Skip to content
ApartBoard Menu
Legal

Security

Revision of 24 September 2026

Specifics rather than general words: who sees what inside the account, what stays in the log, and how to tell us if something looks wrong. We do not collect more than we need and do not complicate what can be simple. If anything is unclear, write to us and we will explain.

Owners' data does not mix

Every record belongs to one owner, and the account’s queries are limited to that owner in the application itself — not by a filter on the screen, but in the database query itself.

A housekeeper working for two owners signs in with one account, but only one owner’s workspace is open at a time: switching is a deliberate act, and the other owner’s data is out of reach while it lasts.

Everyone sees their own

The owner sees the whole of their account. A housekeeper sees only the apartments assigned to her, her own cleanings and her own money. Other people’s bookings, settlements and the account settings are not shown to her.

Passwords

A password is stored only as an irreversible hash: nobody can read it back, ourselves included. Resetting goes through a one-time link sent by email with a limited lifetime.

Two-factor authentication is planned as an extra layer for signing in.

Connection

The site and the account are served over HTTPS: traffic between the browser and the server is encrypted.

Files

Receipts and cleaning photos live outside the web root, and the web server never reaches them. A file opens only through the account: the address checks who is asking, and someone else’s document answers exactly as a missing one would.

Change log

Check-in, extension, check-out, cancellation and edits to a booking are written to the log: who, when, what it was and what it became. The owner can read the log, and nothing in the interface edits it.

Money works the same way: every movement carries its author, method, time and, where there was one, the attached receipt.

Errors and monitoring

Crash reports go to Sentry without personal data: sending request contents and user details is switched off in the configuration.

What we do not do

  • We do not sell data and do not pass it on for advertising.
  • We do not show one owner another owner’s data.
  • We do not ask guests for identity documents and do not store them.
  • We do not take or store bank card details.
  • We load no third-party fonts or trackers: the page talks to our own server and nowhere else.

Found a vulnerability? Tell us

Write to us at [email protected] — describe the steps to reproduce, the time and what you saw. We will be grateful if you stop as soon as you have confirmed the problem.

We answer those emails first and tell you how it ended.

What is up to you

  • Do not share your password — give housekeepers their own logins.
  • Unlink the people who have stopped working for you: access goes away with the link.
  • Check the change log when the numbers in a report do not match what you expect.
  • Do not forward screenshots of receipts and reports to people who should not see them: outside the account the permissions no longer apply.

How long data is kept

Data is kept for as long as the account exists. After an account is deleted, the information is removed from the database within 30 days, except where the law requires otherwise.

Updates to this page

If the security terms change materially, we will tell you in the account or by email. The date of the latest revision is shown at the top of the page.

Questions about this document

Write to [email protected] — we answer within three business days.