint. Challenge our compliance with PIPEDA by contacting us (section 15). If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada (OPC), at www.priv.gc.ca or 1-800-282-1376.
We will respond to access requests within the time PIPEDA allows, normally 30 days, at no cost or at most a minimal cost that we will tell you about in advance. We may need to verify your identity before acting on a request, and in limited cases the law requires or permits us to refuse a request, in which case we will explain why in writing.
If you are outside Canada, you may have similar rights under your local law, and we will honour them to the extent they apply.
11. How we protect information
In short
Encryption in transit and at rest, property-scoped access controls, payments isolated with Stripe, and honest limits: no system is perfectly secure.
We protect personal information with technical and organizational measures appropriate to a service of our size, including:
- Encryption in transit. All traffic between your browser or mobile app and the Service uses HTTPS and TLS.
- Encryption at rest. The database is encrypted at rest by our database provider.
- Property-scoped access. Application access is scoped by role and property, so only the people you invite to a property can see that property's data, and each role sees only what it needs.
- Private document storage. Lease documents, accounting receipts, and message attachments are stored in a private, authenticated store and served only through short-lived expiring links issued after an access check. Photos you choose to publish, such as listing photos, are stored publicly.
- Payment isolation. Raw card and bank details are handled entirely by Stripe and never touch Unitly servers.
- Operational safeguards. Automated database backups with point-in-time recovery, hashed passwords, revocable sessions, and security headers on the web app.
No method of transmission or storage is completely secure, and we do not claim otherwise. We do not currently hold formal security certifications such as SOC 2 or ISO 27001, and we would rather say so plainly than imply otherwise. You can read more about our practices, our subprocessors, and our honest limits on the security page.
12. If something goes wrong: breach notification
In short
If a breach creates a real risk of significant harm to you, we will notify you and the Privacy Commissioner as PIPEDA requires, and we keep records of security incidents.
If we discover a breach of security safeguards involving personal information, we will investigate, contain it, and assess the risk of harm. Where the breach creates a real risk of significant harm to an individual, we will notify the affected individuals and report to the Office of the Privacy Commissioner of Canada as soon as feasible, as PIPEDA requires, and we will notify any other organization or authority that can reduce the risk of harm. We maintain records of breaches of security safeguards as required by PIPEDA.
Where the affected information is tenancy data stored by a landlord, we will notify the landlord promptly so the landlord can meet their own obligations to the individuals concerned.
13. Children
In short
Unitly is for adults; we do not knowingly collect children's information.
The Service is intended for landlords, co-managers, adult tenants, and maintenance helpers. It is not directed to children, and we do not knowingly collect personal information from anyone under the age of majority in their province or territory. Occupant information a landlord records about a household is the landlord's responsibility as described in section 2. If you believe a child has created an account, contact us and we will delete it.
14. Changes to this policy
In short
We will update this policy as the product evolves and give you clear notice of material changes before they take effect.
We may update this Privacy Policy from time to time. The effective date at the top tells you when it was last changed. For material changes, such as new categories of data, new purposes, or new subprocessors handling sensitive data, we will give you reasonable advance notice by email or a prominent notice in the Service before the change takes effect, and where the change involves a new purpose for previously collected information, we will seek fresh consent where PIPEDA requires it.
15. Contact and privacy officer
In short
Our designated privacy contact answers questions, access requests, and complaints, and we aim to respond quickly.
PIPEDA's accountability principle requires us to designate a person responsible for our privacy compliance. Questions, requests, and complaints about personal information should be directed to:
- Privacy contact: Privacy Officer, hello@unitly.cloud (put "privacy" in the subject line and your request reaches the accountable person directly)
- General support: support@unitly.cloud or hello@unitly.cloud
If you are a tenant asking about records your landlord keeps, start with your landlord (section 2); we will help the landlord respond. If you are not satisfied with our response to a privacy concern, you can contact the Office of the Privacy Commissioner of Canada (section 10).