How Nimbus-FM collects, uses, and protects personal information — for a plain-language look at the technical side of how it's protected, see our Security page.
Last updated August 17, 2026
This Privacy Policy describes how Nimbus-FM ("we," "us") handles personal information for three groups of people: visitors to this website, the owners and employees of a company using Nimbus-FM, and the tenants, vendors, or other contacts a company invites into its Client Portal.
Our role in that handling is different depending on the data:
If your organization needs a Data Processing Addendum describing this relationship for a compliance or vendor-review requirement, contact us and we'll work with you on one.
We don't sell personal information, and we don't use it to train AI or machine-learning models without consent.
We use strictly necessary session cookies to keep you logged in — no advertising or retargeting cookies. These cookies are HttpOnly (not readable by JavaScript on the page) and marked Secure and SameSite.
Our marketing site (nimbus-fm.com) uses Cloudflare Web Analytics, a privacy-friendly analytics tool, to see aggregate visitor counts and page views. It doesn't use cookies, doesn't collect personal data or IP addresses, and doesn't track you across other websites — which is also why there's no cookie-consent banner here.
The third parties that process data on our behalf, what we use them for, and what they receive:
| Provider | Purpose | Data disclosed |
|---|---|---|
| Render | Application hosting & database infrastructure | Everything stored in Nimbus-FM — account, employee/client, and business data — since it's the infrastructure the database itself runs on. |
| Stripe | Subscription billing & payment processing | Billing contact name, email, and subscription details. Card numbers go directly to Stripe and never pass through us. |
| Amazon SES (AWS) | Transactional email | Recipient email address, plus the content of that specific email (e.g. a password reset link or notification). |
| Cloudflare | Website analytics for our marketing site | Aggregate, anonymized page-view counts. No cookies, personal data, or IP addresses are collected. |
We don't sell or rent personal information to anyone, and we don't share it with these providers beyond what's described above. We may also disclose information if required by law, such as in response to a valid court order.
Nimbus-FM's infrastructure runs on Render, currently in a US region — Render doesn't yet offer a Canadian region, so data isn't stored exclusively in Canada today, even though Nimbus-FM itself is a Canadian company. If Canadian-only data residency is a hard requirement for your organization, email us and we'll talk through it.
Your data is yours. There's no one-click self-service export today — but you can request an export of your company's data at any time, and we'll provide it in a usable format (typically CSV or JSON), including:
This applies whether you're actively subscribed or canceling your account. If you're canceling, we'd recommend requesting your export before your account and its data are removed — email us to get started.
If we become aware of a security incident that compromises the confidentiality, integrity, or availability of personal information, we will investigate, take steps to contain it, and notify affected customers without undue delay. That notification will describe, to the extent known at the time: what happened, what categories of data were involved, what we're doing in response, and what we recommend you do.
We'll cooperate with a customer's own legal or contractual obligations to notify their tenants, employees, or regulators, and we'll make any legally required regulatory notifications of our own — for example, to Canada's Office of the Privacy Commissioner or BC's OIPC — where the law puts that obligation on us directly, rather than leaving it entirely to the customer.
This policy, including this section, is currently written with Canadian users in mind — Nimbus-FM's customers and their tenants and employees today are primarily located in Canada, and BC's Personal Information Protection Act is the primary framework we operate under. If your organization has employees, tenants, or properties in other provinces, other countries, or specifically Quebec — where Quebec's Law 25 imposes its own distinct requirements — those laws may also apply, and we'd encourage you to flag that to us so we can work out what's needed together. As our customer base grows beyond Canada, we intend to expand this policy to explicitly address other applicable frameworks, such as PIPEDA outside BC, GDPR, or US state privacy laws.
If you're in British Columbia, or elsewhere in Canada, you generally have the right to access the personal information we hold about you, ask us to correct it, and ask how it's collected, used, and disclosed, under BC's Personal Information Protection Act. If you're an employee or tenant added to Nimbus-FM by your employer or landlord, the fastest way to exercise these rights is usually through them directly, since they control your account — but we're glad to help if you reach out to us instead. If you're not satisfied with our response, you can contact BC's Office of the Information and Privacy Commissioner.
Nimbus-FM is a business tool for commercial property management and isn't directed at, or knowingly used by, children. We don't knowingly collect personal information from anyone under 18.
How we technically protect the information described in this policy — encryption, access controls, password security, and more — is covered in detail on our Security page.
We may update this Privacy Policy from time to time. If a change is material, we'll notify active subscribers by email before it takes effect — the same way we handle material changes to our Terms.
Questions about this Privacy Policy, or a request about your personal information? Email support@nimbus-fm.com.