Skip to main content
Back to home

Legal

Privacy Policy

Your trust is the whole product. Here is exactly what we collect, why, where it lives, and the control you keep over it.

Last updated September 5, 2026

Who we are

Soofair Property is property-management software at soofair.com, built for landlords, tenants, and brokers, and in a free beta that has not yet opened to the public. It is operated by Soofair Technologies Inc. (SEC Registration No. 2026070259105-04), Pasay City, Metro Manila, Philippines, which is the personal information controller for the data described here. Our data protection contact is hello@soofair.com. This policy explains what information we collect, why, and the choices you have. It is written to align with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173).

Soofair is for adults. We do not knowingly collect personal data from anyone under 18; if you believe we have, email hello@soofair.com and we will remove it.

Information we collect

Account information: your name, email address, mobile number and the country you sign up in — the number is there so the people you rent with can reach you, and the country decides which market your account belongs to. Your password is stored only as a salted hash using an industry-standard algorithm (bcrypt-style): it travels over an encrypted connection, is processed only transiently to create or check that hash, is never stored in plaintext, and cannot be recovered from the hash.

Property and tenancy records you enter: properties, units, tenants, leases, and payment records, along with any proof-of-payment images and documents you upload.

Much of that is information about other people — your tenants, unit owners, their emergency contacts and prospective renters — and, where you choose to upload them, images of identity documents. You are responsible for having the right to record it and for telling those people that you keep it in Soofair; we hold it on your behalf and use it only to run your account.

Repair records: what needs fixing and where, the priority, the schedule, the vendor's name and phone number, any cost the landlord records, notes the landlord writes, and photographs of the problem and of the finished work. Landlords and tenants use these to arrange repairs and to keep a record of what was done. A repair is readable by the business that owns the property and by the one tenant, if any, whose account is linked to that repair; it is not shared with other tenants of the same property. Repair photographs may show the inside of a home, so upload only what the repair needs.

Inquiry and viewing messages exchanged between landlords, tenants, and brokers through the platform.

Basic server logs, such as request timestamps and IP addresses, kept for security and troubleshooting.

Abuse-prevention counters. To stop someone hammering our public forms — signing in, signing up, resetting a password, asking to join the beta, or sending an enquiry — we count recent attempts. The counter is filed under a keyed one-way hash of the email address or IP address involved — not the address itself, and keyed with a server-held secret, so the stored value cannot be tested against guessed addresses — so these records hold no readable identifier, and we cannot work backwards from one to a person. This applies even when the attempt failed and no account exists. Each counter is deleted automatically about two days after it stops being used.

Beta requests and listing inquiries

If you ask to join the beta on our website, we collect the email address you enter, whether you told us you are a landlord or a broker, and the country section you asked from. If you give a Gmail address we store it in the form Gmail delivers to — without dots or a plus-tag — because Gmail treats every spelling of it as one inbox; any other address is stored as you typed it, in lower case. We also record when you asked, when we last updated the record, how many times that address has asked, and — once an invitation has been sent — when we sent it, which is what stops us mailing the same address again too soon. We use them for one purpose: to email you an invitation link and, if you reply, to answer you.

The invitation email is delivered by Resend, our email provider. We do not add you to a marketing list, we do not sell or share the address, and we send no promotional email to it.

The invitation link expires after 72 hours and can only be used once. We store it only as a one-way hash, so the link in your email cannot be reconstructed from our records.

The request record is deleted automatically once its invitation has been expired for 30 days — that applies whether the invitation was used, replaced, cancelled, or simply never opened. A daily job does this. If we withdraw an invitation, the note our staff keep about withdrawing it holds your email address, and it is deleted along with your request by the same job. If a member of staff deletes a request by hand — for example because you asked us to, or because we judged it to be automated rather than a genuine request — the request goes at once. The note recording that deletion holds your email address, what you asked for and the reason given, and the same daily job deletes it 30 days later.

A request made before the beta opens works differently, because no invitation exists yet: we keep it — that is the point of asking early — until the beta opens and your invitation is sent, after which the 30-day rule above applies, or until you ask us to remove it at hello@soofair.com, which a member of staff does by hand.

To have a request removed sooner, email hello@soofair.com from the address you used and we will delete it within 30 days. That address also reaches us for any security or privacy question.

If you send an inquiry about a public marketplace listing — directly, or through a broker acting for you — we collect the name you give and the email address and/or phone number you choose to share, along with your message and any viewing time. They go to the landlord or broker who manages that listing so they can reply and arrange the viewing, and they are used for nothing else. We keep an inquiry for as long as the landlord keeps the records of that listing; to have it removed sooner, email hello@soofair.com and we will delete it within 30 days.

Cookies and tracking

Soofair sets a single signed session token (JWT) in a secure, HTTP-only cookie to keep you logged in.

We also set one small functional cookie when you choose a country, or dismiss the country suggestion at the top of the page. It stores only that choice — a country code, or the word “dismissed” — so we do not ask you again. It contains nothing about you, and it is not used to track you across the web.

Today, with the Philippines as our only market, we do not look up your location at all. If we publish a second market, your browser will ask us once, after the page has loaded, which country your connection appears to be in. Our hosting provider works that out at the network edge and gives us a two-letter country code — never a city, and never your IP address for this purpose. We use the code to pick a sentence and then discard it: it is not stored, not logged, and not shared. No third-party location service is involved, and the suggestion is only ever a suggestion — we never send you somewhere based on it.

Those two are the only cookies we rely on — we use no advertising trackers and no third-party analytics cookies.

How we use your information

To provide the service: keeping your rental records, coordinating inquiries and viewings, and sending service emails such as account notices.

To secure your account and prevent misuse of the platform.

Soofair staff can open your account to answer a support request. Today that is the founder alone. They see your account details and the records inside it; they cannot see your password, which is stored in a form that cannot be turned back. Every change they make to your account through that tool is written down. Our Data & Security page explains what that record covers and what limits looking.

We do not sell your personal information, and we do not show third-party advertising.

Where your data is stored and processed

Soofair runs on a small set of infrastructure providers: Vercel (application hosting; server functions run in the Singapore region), Neon (our Postgres database, hosted in Singapore), Vercel Blob (storage for uploaded files and images), Cloudflare R2 (a private off-site backup of uploaded files, so they can be recovered after a failure), Resend (transactional email, processed in the United States), and GoDaddy (domain and email services).

When a landlord uses the address map or the address search inside the app, the map area being viewed goes to OpenFreeMap (map tiles) and the address text typed goes to Geoapify (address search). No account data is sent with either.

This means your data may be processed outside the Philippines — primarily in Singapore, with email delivery in the United States. We share with these providers only what is needed to run the service.

Our backup bucket is configured with an Asia-Pacific location preference. That is a best-effort preference, not a guarantee of where the data physically resides, and we do not present it as one.

Backup objects and their metadata are encrypted at rest by Cloudflare using AES-256 with Cloudflare-managed keys, and every transfer is protected by TLS. To be precise about what that does and does not mean: the encryption keys are managed by Cloudflare, not by us. We do not use client-side, end-to-end, or zero-knowledge encryption for backups, so we do not claim that only Soofair can read them.

Your rights

Under the Data Privacy Act you have the right to be informed about how your personal data is processed, to access and correct it, to object to certain processing, to have it erased or blocked, to data portability, and to be indemnified for damages caused by unlawful processing. You may also file a complaint with the National Privacy Commission (privacy.gov.ph).

If a personal data breach that affects you ever occurs, we will notify you and the National Privacy Commission as the law requires.

To be upfront: there is no self-serve “delete my account” button yet. To delete your account and data, email hello@soofair.com and we will complete the deletion from the live service within 30 days. You can request an export of your data at the same address.

A few narrow records survive a deletion. The first kind is an administrative audit entry. We keep one for each support action Soofair staff take on your account, including the entry noting which administrator deleted it and when. Each entry holds your email address, what was done and when. Where a member of staff had to give a reason — suspending an account, deleting one — it holds the reason they typed. If your email address was ever changed by our staff, the entry for that change holds the old address as well as the new one. The other two kinds are audit-trail entries in an organisation you worked in, which keep your name as the person who acted, and the record that a tenant invitation was accepted, which keeps the email address it was sent to.

Each exists so that deletions and past actions stay answerable — “who was that, and who removed them?” The administrative entries are visible only to Soofair’s administrators, the other two only to people who could already see them; each is used for nothing else, and each is kept for as long as the audit trail itself.

Deletion from the live service is not the same as deletion from backups. A backup copy of an uploaded file can persist until it reaches its scheduled expiration — see “Data retention” below for exactly how long and what we do with it in the meantime.

Data retention

We keep your data for as long as your account is active, so your records are there when you need them. When you request deletion, we remove your account and its data within 30 days as described above. Backup copies of uploaded files follow the separate schedule described next.

A beta request is deleted automatically 30 days after its invitation expires, as described in “Beta requests and listing inquiries” above. A request made before the beta opens is kept until its invitation is sent, or until we remove it — on your request, or because we judged it automated. A note that we deleted it, holding the address and the reason, is kept for 30 days and then deleted by the same daily job.

Abuse-prevention counters are deleted automatically about two days after their counting window closes — the same daily job does this. Nothing about a failed sign-in or an abandoned sign-up is kept beyond that.

Uploaded files are copied to a private Cloudflare R2 backup for disaster recovery. Backup manifests are configured to expire 90 days after creation, while file payloads are configured to expire 120 days after creation so supported manifests remain restorable. During the first 30 days after each backup object is created, a bucket-lock rule protects it from deletion or overwriting. Cloudflare states that lifecycle-expired objects are typically removed within 24 hours after expiration, although removal may take longer.

Deleting active data does not immediately remove it from existing backups. A residual backup copy may remain until its backup object reaches its 120-day expiration and Cloudflare completes lifecycle removal. During that period, it is restricted from routine use or further processing and may be accessed only for authorized recovery or security purposes.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected here with a new “Last updated” date. Questions or requests? Email hello@soofair.com.

Questions about this document?

Email us and we reply to the same address. Soofair Property is built for the Philippines.