Skip to main content
LOXAProperty Management
Why switchFeaturesPricingHelpAboutLogin
Get Started

Legal

Privacy Policy

Last updated August 10, 2026

Operational draft only — not legal advice. Counsel review is still required.

What this covers

This policy describes what LOXA Property Management collects when you use loxapm.com and the LOXA application, why we hold it, and who else sees it. It applies to two kinds of people: the operators who run a portfolio in LOXA, and the residents those operators invite to the resident portal.

What we collect

From an operator, at signup: your name, email address, and the name of your organization. From your use of the product: the records you enter, which include property addresses, unit details, owner details, tenant names and contact details, leases, charges, payments, deposits, and any documents you upload.

From a resident: the name, email address, phone number, and billing address your operator entered for you, plus anything you add to your own profile, and the payment details you provide when you pay rent.

Automatically: standard web server and security logs. If you allow analytics, we also collect page paths, page timing, clicks, scrolling, device type, and coarse location to find slow or confusing screens. We do not send portfolio field values, document contents, resident names, or payment details to analytics or advertising tools.

Payment information

Card and bank details are collected and stored by Stripe, not by LOXA. Rent payments run through Stripe Connect to the connected account for the owner of the property, and LOXA takes a platform fee. We store the identifiers Stripe gives us, such as a customer id and the brand and last four digits of a saved payment method. We never see or store a full card number or full bank account number.

Who can see your data

Records belong to the organization that created them. Staff in that organization see them according to the role they were given. A resident sees only their own balance, ledger, payments, and the documents their operator shared with them. One organization cannot read another organization's records.

Who we share it with

We use a small number of service providers to run the product, and we share only what each one needs:

  • Stripe, for payment processing and payouts.
  • Render, for application hosting, database storage, and uploaded document storage.
  • Mailgun, for transactional email such as password resets and payment receipts.
  • Twilio, when your organization sends a consented transactional text message.
  • Anthropic, when you ask LOXA to extract fields from an insurance document; the extracted result remains a draft until a person confirms it.
  • Sentry, for privacy-filtered application error reports without default personal information.

Analytics, advertising, and your choices

LOXA does not load optional analytics or advertising measurement until you choose it. Analytics permission can enable Google Analytics, Microsoft Clarity, and Ahrefs Web Analytics. Marketing permission can enable Google Ads, Meta, OpenAI Ads measurement, and ClickCease. These tools receive the page path and ordinary browser/device signals; application record fields remain masked and no custom resident identifier is sent.

Choose Only necessary, Allow analytics, or Allow all in the privacy bar. You can reopen Privacy choices at any time. Changing the choice stops new optional measurements; providers may retain information already received under their own retention rules.

What we do not do

We do not sell your data. We do not use resident contact details for our own marketing or send portfolio record contents to advertising platforms. If you allow marketing measurement, advertising providers receive limited browser events so we can tell whether an ad led to a page visit, registration, checkout, or subscription.

How long we keep it

Records stay for as long as the organization that owns them keeps its account, because a rent ledger is a financial record that has to remain auditable. If you close your account, email us and we will delete or export your organization's data.

Your choices

You can view and correct most of your own information inside the product. A resident who wants a record corrected should ask their operator, who holds it. To request an export or a deletion, or to ask what we hold about you, email support@loxapm.com.

Security

Traffic is encrypted in transit. Passwords are stored hashed, never in readable form. Access to records is scoped to the organization that owns them and to the role of the person asking. No system is perfect, and we will tell affected customers promptly if we learn of a breach that involves their data.

Changes

If this policy changes in a way that affects how we handle your information, we will update the date at the top and tell account owners by email.

Contact

Questions about this document go to support@loxapm.com.

LOXAProperty Management

LOXA Property Management gives independent owners and lean teams one place for leasing, resident billing, documents, and portfolio reporting.

  • www.loxapm.com
  • support@loxapm.com
  • sales@loxapm.com

Product

Why switchFeaturesPricingHelp centerStart free trial

Company

AboutContact supportBook a demo

Legal

Privacy PolicyTerms of Service
© 2026 LOXA Property Management. All rights reserved.Payments processed by Stripe.
PRIVACY

Choose what leaves the lobby

Essential services keep LOXA secure. With permission, analytics shows us where screens fail; marketing measurement tells us whether an ad led to a signup. Resident and portfolio fields stay masked. Read the privacy policy.