Privacy Policy
How Smart Property Software collects, uses, stores, and protects information across the website, customer portal, billing flows, and Home Assistant services.
We collect the information needed to run the site, deliver the service, support customers, and improve the product without turning customer data into a secondary business.
Who we are
Smart Property Software operates the website at https://www.smartpropertysoftware.com, the customer portal, and related dashboard, automation, and software services. For privacy questions, contact [email protected].
Information we collect
We may collect information you provide directly, including your name, email address, business details, project brief, and any content you submit through contact forms, support messages, or the customer portal.
Where you use our Home Assistant services, we may also process Home Assistant-related information such as entity inventories, room and device structure, dashboards, automation drafts, screenshots, sync snapshots, and other configuration data needed to build, review, deploy, or support your setup.
When you create a portal account or subscribe to the service, we may store account identifiers, login details, subscription status, billing metadata, and customer support history.
How we use information
We use information to respond to enquiries, provide subscriptions and portal access, build dashboards and automations, run AI-assisted generation flows, troubleshoot issues, process support requests, improve product quality, prevent misuse, and comply with legal obligations.
We do not use customer Home Assistant data or API-submitted customer content as marketing material without permission.
Payments and billing
Payments are processed by Stripe. We do not store full payment card details on our own servers. We may store Stripe customer IDs, subscription IDs, invoice status, and related billing metadata so we can manage subscriptions and portal access.
AI-assisted features
Some parts of the service use AI providers to help gather requirements, generate dashboard drafts, refine automations, and support customer workflows. We aim to minimise what is sent to external AI providers by using task-specific packets rather than full customer records wherever possible.
Customer data is intended to remain tenant-scoped within the portal and service backend. We do not intentionally mix one customer’s Home Assistant context with another customer’s data.
Legal bases
Where UK GDPR or similar rules apply, we generally process information because it is needed to perform a contract with you, because we have a legitimate interest in operating and improving the service, because you have given consent where required, or because we must comply with legal obligations.
Sharing information
We may share information with service providers that help us run the business, including infrastructure providers, email providers, payment processors, analytics or monitoring tools, and AI providers used in the service workflow. We only share what is reasonably needed for the relevant task.
We may also disclose information where required by law, to protect our rights, or to investigate misuse, fraud, abuse, or security incidents.
Retention
We keep personal and service data for as long as needed to provide the service, maintain records, support customers, meet legal obligations, resolve disputes, or enforce agreements. Home Assistant snapshots, proposals, and portal records may be retained while an account is active and for a reasonable period afterwards unless deletion is requested and retention is no longer required.
Security
We use administrative, technical, and organisational measures intended to protect customer information. That said, no internet-based service or storage system can be guaranteed to be completely secure.
Your rights
Depending on where you are located, you may have rights to request access to your information, ask for correction or deletion, object to certain processing, restrict processing, or request a copy of your data. To make a request, email [email protected].
Data processors and government requests
Smart Property Software Ltd is the data controller of Platform Data we receive from Meta and customers. The full list of sub-processors we engage (Hostinger, Cloudflare, Microsoft 365, GlitchTip), together with the category of service each one provides and the country in which they process data, is published at smartpropertysoftware.com/legal/data-processors. Our procedure for reviewing, challenging, minimising, and documenting requests for personal data from public authorities is published at smartpropertysoftware.com/legal/government-requests. Both pages are updated before any new sub-processor is engaged or any policy change takes effect.
WhatsApp Business and Meta integrations
Where a customer connects a WhatsApp Business number through SmartTenant or another SPS product, we act as a Meta Tech Provider. As part of that flow, Meta hands us a WhatsApp Business Account identifier, a phone-number identifier, and an OAuth access token scoped to whatsapp_business_management and whatsapp_business_messaging. Access tokens are encrypted at rest using AES-256-GCM and are never returned to the customer’s browser after the initial signup.
Once connected, we send and receive WhatsApp messages on the customer’s behalf using Meta’s Cloud API. Inbound messages, outbound messages, and Meta-supplied delivery statuses are stored against the customer’s account so staff can read and reply from the SmartTenant shared inbox. We do not use WhatsApp message content for marketing, model training, or any purpose other than operating the messaging feature for that customer.
Customers can revoke our access at any time from Meta Business Suite (Settings → Business Integrations → SmartTenant → Remove). Meta then calls our deauthorize webhook and we mark the connection as suspended within minutes. Customers can also email [email protected] or use Meta’s “Data Deletion Request” link to request deletion of all WhatsApp-derived records.
Strava data
When a member connects a Strava account on the Connected Apps page, we request the activity:read_all and profile:read_all scopes — read-only. We pull recent activities (runs, rides, walks, workouts) and basic athlete profile so the member can see their training on the member dashboard. We never write to Strava on the member’s behalf, and disconnecting calls Strava’s deauthorise endpoint and stops further sync.
Apple Health and Android Health Connect
The SmartGyms mobile app can pair with Apple Health (iOS) or Health Connect (Android). One permission grant covers any device or app that writes to those OS-level health hubs — Apple Watch, Garmin, Fitbit, Whoop, Oura, Polar, Suunto, Samsung Health, Wear OS, and others. We read steps, weight, body measurements, and workout sessions in the background and write completed in-app workouts back to the hub so they appear in the member’s other fitness apps. Pairing is opt-in per device and revocable from the OS Settings screen at any time.
Cookies and site operation
The site and portal may use cookies or similar technologies that are required for login sessions, security, and core functionality. Additional analytics or tracking tools may be introduced over time, in which case this page should be updated accordingly.
Changes to this policy
We may update this Privacy Policy from time to time. The version on this page is effective from April 20, 2026.