Skip to content
atriolo

Legal

Privacy Policy

Last updated: May 2, 2026

atriolo (“atriolo,” “we,” “us,” or “our”) operates the atriolo property management platform, including our mobile applications, related websites, and related services (collectively, the “Service”). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Service.

1. Scope and Notice at Collection

This Privacy Policy applies to personal information we collect online and offline in connection with the Service, including when you create an account, manage properties, communicate through the Service, upload files, request support, or otherwise interact with us.

At or before the time of collection, we may provide additional short-form notices describing the categories of personal information collected and the purposes for which that information is used.

2. Information We Collect

2.1 Account Information

When you create or administer an account, we collect information such as your name, email address, phone number, avatar image, account role, and MFA enrollment status if multi-factor authentication is enabled.

2.2 Property Information

We collect property-related information you submit or manage through the Service, such as street addresses, unit details, room configurations, property characteristics, photographs, and property coordinates.

2.3 Contractor and Vendor Information

If you use contractor-related features, we may collect company names, license information, specialties, tax identifiers, insurance details, service areas, and related profile or credential information.

2.4 Financial and Operational Records

We collect information related to quotes, invoices, expenses, bids, billing profiles, inspection records, work orders, approvals, and related property-management records created within the Service. We do not process card payments directly through the Service and do not store full payment card numbers.

2.5 Communications and Workflow Data

We collect messages, notifications, comments, approvals, status changes, and other communications sent through the Service so that messaging, workflow, and activity history features can function.

2.6 Documents, Photos, Signatures, and Media

We collect and store photos, uploaded files, inspection records, signed documents, digital signatures, and related metadata that you or your authorized users create or upload.

2.7 Location and Mapping Data

We collect property coordinates, service-area boundaries, and map search queries entered through the Service. We do not continuously track your device location in the background.

2.8 Device and Technical Information

We collect device and application information needed to operate the Service, such as push notification tokens, device type, operating system details, app version, log data, and crash diagnostics.

2.9 Usage Data

We collect activity logs, QR code scan history, document access history, feature usage data, and other event-level telemetry used to provide, secure, support, and improve the Service.

2.10 Information We Collect From Others

We may receive information from administrators who invite you to the Service, from users who assign you to a property or project, and from service providers that support authentication, notifications, hosting, diagnostics, and storage.

2.11 Device Permissions

The atriolo mobile application requests access to specific device features so the Service can function. Each permission is requested only when needed, and you can grant or deny each one through your device’s system settings.

  • Camera. Used to capture photos of properties, rooms, appliances, maintenance issues, receipts, and documents you choose to record within the Service. atriolo does not access the camera in the background or without your action.
  • Photo Library. Used to upload existing photos and documents from your device into the Service. atriolo accesses only the photos you select and does not scan, index, or upload your full photo library.
  • Push Notifications.Used to deliver alerts about maintenance updates, messages, lease activity, approvals, and other workflow events. You may disable push notifications at any time in your device’s system settings.
  • Local Storage.Used to cache application data, signed-in session information, and offline content so the Service remains usable when your device is offline. Sensitive credentials are stored using your device’s secure keychain or equivalent encrypted storage.

atriolo does not request access to your contacts, calendar, microphone, health data, motion data, or precise background location.

3. How We Use Personal Information

  • To provide, operate, maintain, and secure the Service.
  • To authenticate users and manage accounts, roles, and permissions.
  • To send transactional messages, approvals, alerts, and push notifications.
  • To facilitate communications among property owners, tenants, contractors, managers, and other authorized users.
  • To generate records, reports, invoices, inspection documentation, and operational workflows.
  • To personalize and improve the Service and develop new features.
  • To diagnose outages, detect bugs, monitor errors, and prevent misuse, fraud, and security incidents.
  • To comply with legal obligations, enforce our agreements, and protect rights, safety, and property.

4. How We Disclose Personal Information

  • Service providers and contractors that host, support, secure, and operate the Service on our behalf.
  • Other users you authorize or your organization authorizes, based on account roles and permissions within the Service.
  • Professional advisers, such as legal, compliance, or audit advisers, where reasonably necessary.
  • Governmental or law-enforcement authorities, where required by law or valid legal process.
  • Successors in a corporate transaction, such as a merger, financing, acquisition, restructuring, or sale of assets, subject to appropriate confidentiality measures.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

5. Service Providers We Use

We rely on a limited set of third-party providers to operate the Service. These providers process personal information only on our behalf and under contractual restrictions appropriate to their role.

ProviderPurposeCategories of data involved
SupabaseApplication hosting, authentication, database services, file storage, and infrastructure supportAccount information, property records, documents, communications, operational records, uploaded media, and related metadata
ExpoMobile push notification deliveryDevice push tokens, notification metadata, and message content necessary to deliver notifications
SentryError monitoring, diagnostics, and application reliabilityTechnical diagnostics, device and app details, error traces, and related troubleshooting data; we configure this service not to intentionally send unnecessary personal information
ResendTransactional email delivery, including account, notification, and workflow emailsRecipient email addresses, sender metadata, and message content necessary to deliver transactional emails

6. Cookies, Similar Technologies, and Browser Signals

Our related websites may use cookies, local storage, SDKs, and similar technologies to support authentication, security, website functionality, and performance analytics. Our mobile applications may use SDKs or local storage for similar operational purposes.

Some browsers offer a “Do Not Track” setting. Because there is no uniform industry standard for Do Not Track signals, our websites do not respond to browser-based Do Not Track signals in a uniform way. However, where required by applicable law, we recognize and process valid Global Privacy Control (“GPC”) signals as a request to opt out of any activity that would constitute a sale or sharing of personal information under California law. Because we do not sell or share personal information for cross-context behavioral advertising, we generally treat such signals consistently with our existing practices.

We do not permit third parties to use Service-collected personal information for cross-context behavioral advertising on our behalf.

6.1 Apple App Tracking Transparency

atriolo does not engage in “tracking” as defined by Apple’s App Tracking Transparency (ATT) framework. We do not link personal information collected through the atriolo application with data collected by other companies’ apps or websites for advertising or advertising-measurement purposes, and we do not share data with data brokers. Because atriolo does not track you across other apps and websites, the atriolo application does not present an ATT permission prompt.

7. Data Storage and Security

We use administrative, technical, and physical safeguards designed to protect personal information appropriate to the nature of the information and the risks involved. These measures include encryption in transit, encryption at rest where supported, role-based access controls, row-level security rules, private storage configurations, short-lived signed URLs for file access where appropriate, and monitoring designed to detect unauthorized access or misuse.

No system is completely secure. You are responsible for maintaining the confidentiality of your credentials and using reasonable security practices when accessing the Service.

8. Data Retention and Account Deletion

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, maintain business and legal records, resolve disputes, enforce our agreements, and comply with legal obligations.

  • Account and profile information is generally retained while your account remains active and for a reasonable period afterward for security, compliance, and recordkeeping purposes.
  • Property, project, communications, and operational records may be retained for the duration of the associated account relationship and thereafter as needed for documentation, legal compliance, and dispute resolution.
  • Diagnostics and technical logs are generally retained for shorter periods unless needed for security investigations, fraud prevention, or legal compliance.

8.1 Deleting Your Account

You may delete your atriolo account at any time from within the mobile application by going to Settings → Account → Delete Account. Deletion permanently removes your profile, account-level identifiers, and personal information that is not subject to a legal retention obligation. Records that you have shared with co-owners, tenants, contractors, or property managers (such as property records, leases, or maintenance history) may be retained by those other authorized users where they have an independent right to retain them.

If you are unable to access the in-app deletion option, you may also email hello@atriolo.com and we will process your deletion request within a commercially reasonable period, generally within thirty (30) days after verification, unless a longer period is required or permitted by law.

9. Your Privacy Rights

9.1 Rights Available to All Users

  • Confirm whether we process your personal information.
  • Access personal information we hold about you.
  • Correct inaccurate personal information.
  • Delete personal information, subject to legal and operational exceptions.
  • Receive a portable copy of certain personal information.

9.2 California Privacy Rights

If you are a California resident, you may have rights under California law, including the right to know, access, correct, and delete personal information, and the right to receive information about our collection, use, disclosure, and retention of personal information, subject to applicable exceptions. You also have the right to be free from unlawful discrimination for exercising your privacy rights.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not knowingly use or disclose sensitive personal information for purposes that would require us to offer a right to limit under California law.

To exercise privacy rights, email us at hello@atriolo.com. We may need to verify your identity and authority before processing your request. You may also designate an authorized agent to make requests on your behalf, subject to verification requirements.

9.3 California Categories of Personal Information

In the preceding 12 months, we have collected the following categories of personal information, depending on how the Service is used:

  • Identifiers and contact information.
  • Customer account records and profile details.
  • Commercial or transactional information relating to service activity.
  • Internet or other electronic network activity information.
  • Geolocation information provided through property coordinates or service-area mapping.
  • Audio, electronic, visual, or similar information, such as photos, files, and uploaded documents.
  • Professional or employment-related information, such as contractor profile information.
  • Sensitive personal information in limited contexts, such as account credentials, tax identifiers provided for contractor workflows, and precise geolocation when entered in connection with property records.

We collect these categories from you, from other authorized users or administrators, from your device or browser, and from service providers that support the Service. We use and disclose these categories for the purposes described in Sections 3 through 5 of this Policy.

9.4 EEA and UK Users

If you are located in the European Economic Area or the United Kingdom, you may have additional rights under applicable data protection law, including rights relating to access, rectification, erasure, portability, objection, restriction of processing, and complaint to a supervisory authority. Where applicable, our legal bases for processing include performance of a contract, compliance with legal obligations, legitimate interests, and your consent where required.

10. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information directly from children under 13. If you believe a child under 13 has provided personal information to us, contact us at hello@atriolo.com so we can review and delete it where appropriate.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the revised Policy in the Service, update the “Last updated” date above, and may provide additional notice where appropriate. Changes become effective on the date stated in the revised Policy.

12. Contact Us

If you have questions about this Privacy Policy or want to exercise privacy rights, contact us at hello@atriolo.com.