Privacy Policy
Effective: 18 July 2026
This policy reflects how the Tecurve application actually works — its authentication, data storage, and third-party integrations.
1. Introduction
This Privacy Policy explains how Tecurve ("Tecurve", "we", "us", or "our") collects, uses, stores, and protects information when you use the Tecurve web application (the "Service") — a tool for individual property owners and landlords to track their own properties, tenants, income, expenses, mortgages, insurance policies, and related reminders.
Tecurve is operated as a single-tenant-per-account platform: each user account only ever sees and manages data that the account holder themselves enters. There is no marketplace, listing, or multi-party matching functionality — all property, tenant, and financial records in your account are entered by you, for your own record-keeping.
Who operates the Service and which law applies. Tecurve currently operates without a separately registered legal entity; "Tecurve" refers to the operator of the Service. This policy, and Tecurve's handling of your personal data, are governed by the laws of the United Arab Emirates, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL") and its implementing regulations.
2. Information We Collect
2.1 Account information (provided by you at sign-up)
- Email address — required, used as your login identifier.
- Password — required; never stored in plain text. Only a salted hash is stored. Tecurve enforces a minimum of 8 characters with at least one lowercase letter, one uppercase letter, one digit, and one symbol, both in the browser and on the server.
- Display name (optional) — an optional username you may provide at sign-up.
- Portfolio size band (optional) — a self-selected range (e.g. "1-5", "5-10", "10-20", "20+") indicating roughly how many properties you manage, collected at sign-up to tailor the product.
2.2 Property records (entered by you)
- Property nickname/name, purchase price, purchase date, location/address, and UAE property-registry identifiers where applicable: title deed number, plot number, DEWA premise number, and Makani number.
- Building/project name, unit number, developer name and off-plan project details (for off-plan purchases), and free-text notes you add.
- Co-owner records you enter for a property: co-owner name and ownership percentage. These may relate to individuals who are not themselves Tecurve users (see Section 3 and Section 10).
2.3 Tenant and occupant records (entered by you)
- Tenant name, phone number, and email address.
- Emirates ID number (UAE national identity number) — collected as a text field if you choose to enter it for a tenant or co-occupant.
- Lease start/end dates, annual rent amount, and Ejari (UAE tenancy contract registration) number, registration date, and expiry date.
- Co-occupant name, relationship to the tenant, Emirates ID, and phone number, where you choose to record additional occupants.
2.4 Financial records (entered by you)
- Income entries: amount, payment mode, category, and notes.
- Expense entries: amount, vendor, invoice number, and category.
- Payment schedules: amounts, bank name, payment reference, due dates and status — used for rent instalments, developer/off-plan payment plans, mortgage instalments, and insurance premium due dates.
- Mortgage details: lender name, loan amount, down payment, interest rate, monthly instalment (EMI), and outstanding balance.
- Insurance policy details: insurer name, policy number, premium amount, coverage type, and expiry date.
- Property valuation estimates you record over time.
2.5 Reminders and notification preferences
- Per-reminder-type settings: whether a reminder is enabled, how many days before the due date to notify you, and which channel(s) — in-app, email, or both.
- Reminder state: whether a given reminder has been read or snoozed, and a record of which reminder emails have already been sent (to avoid duplicate emails). This ledger records that an email was sent and when, not its content.
Reminders themselves (e.g. "lease expiring in 14 days") are calculated on demand from your property, tenant, mortgage, insurance and payment-schedule data — they are not stored as a separate list of notification records.
2.6 Contact form submissions
- Name (optional), email address, and message text submitted through the public contact form.
- Your IP address, captured server-side for spam/abuse prevention (rate-limiting) and stored alongside the message.
The contact form is unauthenticated (no login required) and protected by a hidden honeypot field and Cloudflare Turnstile, a bot-verification challenge. Solving the Turnstile challenge sends your browser's token to Cloudflare for verification; see Section 5. See Section 11 for how contact submissions are retained.
2.7 In-app feedback submissions
- Category (feedback / bug / feature request / other), your message, and the page/route you were on when you submitted it.
- Your account email address and user ID (feedback is only available to signed-in users).
2.8 Automatically collected technical information
- IP address — collected only in the context of the public contact form (Section 2.6), for rate-limiting and Turnstile verification. Tecurve does not otherwise log or store IP addresses for general application usage.
3. Information We Do Not Collect
Based on a full review of the database schema, application code, and edge functions, Tecurve does not collect or store:
- Payment card numbers, bank account numbers, or any other payment credentials — Tecurve is not a payment processor and does not integrate with one. Financial fields you enter (rent, mortgage amounts, etc.) are for your own record-keeping only.
- Passport numbers or government-issued photo ID numbers other than the Emirates ID number field, which you may optionally enter for a tenant or co-occupant.
- Scanned or uploaded documents or images of any kind — no property photos, tenant ID scans, lease PDFs, or other file uploads. Tecurve does not use any file storage feature, so no document/image upload capability exists in the application at all.
- Precise device geolocation (GPS coordinates). "Location" fields on a property record are free-text address information you type in, not device-derived location data.
- Date of birth, for you or for tenants/co-occupants.
- Biometric data of any kind.
- Social Security Numbers or non-UAE national identity numbers.
- Advertising identifiers, browsing history across other sites, or any cross-site tracking data — Tecurve does not use any advertising or analytics SDK (see Section 7).
- Social login profile data (e.g. from Google or Facebook) — Tecurve only supports direct email-and-password accounts; no OAuth/social sign-in is implemented.
4. How We Use Your Information
- To create and secure your account, and to authenticate you when you log in.
- To provide the core Service: storing and displaying the property, tenant, financial, and reminder records you enter, and performing calculations (e.g. income/expense totals, upcoming due dates) on that data for you.
- To send you reminder emails about upcoming lease expiries, Ejari renewals, mortgage instalments, insurance renewals, or payment due dates — only for the reminder types and channels you have enabled in your notification settings, and only to your own account email address.
- To send you account-related emails: email verification at sign-up and password-reset emails.
- To respond to messages you send through the contact form or in-app feedback form.
- To detect and prevent abuse of the public contact form (rate-limiting by IP address, bot-challenge verification).
- To notify Tecurve's operator internally when a new account is created or an account is deleted. This internal alert contains only your email address, user ID, and the optional sign-up metadata (display name / portfolio size); it does not include your property, tenant, or financial data.
Tecurve does not use your information for advertising, does not build behavioural or advertising profiles, and does not sell your information.
5. Third-Party Services
Tecurve relies on the following third-party service providers to operate. Each is a data processor acting on Tecurve's instructions — none of them independently use your data for their own purposes (e.g. advertising).
- Supabase — database, authentication, and backend hosting (all application data lives here). Data shared: all account and application data described in Section 2.
- Resend — transactional email delivery (reminder digests, verification emails, password resets, contact/feedback notifications, admin alerts). Data shared: recipient email address and the content of the specific email being sent.
- Cloudflare (Turnstile) — bot/spam verification on the public contact form. Data shared: a verification token generated by your browser, plus your IP address, sent to Cloudflare for validation.
Tecurve does not use any analytics, advertising, error-monitoring, or session-recording third party (e.g. Google Analytics, Meta Pixel, Sentry, PostHog, Mixpanel). Tecurve does not integrate any payment processor, SMS provider, or mapping/geolocation SDK.
Weekly encrypted backups of the database (see Section 8) are stored as artifacts and releases within Tecurve's private GitHub repository. GitHub, as the hosting platform for these backups, is therefore also a data processor with encrypted access to a copy of the database.
6. Authentication
- Tecurve uses Supabase Auth for account creation and login, via email address and password only — there is no "Sign in with Google/Facebook/Apple" option and no magic-link login.
- Passwords are never stored by Tecurve in readable form; Supabase Auth stores a salted hash. Tecurve enforces a minimum 8-character password with mixed case, a digit, and a symbol.
- New accounts must verify their email address before the account is fully usable.
- Forgotten passwords are reset via an emailed, single-use reset link, not by Tecurve staff having access to or resetting your password directly.
- Your session is kept signed-in in your browser's local storage, which stores your access and refresh tokens so you don't need to log in on every visit. Signing out, or clearing your browser's site data, removes these tokens from your device.
- Multi-factor authentication (MFA) is not currently offered.
- Deleting your account (Section 12) requires you to re-enter your current password as a secondary confirmation step, even though you are already signed in.
7. Cookies and Tracking Technologies
Tecurve does not use cookies for tracking, advertising, or analytics, and does not use any third-party tracking pixel or script.
What is actually stored in your browser:
- Local storage: your authentication session (access and refresh tokens), so you remain signed in between visits. This is functionally required for the Service to work and is set by the authentication library, not by a tracking script.
- Session storage: a single, non-personal flag recording that today's reminders pop-up has already been shown to you. This clears automatically at the end of your browser session and contains no personal data.
- One cookie: an interface-preference cookie that remembers whether the app's sidebar menu is open or collapsed. It stores only a UI-state value and is unrelated to authentication, tracking, or advertising.
Because this storage is strictly necessary for the Service to function and no non-essential, advertising, or third-party tracking cookies are used, Tecurve does not display a cookie-consent banner. Under the PDPL, this strictly functional storage does not require separate consent.
8. Data Storage
- All application data (accounts, properties, tenants, financial records, reminders, feedback, and contact messages) is stored in a Supabase-hosted PostgreSQL database, hosted in Amazon Web Services' Asia Pacific (Tokyo) region (ap-northeast-1) in Japan.
- Every table that holds your personal records is protected by database-layer access controls that restrict access so that, through the application's normal API, an account can only read or write rows it owns. Public contact-form submissions are locked down further — end users, including the submitter, cannot read them back through the API at all.
- Weekly encrypted database backups run automatically and are stored as GitHub Actions artifacts and, once a month, as a longer-term GitHub Release within Tecurve's private source-code repository. Backups are encrypted with AES-256 before leaving the database; the decryption passphrase is kept as a separate secret, not stored alongside the backup files.
- Outbound transactional emails (reminders, verification, password reset, contact/feedback notifications) are processed by Resend to deliver the message to your inbox.
9. Data Security
- Passwords are hashed, never stored or logged in plain text.
- Database access is governed by access-control policies scoped to each authenticated user, enforced at the database layer, not just in application code.
- Server-only credentials (including database admin keys and all third-party API keys) are kept as server-side secrets and are never bundled into or exposed by the code that runs in your browser.
- Sensitive backend operations (sending reminder emails, deleting an account) run as server-side functions, authenticated either by your session token or, for scheduled/system jobs, by a separate server-held secret — never by a client-supplied value alone.
- Account deletion requires re-authentication with your current password (Section 6).
- Database backups are encrypted (AES-256) before storage, and each backup run automatically verifies that the encrypted file can be decrypted and restored.
- Exported files are outside these protections. Data you export from Tecurve (see Section 13) is downloaded to your own device as an unencrypted Excel or PDF file. Once exported, it is no longer covered by the access controls above — keep exported files somewhere secure, avoid sharing them over unsecured channels, and delete them when you no longer need them.
No method of storage or transmission is completely secure. While Tecurve takes the measures above, it cannot guarantee absolute security.
10. Your Rights
Under the UAE PDPL, and subject to the conditions and exceptions in that law, you have the right to:
- Be informed about how your personal data is processed (this policy).
- Access the personal information Tecurve holds about you, and request a copy of it.
- Correct inaccurate or incomplete information — for most fields, you can do this directly within the app.
- Request deletion of your personal data and your account (see Section 12).
- Request that Tecurve restrict or stop certain processing, and object to processing in the circumstances allowed by law.
- Request portability of your data — you can export it yourself at any time in a structured, machine-readable format from the Reports & Export page in the app (see Section 13).
- Withdraw consent for optional communications — reminder emails can be turned off per reminder type in your notification settings.
To exercise any right that isn't directly available in the app's interface, contact Tecurve using the details in Section 17. If you believe your data has not been handled in line with the PDPL, you may also lodge a complaint with the UAE Data Office (the competent supervisory authority).
11. Data Retention
- Your account and application data (properties, tenants, financial records, reminders, notification settings) are retained for as long as your account remains open, so the Service can function, and are deleted when you delete your account (Section 12).
- Public contact-form submissions are retained in Tecurve's database and may be removed manually by an operator. They are not linked to a user account and so are not affected by the account-deletion process in Section 12.
- The reminder-email ledger (a record that a given reminder email was already sent) is deleted along with your other account data when your account is deleted.
- Encrypted weekly database backups are retained for up to 90 days (rolling artifacts). Monthly backups are retained indefinitely as long-term disaster-recovery archives. This means that after you delete your account, a copy of your data may continue to exist in an encrypted backup after it has been removed from the live application; it is overwritten or removed only in the ordinary course of backup rotation.
12. Account Deletion
- You can permanently delete your Tecurve account from within the app. You will be asked to re-enter your current password to confirm the request.
- Deletion is immediate and permanent (a "hard delete"), not a soft delete or deactivation — there is no recovery/undelete window once the request is confirmed.
- Deleting your account permanently removes: your login credentials, all properties, tenants and co-occupants, income and expense records, payment schedules, mortgages, off-plan and insurance details, property valuations, reminder settings and history, and your feedback submissions.
- As noted in Section 11, encrypted database backups created before your deletion request may retain a copy of your data until that backup is rotated out (up to 90 days for weekly backups; monthly archives are retained indefinitely for disaster recovery).
13. Data Export
You can export your data at any time from the Reports & Export page inside the app. Exports are produced in commonly used, machine-readable formats — an Excel workbook (.xlsx) or a PDF summary report — and can be filtered by property, date range, and data type. Exports are generated from your own account only.
Exported files may contain personal data about third parties you have recorded (for example tenant contact details). Once downloaded, those files are outside Tecurve's control, and you are responsible for storing and handling them lawfully.
If you need your data in a different format, or need help exercising your PDPL data-portability right, contact Tecurve using the details in Section 17. We will respond within a reasonable period — and in any event within the timeframe required by applicable law (generally within 30 days) — after we have verified your identity.
14. Children's Privacy
Tecurve is a property-management tool intended for adults who own or manage real property, and is not directed at children. Tecurve does not knowingly collect personal information from children. If you believe a child has provided personal data to Tecurve, contact us using the details in Section 17 and we will delete it.
15. International Data Transfers
Your personal data is stored and processed outside the United Arab Emirates. The Supabase database that holds your account and application data is hosted in Amazon Web Services' Asia Pacific (Tokyo) region (ap-northeast-1) in Japan. Encrypted database backups (hosted by GitHub) and transactional email delivery (Resend) may be processed in other countries, including the United States. Where this involves a cross-border transfer of personal data, Tecurve relies on its service providers' contractual and security safeguards for such transfers, and on the transfer mechanisms permitted under the PDPL.
16. Changes to this Policy
Tecurve may update this Privacy Policy from time to time to reflect changes in the Service or applicable law. The "Effective date" at the top will be updated accordingly, and where changes are material we will take reasonable steps to bring them to your attention (for example, by email or an in-app notice) before they take effect.
17. Contact Information
Questions, requests, or concerns about this Privacy Policy or your personal data can be directed to:
- Email: contact@tecurve.com