Privacy Policy
May 5, 2026
How SeekaKey handles personal information, providers, retention, and privacy choices.
1. Controller, Contact, and Items to Confirm
SeekaKey processes personal information to operate a residential rental platform connecting renters, landlords, and verification workflows. The controller is the operator of the SeekaKey service.
Privacy contact and privacy officer / DPO contact: support@seekakey.com. The approved privacy officer or DPO name is not yet confirmed in this repository.
Legal/admin confirmation pending: SeekaKey's registered legal entity name and street mailing address are not confirmed in current source. Do not treat this page as legal-review complete until those approved details replace this blocker.
2. Data Categories, Sources, Purposes, and Legal Bases
Primary sources are you, landlords, your product interactions, and providers acting for the service. Each category below states its primary legal basis.
- account/authentication: Clerk identity, email, role, session, and account-security data to create accounts, maintain sessions, and protect the service. Legal basis: contract performance, account security, and fraud or abuse prevention.
- profile, preferences, and work-location data: contact fields, search criteria, notification preferences, and work-location details to personalize searches, commute information, and the rental experience. Legal basis: contract performance, consent for optional preferences, and requested notices.
- property listings and images: listing text, attributes, price, availability, media, and upload metadata supplied by landlords to publish, moderate, and manage listings. Legal basis: contract performance with landlords and legitimate moderation interests.
- matches, likes, and skips: discovery interactions used to present listings, avoid repetition, and facilitate renter-landlord matches. Legal basis: contract performance and legitimate interests in improving discovery.
- messages, rooms, and reports: conversation content, attachments, room metadata, and reports used for messaging, safety, moderation, and necessary audits. Legal basis: contract performance, legitimate safety interests, and applicable legal obligations.
- verification document files and metadata: uploaded documents, metadata, review outcomes, and audit trails to verify eligibility, reduce fraud, and support correction or dispute rights. Legal basis: consent, fraud or abuse prevention, and applicable legal obligations.
- account lifecycle, deletion, and export data: requests, statuses, and events needed to handle managed requests, exports, and security or retention obligations. Legal basis: legal obligations, contract performance, and service security.
- cookies, local telemetry, optional PostHog product analytics, Sentry/operations logs, maps/location calls, and notifications: session, language, consent, diagnostics, error, geocode, distance, limited product events, and transactional email data needed for operation, reliability, security, accepted measurement, and requested notices. Legal basis: contract performance, legitimate reliability and security interests, consent for optional product analytics, and requested notices.
3. Retention and Deletion
We keep data only when it supports active product use, safety, operations, legal obligations, audit needs, or managed requests. Deletions and legal holds are handled as operational work where source does not yet define complete automation.
- Messages and rooms are retained until room closure plus 30 days; attachments follow deletion of the parent message.
- Open message reports are retained for 30 days. Reviewed reports are retained indefinitely for legal, safety, and audit needs.
- Local telemetry stays in the browser until cleared by the user or browser; it is not a vendor upload path by itself.
- For accounts, profiles, listings, verification records, files, logs, backups, and providers, periods not defined in source are governed by product, safety, legal, audit, provider-backup, and managed-request criteria.
4. Providers and Subprocessors
These providers may process personal information according to their current role, configuration, and applicable contracts. The links below are public starting points; they do not prove every provider dashboard is configured or verified.
A maintained register of subprocessors, data categories, regions to confirm, and DPA status is available in the repository: subprocessor register.
- Clerk - authentication and sessions (privacy, DPA).
- Vercel - hosting, deployment, and infrastructure logs (privacy, DPA).
- Convex - messaging, rooms, and reports (privacy, DPA).
- Supabase - verification document storage (privacy, DPA).
- UploadThing - property image upload transport; public DPA to confirm (privacy, regions and ACLs).
- Google Maps / Google Cloud - geocoding, maps, places, routes, and location data (privacy, DPA).
- Sentry - error monitoring and operations logs (privacy, DPA).
- PostHog - optional product analytics and future feature flag signals when configured (privacy, DPA).
- Resend - verification transactional email when configured (privacy, DPA).
- Upstash Redis - optional rate limiting and cache when configured (legal documents, DPA).
- PostgreSQL/Prisma database host category: application persistence through PostgreSQL and Prisma; the database host and its privacy/DPA links must be administratively confirmed. (Prisma privacy, Prisma DPA).
5. Cross-Border Transfers
SeekaKey and its providers may process data outside your province, state, or country. Where required, we rely on adequacy decisions, standard contractual clauses, data-processing terms, contractual measures, and provider security controls. This statement depends on provider contracts and policies; it does not claim provider dashboard proof.
6. Your Rights and Choices
Depending on where you live and the context, GDPR, PIPEDA, Quebec Law 25, and CPRA/CCPA may give you rights to access, correction, deletion, restriction, portability, objection or withdrawal of consent, complaint or recourse with a competent authority, no discrimination, opt-out of sale/share, and limit sensitive personal information where applicable.
SeekaKey does not sell personal information and does not share personal information for cross-context behavioral advertising in the current repository runtime.
Requests can be sent to support@seekakey.com. We may need to verify your identity, limit a response to protect other people, or retain some data for legal, safety, audit, or provider-backup reasons.
7. Export, Deletion, and Support
Signed-in users can download a self-service JSON export from Settings. The export covers app-owned SeekaKey data in the current scope, including relevant Prisma records and Convex conversations where the user participates.
The self-service export does not include raw verification document binaries, provider backups, Sentry events, external vendor logs, reviewed internal moderation notes, or data retained only for legal or safety operations. For those categories, contact support@seekakey.com for a managed privacy request.
8. Automated Decisions, Matching, and Verification
No solely automated decision with legal or similarly significant effect is declared for the current runtime. Renter grade, matching, discovery preferences, and verification are product-assistive, manual, or consent-gated flows; they remain subject to applicable review, accuracy, correction, and dispute rights.
9. Children and Minors
SeekaKey is a residential rental platform for people able to search for, offer, or manage housing. It is not directed to children under 18 and does not knowingly request their personal information. If a parent, guardian, or representative believes a minor submitted information, contact support@seekakey.com for review and appropriate deletion.
10. Cookies, Telemetry, and Error Monitoring
SeekaKey uses strictly necessary cookies and local storage to maintain session state, language, consent, and essential preferences. Browser-local telemetry may initialize and remain local in the browser; non-essential provider or vendor measurement uploads, including PostHog when configured for product analytics, remain off until you explicitly accept them where that choice is presented.
Local/browser-only telemetry remains in the browser. PostHog, when the project token is configured, is used for optional consented product analytics with autocapture and session replay disabled in the current runtime. Sentry, when the DSN is configured, is used for operational error monitoring with limited diagnostic data collection and Replay disabled; these flows are not marketing tracking.