Privacy Policy
Effective: May 8, 2026
CREDashboard is an internal operations platform built and operated by BPS Partners FL(“we”, “us”) to manage our commercial real estate portfolio. This page explains what data the platform stores, who has access, and how we protect it.
Who this policy is for
- Team members with login access (employees, contractors, authorized vendors).
- Tenants, vendors, leads, and counterparties whose information we record and act on as part of normal property operations.
- Email recipients who receive correspondence sent from
send.bps-partners.comthrough this platform.
What we collect
Operational records: property details, tenant lease terms, rent and payment status, vendor contracts and certificates of insurance, lead and acquisition pipelines, project budgets and milestones, internal notes and meeting tasks.
Contact information: names, business email addresses, phone numbers, and roles for tenants, vendors, brokers, and other counterparties we do business with.
Email correspondence: outbound emails we send through the platform and inbound replies we receive at our managed addresses are stored in full so we can keep a complete record of communications tied to a property, tenant, or vendor.
Account data (team members only): name, work email, hashed password, multi-factor authentication factors, role and permissions, IP and timestamp of recent logins, and an audit log of actions taken inside the app.
Files and documents: lease agreements, certificates of insurance, project documents, signed correspondence, and other files our team attaches to records.
How we use it
- To run BPS Partners' commercial real estate operations.
- To send transactional email (renewal notices, COI requests, collections correspondence, internal digests). Emails sent from this platform are operational, not marketing.
- To generate AI-assisted drafts and summaries of communications using Anthropic's Claude API. Drafts are reviewed by a team member before anything is sent.
- To detect anomalies (overdue tasks, expiring leases, payment delinquencies) and surface them to the responsible team member.
- For legitimate business records, audit, tax, and legal compliance.
Who we share it with
We use the following service providers to run the platform. Each receives only the data needed for their role and is contractually required to protect it:
- Supabase (Postgres database, authentication, file storage).
- Vercel (web application hosting, edge functions).
- Resend (sending and receiving email on
send.bps-partners.com). - Anthropic(Claude API for AI-assisted drafting and summarization). Per Anthropic's commercial terms, content sent through the API is not used to train their models.
- Sentry(error monitoring — receives stack traces and minimal request context, not full user data).
- Upstash(rate-limiting metadata only — not your records).
- Microsoft 365 / Teams (login federation and notification webhooks).
We do not sell, rent, or transfer your information to advertisers, data brokers, or other third parties. We may disclose information when required by law (subpoena, court order) or to protect our legal rights.
How we protect it
- All traffic is encrypted in transit (HTTPS / TLS 1.2+).
- Data at rest is encrypted by Supabase (AES-256).
- Multi-factor authentication is required for admin accounts. Strong passwords (12+ characters with mixed case + digits) are enforced.
- Database access is gated by Row-Level Security policies tied to each team member's role and workspace permissions.
- We log every action taken inside the app to an immutable audit trail.
- Daily automated database backups, retained for 7 days.
- Sensitive endpoints are rate-limited to prevent brute-force and abuse.
How long we keep it
Operational records (tenants, leases, vendors, projects, correspondence) are retained for the duration of the business relationship plus a reasonable period for legal, tax, and audit purposes — typically 7 years after the relationship ends.
Audit logs are retained for 2 years. AI-generated drafts that are never sent are pruned after 14 days. Account data is retained while the account is active and deleted within 30 days of account closure unless we're required to keep it.
Your rights
If you are a tenant, vendor, lead, or other counterparty whose data we hold, you may request to:
- See what information we have about you.
- Correct inaccurate information.
- Delete information that is no longer needed for an active business relationship or legal obligation.
- Receive a copy of the information you provided to us.
To exercise these rights, email privacy@bps-partners.com. We aim to respond within 30 days.
Breach notification
If we become aware of a security incident that compromises personal information, we will notify affected individuals and, where required, the Florida Department of Legal Affairs in accordance with the Florida Information Protection Act (FIPA), generally within 30 days of discovery.
Children
CREDashboard is a B2B tool. We do not knowingly collect information from anyone under 18.
Changes to this policy
We may update this page from time to time. The effective date at the top reflects the most recent change. For material changes, we'll notify team members via email or in-app notice.
Contact
Questions about this policy or how your data is handled? privacy@bps-partners.com