Privacy Policy
1. Who this applies to
This policy explains how Top Hat handles personal information for two groups of users:
- Owners / landlords — our primary customers, who manage properties in Top Hat.
- Tenants — invited by an owner to view their tenancy and submit repair requests. For tenant records, the owner is the controller and Top Hat processes the data on the owner's behalf.
It also covers visitors to our website.
2. What we collect
We practise data minimisation — we collect only what the product needs to function.
From owners: name, email, password (stored hashed by our auth provider), organization name, timezone and currency preferences, and the property, unit, lease, financial, maintenance, document, and expense records they enter.
From tenants: name, email, phone, the unit/lease they are linked to, maintenance requests and photos they submit, and rent status derived from records the owner maintains.
Documents: files an owner uploads (e.g. lease agreements, IDs, insurance, receipts) and any files a tenant attaches to a repair request.
Automatically: standard technical data such as IP address, device/browser type, and security and error logs needed to operate and protect the service. Three specifics worth naming plainly:
- Essential cookies: we set a small number of strictly-necessary cookies to keep you signed in and to secure your session. We do not use advertising or third-party tracking cookies.
- Abuse protection: we keep short-lived counters keyed to IP address (or account) on sign-in, sign-up, invitation, and repair-submission endpoints to throttle abuse. These counters hold no personal content and expire within one hour.
- Error monitoring: when something breaks we receive a technical error report (via Sentry). We deliberately strip these reports before they leave the app: no cookies, no form contents, no query strings, no email addresses — at most an internal account identifier, so we can fix your problem without reading your data. We do not use session replay.
We also store your notification preferences (which alerts you've turned on or off).
We do not collect or store tenant payment-card or bank-account numbers. Rent payments are recorded manually by the owner at launch; any future integrated payments will be handled by a PCI-compliant payment processor, not stored by Top Hat.
3. How we use it
- to provide the service (manage portfolios, surface risk, enable repair requests);
- to authenticate users and keep accounts secure;
- to send transactional email (invitations, reminders, digests) via our email provider;
- to monitor, debug, and improve reliability and security;
- to comply with legal obligations.
We do not sell personal information, and we do not use it for third-party advertising.
4. Legal bases (where applicable, e.g. UK/EU)
Where data-protection law requires a legal basis, we rely on: performance of a contract (providing the service), legitimate interests (security, service improvement), consent (where specifically requested), and legal obligation.
5. How data is shared
- Within an owner's organization: owners can see the records in their own organization. Tenants can see only their own records and documents explicitly shared with them.
- Service providers (sub-processors): Supabase (database, authentication, file storage), Vercel (application hosting), Resend (transactional email), and Sentry (error monitoring). Each processes data only to provide their service to us. We keep this list current; if we add or change a sub-processor we will update this policy, and for material changes we will give reasonable advance notice.
- Legal: where required by law or to protect rights, safety, and security.
- We never share one owner's data with another owner, or one tenant's data with another tenant.
6. Where data is stored
Data is currently hosted in the United States (Supabase region us-east-1) and processed by the providers listed above. As we expand internationally, we may add regional hosting and will update this policy and apply appropriate safeguards for cross-border transfers (e.g. Standard Contractual Clauses where relevant).
7. Security
We apply layered safeguards including encryption in transit and at rest, strict per-organization data isolation (row-level security), private document storage accessed only through short-lived authorized links, least-privilege access, and monitoring. No system is perfectly secure, but we take protection seriously.
8. Retention
We keep personal information for as long as an account is active and as needed to provide the service. Financial and lease records may be retained longer where law requires. On deletion requests we remove or anonymise data, except where we must retain certain records to meet legal obligations.
9. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent.
- Owners can manage and export much of their data in-product, and can request account deletion.
- Tenants: because an owner controls the tenancy records, some requests about tenancy data may be directed to your landlord; you may also contact us at privacy@silkcotton.co and we will assist and, where appropriate, coordinate with the owner.
To exercise rights, contact privacy@silkcotton.co. We respond within the timeframe required by applicable law.
10. Children
Top Hat is not intended for anyone under 18, and we do not knowingly collect their data.
11. Changes
We may update this policy; we will post the new effective date and, for material changes, provide reasonable notice.
12. Contact
Edward Inglefield (Top Hat / Silk Cotton Studios), Trinidad & Tobago. Postal address available on request. Email: privacy@silkcotton.co.
Top Hat currently serves Trinidad & Tobago; we do not presently require an EU/UK representative or Data Protection Officer. If we expand into those markets we will appoint any required representative and update this section.