Parapet

Privacy Policy

Last updated 27 July 2026

Parapet tracks certificates of insurance for property managers. Doing that means handling personal data belonging to three different groups of people: our customers, the vendors they work with, and the insurance agents who issue certificates. This page says what we collect, why, where it goes, and what you can ask us to do about it.

The short version. We hold what you put into Parapet and the certificates your vendors upload. Certificates are sent to Anthropic to be read automatically — that is the core of how the product works, and it is the disclosure most worth your attention. We do not sell personal data, and we do not use your certificates to train anyone's models.

Who we are

Parapet is independently owned and operated — one founder, no outside investors — serving property managers primarily in the United States. Your data is stored and processed in the United States; the founder who administers those systems works from the Philippines. There is more detail on that, and on who can reach what, on our security page.

For any privacy question, or to exercise any right described below, email privacy@parapethq.com — it reaches the founder directly, not a queue. Postal address is available on request and is included in our commercial correspondence.

What we collect

If you are a customer

If you are a vendor or an insurance agent

You will usually reach Parapet through a link a customer sent you, without creating an account. In that case we hold:

A certificate of insurance can contain the name and direct contact details of an individual agent. Where that happens, those details are personal data and this policy covers them.

If you only visit parapethq.com

Why we use it

PurposeData used
Reading a certificate and checking it against your requirementsThe uploaded file and the fields read from it
Emailing vendors an upload link and expiry remindersVendor contact email, organisation name
Signing you in and keeping your account secureEmail, hashed password, session tokens
Producing the audit trail our customers rely on for their own complianceActor, action, timestamp, IP address
Keeping the service running and diagnosing faultsError reports, which exclude document contents and credentials
Understanding whether our marketing worksMarketing-site analytics only

Who else processes your data

We use the following providers. They act on our instructions and may not use your data for their own purposes.

ProviderWhat it handles
AnthropicCertificate PDFs. Each uploaded certificate is sent to Anthropic's API to extract its fields. This is how extraction works; there is no version of the product that skips it. Anthropic does not train models on data submitted through its API.
Amazon Web ServicesCertificate files (S3, United States) and outbound email (SES)
RailwayApplication servers, the database and the job queue
VercelHosting for this site and the web application
CloudflareDNS and network routing
SentryError reports. Configured not to carry document contents, passwords or tokens
PostHogAnalytics for this marketing site only
TallyThe contact form on this site
Have I Been PwnedChecks new passwords against known breaches. Only the first five characters of a hash are ever sent — your password never leaves our server

We do not sell personal data, and we do not share it for advertising.

Where your data is held

Your data is stored and processed in the United States. Certificate files live in a US-region object store and the database runs in a US region; we do not replicate customer data anywhere else.

Administrative access is a separate question, and worth answering plainly. Parapet is operated from the Philippines, so the one account with production access signs in from there. That access belongs to a single named person, every provider account behind it is protected by two-factor authentication, and Parapet has no "sign in as customer" feature — the internal admin surface covers signup approvals only, not your vendor records. Reaching your data means going to the database deliberately, which happens for a support request or an incident and not otherwise. Our security page sets out the controls in full.

How long we keep it

How we protect it

What we do not yet do. We are a young product and would rather say so than imply otherwise. We do not currently hold a SOC 2 report, we do not scan uploaded files for malware, and two-factor authentication is not yet available. If any of those matter to your procurement process, ask us before you buy rather than after.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, or stop using it for a particular purpose. Email privacy@parapethq.com and we will respond within 30 days.

If you are a vendor or an agent, the certificate you uploaded belongs to the customer who requested it — they decide how long to keep it. We will pass your request to them and help them action it. Ask us and we will tell you who that customer is.

Where the law gives you specific rights — for example under the GDPR or the California Consumer Privacy Act — those rights apply and are not limited by this page.

Cookies

The application uses one strictly necessary cookie to keep you signed in. This marketing site uses PostHog, which sets an identifier to count returning visitors. We run no advertising cookies and no cross-site tracking.

Children

Parapet is a business tool and is not directed at anyone under 16.

Changes

If we change this policy materially we will update the date above and, for changes that affect customers, email account owners. Past versions are available on request.

Contact

privacy@parapethq.com