Privacy Policy
The short version: we collect only what we need, we never sell your data, and we take your privacy seriously.
What We Collect
- Account info — your name and email address.
- Property data — addresses, tenant details, financial records, documents, and photos you choose to upload.
- Usage data — how you interact with the app, so we can improve it.
- Technical data — browser type, device info, and IP address.
Why We Collect It
- To provide and operate the service.
- To communicate with you about your account.
- To improve the product based on how it's used.
- To ensure security and prevent fraud.
- To comply with legal obligations.
Where We Store It
Your data is stored on servers within the European Union. All data is encrypted in transit (TLS) and at rest. We follow industry-standard security practices to keep your information safe.
Who We Share With
We do not sell your data. Ever.
We only share data with:
- Infrastructure providers (hosting, email delivery) — under strict data processing agreements.
- Legal authorities — only when required by law (court order, valid legal process).
- You — with your explicit consent, if you ask us to share something on your behalf.
Your Rights (GDPR)
You have the right to:
- Access your personal data.
- Correct inaccurate information.
- Delete your account and all associated data.
- Export your data in a portable format.
- Object to processing of your data.
- Withdraw consent at any time.
To exercise any of these rights, email hello@buurman.io. We will respond within 30 days.
Google Sheets Export (Optional Integration)
If you choose to use the Export to Google Sheets feature (available on Big and Mega plans), the following applies:
- You consent every time. Each export opens a Google sign-in popup where you explicitly authorize Buurman. We never store or reuse the authorization — the access token lives only for the duration of that one export and is then discarded.
- Minimum scope. Buurman requests only the
drive.filescope, which Google classifies as non-sensitive. This scope only allows Buurman to read or modify files Buurman itself created in your Drive — we cannot see, list, or touch any of your other Google Drive content. - Where the data goes. When you trigger an export, the team data you chose to export (e.g. contacts, transactions, dashboards, or your full takeout) is sent from our servers to Google's Sheets and Drive APIs over an encrypted connection, and the resulting spreadsheet is created in your Google Drive under a folder we create called “Buurman exports”. The file is owned by you, not by Buurman.
- Google's privacy policy applies to the data once it lives in your Drive. See Google's Privacy Policy for details on how Google handles data you store with them.
- We don't keep a copy. Buurman does not retain the exported spreadsheet, its id, or its contents server-side beyond the response of the export request itself. We log metrics about success/failure and duration but not the data.
- You stay in control. You can revoke Buurman's access to your Google account at any time at myaccount.google.com/permissions. The next export will simply re-prompt for consent.
Buurman's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies
We keep cookies to a minimum:
- Session cookies — to keep you logged in.
- No third-party tracking cookies.
- No advertising cookies.
Data Retention
- We keep your data for as long as your account is active.
- After account deletion, all personal data is permanently removed within 30 days.
- We may retain anonymized, aggregated data for internal analytics.
Children
Buurman is not intended for users under 18 years of age. We do not knowingly collect data from minors.
Changes
We may update this policy from time to time. We will notify you of any significant changes via email. Your continued use of the service constitutes acceptance.
Questions?
Privacy questions or concerns? We're here to help: hello@buurman.io
