Nimbus-FM
← Back to Nimbus-FM
Legal

Privacy Policy

How Nimbus-FM collects, uses, and protects personal information — for a plain-language look at the technical side of how it's protected, see our Security page.

Last updated August 17, 2026

Overview

This Privacy Policy describes how Nimbus-FM ("we," "us") handles personal information for three groups of people: visitors to this website, the owners and employees of a company using Nimbus-FM, and the tenants, vendors, or other contacts a company invites into its Client Portal.

Our role in that handling is different depending on the data:

  • Service provider / processor. For employee and client/tenant records a company enters about its own staff and contacts, that company is the one who decides what's collected and how long it's kept — we act on their instructions, as their service provider. A question about those specific records is usually fastest to resolve through your company directly, though we're glad to help if you reach out to us instead.
  • Controller / organization. For account administration, billing, security and audit logs, support interactions, and this website, we're the ones deciding why and how the data is collected and used — the same way any SaaS vendor is responsible for its own operational data.

If your organization needs a Data Processing Addendum describing this relationship for a compliance or vendor-review requirement, contact us and we'll work with you on one.

Information We Collect

  • Account information. When someone signs up, we collect their name, email address, phone number, company name, and a password (stored as a one-way bcrypt hash, never in plain text).
  • Employee records. A company's administrators can add employee profiles — name, job title, phone, email, and, if they're given login access, a password.
  • Client / tenant records. Administrators can add client (tenant, vendor) contacts — name, contact name, title, phone, email, and address — and optionally grant Client Portal login access.
  • Operational business data. Property, work order, preventive maintenance, lease, and equipment records a company creates while using the Service. Some of this is free text captured at a point in time — like a work order's "requested by" name, phone, or email — which isn't automatically kept in sync with anyone's account elsewhere in the app.
  • Payment information. Billing runs entirely through Stripe. We never receive or store card numbers ourselves.
  • Session & security data. A session cookie identifying you while logged in, and — for abuse prevention — the IP address behind login, signup, and demo requests, processed transiently to enforce rate limits.
  • Audit trail. Sensitive actions (edits, deletions, permission changes) are recorded with the actor's name, the action taken, and a timestamp.

How We Use It

  • To provide and operate the Service — storing your data and showing it back to the right people.
  • To secure accounts and prevent abuse, through rate limiting and monitoring for suspicious activity.
  • To process payments and manage subscriptions, via Stripe.
  • To provide support. In limited circumstances, authorized Nimbus-FM personnel can access an account through an internal support tool — most commonly to help a company recover access after an administrator is locked out. That access is:
    • restricted to authorized Nimbus-FM personnel only,
    • used for support or technical troubleshooting, never routine or discretionary browsing of customer data,
    • limited to what's reasonably necessary to resolve the issue,
    • logged every time, and
    • ended as soon as it's no longer needed.
  • To send service email — password resets, receipts, and product updates — via our email provider, Amazon SES.
  • To comply with legal obligations.

We don't sell personal information, and we don't use it to train AI or machine-learning models without consent.

Cookies

We use strictly necessary session cookies to keep you logged in — no advertising or retargeting cookies. These cookies are HttpOnly (not readable by JavaScript on the page) and marked Secure and SameSite.

Our marketing site (nimbus-fm.com) uses Cloudflare Web Analytics, a privacy-friendly analytics tool, to see aggregate visitor counts and page views. It doesn't use cookies, doesn't collect personal data or IP addresses, and doesn't track you across other websites — which is also why there's no cookie-consent banner here.

Who We Share It With

The third parties that process data on our behalf, what we use them for, and what they receive:

ProviderPurposeData disclosed
RenderApplication hosting & database infrastructureEverything stored in Nimbus-FM — account, employee/client, and business data — since it's the infrastructure the database itself runs on.
StripeSubscription billing & payment processingBilling contact name, email, and subscription details. Card numbers go directly to Stripe and never pass through us.
Amazon SES (AWS)Transactional emailRecipient email address, plus the content of that specific email (e.g. a password reset link or notification).
CloudflareWebsite analytics for our marketing siteAggregate, anonymized page-view counts. No cookies, personal data, or IP addresses are collected.

We don't sell or rent personal information to anyone, and we don't share it with these providers beyond what's described above. We may also disclose information if required by law, such as in response to a valid court order.

Where Your Data Is Stored

Nimbus-FM's infrastructure runs on Render, currently in a US region — Render doesn't yet offer a Canadian region, so data isn't stored exclusively in Canada today, even though Nimbus-FM itself is a Canadian company. If Canadian-only data residency is a hard requirement for your organization, email us and we'll talk through it.

How Long We Keep It

  • Your account and its business data (properties, work orders, leases, and so on) are kept for as long as your company's account is active. There's currently no self-service way to delete an entire company account — contact us directly if you need your company's data removed, and we'll work with you.
  • A company's administrators can delete individual employee or client records at any time. A client with no work order history is removed outright; a client tied to existing work orders is anonymized instead — their name, contact info, and login are cleared, while the underlying work order is kept as a historical business record.
  • Session tokens expire automatically after 30 days, and password-reset links expire after an hour; expired tokens are purged on a regular schedule.
  • Security audit log entries are kept indefinitely. This is a deliberate exception to the rest of this section: an audit trail is only useful for investigating a dispute or security incident if it can't quietly disappear on a timer, so we don't currently purge it. To limit the privacy impact of that, each entry holds only minimal information — an actor's name, the action taken, and when — not a copy of the record that was changed. We'll revisit this if we can introduce a fixed retention window without compromising what the log is for.
  • Data from the free, self-serve demo is synthetic, not real data, and is automatically and permanently deleted two hours after the demo starts.

Data Export & Portability

Your data is yours. There's no one-click self-service export today — but you can request an export of your company's data at any time, and we'll provide it in a usable format (typically CSV or JSON), including:

  • Properties, work orders, and preventive maintenance records
  • Equipment and leases
  • Employee and client/tenant contacts
  • Uploaded attachments (photos, documents)
  • Audit history

This applies whether you're actively subscribed or canceling your account. If you're canceling, we'd recommend requesting your export before your account and its data are removed — email us to get started.

Security Incidents

If we become aware of a security incident that compromises the confidentiality, integrity, or availability of personal information, we will investigate, take steps to contain it, and notify affected customers without undue delay. That notification will describe, to the extent known at the time: what happened, what categories of data were involved, what we're doing in response, and what we recommend you do.

We'll cooperate with a customer's own legal or contractual obligations to notify their tenants, employees, or regulators, and we'll make any legally required regulatory notifications of our own — for example, to Canada's Office of the Privacy Commissioner or BC's OIPC — where the law puts that obligation on us directly, rather than leaving it entirely to the customer.

Your Rights

This policy, including this section, is currently written with Canadian users in mind — Nimbus-FM's customers and their tenants and employees today are primarily located in Canada, and BC's Personal Information Protection Act is the primary framework we operate under. If your organization has employees, tenants, or properties in other provinces, other countries, or specifically Quebec — where Quebec's Law 25 imposes its own distinct requirements — those laws may also apply, and we'd encourage you to flag that to us so we can work out what's needed together. As our customer base grows beyond Canada, we intend to expand this policy to explicitly address other applicable frameworks, such as PIPEDA outside BC, GDPR, or US state privacy laws.

If you're in British Columbia, or elsewhere in Canada, you generally have the right to access the personal information we hold about you, ask us to correct it, and ask how it's collected, used, and disclosed, under BC's Personal Information Protection Act. If you're an employee or tenant added to Nimbus-FM by your employer or landlord, the fastest way to exercise these rights is usually through them directly, since they control your account — but we're glad to help if you reach out to us instead. If you're not satisfied with our response, you can contact BC's Office of the Information and Privacy Commissioner.

Children's Privacy

Nimbus-FM is a business tool for commercial property management and isn't directed at, or knowingly used by, children. We don't knowingly collect personal information from anyone under 18.

Security

How we technically protect the information described in this policy — encryption, access controls, password security, and more — is covered in detail on our Security page.

Changes to This Policy

We may update this Privacy Policy from time to time. If a change is material, we'll notify active subscribers by email before it takes effect — the same way we handle material changes to our Terms.

Contact

Questions about this Privacy Policy, or a request about your personal information? Email support@nimbus-fm.com.

Nimbus-FM
© 2026 Nimbus-FM. Commercial Property Maintenance Software.