Privacy policy
Last updated 12 September 2026
Commonage is operated by Digital Tide LLC (“we”). This policy covers the Commonage service and this website. It describes what we collect, why we collect it, who it is shared with, and how long it is kept.
Commonage is software a community association uses to run itself. In most cases the association is our customer and decides what goes into the system; we process that information on its behalf. Where that is the arrangement, the association is the party to ask about its own records, and we support it in answering you.
This website
The pages on commonage.app are static files. They set no cookies, run no analytics, and load nothing from a third party. Visiting this site does not create a record about you beyond the ordinary server logs our hosting provider keeps.
What the service collects
Every table in Commonage carries a classification, and that classification determines how long the record is kept and how it is protected.
| Category | Examples | Retention |
|---|---|---|
| Public | Community name, published governing documents | Indefinite |
| Internal | Settings, workflow definitions, feature configuration | Indefinite |
| Confidential | Owner name, property address, unit, contact details | Life of the relationship plus 7 years |
| Restricted | Ledger entries, payment methods, ballots, resale certificates | 7 years, as records law requires |
| Credentials | API keys and private keys | Until rotated |
Credentials are never stored in our database. They live only in AWS Secrets Manager. Confidential and restricted records are encrypted at rest with a managed key, and access to restricted records is logged.
Information you give us directly
- Your identity. Name and email address, so the system knows who is signing in and what they are entitled to see.
- Your connection to a property. Address, unit and the role you hold in the association — owner, resident, board member.
- What you submit. Requests, architectural review applications, votes, messages and documents you upload.
- Payment details, when you pay dues or fees. Card numbers go to our payment processor and are not stored on our systems.
Information we generate
- An audit trail. Who changed what, and when. This is how a board answers a question about a decision months later, and we keep it deliberately.
- Authentication events. Sign-ins and sign-in attempts, to detect account misuse.
Resident information is never written to an application log, an error report, or a chat channel. That is a rule we enforce in the system, not a preference.
Ballots
Where a vote is conducted by secret ballot, the ballot is stored so that the result can be verified without the choice being attributable to the voter. Ballots are append-only: once cast, a ballot is not edited or deleted, including by us.
Who we share it with
We do not sell personal information and we do not share it for advertising. The service depends on the providers below, each of which is bound to use the information only to deliver its part of the service.
| Provider | What it does | What it receives |
|---|---|---|
| Amazon Web Services | Hosting, storage, encryption keys | All application data, held in the United States |
| Clerk | Sign-in and session management | Name, email address, authentication events |
| SendGrid (Twilio) | Delivers the email Clerk sends, as its subprocessor | Email address and the contents of authentication messages |
| “Sign in with Google”, if you choose it | Name, email address and Google account identifier. We request no access to Gmail, Drive, Calendar or contacts | |
| Stripe | Processes dues and fee payments | Payment details and any identity information payments law requires |
We also disclose information where the law requires it, where an association is entitled to its own records, and to a successor if the business is transferred. Any new provider that would receive information identifying a resident is reviewed before it is used, and this page is updated when the list changes.
Using data to improve the service
We may use de-identified, aggregated information — figures that do not identify any person, property or community — to operate and improve Commonage. Using information that does identify you for anything beyond delivering the service requires your consent first.
Your rights
Depending on where you live, you may have the right to ask for a copy of your information, to have it corrected, to have it deleted, or to object to how it is used. Write to us and we will help.
Two limits worth stating plainly. Where your association is the customer, requests about the association’s records may need to go to the association, and we will tell you if that is the case. And some records — ledger entries, ballots, statutory association records — we are required to keep for a period set by law, so they cannot be deleted on request.
Children
Commonage is not directed at children and we do not knowingly collect information from anyone under 13. If you believe a child has given us information, write to us and we will remove it.
Changes
When this policy changes, the date at the top changes with it. Where a change materially affects how we handle your information, we will say so through the service rather than rely on you noticing.
Contact
Digital Tide LLC — privacy@commonage.app