Privacy Policy
Last updated: 2026-08-20
This Privacy Policy describes how CaribCompass (“we”, “us”,“our”) collects, uses, and shares information when you use the CaribCompass property-management platform (the “Service”).
Our role: controller vs processor
CaribCompass has two roles depending on whose data is at issue:
- Controller for information about our direct customers (the landlord organisations that subscribe to the Service and the individual staff, admins, and owners who log in), for billing, account administration, and product analytics.
- Processor for the tenant, applicant, lease, and property information that a landlord organisation puts into the Service. In that case the landlord organisation is the controller and CaribCompass acts on their documented instructions. Tenants should direct data-subject requests about their tenancy records to their landlord first; we will assist the landlord in responding.
1. Information We Collect
Information you provide
- Account information — your name, email address, bcrypt-hashed password, optional phone number, the company you belong to, and your role.
- Property and tenancy records — properties, units, leases, tenants, applicants, bills, payments, expenses, maintenance requests, documents, and related records that you or your team enter into the Service.
- Subscription payment information — when your company pays for a plan, our payment processor (SKN Pay) collects card data on our behalf. CaribCompass stores only the transaction identifier, the plan and amount, and internal invoice metadata. Card numbers do not reach our servers.
- Tenant rent-payment information — for tenants who pay rent through the Service, SKN Pay similarly handles card data. We store the transaction identifier, the amount, and (for aggregator-mode payments) our fee split.
- Communications — messages, support requests, and other correspondence you send to us.
Information collected automatically
- Log data — IP address, browser and device type, pages visited, timestamps, and referring URLs. Used for security, diagnostics, and rate-limiting.
- Cookies and similar technologies. We use two categories of cookies, both first-party:
- Strictly necessary: session authentication, CSRF protection, and impersonation state. The Service does not function without these.
- Preferences: remembered UI state (which sidebar sections are open, the current company for multi-company users). Non-essential.
- Audit log — records of significant actions taken in the Service (creating, editing, voiding, deleting records; sign-ins; role/permission changes; plan changes; feature overrides). Used for security, accountability, and dispute resolution. Retention is configured per platform (default 365 days).
2. How We Use Information
- To operate, maintain, and provide the Service to you and your team.
- To authenticate users and secure accounts (including detecting suspicious sign-ins).
- To send transactional emails on your behalf — rent bills, receipts, portal invites, notification digests, password resets, subscription invoices, and platform announcements. We do not use your data for marketing without your consent.
- To process subscription and rent payments through SKN Pay.
- To respond to support requests and communicate service updates.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To comply with legal, tax, and regulatory obligations, including responding to valid legal process.
- To enforce our Terms of Service.
- To improve the Service using aggregate, non-identifying usage patterns.
3. Legal Basis for Processing (EEA/UK Users)
If you are in the European Economic Area or the United Kingdom, we process personal data on the following legal bases:
- Performance of contract (Article 6(1)(b) GDPR) — to deliver the Service you subscribed to.
- Legitimate interests (Article 6(1)(f)) — to operate, secure, and improve the Service; to prevent abuse; to protect our rights.
- Consent (Article 6(1)(a)) — where we ask you for it, e.g., non-essential cookies.
- Legal obligation (Article 6(1)(c)) — where we are required by law to retain or disclose data.
4. Sharing of Information
We share personal information only in the following circumstances:
- Within your workspace — with other authorised users of your company account, subject to their role and access scope.
- Sub-processors that help us operate the Service, under contractual data-protection obligations. Current sub-processors include:
- Resend — transactional email delivery.
- SKN Pay — payment processing.
- Our hosting infrastructure provider and the S3-compatible object storage provider used for document uploads.
- Legal obligations — when required by law, subpoena, or valid governmental request, or to protect our rights, your safety, or the safety of others. We do our best to notify you before we comply, unless we are prohibited from doing so.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections and to the successor being bound by equivalent privacy commitments.
We do not sell your personal information, and we do not share it with third parties for their own marketing purposes.
5. Data Retention
We retain personal data for as long as your account is active and for a reasonable period afterward to meet legal, tax, and accounting obligations (typically seven years for financial records in most jurisdictions we operate in). Audit-log entries are retained per the retention window configured in your platform settings (default 365 days). You may request deletion of your account and associated personal data at any time (subject to lawful retention obligations). Backups age out automatically on our rolling backup schedule.
6. Your Rights
Depending on where you live, you may have the following rights regarding your personal information:
- Access and receive a copy of the information we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion of your personal information.
- Object to or restrict certain processing activities.
- Withdraw consent where processing is based on consent.
- Data portability — receive your data in a structured, commonly-used format.
- Lodge a complaint with your local data-protection authority.
If you are a tenant, applicant, or owner and want to exercise rights over data held by a landlord organisation that uses CaribCompass, contact your landlord first — they control that data. If they are unable to respond and you believe we are the appropriate contact, email us at privacy@caribcompass.com and we will help route the request.
Otherwise, to exercise these rights, email us at privacy@caribcompass.com. We will respond within thirty (30) days, or sooner where required by law.
7. Security
We implement industry-standard technical and organisational measures to protect personal information, including:
- TLS encryption in transit for all connections to the Service.
- bcrypt password hashing.
- AES-256-GCM encryption at rest for sensitive per-company credentials (e.g., merchant payment keys).
- CSRF protection on state-changing endpoints, plus same-origin checks on admin actions.
- HMAC-SHA256 signature verification on inbound payment webhooks with a 5-minute replay window.
- Two-factor authentication (available for staff accounts).
- Least-privilege access controls and audit-logged administrative actions.
- Isolated production credentials, encrypted backups, and rotation of long-lived secrets.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the appropriate authorities without undue delay and, where feasible, within seventy- two (72) hours of becoming aware, in accordance with applicable law. Notifications go to your account's Company Admin email and, for material breaches affecting individual users, to the affected person's registered email.
To report a suspected vulnerability, please email security@caribcompass.com.
8. International Transfers
Depending on where our servers and sub-processors are located, your information may be transferred to and processed in countries other than your own. When we transfer personal data outside your region, we rely on lawful transfer mechanisms such as the European Commission's standard contractual clauses, the UK international data transfer agreement, or an adequacy determination where one applies.
9. Children
The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us and we will delete it.
10. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above and, for material changes, provide at least thirty (30) days' notice through the Service or by email to Company Admins. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
11. Contact
Questions about this Privacy Policy or our data practices? Email us at privacy@caribcompass.com. Security issues to security@caribcompass.com.