Privacy Policy
Last updated 27 July 2026
Parapet tracks certificates of insurance for property managers. Doing that means handling personal data belonging to three different groups of people: our customers, the vendors they work with, and the insurance agents who issue certificates. This page says what we collect, why, where it goes, and what you can ask us to do about it.
The short version. We hold what you put into Parapet and the certificates your vendors upload. Certificates are sent to Anthropic to be read automatically — that is the core of how the product works, and it is the disclosure most worth your attention. We do not sell personal data, and we do not use your certificates to train anyone's models.
Who we are
Parapet is independently owned and operated — one founder, no outside investors — serving property managers primarily in the United States. Your data is stored and processed in the United States; the founder who administers those systems works from the Philippines. There is more detail on that, and on who can reach what, on our security page.
For any privacy question, or to exercise any right described below, email privacy@parapethq.com — it reaches the founder directly, not a queue. Postal address is available on request and is included in our commercial correspondence.
What we collect
If you are a customer
- Account details — your name, email address, role, and a hashed password. We never store your password itself.
- Organisation details — your company name, legal name, and the list of legal entities a certificate may name as holder.
- Vendor records you create — vendor name, trade, contact name, email, phone and address, plus any notes you add.
- Activity records — an append-only audit log of actions taken in your account, including the acting user and the originating IP address.
If you are a vendor or an insurance agent
You will usually reach Parapet through a link a customer sent you, without creating an account. In that case we hold:
- The certificate you upload, as a file, and the fields read from it — insured name, producer (agency) name, certificate holder, policy numbers, coverage types, limits, effective and expiry dates, and any attached endorsement forms.
- The contact details our customer recorded for you, so we can send the upload link and expiry reminders.
A certificate of insurance can contain the name and direct contact details of an individual agent. Where that happens, those details are personal data and this policy covers them.
If you only visit parapethq.com
- Analytics — we use PostHog on this marketing site to count page views and which buttons get clicked. This is the only place we run analytics; the Parapet application itself carries no analytics or advertising trackers.
- Anything you type into our contact form, which is hosted by Tally.
Why we use it
| Purpose | Data used |
|---|---|
| Reading a certificate and checking it against your requirements | The uploaded file and the fields read from it |
| Emailing vendors an upload link and expiry reminders | Vendor contact email, organisation name |
| Signing you in and keeping your account secure | Email, hashed password, session tokens |
| Producing the audit trail our customers rely on for their own compliance | Actor, action, timestamp, IP address |
| Keeping the service running and diagnosing faults | Error reports, which exclude document contents and credentials |
| Understanding whether our marketing works | Marketing-site analytics only |
Who else processes your data
We use the following providers. They act on our instructions and may not use your data for their own purposes.
| Provider | What it handles |
|---|---|
| Anthropic | Certificate PDFs. Each uploaded certificate is sent to Anthropic's API to extract its fields. This is how extraction works; there is no version of the product that skips it. Anthropic does not train models on data submitted through its API. |
| Amazon Web Services | Certificate files (S3, United States) and outbound email (SES) |
| Railway | Application servers, the database and the job queue |
| Vercel | Hosting for this site and the web application |
| Cloudflare | DNS and network routing |
| Sentry | Error reports. Configured not to carry document contents, passwords or tokens |
| PostHog | Analytics for this marketing site only |
| Tally | The contact form on this site |
| Have I Been Pwned | Checks new passwords against known breaches. Only the first five characters of a hash are ever sent — your password never leaves our server |
We do not sell personal data, and we do not share it for advertising.
Where your data is held
Your data is stored and processed in the United States. Certificate files live in a US-region object store and the database runs in a US region; we do not replicate customer data anywhere else.
Administrative access is a separate question, and worth answering plainly. Parapet is operated from the Philippines, so the one account with production access signs in from there. That access belongs to a single named person, every provider account behind it is protected by two-factor authentication, and Parapet has no "sign in as customer" feature — the internal admin surface covers signup approvals only, not your vendor records. Reaching your data means going to the database deliberately, which happens for a support request or an incident and not otherwise. Our security page sets out the controls in full.
How long we keep it
- Certificates and vendor records — for as long as the customer's account is active, because the point of the product is a durable record.
- Audit log entries — retained long-term and never edited or deleted; the application has no ability to alter them. They are a compliance record for our customers.
- Deleted accounts — personal details are scrubbed automatically after a 30-day grace period.
- Database backups — kept for 30 days, then deleted automatically.
How we protect it
- Traffic is encrypted in transit (HTTPS).
- Certificate files are held in a private, versioned object store; download links are short-lived and issued only to a signed-in user entitled to that certificate.
- Passwords are hashed with bcrypt and checked against known breaches at signup.
- Each customer's data is isolated by organisation, enforced in the application on every query.
- The audit log is append-only at the database level: the application's database account has no permission to update or delete an entry.
- Document contents, passwords and tokens are excluded from application logs.
What we do not yet do. We are a young product and would rather say so than imply otherwise. We do not currently hold a SOC 2 report, we do not scan uploaded files for malware, and two-factor authentication is not yet available. If any of those matter to your procurement process, ask us before you buy rather than after.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or stop using it for a particular purpose. Email privacy@parapethq.com and we will respond within 30 days.
If you are a vendor or an agent, the certificate you uploaded belongs to the customer who requested it — they decide how long to keep it. We will pass your request to them and help them action it. Ask us and we will tell you who that customer is.
Where the law gives you specific rights — for example under the GDPR or the California Consumer Privacy Act — those rights apply and are not limited by this page.
Cookies
The application uses one strictly necessary cookie to keep you signed in. This marketing site uses PostHog, which sets an identifier to count returning visitors. We run no advertising cookies and no cross-site tracking.
Children
Parapet is a business tool and is not directed at anyone under 16.
Changes
If we change this policy materially we will update the date above and, for changes that affect customers, email account owners. Past versions are available on request.