Skip to main content
Privacy policy

Your information, handled with purpose

This policy explains what Bello Homes LLC ("Bello Homes") collects through its property-management services and mobile app, why we use it, how long it is kept, and how to make a privacy request.

01 / Collection

What we collect and why

This policy applies when you visit our website, book a stay directly with us, use the guest portal, use the Bello Homes Owner Dashboard, team application, or mobile app, or otherwise interact with our Services. We collect personal, financial, and operational information only for defined service-delivery purposes, not to build advertising profiles.

Guest information

Identity and contact: name, email address, phone number, preferences, notes, and messages sent through forms or email. Stay and payment records: reservations, party size, dates, status, amounts, reservation codes, and payment references. Content: messages exchanged through the guest portal, email, or text; support details; claim descriptions; and evidence photos you choose to submit. Booking-terms acceptance and stay-delivery records: when you book directly, we record your acceptance of the Booking Terms (timestamp, terms version, IP address, and browser identifier) and events showing the stay was delivered — such as guest-portal access and door-code retrieval — kept as part of the reservation record and used to resolve billing questions and payment disputes.

Owner information

Contact, account, and property: owner name, email, phone, notes, login credentials, property address and type, photos, descriptions, pricing preferences, and operating records. Passwords are stored as salted hashes. Financial and documents: payout preferences, tax-relevant identifiers when required for invoicing or 1099 reporting, statements, mortgages, invoices, workbooks, receipts, agreements, maintenance records, deeds, and tax records.

Team and operations

Account context: profile identifier, name, email, phone, timezone, avatar, assigned role, account status, and last-seen timestamps. Service delivery: property work, handoffs, administrative actions, vendor contact details, invoice records, and the evidence needed to coordinate and audit authorized work.

Collected automatically or through authorized integrations

  • Usage data. Pages viewed, links clicked, time on page, and actions taken in the dashboard.
  • Device data. IP address, browser type, device type, and approximate location derived from IP.
  • Cookies and local state. Cookies support authentication, session management, and basic analytics; browser local and session storage support normal site operation. See Cookies and local storage for your choices and the mobile-app details.
  • Booking platforms. With your authorization, we receive reservation, guest, and payout data from connected platforms such as Airbnb and VRBO.
  • Payment-notification email. Payment notifications delivered to our monitored payments mailbox — for example from QuickBooks Online (Intuit Inc.), Venmo, or Zelle — are read so we can record what the notification itself states: the amount, the payment date, the payer name or handle shown in the message, any memo or invoice reference, and any receipt attached to the email. We are not connected to Intuit's API and do not read or write your QuickBooks company file. See Your QuickBooks data.
  • Email delivery. When we send statements, invoices, or notifications, the recipient address, subject, and delivery status pass through our email provider.

How we use this information

  • Operate, maintain, and improve the Services. Manage reservations, guest communications, cleaning, maintenance, claims, staging, owner reporting, and service-provider coordination.
  • Accounts and access. Authenticate admin-provisioned team and owner accounts, apply role-based access, and keep a record of sensitive administrative activity.
  • Payments, reports, and communications. Generate statements, invoices, and reports; maintain booking amounts, statuses, reservation codes, and payment references; and communicate about accounts, properties, statements, and important updates.
  • Security and support. Detect, investigate, and prevent fraud, abuse, or security incidents; preserve handoffs; respond to support needs; and maintain operational and audit evidence.
  • Legal obligations. Comply with tax reporting, record-keeping, and other applicable legal requirements.

We do not use your data to train AI models, do not sell your personal information, and do not share it with advertisers.

How we protect information

  • Encryption and private storage. All Services are served over HTTPS with modern TLS configurations. Financial documents use private storage and short-lived signed links. Third-party provider credentials are held in our platform provider's managed secret store rather than in application tables: where the database references a credential at all, it stores a pointer that names the managed secret, never the secret value.
  • Accounts and access. Passwords are stored as salted hashes; we cannot view or recover a plaintext password. Every team and owner account requires two-factor authentication, administrative and staff access uses TOTP, and database-level row controls and role-based, least-privilege access limit personal and operational records.
  • Production safeguards. Production-system access is restricted to a small group of authorized Bello Homes personnel protected by strong authentication. Released application assets are integrity-checked, and money-affecting administrative actions are recorded in an append-only audit trail.

No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your data, we will notify affected users and take appropriate corrective action. Read more on our security page.

App context. The Bello Homes app is a line-of-business tool for authorized team members and owners. Usable access is provisioned by an administrator; the app offers no self-signup. We show no advertisements, do not sell personal information, and do not use app data for cross-app or cross-site advertising tracking.

Sources · PII Inventory v1.0 §§2–7 · Data Protection Policy v1.0 §§2–4 · Security Policy v1.0 §§2–3 · Support Model v1.0 §§3–4
02 / Retention

Retention follows purpose

We retain personal data only while it remains operationally or legally necessary. Because the obligations differ by record, we do not apply one universal retention period.

  • Account, property, and financial records. We retain these records while a management agreement is active and for a reasonable period afterward to meet tax, legal, and audit requirements. Financial records are typically retained for seven years.
  • Property-condition photos. Operational photos documenting property condition, such as checkout documentation, are automatically archived 90 days after a case closes and permanently deleted shortly afterward.
  • Enforced retention engine (control 0250). Enabled classes are evaluated by the daily data-retention sweep at 03:30 UTC, with each class capped at 500 eligible rows per run. Dry runs are recorded without deleting data.
  • Configured windows. Depending on the class, enabled defaults use 14-day post-deletion grace periods, 30-day and 90-day windows, or 12-month and 24-month windows. Administrators can disable a class without a code change.
  • Separately managed records. Claims and ownership records use dedicated sweeps. Guest master records use the request process rather than an automatic purge.
  • Important exclusions. Financial aggregates and source records, vendor-invoice master records, and other listed exclusions are not automatically purged by control 0250. The audit-log purge is disabled pending explicit owner approval.

The source of these rules is the Bello Homes Data Retention Schedule v1.0. A disabled rule does not run, and records needed for an applicable operational or legal reason remain restricted until that reason ends.

Sources · Data Protection Policy v1.0 §5 · Data Retention Schedule v1.0 §§1–3 · PII Inventory v1.0 §8
03 / Deletion

Privacy and deletion requests

We verify the identity or authority of a requester before acting. Information that is no longer required is deleted or irreversibly anonymized; information that must remain is restricted and kept only while that reason applies.

  • Guest DSR capability (control 0251). An authorized administrator records the verified request and executes ledgered anonymization across the identified guest-data locations.
  • Financial integrity remains. Amounts, dates, statuses, reservation codes, and payment references remain unchanged when required for transactional integrity, while the guest identity attached to those records is removed.
  • Completion is checked. The administrator reviews the execution record, per-table counts, and error summary. Historical audit-trail copies are masked on a targeted, best-effort basis and any limitation remains part of the execution summary.
  • 30-day commitment. We respond to verified privacy requests within 30 days. For an account-deletion request, we deactivate the account promptly and delete personal information within 30 days, except records we must keep by law. Where an approved workflow irreversibly anonymizes identifying information instead of deleting the surrounding transaction, the identity is removed while required financial facts remain intact.

How to submit a request

Email team@bellohomes.co from the address on your account with the subject “Delete my account,” ask any Bello Homes administrator, or use the existing channel through which you communicate with us: the PMS inbox, your OpenPhone SMS conversation, or another monitored email rail. State that the message is a privacy request and provide enough information for the team to verify your identity or authority. Do not send a password, one-time code, or other credential.

You may likewise request deletion of personal data that is not subject to a legal retention obligation. If you no longer have an existing conversation, the details in Contact and policy changes provide a starting point. Suspected privacy incidents enter the documented escalation path immediately.

Sources · Data Protection Policy v1.0 §§6 and 10 · Support Model v1.0 §§3 and 5 · Data Retention Schedule v1.0 §3
04 / Sharing

Processors and sharing

We share information only with service providers who help us run the Services. They are bound by contractual obligations to protect the information, use it only for the purposes we specify, and receive only what is needed for their role. We do not sell personal information or share it for advertising.

Supabase
Database, authentication, private file storage, and edge functions for account, property, booking, and operational data.
Cloudflare
Website and app hosting, DNS, content delivery, file storage, edge compute, and traffic handling for all Service traffic and stored data.
Stripe
Payment processing for direct bookings. Payment-card details are entered directly with Stripe and never stored on our systems; we retain only amounts, status, and a payment reference. Stripe also records your acceptance of our booking terms when required at checkout.
Intuit (QuickBooks Online)
Not connected today. No Bello Homes system holds an Intuit authorization or exchanges data with QuickBooks Online; we only receive QuickBooks payment-notification email like any other inbound mail. If the accounting integration is enabled in the future, customer and invoice data would be shared with Intuit for invoicing, and we would update this policy before that happens.
Mailgun
Email delivery and receiving on bellohomes.co, including recipient address, subject, and message body for emails we send and receive.
OpenPhone
Business phone and text messaging using phone numbers and message content for stay-related and operational communications.
Booking platforms (Airbnb, VRBO, etc.)
Reservation and guest management. Property and listing data is shared as authorized, and reservation, guest, and payout data is received from connected platforms.
Google Firebase Cloud Messaging (FCM)
Dormant and off today. FCM is used for push-notification delivery only when the push rail is activated; provider credentials are not yet provisioned.

Information sent through these processors is limited to what is needed to deliver, receive, and preserve the relevant service or operational record.

Sources · Data Protection Policy v1.0 §8 · Support Model v1.0 §3 · Mobile M1 control 0254
05 / SMS

Text messages (SMS)

If you provide a phone number, we may text you about your stay—booking confirmations, check-in details, and replies to questions you send us.

Message frequency varies with your conversation, and message and data rates may apply. Reply STOP at any time to opt out, or HELP for help. We do not send marketing texts without your consent, and we never share your number with third parties for their marketing.

06 / QuickBooks

Your QuickBooks data, specifically

Bello Homes is not connected to QuickBooks Online today. We hold no Intuit authorization and no long-lived refresh token for any owner's company file, and no Bello Homes system reads from or writes to QuickBooks. An earlier version of this policy described that integration as if it were running; this section corrects that.

What actually happens today

  • Payment-notification email only. When QuickBooks Online, Venmo, or Zelle emails a payment notification to our monitored payments mailbox, we record what the notification itself states: the amount, the payment date, the payer name or handle shown in the message, any memo or invoice reference, and any receipt attached to the email.
  • No connection to Intuit. That rail reads mail we already receive. It does not sign in to QuickBooks, does not call Intuit's API, and gives us no access to your company file, customer list, chart of accounts, invoices, or payroll.
  • Recorded for reconciliation, and correctable. Captured payments are used to reconcile owner statements. You may ask us to correct or remove a captured record through Privacy and deletion requests.

If we connect QuickBooks Online in the future

We will update this policy before any Intuit integration goes live. From the moment it does, these commitments apply:

  • We would store the long-lived refresh token issued by Intuit encrypted, in database records separate from public-facing systems, and reach it only from authenticated server-side processes.
  • We would use it solely to create invoices and read the accounting data needed to reconcile your statements — never employee payroll, personal Intuit account information, or unrelated company files.
  • We would log every action taken against your QuickBooks data in an internal audit log.
  • You, or a Bello Homes administrator acting on your behalf, could disconnect the integration at any time; disconnecting immediately revokes our access.
  • We never sell, share, or use QuickBooks data for any purpose other than delivering the accounting features you requested.

Correction · July 24, 2026. This section, the payment-notification entry in What we collect and why, and the Intuit entry in Processors and sharing were corrected to state that the QuickBooks Online integration is not connected. No other terms changed, and no data was collected under the earlier description.

Update · July 31, 2026. Direct booking with card payment is now live. The guest-information entry in What we collect and why now describes the booking-terms acceptance record (timestamp, terms version, IP address, browser identifier) and stay-delivery events (guest-portal access, door-code retrieval) retained with each direct reservation, and the Stripe entry in Processors and sharing reflects that payment processing is active.

For more information about Intuit's handling of data flowing through QuickBooks Online, see the Intuit Global Privacy Statement.

07 / Rights

Your rights

Depending on where you live, you may have rights under laws such as the California Consumer Privacy Act (CCPA) or the EU/UK General Data Protection Regulation (GDPR), including rights to access, correct, delete, port, or restrict the processing of your personal data.

To exercise any of these rights, email team@bellohomes.co. We verify the request as described in Privacy and deletion requests and will respond within 30 days.

08 / Children

Children

The Services are not directed to children under 13, or under 16 in the European Economic Area, and we do not knowingly collect personal information from children.

If you believe a child has provided us with personal information, contact us and we will delete it.

09 / International

International data transfers

Bello Homes is based in the United States, and our service providers operate primarily in the United States.

If you access the Services from outside the United States, your information will be transferred to and processed in the United States, which may have different data-protection rules than your home country.

10 / Cookies

Cookies and local storage

Cookies are small files used for authentication, session management, and basic analytics. You can disable cookies in your browser, but this will impair dashboard functionality.

The website and a normal WebView may also retain site resources and use local or session storage for ordinary site operation. The native shell creates no additional application-data cache. Native preferences hold only a non-secret session-present flag—not a session, profile, property, guest, reservation, statement, biometric value, or push token. We do not use cookies or local storage for cross-app or cross-site advertising tracking.

11 / Mobile

Mobile-app details

One app serves authorized owners and team members; the signed-in role determines the experience. The native shell adds a narrow device layer around the existing Bello Homes service.

Push tokens

If you allow notifications and provider registration succeeds, a provider token, platform, app version, and timestamps are stored in the device_tokens table and linked to your profile. Authenticated users can read only their own rows. Registration is optional and the token is revocable; sign-out revocation is best-effort when the device is offline or interrupted. Delivery remains dormant today.

Biometric unlock

Face or fingerprint evaluation happens through the operating system on your device. Bello Homes receives no biometric template or biometric secret, and nothing biometric is transmitted to our servers. The gate protects the display of an existing signed-in session; it does not replace account authentication or TOTP.

Camera and photos

Existing upload controls let you choose files from your device for authorized workflows such as cleaning, claims, and staging evidence. If the operating system offers capture through its file picker, you decide whether to use it. Bello Homes receives only the files you select. Claim photos and other evidence follow the access and retention rules for their private storage class. The current shell does not claim a separate native camera plugin.

Offline and local state

The native shell creates no additional application-data cache. Normal WebView defaults may retain site resources and the website's local or session storage. Native preferences hold only a non-secret session-present flag—not a session, profile, property, guest, reservation, statement, biometric value, or push token. Offline overlays contain static text.

Sources · Mobile Architecture v1.0 §§Biometric, Push, Offline, and Data handling · Mobile M1 control 0254 · PII Inventory v1.0 §§2 and 5
12 / Contact

Contact and policy changes

Use an existing monitored support channel for a privacy request. For a security concern, use the dedicated security address below.

Bello Homes — Privacy
Privacy and data-rights requests: team@bellohomes.co
General email: team@bellohomes.co
Phone: +1 (984) 205-8020
Security reports: security@bellohomes.co
Raleigh, North Carolina, USA

Service health is published on our status page. Our access, application-security, and disclosure practices are summarized on our security page.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will post the updated version at this URL and update the “Effective date” shown above. For significant changes, we will also email account holders.

Effective date: July 18, 2026. This policy is versioned and reviewed at least annually. A material change to data classes, purposes, storage, access controls, retention, deletion handling, or processors triggers an earlier review when needed. The current version and effective date are published at this URL.