Privacy Notice

Version:
2026-08-3
Effective date:
2026-08-05

This notice explains what information BeforeKeys processes, why, and the choices you have. It is written in plain language.

1. Who we are and what this covers

BeforeKeys is a tenancy-documentation service that helps tenants keep an organised record of their rental: move-in inspections, documents, rent payments, communications, repairs and reminders.

The data controller is Natalie Alexis, an individual entrepreneur (Empresário em Nome Individual) established in Portugal and trading as BeforeKeys, contactable at privacy@beforekeysapp.com. This Privacy Notice applies to the BeforeKeys website and web application, including the account area and the purchase and subscription flows offered inside it.

Legal owner name
Natalie Alexis
Trading name
BeforeKeys
Entity type
Empresário em Nome Individual (ENI)
Registered or business contact address
Rua De Sao Nicolau 10 Porto, Portugal 4150-561
Country of establishment
Portugal

Payment information is handled separately by Paddle, our payment provider and Merchant of Record. See “Payments, subscriptions and Paddle” below.

2. Information we process

Account information

  • Account identifier (an internal user ID)
  • Email address
  • Authentication information managed by our authentication provider, including sign-in method (email and password, or Google sign-in) and session tokens
  • Display name and profile details you choose to add
  • Language preference (English or European Portuguese)
  • Account role information used to control access

Tenancy and property information you add

  • Properties: address and property details you enter
  • Tenancies: nickname, dates, rent amount, deposit and lease details you enter
  • Move-in inspections: rooms, checklist items, condition notes, meter readings and access items (for example keys and fobs)
  • Uploaded photos, evidence files and documents, together with file names, sizes and types
  • Rent payment records you enter, including amounts, dates and status
  • Communications you import or record, including message text you paste or upload
  • Repair issues and repair updates
  • Reminders you create
  • Generated reports and exports you produce

Automated summaries

When you ask for a summary of a document or a communication, the extracted text is sent to our AI provider to produce a draft summary that you review and approve. We keep the resulting draft, the approved summary, references back to the source, and usage counters used to apply fair-use limits.

Technical and security information

  • Activity and audit records of key actions in your account
  • Error and diagnostic records when something fails
  • Standard server and security logs generated by our hosting and database providers
  • The browser user agent recorded alongside consent evidence at checkout

We do not run advertising trackers, and we do not sell personal information.

3. Payments, subscriptions and Paddle

Purchases and subscriptions are processed by Paddle, which acts as the payment provider and Merchant of Record for those transactions. Payment is completed inside Paddle’s own hosted checkout, not inside BeforeKeys.

Card details

  • BeforeKeys does not collect or store your full card number.
  • BeforeKeys does not collect or store your CVV or security code.
  • BeforeKeys does not receive your full card expiry information.
  • BeforeKeys never sees or retrieves your complete card information.

Billing information BeforeKeys does store

To operate access, entitlements and billing support, we store a limited set of billing metadata:

  • Your internal BeforeKeys user ID
  • Internal billing record identifiers (customer, purchase, subscription, checkout attempt and event records)
  • A Paddle customer reference, plus an email snapshot and country code returned by Paddle
  • A Paddle subscription reference and a Paddle transaction reference
  • A checkout-attempt reference, its purpose, status, expiry and completion time, and where relevant the tenancy it relates to and the source subscription being replaced
  • Our internal product and price identifiers, price code, amount, currency and billing interval
  • Transaction status and purchase status, including purchase, refund and revocation timestamps
  • Subscription status, current period start and end, cancellation flags and timestamps, grace period end, payment-failure timestamp and any pending plan change
  • Entitlement state: which access has been granted, its scope, start and end dates and status
  • Consent evidence: the purpose, the acknowledgements you ticked, the disclosures shown, the copy version, the locale, the browser user agent and the timestamp
  • Environment (sandbox or live) and payment provider name
  • Webhook event metadata from Paddle: event identifier, event type, timestamps, resource type and reference, a payload hash, processing status and error or ignore reasons

The Paddle customer, subscription and transaction references are opaque identifiers issued by Paddle. They are not card numbers and cannot be used to reconstruct card details.

Paddle’s own processing

Paddle independently collects and retains payment, billing, tax, invoicing, fraud-prevention and transaction records in its own capacity. Paddle’s own privacy and buyer terms apply to that processing, and BeforeKeys cannot delete records Paddle retains for its own legal and accounting purposes.

Saved payment methods

  • Paddle’s optional saved-payment-method feature is disabled for BeforeKeys.
  • BeforeKeys does not show its own “save my card” checkbox.
  • Move-In Record purchases always open a fresh Paddle-hosted checkout.
  • BeforeKeys does not silently charge a subscription’s payment method for a separate Move-In Record purchase.
  • Recurring subscription billing stays separate from any unrelated future purchase.

Annual upgrade acknowledgements

When you upgrade a monthly Tenancy Vault subscription to annual billing, BeforeKeys asks you to tick two acknowledgements before handing you over to Paddle:

  • That you will review the final amount payable today with Paddle at checkout.
  • That annual billing recurs until you cancel.

These acknowledgements are records of what BeforeKeys disclosed to you. They are not the card-payment authorisation. The payment itself is authorised and confirmed by you inside Paddle’s hosted checkout, and your access changes only after Paddle confirms the transaction to us.

4. Why we process information, and on what legal basis

  • Providing the tenancy-documentation service — performance of our contract with you.
  • Creating and administering your account — performance of our contract with you.
  • Storing the tenancy information you choose to add — performance of our contract with you.
  • Producing automated summaries you request — performance of our contract with you.
  • Processing purchases and subscriptions — performance of our contract with you.
  • Managing entitlements and access to paid features — performance of our contract with you.
  • Customer and billing support — performance of our contract with you, and our legitimate interest in resolving issues.
  • Security, abuse and fraud prevention — our legitimate interest in protecting the service and its users.
  • Maintaining operational, consent and audit records — our legitimate interest in accountability, and compliance with legal obligations where applicable.
  • Complying with accounting, tax and other legal obligations — compliance with a legal obligation.
  • Improving reliability and diagnosing errors — our legitimate interest in a stable service.
  • Sending service communications about your account, purchases and important changes — performance of our contract with you.

BeforeKeys does not currently send marketing email. If marketing is introduced, it will be described here and, where required, will be based on your consent, which you can withdraw at any time.

We do not rely on consent as a catch-all basis. Consent is used only where it is genuinely the appropriate basis.

5. Who we share information with

We share information only with the categories of recipients we actually use:

  • Hosting, database and file-storage providers that run the application and store your data.
  • Our authentication provider, which manages sign-in, sessions and password handling.
  • Paddle, as payment provider and Merchant of Record for purchases and subscriptions.
  • Our AI provider, which processes the text you submit for an automated summary.
  • Email delivery used for account and service messages such as sign-in confirmations and password resets.
  • Error and operational monitoring used to detect and diagnose failures.
  • Professional advisers, such as legal and accounting advisers, where necessary.
  • Public authorities, where we are legally required to disclose information.

We name Paddle.com Market Ltd because it is the Merchant of Record for every purchase and appears on your receipt. Our other providers are used only in the roles described above, and we do not sell your information or share it for advertising.

6. International processing

Some of our service providers may process information outside the country where you live, including outside the European Economic Area. Where that happens, we rely on the transfer safeguards offered by that provider, such as European Commission standard contractual clauses or an adequacy decision.

If you would like to know which safeguard applies to a specific provider, contact us using the details in the Contact section and we will tell you.

7. How long we keep information

We keep information for as long as needed for the purpose it was collected for. Because different records serve different purposes, we apply the criteria below rather than a single fixed period for everything.

  • Active account data — kept while your account exists, so the service works for you.
  • Tenancy records, inspections, payments, communications, repairs and reminders — kept while the related tenancy exists in your account.
  • Deleted tenancy data — removed from the application when you delete it; residual copies may persist briefly in provider backups until those backups cycle.
  • Uploaded files and evidence — kept while the record they belong to exists; files no longer linked to a record are removed by a scheduled cleanup process.
  • Transaction and accounting records — kept for as long as accounting and tax law requires.
  • Subscription and entitlement records — kept while needed to evidence what access was granted and when.
  • Consent evidence — kept as a record of what was disclosed and acknowledged at the time of purchase.
  • Webhook event records — kept for reconciliation, dispute handling and audit of billing events.
  • Security and operational logs — kept for a limited period appropriate to security monitoring and debugging.
  • Payment records held by Paddle — controlled by Paddle and retained under Paddle’s own policies; BeforeKeys cannot delete them.

You can delete your tenancy records at any time from your account. When you close your account, we remove your account and tenancy data except records we must keep for accounting, tax, billing-dispute or security reasons.

8. Your rights

Depending on where you live and the circumstances, you may have the right to:

  • Access the personal information we hold about you.
  • Ask us to correct information that is inaccurate or incomplete.
  • Ask us to delete information.
  • Ask us to restrict how we use information.
  • Object to processing based on our legitimate interests.
  • Receive information you provided in a portable format.
  • Withdraw consent, where we rely on consent.
  • Complain to your national supervisory authority.

Not every right applies in every situation. Some information must be kept to meet legal, accounting or security obligations, and requests are assessed individually.

Data-subject request mailbox
privacy@beforekeysapp.com

9. Security

We use technical and organisational measures appropriate to the service, including encrypted connections, access controls that restrict records to the account that owns them, authenticated file access, server-side checks on sensitive operations, and verification of incoming payment notifications before they change anything.

No online service can be completely secure. We do not claim absolute security or zero risk, and this notice makes no certification claim.

10. Children

BeforeKeys is intended for adults managing their own tenancy records and is not designed for children.

You must be at least 18 years old to create an account. If we learn that an account was created by someone under 18, we will close the account and delete the associated data, except anything we must keep by law.

11. Changes to this notice

The version identifier and effective date at the top of this page identify the version currently in force. Earlier versions are retained so past wording is not lost.

We may update this notice as the service changes. Where a change is material, we will give additional notice through the service or by email, and in some cases we may ask you to acknowledge the change.

12. Contact

For any privacy question, including a rights request, contact BeforeKeys using the details below.

Privacy / data-subject email
privacy@beforekeysapp.com
Postal contact address
Rua De Sao Nicolau 10 Porto, Portugal 4150-561
General support email
support@beforekeysapp.com
Data controller name
Natalie Alexis, trading as BeforeKeys
Controller contact
privacy@beforekeysapp.com

For questions specific to a payment, invoice or refund, Paddle handles those enquiries as Merchant of Record.