PaxRent

Privacy Policy

Last updated: July 23, 2026

PaxRent ("we," "us," or "our") operates the PaxRent property management platform. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.

1. Information We Collect

Information You Provide

  • Account information: Name, email address, phone number, and role when you create an account or are invited to the platform
  • Profile information: Mailing address, date of birth, emergency contacts, and other details relevant to your property management relationship
  • Property information: Property addresses, unit details, lease terms, and related documents
  • Financial information: Payment details are collected and processed by Stripe, our third-party payment processor. PaxRent does not directly store payment card numbers.
  • Communications: Messages, maintenance requests, and other communications sent through the platform
  • Contact form submissions: Name, email, phone number, property address, and message content submitted via marketing site contact forms
  • Screening information: Social Security numbers, driver's license numbers, and other information submitted for tenant background checks (processed by third-party screening providers)
  • Tax identification: Social Security numbers (SSN) or Employer Identification Numbers (EIN) for property owners and vendors, collected for IRS 1099 tax reporting. Tax IDs are encrypted at rest and only the last four digits are stored in plaintext for display.

Information Collected Automatically

  • Usage data: Pages visited, features used, actions taken, timestamps, and session duration
  • Device information: Browser type, operating system, device type, and screen resolution
  • Analytics data: Aggregated website usage through Google Analytics on marketing pages
  • Log data: IP addresses, access times, and error logs for security and debugging purposes

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process rent payments and financial transactions
  • Send notifications about maintenance requests, payments, leases, and other property management activities via email, SMS, and in-app notifications
  • Facilitate communication between property managers, tenants, owners, and vendors
  • Process tenant applications and background checks
  • Generate financial reports and owner statements
  • Respond to inquiries and provide customer support
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations

3. SMS and Text Messaging

SMS opt-in is a discrete consent action that is separate from accepting these Terms or our Privacy Policy. If you enable SMS notifications in your account settings, we will use your phone number to send property management notifications via text message. Our SMS messaging practices include:

  • Opt-in only: SMS is disabled by default. You must explicitly enable SMS notifications in your notification preferences. Accepting our Terms of Service or Privacy Policy does NOT enroll you in SMS communications.
  • Per-category granular consent: Each notification type (maintenance, payments, leases, etc.) has its own SMS toggle that defaults to OFF.
  • Message types: Maintenance updates, payment notifications, lease reminders, move-in/move-out updates, and general announcements.
  • Opt-out: Reply STOP to any message, disable SMS in your notification preferences, or email support@paxrent.com.
  • No sharing: We do not sell, rent, or share your mobile information, including your phone number and SMS opt-in consent, with third parties or affiliates for marketing or promotional purposes.
  • Service provider: SMS messages are delivered through Twilio, our messaging service provider, which processes your phone number solely for message delivery.

For complete SMS terms, see our SMS Terms & Conditions. For a public walkthrough of the discrete opt-in flow, see our SMS opt-in flow.

4. Calendar Integrations

PaxRent offers an optional calendar integration that lets you sync your PaxRent activity (such as maintenance and vendor appointments, inspections, showings, move-in and move-out events, and lease dates) to your own Google or Microsoft Outlook calendar. This integration is off by default and is enabled only when you explicitly connect a calendar, or add a subscription link, from your account settings.

Dedicated PaxRent calendar. When you connect a calendar, PaxRent creates a separate calendar named "PaxRent" inside your Google or Microsoft account and writes only PaxRent events to it. We do not write to your default or primary calendar, and we do not modify or delete events that PaxRent did not create.

What we send. The events we create contain PaxRent activity details such as the title, date and time, location (for example, a property address), and a short description (for example, a work order summary). This information is stored in the calendar you connected, inside your own Google or Microsoft account.

Google (read access is blocked by Google's permissions). For Google, PaxRent requests only the calendar.app.created permission. This narrow permission lets an app create and manage only the calendars it creates itself. PaxRent cannot read, edit, or even see your existing Google calendars or events; Google's permission model prevents it.

Microsoft Outlook (read access is limited by our own design). Microsoft does not offer an equivalent "app-created calendars only" permission. The permission PaxRent requests for Outlook (Calendars.ReadWrite) would technically allow access to all of your calendars. PaxRent limits itself by design to only the dedicated "PaxRent" calendar it creates, and never reads or writes your other calendars. The difference from Google is that this limit is enforced by our own code rather than by Microsoft's permission model.

Token storage. To keep your calendar in sync, PaxRent stores the access and refresh tokens that Google or Microsoft issue when you connect. These tokens are encrypted at rest using AES-256-GCM encryption and are used only to create and update your PaxRent calendar events.

iCal subscription feed. As an alternative to connecting an account, PaxRent can give you a personal subscription link (an .ics feed URL) that you add to any calendar app, including Apple Calendar. This link is unique to you and is signed so that it cannot be guessed. Anyone who has the link can view the PaxRent event details it contains, so treat it like a password and share it carefully. You can rotate the link at any time from your account settings, which immediately disables the previous link.

Disconnecting and revoking access. You can disconnect a calendar at any time from your account settings. Disconnecting stops further syncing and removes PaxRent's stored connection, including the encrypted access tokens, from our systems. To fully revoke the permission you granted, you can also remove PaxRent from your Google Account or Microsoft Account security settings. Disconnecting does not delete events already written to your "PaxRent" calendar; you can remove that calendar yourself from within Google Calendar or Outlook.

5. Information Sharing

We do not sell, trade, or rent your personal information to third parties. We may share your information in the following limited circumstances:

  • Within your organization: Your property manager and authorized team members can access information relevant to managing your property relationship
  • Service providers: We share information with trusted third-party services that help us operate the platform. See our Subprocessors page for the complete list.
  • Background check providers: Applicant screening information is shared with authorized consumer reporting agencies for the purpose of tenant screening, with the applicant's explicit consent
  • Tax reporting: Owner and vendor tax identification numbers are used by your property management company to prepare IRS 1099 forms as required by federal tax law. PaxRent stores this data on behalf of the property management company and does not independently file tax reports.
  • First-class mail service: When your property manager sends a legal notice (for example, a Demand for Possession) that requires physical mail delivery, PaxRent transmits the recipient's name, mailing address, sender return address, and notice document contents to a third-party first-class mail service that prints, posts, and tracks the letter through USPS. The mail service acts as a service provider/processor under CCPA and as a processor under GDPR, is bound by a data processing agreement, and processes this data only to deliver the mail. The current mail service vendor is listed on our Subprocessors page.
  • Legal requirements: We may disclose information when required by law, court order, or governmental regulation
  • Safety: We may share information to protect the rights, safety, or property of PaxRent, our users, or the public

6. Cookies and Tracking

We use cookies and similar browser storage for authentication, session management, and user preferences. We also use the technologies below to understand how the marketing site and the platform are used. You can decline or revoke this analytics tracking at any time using the controls described in this section.

Marketing site analytics

Pages on www.paxrent.com may load Google Analytics 4 to measure aggregate visit traffic. GA4 only loads after you accept cookies in the consent banner shown on your first visit. If you decline, no GA4 script and no GA4 cookies are loaded.

Product analytics on the platform

When you sign in to app.paxrent.com, we use PostHog as our product analytics provider to understand how the platform is used and to reproduce user-reported issues. PostHog is listed on our Subprocessors page along with the data it receives. PostHog captures the following on the platform:

  • Pageviews and pageleaves: which screens you open and how long the page was active.
  • Autocapture: clicks on buttons and links, and form submission events. Autocapture records that an element was interacted with, not the values typed into form fields.
  • Session recordings: a replay of how the page rendered and was navigated, used to debug issues.

Sensitive content is masked before it leaves your browser:

  • All form inputs are masked by default via PostHog's maskAllInputs: true session-recording option. The recording shows that a field exists, never the value entered into it. This applies to text inputs, textareas, and select elements.
  • Anything matching the [data-ph-mask] selector has its text content masked. We apply this attribute to surfaces that may render personal information, such as tenant names in lists, payment amounts, and screening details.

How platform analytics consent works and how to opt out

On the platform (app.paxrent.com), product analytics are enabled when you accept our Terms of Service, which incorporate this Privacy Policy. Accepting Terms serves as your notice of and consent to product analytics collection. You can opt out at any time using any of the paths below, and your choice is honored immediately and remembered for one year.

  • In-app opt-out (Do Not Sell or Share): visit Settings > Account > Privacyand click “Do Not Sell or Share My Personal Information.” This sets an opt-out cookie that disables PostHog for your account on this device.
  • URL parameter: append ?analytics_optout=1 to any platform URL to set a one-year opt-out cookie that disables PostHog without navigating to Settings. Append ?analytics_optout=0 to clear the opt-out.
  • Browser-level controls: blocking cookies for app.paxrent.com in your browser settings has the same effect.

The marketing site (www.paxrent.com) displays a consent banner on your first visit for GA4. Your choice is stored in your browser's local storage under the key paxrent-cookie-consent.

Once analytics are opted out or revoked, no further analytics events or session recordings are sent from your device. To request deletion of past data tied to your account, contact privacy@paxrent.com.

7. Data Security

We implement industry-standard security measures to protect your personal information, including:

  • Encryption in transit (TLS/HTTPS) and at rest
  • Secure authentication via WorkOS with support for multi-factor authentication
  • Role-based access controls limiting data access to authorized users
  • Regular security audits and monitoring
  • SOC 2 certified infrastructure providers (Vercel, Neon)

No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Financial records are retained as required by applicable law. Upon account termination, we will delete or anonymize your data within a reasonable period, subject to legal retention requirements.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your personal information
  • Opt out of marketing communications
  • Opt out of SMS messaging at any time
  • Request a copy of your data in a portable format

To exercise these rights, contact us at privacy@paxrent.com.

10. Children's Privacy

The Service is not intended for children under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify active users of material changes via email or in-app notification. Changes will be posted on this page with an updated revision date.

12. Contact Us

If you have questions about this Privacy Policy or your personal data, contact us at: privacy@paxrent.com


See also: Terms of Service | Payment Services Addendum | SMS Terms & Conditions | SMS Opt-In Flow | Subprocessors

PaxRent is a service of Focal Point Solutions LLC, DBA PaxRent.