Privacy Policy

This policy covers companies that subscribe to VNYPM Compliance and the people those companies invite. It also covers the iOS and Android apps (bundle id com.vnypm.compliance).

Who operates the service

Venture NY Property Management LLC (“VNYPM”), 43-10 11th Street, Long Island City, NY 11101, operates the tracker at vnypmcompliance.com. VNYPM is the platform owner. Each subscribing company is a separate organization inside the system.

What we store

For a company: its name, logo, billing contact, Stripe customer id, plan, and the buildings it chooses to track. For a person: name, email, role, and which buildings they are allowed to open. For the work itself: notes, assignments, file uploads, report files, and alert preferences. Passwords are stored by the login provider, not in the tracker tables.

City open data (HPD, DOB, DOF, and the rest) is fetched from New York City and may be stored once per building so it is not downloaded again for every company. That cache is city data. It is not your notes.

If someone installs the phone app and allows notifications, we also store a push token from Apple or Google, the platform (iOS or Android), and a random device id created on that phone. The token is stored with that person’s account and with the organization the account belongs to, so the morning alert job can reach that phone and only that company’s buildings. Signing out deletes the token.

Face ID and fingerprint

The phone app can ask the operating system to unlock a session the person chose to keep with “Keep me signed in”. Face ID, Touch ID, and fingerprint checks run on the device through Apple LocalAuthentication and Android BiometricPrompt. The app receives only success or cancel. It does not receive, store, or transmit a face image, a fingerprint, or any biometric template.

A report PDF that is shared from the phone is written to the app’s cache for the system share sheet. That share does not upload the file anywhere else.

Ownership and confidentiality

Your company owns the data it enters: notes, assignments, overrides, reports, and the choice of which buildings to follow. VNYPM keeps that data confidential, does not sell it, and does not resell it to another property manager or to a data broker. Another subscribing company cannot read it. VNYPM staff users cannot read it. Only the platform owner can open a company for support, and that opening is logged.

Billing

Card numbers are entered on Stripe’s pages. VNYPM stores the Stripe customer and subscription ids and the billing status, not the card number. Invoices are available in the Stripe customer portal.

How long it stays

Data stays while the subscription is active so the tracker and the reports keep working. If a company is closed, VNYPM deletes or returns that company’s private rows on request, except records we must keep for tax, security, or a legal claim. City open data is not deleted just because one company leaves, because it is not that company’s data. Device tokens are deleted when the person signs out, when the account is removed, or when Apple or Google reports that the token is no longer valid.

Who we use to run it

The application is hosted on Vercel. Accounts and the database are on Supabase. Email, when enabled, goes through Resend. Payments go through Stripe. Phone notifications go through Apple Push Notification service and Google Firebase Cloud Messaging. Those two see the device token and the notification text, and only so the alert can be delivered. Each of those processors handles data only to provide the service. We do not authorize them to use subscriber data for their own marketing.

Questions: info@vnypm.com.