Last updated: September 2, 2026
Haptco is a rental bookkeeping app for individual landlords, built and run by Neal Chou, who uses it to manage his own rentals. This policy explains what information Haptco holds, how it is used, and the choices you have. It is written in plain language on purpose.
You create an account with your email address and a password. You can also add a name and phone number to your profile. Your email address is how we identify your account and how notification emails reach you.
Haptco stores the records you add to run your rentals: properties and units, leases, rent, late fees, expenses, maintenance requests, your vendor directory, quotes those vendors send back, listings, rental applications, and screening records.
Some of these records contain personal information about your tenants, applicants, and the vendors you add — names, contact details, lease terms, payment history, and screening details. You decide what to enter, and you are responsible for having a lawful basis to collect and store it. In plain terms, you are the owner of your tenants’ information; Haptco stores and processes it on your behalf so you can manage your rentals.
Haptco has an operator view, used from a separate support account and by nobody else, so that questions sent to support can be answered. It lists every account with its email address, when it was created, when it was last used, and how many properties, units and tenants it holds.
From that list an operator can open one account and see the records in it: your properties with their addresses, your units, your tenants’ names and contact details, your lease dates and rent, and your most recent rent charges and payments. It does not show your uploaded documents, your assistant conversations, or the contents of any message. Every time an account is opened, that is written to a log recording who opened it, whose account it was, and when — the record is written before the records are shown, so a look that leaves no trace is not possible.
This exists to answer your questions, not to read your books. If you would rather nobody opened your account, email us and say so, and we will note it and ask before doing it.
The tenant portal link is worth treating as a key. Anyone holding it can see that unit’s rent without signing in — what is owed, any late fee, and the last six months of payments — alongside the maintenance requests for it. It is limited to the tenancy that is current today, so a new tenant never sees the previous one’s rent or requests, and it never shows a street address or another unit. Rent cannot be paid through it. If a link is forwarded to someone it should not reach, replacing it on the unit is what revokes the old one.
Haptco records rent, late fees, and payments as bookkeeping entries. It does not collect, hold, move, or process money, and there is no payment processor connected to the app. When a payment is marked paid, that is a note in your books, not a transfer of funds.
You can upload files such as listing photos, screening documents, expense receipts, and tenant or property documents. Tenants can also attach photos when they submit a maintenance request through their portal link. These files are kept in secure file storage provided by Supabase.
One exception is worth stating plainly: if you request quotes from vendors on a maintenance request, the photo attached to that request is shown on the private quote page each vendor opens from their email. Those vendors are not signed in to Haptco — the link itself is what lets them see it — so only request quotes on a job whose photo you are willing to show the contractors you picked.
Some features use AI. When you use one, the content it needs is sent to Anthropic’s API to produce a result:
The AI model is Claude, made by Anthropic. Under Anthropic’s commercial API terms, the data sent through the API is not used to train Anthropic’s models. AI results are aids meant to save you time — review them before you rely on them.
Haptco can send you, the landlord, notification emails: an alert when a tenant submits a maintenance request, an alert when someone applies to one of your listings, an alert when a vendor answers a request for quotes, and a daily digest of things that need attention (overdue rent, leases ending soon, open maintenance, new applications, quotes you have not seen, and a monthly summary). There is also one you ask for directly: a test copy of the screening invite, sent to your own address when you press “Send myself a test invite” in Settings, so you can check the link works before an applicant relies on it. These are delivered through Resend, which receives your email address and the message. You choose which of the notifications you receive in Settings; the test copy is only ever sent when you press the button.
One check-in, once: the morning after you create an account, if it has no tenant in it yet, Haptco sends a short note from Neal, the founder, offering to set your records up for you. It is sent one time only, replying to it reaches him directly, and it is never sent to an account that already has a tenant.
Account emails — confirming your address and resetting your password — are sent through Supabase.
Applicant email — when you send a screening invite, Haptco emails the applicant a link to the screening provider you configured, with your address as the reply-to. Haptco does not take payment for screening and does not run the check. There are two ways to check that link before an applicant depends on it, and neither involves anyone else. You can open it yourself from Settings: your browser goes to your provider exactly as it would if you typed the address, and Haptco adds nothing to it — no identifier, and nothing about the property or the applicant. You can also send yourself a test copy of the invite, which goes to the address on your own account and nowhere else — you cannot direct it elsewhere — and carries a made-up applicant and property in place of anyone real.
Finding a contractor — if you have no vendors saved, Haptco offers a link that searches a map provider for a trade near one of your properties. Nothing is sent unless you click it. The link carries the trade word, such as plumber, and the postal code of that property — or its town and state, where no postal code is saved — never the street address, never a tenant’s name, and nothing about the job. The map provider is not one of Haptco’s service providers listed below; it receives this only because your own browser goes there, the same way it would if you typed the search yourself. Haptco does not choose, rank, check or endorse anyone who appears in those results, and nothing comes back into Haptco — whoever you decide to use, you add yourself.
Address suggestions — if address autocomplete is turned on for your account, then while you type a property’s address into the add-property form, that text is sent to a map provider (Geoapify) to suggest matching addresses; your browser goes there directly, the same way the contractor link above works. It receives only what you type into that one field, never the rest of your account, and it is off unless configured — and, like the contractor search, that provider is not one of Haptco’s service providers listed below.
Vendor email — there are three ways to contact a vendor, and they work differently. The “Email” button on an assigned vendor opens your own email app, and that message is sent from your account, not from our servers. Requesting quotes is the second way: Haptco’s servers send that one for you, to the vendors you tick, through Resend. It is sent as “your name via Haptco”, your address is the reply-to, and the message says you asked us to send it and that replying is how a vendor asks to be taken off your list. The third is the acceptance notice: when you accept a vendor’s quote, Haptco emails that vendor to say they got the job, sent the same “your name via Haptco” way with your address as the reply-to — but automatically, the moment you click Accept, with no message to review first. For the latter two, Resend receives those vendors’ email addresses and the message. You are the sender of all three. For the “Email” button and the quote request, you choose the recipients and the wording before anything goes; the acceptance notice has no such step — it goes automatically, worded from the accepted quote’s details, to whichever vendor you just chose to hire.
Haptco relies on a small number of service providers, each receiving only what it needs to do its job:
Haptco counts page views, so we can tell which pages people actually reach. This is Vercel Web Analytics, part of the hosting Haptco already runs on. It sets no cookies and stores nothing on your device, and it runs on haptco.com itself rather than through an outside tracking network — though Vercel, as our host, receives and keeps the counts.
For each page view, Vercel records the time, which page it was, the page you arrived from, an approximate location worked out from your internet connection (roughly the city), your browser and operating system, and whether you are on a phone, tablet, or desktop. Vercel reports this back to us as totals rather than as a record of any one person, and states that visitors are counted using a short-lived code derived from the request that resets every 24 hours — so a visitor is not recognised from one day to the next, and is not followed to any other website. Automated traffic is excluded.
Alongside page views, Haptco counts nine actions. Six tell us whether the landing page is useful: that a spreadsheet was dropped on it — recorded, when the file is small enough to open, as one of four counts saying only how the drop went: read cleanly, read with some tabs set aside, declined because none of it could be read as a rent roll, or unreadable — and that an account was created, recorded as one of two counts depending on whether a dropped spreadsheet had been read first. Three tell us whether a new landlord gets set up, and are counted only during an account's first two weeks: that a first property was added, that a first tenant was added, and that a first spreadsheet import completed. Each of these sends a short label naming the action, and the landing-page actions also send, if you followed a link we posted somewhere, one further word naming where that link was — chosen from a short fixed list we maintain, such as a forum or a landlord association. Nothing else is sent. No part of your spreadsheet is included: it is read on your device and never uploaded, and these counts carry no file name, no amounts, no addresses, and no tenant details. The word naming the link is the same for everyone who arrives that way, so it cannot tell you apart from anybody else, and it is not stored on your device or remembered after you close the tab.
Tenant portal links, public listing links, and vendor quote links are left out of this counting entirely, and the web address is trimmed to the page itself before anything is sent — so the private part of a link is never included. This applies to the nine action counts as well.
On the public pages only — the home page, this policy, the terms, and the sign-in page — Haptco also runs Google's advertising tag, so we can tell which adverts bring people here. This one is different from the counting above in two ways you should know about: it belongs to Google rather than to our host, and it does set cookies. It is not loaded anywhere inside the app. It does not run on any page showing your properties, tenants, or payments; it does not run on tenant portal, listing, or vendor quote links; and it does not run at all once you are signed in. On the public pages where it does run, this shares information about you with Google for advertising measurement: the address of the page, your IP address, the cookie Google sets in your browser, the advert-click identifier if you arrived from an advert, and the same details your browser gives any website you visit. If you create an account on the sign-in page, Google is also told that an account was created, so we can tell which adverts actually lead to sign-ups rather than only to visits. That signal is sent at the moment you submit the form. It carries no part of your email address, no name, and nothing you later put into Haptco — and Google's "enhanced conversions" features, which would attach a scrambled form of the address you typed, are all turned off for this account. It is not sent if you only sign in, and it is not sent from anywhere inside the app.
Correction, 17 August 2026: between 13 August 2026, when the advertising tag was added, and this date, the paragraph above said that signal carried nothing about the account, including no part of your email address. That was wrong. Google's "enhanced conversions" features — there is more than one, and Google lists them as separate settings — are switched on by default when the tag is configured, and while they were on, a scrambled (hashed) form of the address typed into the sign-up form could be sent to Google together with that signal. They have all now been turned off, and the paragraph above describes what is sent.
Two different things are worth keeping apart here, because a single sentence covering both would read as a bigger promise than we can make. On the public marketing pages, the advertising tag described above does share information about visitors with Google, and that is sharing for advertising. It is limited to those pages.
What is never shared for advertising, and never sold, is what you put into Haptco: your account, your properties, your tenants, and your payments do not reach Google or any advertising network. The tag is not loaded inside the app, so no page showing those records is measured by an advertising network, and none is present on a tenant portal, listing, or vendor quote link. There is no Google Analytics and there is no session-recording tool — nothing watches what you type or replays your screen. Inside the app, the page-view and action counting described above remains the only measurement, and the records you enter are not used to build products for anyone else.
Your browser stores a few small items so the app works smoothly: your light or dark theme choice, your onboarding progress (including a note of which of the one-time action counts above were already sent, so none is counted twice), minor form conveniences, the page you were heading to before you signed in, a draft of the property details you enter on the landing page before you create an account (so your setup carries over when you sign up), a short summary of a spreadsheet you drop on the landing page, a brief note that you started signing in with Google or an email sign-in link, and — if you use the assistant — your recent conversation with it. Your login session is also kept in your browser so you stay signed in.
The spreadsheet summary is what the landing page showed you about a file you dropped — how many properties and units it appeared to cover, the months it spanned, and the total it showed — so that /import can offer to carry it over. If you drop a file before creating an account, the file itself is also kept in your browser’s local storage — never uploaded, and never leaving your browser — so that /import can bring it in after you sign up; it is removed once imported, or if you start over.
The assistant conversation is kept only in the browser tab you are using — up to the last forty messages, and fewer when they are long, because the space set aside for it is small — so it survives a page reload. It is cleared when you sign out, and it is never restored under a different account. When the assistant proposes an action for you to approve, that proposal is not stored.
Haptco can be installed as an app and opened offline. Apart from the items listed above, it only saves the app’s screens for offline use — your books, your ledger and your reports are not downloaded to your device.
Haptco keeps your data for as long as your account is active. You can edit or delete your records inside the app at any time, including individual properties, tenants, documents, and expenses; when you delete a record, it is removed from your books — most records are erased from the live database immediately, and some (like expenses) are permanently flagged as deleted and excluded from your books and reports. You can also print or export reports, such as the owner statement and the Schedule E summary.
To request a copy of all your data, or to delete your entire account and everything in it, email support@haptco.com and we will take care of it.
Haptco is a tool for running a rental business and is not intended for children. We do not knowingly collect information from children.
If we make a meaningful change, we will update this page and the date at the top.
Questions about privacy? Email us.