Privacy Policy

Effective date: August 14, 2025

Controller: ApartPay ("we," "us")

Contact: support@apartpay.ge

1. Scope

This policy covers the ApartPay mobile app and the manager web dashboard. It supports payments, building access via digital keys and QR codes, and maintenance requests.

2. Data We Collect

Account data:

Name, email, phone, unit/role, building affiliation.

Payment data:

Invoices, amounts, status, timestamps; card and bank details handled by PCI-compliant processors.

Access data:

Digital key identifiers, access events (door/gate/elevator), QR scans, timestamps.

Maintenance data:

Tickets, text, photos.

Device and usage data:

App version, device model/OS, IP, diagnostics, crash logs.

Communications:

Support messages, in-app notices.

3. How We Use Data

  • Provide app functions: billing, access control, maintenance workflows, reminders
  • Authenticate users and authorize building-level actions
  • Prevent fraud and secure facilities
  • Analyze performance and improve reliability
  • Comply with law and enforce terms

4. Legal Bases (GDPR/UK GDPR)

  • Contract performance
  • Legitimate interests (security, service improvement)
  • Consent where required (notifications, certain analytics)
  • Legal obligation

5. Sharing and Disclosure

  • Your building's management and authorized staff for operations and compliance
  • Service providers under contract: cloud hosting, payment processors, access-control vendors, customer support, analytics
  • Legal and safety requests
  • Business transfers if we merge, sell assets, or reorganize

We do not sell personal data or permit third-party advertising tracking.

6. Payments

We do not store full payment card numbers or bank credentials. Processing occurs with audited payment providers. Receipts and settlement metadata are kept for accounting.

7. Access Control Integrations

The app works with smart locks and entry systems. We log access attempts and results to secure property and diagnose issues. Digital keys are scoped to user roles and building policies.

8. Retention

We retain data only as long as needed for the service and legal requirements. Criteria include account status, dispute windows, and statutory retention for financial records.

9. Security

Encryption in transit is enforced for all personal and financial data. We apply access controls, key management, and monitoring. No method is 100% secure.

10. International Transfers

If data moves outside your region, we use legal mechanisms such as standard contractual clauses.

11. Your Rights

Where applicable: access, correction, deletion, portability, restriction, objection, and withdrawal of consent. Exercise rights via the contact above.

California residents: rights to know, delete, correct, and to opt out of "sale/share." We do not sell or share for cross-context advertising.

12. Children

Not directed to children under 13. No knowing collection from children.

13. App Permissions

Camera:

Scan QR codes for doors and elevators.

Bluetooth/NFC:

Communicate with supported locks and readers.

Notifications:

Bill reminders, access alerts, maintenance updates.

Photos/Media:

Attach images to maintenance requests.

14. Third-Party SDKs

We may use SDKs for payments, diagnostics, and crash reporting. Each provider processes data under its own policy and contract with us.

15. Changes

We will update this policy as the service evolves. Material changes will be signaled in-app or by email before they take effect.

Built with v0