Security & trust
SpotsOnSpots gives your property management team a clean tool to run an in-building parking marketplace: residency-verified listings, written agreement template, and a clear escalation path back to your team for any dispute.
Residency verification
Every Owner and every Renter is verified as a current resident of their Building before a listing goes live and before a rental request is approved.
Verification is performed by Building management against the HOA roster, not by SpotsOnSpots independently. Our role is to surface the listing or request to the verified Building admin and to block it from going live until they approve.
A Building can pause new sign-ups, revoke access for a specific resident, or remove a listing at any time.
Closed-loop access
SpotsOnSpots is not open to the public. The marketplace is scoped to residents of participating Buildings only. There are no commuters, no non-resident renters, no guests browsing the platform.
Building access (fobs, gate codes, license-plate recognition) is unchanged. SpotsOnSpots operates on top of your existing access control, not in place of it. When a rental is approved, the Owner grants garage access through the Building's existing guest process, ideally plate-based or a garage-only credential rather than a shared personal fob. Our Garage Access Guide covers the safe way to grant access and how to close it out at the end of a term.
Data & infrastructure security
SpotsOnSpots runs on managed, industry-standard infrastructure. The controls below protect resident data end to end.
- Encryption in transit. Every connection is HTTPS/TLS, and HTTP Strict Transport Security is enforced for a year, so browsers never fall back to an unencrypted connection.
- Encryption at rest. Resident data is stored in managed PostgreSQL on Supabase, encrypted at rest with AES-256.
- Per-building isolation, enforced in the database. Access is controlled by PostgreSQL Row-Level Security on every table, not just in the interface. A resident, owner, or admin can read only what their role and building allow — a resident of one building cannot see another building's spots, roster, or contact details, even through the API.
- Authentication. Sign-in is handled by Supabase Auth. Passwords are hashed with bcrypt and never stored or transmitted in plain text; sessions use an HTTP-only cookie.
- Hardened delivery. A strict Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and a restrictive Permissions-Policy are set on every page to mitigate cross-site scripting, clickjacking, and MIME-sniffing.
Data minimization
We deliberately hold as little sensitive data as possible.
- No payment card or bank data. Payments happen directly between residents, off-platform, so SpotsOnSpots never touches card numbers, bank accounts, or routing details, and stays out of PCI scope.
- No government identifiers. We do not collect Social Security numbers, dates of birth, or driver's-license numbers.
- What we do hold: name, unit, email, phone, vehicle and license plate (for an active rental), and the payment-app handle an owner chooses to display. Contact details are exchanged between two residents only after a rental is approved, never shown to anyone browsing.
Where your data lives, and leaves
A Building's directory, listings, rentals, and full action log export to CSV from the dashboard at any time. If a Building ends its subscription, its data stays exportable, and we delete it on request within 14 days, subject to legal retention obligations.
Subprocessors: Supabase (database, authentication, storage; United States, us-east-2), Resend (transactional email), Netlify (hosting), and SimpleAnalytics (cookieless, no personal identifiers). Full detail is in our Privacy Policy.
Incident response
If we confirm a security incident affecting a Building's data, we notify that Building's admin promptly — our target is within 72 hours of confirmation — with what we know and the steps we're taking, and we coordinate on any resident notice. You can report a suspected issue any time at hello@spotsonspots.com.
Documentation for your review
For a property-management or IT review, download the Security & Privacy Overview (PDF): a single document covering our data handling, infrastructure, subprocessors, and answers to a standard vendor-security questionnaire.
Being straight about our stage: SpotsOnSpots is early and independently operated. We do not yet hold a SOC 2 attestation, and additional admin-account protections, including multi-factor authentication, are being rolled out. We're glad to walk your team through any of this directly.
Written rental agreement
Every approved rental is encouraged to be documented with a written agreement covering term, rate, payment method, access, and termination. SpotsOnSpots provides a downloadable rental agreement template as a starting point.
The agreement is between Owner and Renter; SpotsOnSpots is not a party.
Dispute escalation
If something goes wrong between an Owner and a Renter, here's how it's handled:
- Direct conversation. Most disputes are resolved between neighbors with a single conversation. Encouraged first.
- Property management. Your property management team is the mediator and authority for any resident-to-resident dispute that can't be worked out directly: garage access, vehicle damage, behavioral concerns, payment disagreements. They use the platform dashboard to revoke listings or suspend accounts when needed.
- Account removal. If a user violates the terms or building rules, property management can revoke their access from the dashboard. Removed users can't list, rent, or browse.
SpotsOnSpots is a marketplace platform; we do not directly mediate resident-to-resident disputes. Your property management team owns that relationship.
What SpotsOnSpots is not
It's important to be clear about the platform's role:
- SpotsOnSpots is not a real estate broker. We don't list units or arrange leases.
- SpotsOnSpots is not a property manager. Your PMC operates, maintains, and enforces rules within your building. We just give them a dashboard.
- SpotsOnSpots is not a payment processor. Owners and Renters arrange payment directly using third-party methods (Venmo, Zelle, ACH, check). SpotsOnSpots does not take any percentage of resident-to-resident rentals.
- SpotsOnSpots is not an insurer. Vehicle damage and liability are between the residents and their respective personal insurance policies. Garage common-element damage falls under your existing building rules.
- SpotsOnSpots is not a support team. Resident-to-resident issues are handled by your property management team. We don't mediate disputes, take service calls, or run on-call coverage.
What we are: a single dashboard your property management team uses to run resident parking. Unit ↔ spot ↔ resident ↔ vehicle ↔ rental, all in one editable, searchable, exportable system of record.
Contact
Security or trust questions? Email hello@spotsonspots.com. We respond within 24 hours on weekdays.