Privacy Policy

Last updated: June 2026

1. Who we are

Crassus ("we", "us", "our") is a property management platform operated as a private service. Our primary contact for privacy matters is support@crassus.pro.

2. What data we collect

We collect only the data necessary to provide the service:

  • Account data — your name, email address, and organisation name, provided when your account is created by an administrator.
  • Property data — property addresses, lease agreements, tenant details, invoices, and expenses that you enter into the platform.
  • Usage data — standard server logs (IP address, request timestamps, browser or app version) retained for up to 90 days for security and debugging purposes.
  • Email delivery data — open and delivery status of invoice emails sent via our email service provider, to help you confirm invoices were received.

3. How we use your data

  • To provide and operate the Crassus platform and iOS companion app.
  • To send invoices and payment reminders on your behalf to your tenants.
  • To authenticate your account securely.
  • To diagnose technical issues and maintain service reliability.
  • To respond to support requests you send to us.

We do not use your data for advertising, profiling, or any purpose beyond operating the service.

4. Data sharing

We do not sell or rent your personal data. We share data only with the following sub-processors, strictly to deliver the service:

  • Railway — cloud infrastructure hosting the backend and database.
  • Amazon S3 — storage for generated invoice PDF files.
  • Resend — transactional email delivery (invoices and reminders).

Each sub-processor is bound by data processing agreements and applicable privacy law.

5. Data retention

We retain your account and property data for as long as your account is active. If you request deletion of your account, we will permanently delete your data within 30 days, except where retention is required by law (e.g. tax record obligations).

6. Security

All data is transmitted over HTTPS. Passwords are stored as salted hashes and never in plain text. Access tokens expire and are not stored server-side. We apply reasonable technical and organisational measures to protect your data against unauthorised access.

7. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated data.
  • Object to or restrict certain processing activities.
  • Receive a copy of your data in a portable format.

To exercise any of these rights, email support@crassus.pro. We will respond within 30 days.

8. iOS app

The Crassus iOS companion app connects to the same backend as the web platform using the same account credentials. It stores only an authentication token in your device's secure Keychain. No personal data is stored locally on your device beyond this token. The app does not access your contacts, location, camera roll, or any other device data beyond what you explicitly scan during expense capture (which is processed entirely on-device by Apple's Vision framework and not sent to our servers).

9. Cookies

The Crassus web app does not use tracking cookies. Authentication state is managed via a token stored in your browser's local storage, used solely to maintain your session.

10. Changes to this policy

We may update this policy from time to time. We will notify registered users by email if changes are material. The date at the top of this page reflects when the policy was last revised.

11. Contact

Questions about this policy or your data: support@crassus.pro

© 2026 Crassus. All rights reserved.