Trust
What we store, what we never store, how long we keep it, and exactly what happens to your data when you leave. No legalese — the version a security reviewer can actually read.
Last reviewed: 2026-07-11
PropSocket connects to your Property Management System (PMS) — the software you already use to run your properties, like Entrata — pulls the records you scope, and normalizes them into one consistent shape we call the Common Data Model. That synced data is the product. This page explains exactly what that means for the data you trust us with.
A note on roles before anything else: for the resident and lease data we sync, you are the data controller and PropSocket is your data processor. You decide what flows in and why; we process it on your instructions. If you need to handle a request from one of your residents, seeData subject requests.
For the current release, we store the property-management data we sync from your PMS, plus the operational records we need to run and debug the service.
Five record types, normalized into the Common Data Model:Property, Unit, Resident, Lease, andLease-Resident (the link between a lease and the people on it). Resident records can include contact details — name, email, phone, address — and, only when your PMS provides it, a date of birth and the last four digits of a Social Security Number.
We never store a full Social Security Number. Where your PMS provides one, it is masked or hashed the moment we ingest it, so the complete number is never persisted anywhere — not in our database, in raw API responses, or in logs.
We also store the basics needed to run your account: user names, work emails, and your Organization's settings.
One set of retention windows applies to every customer on every plan. Retention is not a paid upgrade. Where a window is "rolling," we keep that many days at any moment and let older records age out automatically.
| Data | How long we keep it |
|---|---|
| Your property-management records Property, Unit, Resident, Lease, Lease-Resident | For the life of your contract, plus 30 days after cancellation, then permanently deleted |
| Sync logs | 90 days, rolling |
| Webhook delivery logs | 30 days, rolling |
| API request logs | 30 days (up to 90 in larger environments) |
| Audit logs | Retained internally; provided to your team on request |
| Your PMS credentials | Encrypted at rest; permanently deleted by an automated job 7 days after you remove the integration or cancel |
| Backups | Encrypted automated backups, aged out within 30 days |
One thing to know about backups.Deleted data may still exist in our encrypted backups until they age out, which happens within 30 days. This applies to everything above — including data you ask us to hard-delete. We cannot reach into a sealed backup to remove a single record; the backup simply expires on its own schedule.
These two terms come up in every security review, so here is the difference in plain terms.
When a record is deleted in your PMS — a resident moves out, a lease ends — PropSocket marks the record as removed rather than erasing it. The record stays in our system with a "deleted" flag and a timestamp. This is deliberate: it keeps your historical reporting intact and lets your systems tell the difference between "this never existed" and "this existed and was removed."
By default, our API and dashboard hide soft-deleted records, so you see your current state. If you need the removed ones — for an audit, a reconciliation, or a report — you can ask for them explicitly. During normal operation, we never physically erase synced records.
A hard delete permanently removes the record from our active database. We hard-delete in exactly two situations:
After a hard delete, the only place a copy can remain is an encrypted backup, which ages out within 30 days as described above.
One hard limit, stated plainly.Once we have sent a record to your systems in a webhook, we cannot recall it. That copy now lives in your environment and is governed by your retention practices, not ours. Hard-deleting on our side does not reach back into your warehouse, your CRM, or anywhere else you forwarded the data.
Your synced data is yours. Cancelling does not trap it, and it does not vanish the moment you give notice. Here is the sequence.
Need it sooner? Ask. We can run an early hard-delete on a verified request — seeData subject requests. And remember the webhook limit above: anything we already pushed to your systems is on your side now.
This page covers what we do with your data. For the live picture of our compliance posture — SOC 2 status, our subprocessor list, encryption and access controls, and document requests like our Data Processing Agreement — see our Trust Center.
trust.resultstheory.com — audit status, subprocessors, and our DPA, kept current automatically.
PropSocket's SOC 2 Type II audit is in progress — we've engaged an independent audit firm and we're in the observation period, with our report expected in Q4 2026. Once complete, we expect to make the Type II report available to customers under NDA on request; today we can share our audit scope.
If your security or compliance team needs something this page doesn't cover, emailprivacy@propsocket.iofor data-handling and deletion questions, orour contact pagefor anything else. A real person will reply within one business day.
Send your security questionnaire our way. We answer the real questions, with real numbers — and a human, not a form, on the other end.