Onnu Colabs provides Chaabi. Property-management organizations usually determine why tenant, applicant, owner, vendor, employee, and property information is processed; in that context, the organization is the controller and we process information to provide the service. We are responsible for account, website, support, security, and product information we collect for our own purposes.
1. Information we handle
- Account and identity: name, email, phone number, organization, role, authentication factors, session and device security information.
- Property operations: properties, units, owners, occupants, leases, applications, leads, vendors, staff, work orders, inspections, access and parking records, messages, notes, reminders, and audit history.
- Financial records: rent, invoices, payments, deposits, trust records, expenses, tax attributes, reconciliation, and related references. Apple processes App Store payment-card details; Chaabi does not receive the full card number.
- Files and media: documents, signatures, photos, scans, receipts, floor plans, 3D captures, attachments, generated reports, exports, and encrypted backups.
- Device and diagnostics: app version, operating system, device/session identifiers, security events, crash and error diagnostics, IP-derived security context, and feature settings.
- Optional integrations: information needed for a feature you enable, such as document signing, email, calendar, reminders, contacts, mapping, printing, camera, microphone, speech, Bluetooth, or iCloud documents.
2. How information is collected
We receive information from you, your organization, invited portal users, the app and connected portals, enabled integrations, and service providers that operate authentication, hosting, delivery, or diagnostics. Device permissions are requested when a feature needs them and can be managed in system settings.
3. Why we use information
- provide, synchronize, back up, and support the service;
- authenticate users and enforce organization and role boundaries;
- render documents, reports, communications, and requested exports;
- process subscriptions and enabled integrations;
- detect abuse, investigate incidents, preserve audit evidence, and protect people, records, and infrastructure;
- comply with law and enforce agreements;
- improve reliability using minimized or aggregated diagnostics where practical.
Chaabi does not sell personal information or use it for cross-context behavioral advertising.
4. Where information is stored
The iOS app keeps an encrypted, organization-scoped local store and protected files on the device. If cloud sync is enabled, selected records are stored in the organization's hosted workspace. If encrypted backup or iCloud backup is enabled, backup archives are written only through those chosen features. Widgets and Watch use minimized snapshots designed for their displayed functions.
5. Service providers and disclosures
We disclose information only as needed to operate requested functions, protect the service, complete a business transaction with appropriate safeguards, or comply with lawful process. Providers may include Apple for the App Store, device services, and iCloud; Supabase for hosted database, authentication, storage, and functions; Vercel for portal and website hosting; and communications, mapping, email, or document-signing providers when those features are used. See our named Subprocessor List for the current providers, purposes, and stated processing locations. Access is limited by role, organization, purpose, and provider contract where applicable.
6. Retention and deletion
Chaabi uses record-specific retention windows, subject to an organization's longer setting, legal hold, and applicable law. The standard property-management policy is: declined applications are deleted after 120 days, applications in Recently Deleted are deleted after 30 days, unconverted leads with no activity are deleted after 365 days, email-delivery logs are deleted after 12 months, chat conversations are deleted after two years without activity, and security-audit events are deleted after seven years. An organization administrator can choose a longer window for those six categories; the minimums cannot be shortened. Portal delivery events remain bounded at 90 days, and one-time authentication artifacts use shorter operational windows.
When metadata is deleted, associated Storage objects are queued for deletion and retried by an independent worker until the object is removed. Tenant, lease, financial, signed, and frozen-history records are retained separately when required to preserve legal, accounting, evidentiary, or shared-organization history. Audit-chain checkpoints retain only the final expired hash and sequence, not the event payload or actor identity. An organization can export data, suspend access immediately, and request an account-level purge. Scheduled deletion is paused while a legal hold or requested export is pending, and an account purge is delayed and verified so shared-organization ownership and dependent records can be handled safely.
7. Security
Safeguards include organization-scoped authorization, row-level database controls, encryption in transit, encrypted local persistence, protected device files, Keychain storage, optional device authentication and MFA, signed/encrypted backups, restricted service credentials, audit events for privileged actions and selected sensitive reads, and monitoring. No safeguard is perfect; report suspected incidents to privacy@onnucolabs.com.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing, or withdraw consent. Start with the organization that invited you when it controls the record. You may also contact us. We will verify identity and authority, and may retain information where law, fraud prevention, dispute handling, security, or another person's rights require it.
You can manage device permissions in Apple Settings, integration connections inside Chaabi, App Store subscriptions through Apple, and cloud/backup choices in App Data settings.
9. Children and sensitive use
Chaabi is business software and is not directed to children. Do not use it to collect information from a child unless your organization has a lawful basis, appropriate notices and consent, and configured access and retention controls.
10. International processing
Information may be processed in countries where we or our providers operate. We use contractual and technical safeguards required for applicable cross-border transfers. Organizations remain responsible for selecting a deployment and workflow appropriate to their legal obligations. Chaabi does not represent the service as Canadian-only or promise that all processing occurs in Canada; the named subprocessor list identifies the current cross-border providers.
11. Changes and contact
We will update the effective date when this policy changes and provide additional notice for material changes when required. Privacy requests may be sent to privacy@onnucolabs.com. General support is available at hello@onnucolabs.com. See also our Terms of Use.