Skip to main content

Privacy Policy

Effective date: September 21, 2026

1. What We Collect

DepositHawk collects the following personal information to operate the Service:

  • Account information — name, email address, and password when you create an account.
  • Lease and property details — addresses, unit numbers, lease start and end dates, move-in/move-out dates, rent amounts, and security deposit amounts.
  • Dispute information — deduction descriptions, state selections, landlord contact information, and demand letter inputs.
  • Photos and documents — move-in/move-out condition photos, lease documents, and evidence uploads you provide.
  • Communication logs — records of landlord communications you log through the Service (dates, descriptions, and categories).
  • Fee audit data — utility bills, recurring charges, and fee records you enter for junk fee analysis.
  • Retaliation events — records of potential landlord retaliation events you report.
  • Payment records — purchase history and subscription status (payment card details are handled exclusively by Stripe and never touch our servers).
  • Rights-check and letter inputs — your state, dates, deposit and deduction amounts, and what you type into a letter form. When you start checkout, these travel with your order to Stripe and are stored with your purchase so we can build your letter.
  • Email you give us before buying — if you ask us to email your results or remind you of a deadline, we keep that email with the state, dates and amounts you entered.
  • Answers about how your dispute went — if you tap an answer in one of our follow-up emails, we keep it, anything you choose to write with it, and whether you agreed to let us publish it. We publish nothing without that agreement.
  • Usage and device data — pages viewed, buttons clicked, the page you came from, which of our links sent you to the rights check, and browser and device type, collected by Google Analytics and by our own event log.
  • Advertising click data — if you arrive from a Google ad, the Google click ID (gclid, or a similar Google ad tag) and the campaign tags in the link.
  • Help and support messages — what you type into the help assistant or send to support.

2. How We Store Your Data

Your data is stored across the following services:

  • Supabase (PostgreSQL) — account data, lease details, dispute records, communication logs, fee audit data, and all structured information.
  • Supabase Storage — photos and document uploads.
  • Stripe — payment method details, transaction history, and subscription records.
  • SendGrid — email delivery logs and transactional email records.
  • Vercel — hosts the website and keeps short-term request logs, including IP addresses.

All data is transmitted over encrypted connections (TLS). Database access is restricted to authenticated application requests.

3. Third-Party Services

We share data with these companies to run and measure the Service:

  • Stripe, Inc. — processes payments. DepositHawk never sees or stores your payment card number. See the Stripe Privacy Policy. With each checkout we send Stripe the order details (product, state, dates and amounts for your letter), a random visitor ID, the visit-source data described in section 5, and which of our pages sent you to the rights check. If you typed your email on our site before checkout, we may pass it to Stripe to prefill the checkout form.
  • SendGrid (Twilio) — sends transactional and lifecycle emails on our behalf.
  • Google Analytics (GA4) — measures how the site is used: page views, clicks and purchases, tied to a random Google Analytics ID in your browser. When you buy, our server also reports the purchase (order ID and amount) to Google Analytics through the GA4 Measurement Protocol, so purchases are counted even when a browser blocks the Google tag.
  • Google Ads — if you came from one of our ads, we use the Google click ID (gclid) and Google’s conversion measurement to find out whether the ad led to a purchase, and we report the purchase (order ID and amount) to Google Ads. Ad personalization is turned off in our Google tag.
  • Anthropic — powers the help assistant and helps sort support emails. What you type into the assistant, or send to support, may be sent to Anthropic’s API to draft an answer. Anthropic does not use this data for model training.
  • Supabase and Vercel — host our database, file storage and website.

We do not sell your personal information, and we don’t give it to other companies to market their own products to you. We use Google’s tools only to measure our own site and ads, as described above.

4. Email Communications

Transactional emails (purchase confirmations, document delivery, dispute updates) and lifecycle emails (lease check-ins, renewal reminders) are sent via SendGrid using the email address associated with your account.

You can manage your email preferences from your dashboard settings. Every non-transactional email includes an unsubscribe link.

If you ask us to email your results or a deadline reminder, we use that address for what you asked for and for a short series of follow-up emails about your deposit. Every one of them has an unsubscribe link.

After you buy a demand letter, some of our follow-up emails ask whether your landlord paid. Answering is optional, and every one of them has an unsubscribe link.

5. Cookies and Similar Technologies

DepositHawk uses the following cookies and browser storage:

  • Session cookies — required to keep you logged in and maintain your session, and short-lived cookies (up to an hour) that carry the secure code from a link in one of our emails, so the code stays out of the page address.
  • dh_aid — a random visitor ID, kept for one year. It links page events on this site to a checkout, so we can see which pages led to a purchase. It doesn’t contain your name or email.
  • dh_attr — where your first visit came from (campaign tags, the referring site, the first page you saw, the Google click ID and your Google Analytics ID), kept for 90 days.
  • dh_gclid — if you arrive from one of our Google ads, that ad’s click ID (or a similar Google ad tag), kept for 30 days and replaced by the next ad click. Our server sets it and page scripts can’t read it. It lets us tell whether a purchase followed an ad, even if you first found us another way.
  • Google Analytics and Google Ads cookies (such as _ga and _gcl_au) — set by the Google tag to measure visits and ad conversions.
  • Browser storage — a referral code if you arrived through a referral link, and your in-progress form answers so you don’t lose them, including a move-out date you enter on a deposit guide and carry into the rights check.

You can block or delete cookies in your browser settings. Blocking analytics and advertising cookies doesn’t stop you from using the rights check or buying a letter.

6. Data Retention

Your data is stored for as long as your account is active. If you request account deletion, we will delete your personal data within 30 days, except where we are required to retain records for legal or financial compliance purposes (e.g., payment transaction records required by tax law).

If you buy without an account, or give us your email before buying, we keep your order, the details you entered for your letter and your email until you ask us to delete them. Our own page-event records are kept the same way. The dh_aid, dh_attr and dh_gclid cookies expire on the schedule in section 5. To have any of this deleted, email support@deposithawk.com. We’ll delete it within 30 days, except records the law requires us to keep, such as payment records for tax purposes.

7. Your Rights

You have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request correction of inaccurate data.
  • Deletion — request deletion of your account and associated data.
  • Data export — request an export of your data in a portable format.

If you have an account, you can delete it yourself under Settings in your dashboard. That removes your account and the case records tied to it. It does not reach records kept only under your email address, such as purchase records and email preferences. To delete those, get an export of your data, or use any other right above, contact us at support@deposithawk.com to exercise any of these rights. We will respond within 30 days.

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what data we collect and to opt out of any sale of personal information. We do not sell personal information.

8. Children’s Privacy

DepositHawk is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact us at support@deposithawk.com and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service. Your continued use of DepositHawk after changes are posted constitutes acceptance of the updated policy.

10. Contact

Questions about this Privacy Policy or how your data is handled? Email us at support@deposithawk.com.

Prompt Critical, LLC — PO Box 524133, Bronx, NY 10452