CoHost Pro — Privacy Policy
Effective Date: 2026-04-29 · Last Updated: 2026-04-29
1. Who We Are
CoHost Pro (“we,” “us,” “our”) is a property management platform operated by NetAesthetics LLC, a company registered in Washington, D.C., United States. This Privacy Policy explains how we collect, use, share, and protect personal information when you use our platform, fill out forms hosted on our domain (such as /forms/<company>/contact or /apply/<company>), or otherwise interact with us.
This policy applies to:
- Property managers (and their team members) who use the CoHost Pro platform to manage their property-management business
- Homeowners who apply to list properties through partner property managers, or who complete onboarding sessions through our platform
- Form submitters — anyone who fills out a public form hosted at
/forms/<company>/<form-type>
It does not cover:
- Property managers’ own marketing websites (linked to from our forms but operated by them under their own privacy practices)
- Third-party services we link to but do not control (e.g., Google’s reCAPTCHA terms, Google Maps Platform terms)
2. Information We Collect
2.1 From property managers and their team
- Name, email, phone, role within the company
- Company information: name, slug, addresses, website URL, branding assets (logo, brand colors, welcome video)
- Authentication credentials (managed via our authentication provider; we do not see plaintext passwords)
- Activity within the platform: who performed which action when (audit log)
2.2 From homeowners (applications and onboarding)
- Name, email, phone, mailing address
- Property details: address, type, bedrooms, bathrooms, sleeps, square footage, photos
- Identity verification information when required by the property manager
- Banking information for revenue distribution (encrypted at rest)
- Tax-related information (e.g., W-9 / W-8 details) when applicable
- Photos and videos of properties
2.3 From form submitters (contact and similar public forms)
- Name (first and last)
- Phone (when provided)
- Property address (when provided)
- Free-text message content
- Marketing-source information when present (referer header, UTM parameters)
2.4 Automatically when you visit
- IP address
- Browser and device information (user agent string)
- Referrer URL (where you came from before reaching us)
- Pages visited and approximate time spent
- Approximate geographic region (derived from IP)
2.5 From cookies and analytics — only when you grant consent
On public form pages (/forms/* and /apply/*), if you accept the consent banner:
- Google Analytics 4— anonymized session data, event interactions, conversion attribution. Sent to the property manager’s own GA4 property when they have configured one.
- Microsoft Clarity — behavioral session recordings (mouse movement, scroll, click patterns), heatmaps. Form input values are masked by default and never recorded in plain text.
If you decline the banner, neither service runs and no analytics cookies are set.
3. How We Use Your Information
- Operate the CoHost Pro platform and provide the services you have requested
- Route form submissions and applications to the relevant property manager
- Send transactional emails (account creation, password reset, application status updates, onboarding reminders)
- Improve product reliability, performance, and user experience
- Analyze form completion patterns and identify usability friction (only with consent)
- Detect and prevent fraud, spam, abuse, and unauthorized access
- Maintain audit logs for security and compliance
- Comply with legal and regulatory obligations
4. How We Share Your Information
We do not sell your personal information. We share it with the following categories of third parties, each acting as a service provider or processor on our behalf:
| Service | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | United States |
| Resend | Transactional email delivery | United States |
| Vercel Inc. | Web hosting, edge runtime, request routing | United States (multiple regions) |
| Google LLC — Maps Platform | Address autocomplete on forms | Global |
| Google LLC — reCAPTCHA | Spam and bot prevention on public forms | Global |
| Google LLC — Google Analytics 4 | Conversion and funnel analytics (per-property-manager when configured; only with your consent) | Global |
| Microsoft Corporation — Clarity | Behavioral analytics and session recordings (per-property-manager when configured; only with your consent) | Global |
| The relevant property manager | When you submit a form or application, that information is delivered to the property manager you contacted | Varies (managed by the property manager) |
Each of the above operates under its own privacy practices. We choose providers we believe are reputable, but we do not control their internal policies. Links to their privacy policies are available on their websites.
We may also disclose personal information if required by law, court order, or to protect the rights, property, or safety of CoHost Pro, our users, or others.
5. Data Retention
- Form submissions: retained for as long as the property manager’s account is active, plus a reasonable backup window (typically 30 days) after deletion or account closure
- Onboarding data: retained while the homeowner remains an active client of the property manager; deleted on request from the homeowner or property manager subject to legal retention requirements
- Audit logs: retained as long as needed for security investigations, compliance obligations, and incident response
- Rate limit and operational logs: retained briefly (typically less than 24 hours) and used only to enforce abuse-prevention limits
- Analytics data: subject to Google Analytics and Microsoft Clarity retention policies (typically up to 14 months for GA4 by default; up to 1 year for Clarity by default). Property managers configure their own retention windows in their analytics consoles.
You can request deletion of your personal information at any time — see Your Rights.
6. Security
We use industry-standard practices to protect your information:
- Transport encryption (HTTPS / TLS) for all data in transit
- Encryption at rest for sensitive fields (banking information, tax identifiers)
- Role-based access controls within the platform
- Row-level security on the database, enforced per account
- Audit logging of administrative actions
- Spam and bot prevention via reCAPTCHA, server-side rate limiting, and behavioral signals
- Per-action body size limits and content security headers on public surfaces
No system is perfectly secure. If we discover a breach affecting your personal information, we will notify affected users in accordance with applicable law.
7. Your Rights
7.1 California residents (CCPA / CPRA)
You have the right to:
- Know what personal information we collect about you
- Access and receive a copy of your information
- Correct inaccurate information
- Delete your information (subject to certain exceptions)
- Opt out of the sale or sharing of personal information
- Limit the use of sensitive personal information
- Be free from retaliation for exercising your rights
We do notsell personal information for monetary value. We do share certain identifiers and behavioral data with analytics providers (Google Analytics, Microsoft Clarity) only when you have granted consent. You can withdraw that consent at any time via the consent banner or by clicking “Privacy choices” in our public form footers.
To exercise your rights, email privacy@cohost.pro.
7.2 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)
If you are in the EEA, UK, or Switzerland, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request erasure (“right to be forgotten”)
- Restrict or object to processing
- Data portability (receive your data in a portable format)
- Withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal
- Lodge a complaint with your local supervisory authority
Our legal bases for processing are:
- Contract — to provide the services you have requested (account, applications, etc.)
- Legitimate interests — to operate, secure, and improve the platform
- Consent — for analytics tools (Google Analytics, Microsoft Clarity) on public surfaces
- Legal obligation — for tax, accounting, regulatory, and fraud-prevention purposes
To exercise your rights, email privacy@cohost.pro.
7.3 Other jurisdictions
We honor data subject rights as required by applicable law. Email privacy@cohost.pro with any request and we will respond within the period required by your jurisdiction’s law (typically 30–45 days).
8. International Data Transfers
We are a US-based service. Personal information is processed and stored primarily in the United States and may be subject to US laws and government access requests. If you access our service from outside the United States, your information will be transferred to, stored in, and processed within the US.
Where required by law, we rely on appropriate safeguards for cross-border transfers, including Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable.
9. Cookies and Similar Technologies
When you visit our public form pages (/forms/* and /apply/*), we may use cookies and similar technologies, but only after you grant consent through the banner shown on first visit. The categories include:
- Strictly necessary — required for the form to function (CSRF protection, captcha state, consent state itself); always active
- Analytics — Google Analytics, Microsoft Clarity; active only when consent is granted
- Functional — your interaction preferences with the platform
You can change your consent at any time by clicking “Privacy choices” in the form footer. We do not use cookies for advertising or third-party retargeting.
10. Children’s Privacy
Our service is not directed to children under 16. We do not knowingly collect personal information from children. If we learn we have collected information from a child without parental consent, we will delete it promptly. If you believe we have inadvertently collected information from a child, please contact us at privacy@cohost.pro.
11. Changes to This Policy
We may update this policy from time to time. The “Last Updated” date at the top reflects the most recent revision. Significant changes will be communicated via email to active platform users at least 30 days before they take effect, where feasible. Your continued use of the platform after a change constitutes acceptance of the updated policy.
12. Contact Us
For privacy questions, requests, or complaints:
- Email: privacy@cohost.pro
- Mail: NetAesthetics LLC, 2001 L Street N.W., Suite 500, Washington, DC 20036
If you are in the EEA, UK, or Switzerland and we have not satisfactorily resolved your concern, you have the right to lodge a complaint with your local data protection authority.