Civic Quarters

Privacy Policy

Last updated: September 2, 2026

Civic Quarters, Inc. (“Civic Quarters,” “we,” “us,” or “our”) provides software that helps homeowners associations (“HOAs” or “associations”) and their residents, board members, property managers, and vendors manage community governance, dues, documents, and communication (the “Service”). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices and rights available to you.

This policy applies to visitors to civicquarters.com and to residents, board members, property managers, and vendors who use the Service (collectively, “Users”).

How to read this policy: associations and residents

Most information in the Service belongs to a community. When your HOA uses Civic Quarters, the association decides what records are kept, who inside the community can see them, and how long they are retained under the law that governs that association. For that information we act as a service provider to your HOA and follow its instructions. If you ask us to delete or change a community record, we may need to route your request to your association, and we will tell you when we do.

We also act as a business in our own right for the information we control directly: the accounts of the customers who buy our software, our billing relationship with them, visitors to our website, and our own support and security records. For that information the rights described below apply to us directly.

1. Information We Collect

Information you provide to us

  • Account information. Name, email address, phone number, mailing address, and login credentials.
  • Community and property information. Unit or lot address, HOA role (resident, board member, treasurer, property manager, vendor), tenancy dates, and — where a community enables the feature — vehicle, pet, and guest-access registrations.
  • Financial information. Dues payment history, account balances, and billing contact details. Full payment card and bank account numbers are collected and stored directly by our payment processors, Stripe and Plaid. Civic Quarters does not store full card or bank account numbers on our own servers.
  • Governing and community documents. CC&Rs, bylaws, architectural review (ARC) guidelines, meeting minutes, budgets, and other documents uploaded by a community’s board or management.
  • Communications and content you submit. Architectural review requests, violation reports and photos, maintenance and work-order requests, forum posts and marketplace listings, messages, ballots and votes, and questions submitted to our AI assistant (“Civic Brain”).
  • Audio and transcripts. Where a community enables our meeting-transcription feature, audio recordings of board meetings and the resulting text transcripts. These are handled as association governance records.
  • Vendor information. For vendors dispatched through the Service: business name, contact information, certificates of insurance, licenses, and invoices.

Information collected automatically

  • Device and usage data — IP address, browser type, pages visited, and timestamps — collected through standard web server technologies.
  • Log data generated by the Service, including sign-in activity and actions taken within the platform, for security and audit-trail purposes.

Information from third parties

  • Payment status and limited account details from Stripe and Plaid, needed to reconcile dues payments.
  • Where a community enables the integration, data exchanged with accounting platforms such as QuickBooks or Xero, or with other systems connected by API or webhook at the community’s direction.

Sensitive Personal Information

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), certain information may be classified as “Sensitive Personal Information,” including precise geolocation. Photos submitted with a violation report or maintenance request may contain embedded location metadata if your device records it, and we treat that metadata as Sensitive Personal Information. We use Sensitive Personal Information only to provide the Service — for example, to display a violation report as it was submitted — and never to infer characteristics about you. California residents have the right to limit our use of Sensitive Personal Information to these purposes; see “Your Privacy Rights” below.

Cookies and similar technologies

We use only strictly necessary cookies and equivalent browser storage required to sign you in, keep your session secure, and remember basic interface preferences. We do not use analytics, advertising, or third-party tracking technologies on the Service, we do not use cookies to serve targeted advertising, and we do not permit third parties to use Service cookies for their own purposes.

2. How We Use Information

We use personal information to:

  • Provide, operate, and maintain the Service — including resident and board portals, dues billing, document access, community websites, and vendor dispatch.
  • Power Civic Brain, our AI assistant, which reads a community's uploaded governing documents to answer questions with citations. See “Artificial Intelligence Features” below.
  • Process payments and maintain accurate dues, delinquency, and financial records on behalf of the HOA.
  • Send administrative and legally required communications: dues notices, violation notices, meeting and voting notices, service updates, and security alerts.
  • Send text messages for vendor work-order dispatch and other notifications you have opted into, where a community enables them — see “Text Message (SMS) Communications” below.
  • Maintain an audit trail of governance actions — votes, approvals, and document changes — as required for HOA recordkeeping.
  • Detect, investigate, and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations, including those specific to HOA governance and recordkeeping under applicable state law.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We do not use resident data to serve third-party advertising.

Artificial Intelligence Features

Civic Brain answers questions using the governing documents a community has uploaded, and cites the document and section it relied on. To do this, the question and the relevant document excerpts are sent to our AI model providers:

  • Anthropic (Claude models) — generates the written answer from the cited excerpts.
  • Voyage AI — converts documents and questions into numerical representations so the right passages can be retrieved.
  • Google (Gemini models, accessed through our hosting platform’s AI gateway) — powers only the public demonstration assistant on our marketing site and sample community, which operates on fictional demonstration data and never on real community records.

These providers process this content under their commercial API terms, which do not permit customer content submitted through those APIs to be used to train their models. Civic Quarters does not train any model of its own on community data. We do retain limited logs of Civic Brain activity to diagnose errors and measure answer accuracy. Civic Brain provides information drawn from your community's documents; it does not provide legal advice, and its answers should be confirmed against the governing documents themselves for any consequential decision.

Text Message (SMS) Communications

Where you provide a mobile number and opt in, we — or vendors dispatched through the Service, using Twilio — may send you text messages about work orders, dues, or account activity. Message and data rates may apply. Message frequency varies.

Reply STOP to any message to stop all text messages from the Service. Reply HELP for help. Opting out of text messages does not end your obligations to your association: legally required notices, including dues, violation, meeting, and election notices, will continue to be delivered by email and, where the law or your governing documents require it, by postal mail. We do not sell mobile opt-in information and we do not share it with third parties for their own marketing purposes.

3. Who We Share Information With

Your own HOA or community. Because the Service is built around HOA governance, information you submit — dues status, violations, ARC requests, votes, forum posts — is visible to your community’s board, management, and other authorized roles as defined by that community’s permission settings. This is a core function of the Service, not a disclosure to an outside party.

Service providers. We share information with vendors who help us operate the Service:

  • Stripe and Plaid — payment processing and bank account verification.
  • Twilio — text message delivery for work-order dispatch and notifications, where enabled.
  • Anthropic, Voyage AI, and Google — AI model and retrieval services powering Civic Brain, as described above.
  • Cloud infrastructure, database, storage, and email-delivery vendors necessary to run the Service.

Vendors dispatched by your community. Limited to the information needed to complete a work order, such as the unit address, issue description, and any attached photos.

Legal and safety. We may disclose information where required by law, subpoena, or court order, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Civic Quarters, our Users, or the public.

Business transfers. If Civic Quarters is involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy or a successor policy with equivalent protections.

We do not share full payment card or bank account numbers with any party other than Stripe and Plaid, who are bound by their own data-security obligations (PCI-DSS for Stripe; banking-grade security standards for Plaid). Every service provider listed above is contractually restricted to using personal information only to perform services for Civic Quarters, consistent with the CCPA/CPRA’s requirements for service provider relationships.

4. Data Retention

Associations are subject to state-specific recordkeeping laws, and retention in the Service follows the law that governs each community. Where a community is located in a state with its own HOA or condominium recordkeeping statute — for example the Davis-Stirling Act in California, Chapter 720 of the Florida Statutes, or Chapter 209 of the Texas Property Code — we retain that community's records for the longest applicable statutory period. Where no statute applies, we apply the baseline periods below:

  • Association financial and accounting records: a minimum of seven (7) years.
  • Governing documents, board meeting minutes, and executed vendor contracts: retained for the lifetime of the community's active account.
  • Election materials and ballots: a minimum of one (1) year after the election.
  • General correspondence and resolved maintenance tickets: only as long as necessary to provide the Service, or as directed by the community's board of directors.

When an account or community is terminated, we retain the minimum data necessary to comply with legal, tax, and audit obligations, and delete or anonymize the remainder within ninety (90) days. Backup copies are purged on our ordinary backup rotation.

5. Your Privacy Rights

General rights

Depending on where you live, you may have the right to:

  • Request access to, correction of, or deletion of your personal information.
  • Object to or restrict certain processing.
  • Request a copy of your data in a portable format.
  • Appeal a denial of any of the rights listed here.
  • Opt out of non-essential communications. Dues, violation, meeting, election, and other notices required by law or by your governing documents are not optional, because they are a condition of your association membership rather than marketing.

Limits on deletion. We cannot delete records we are required to keep. Where a deletion request covers association records subject to a statutory retention period, or records we must retain for legal, tax, audit, or security reasons, we will delete what we can, explain what we must keep and why, and delete the remainder once the retention period ends.

We respond to verifiable requests within the time required by applicable law — for California residents, within 45 days of receipt, which we may extend once by an additional 45 days with notice to you explaining the delay. We verify requests by matching the information you provide against the information already on file for your account. You may designate an authorized agent to submit a request on your behalf, subject to our ability to verify that agent's authority.

California privacy rights (CCPA/CPRA)

California residents have the right to know and access the specific pieces of personal information we have collected about them, the right to request deletion or correction of that information, the right to limit our use of Sensitive Personal Information to the purposes described in this policy, the right to opt out of the sale or sharing of personal information, and the right not to face discrimination for exercising any of these rights.

Non-discrimination. We will not deny you the Service, charge you a different price, or provide a different level or quality of service because you exercised any of the rights described in this policy.

Global Privacy Control. Because we do not sell or share personal information, an opt-out-of-sale/share signal has no additional effect on our processing today. Where applicable, we honor the Global Privacy Control (GPC) signal as a valid opt-out preference.

Other state privacy laws

A number of other states — including Virginia, Colorado, Connecticut, Texas, Utah, Oregon, and others — have comprehensive consumer privacy laws that grant rights similar to those described above. Most apply only once a company crosses a revenue or consumer-volume threshold, and we do not currently meet those thresholds. Regardless of whether a threshold applies, residents of any state may submit the requests described in this section and we will honor them consistent with applicable law and with the recordkeeping obligations of the association whose records are involved.

How to exercise your rights

To exercise any of these rights, or to submit a verifiable consumer privacy request, contact us at support@civicquarters.com. Please include “Privacy Request” in the subject line so your request is routed for handling within the required response window.

6. Data Security

We use administrative, technical, and physical safeguards designed to protect personal information. These include encryption of data in transit and at rest, role-based access controls that limit data visibility to a User’s authorized role within their own community, audit logging of governance and administrative actions, and reliance on PCI-compliant processors for payment data. Demonstration environments — including our sample community, Bali Hai Estates — are logically isolated from live production data and cannot generate real payments.

In the event of a security incident affecting your personal information, we will notify affected Users and communities, and any regulators where required, consistent with applicable state breach-notification law. No system is completely secure, and we cannot guarantee absolute security.

7. Children’s Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.

8. International Users

The Service is intended for HOAs and residents located in the United States and is not directed to individuals outside the United States. If you access civicquarters.com from outside the United States, your information will be processed in the United States, which may not provide the same level of data protection as your home jurisdiction.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date, and where changes are material we will provide additional notice, such as an email or in-app notification, to Users.

10. Contact Us

Civic Quarters, Inc.
Carlsbad, California
Privacy inquiries: support@civicquarters.com