Privacy Policy
Last updated: August 25, 2026 · Version 2026-08-25.1
The short version
Expoalb combines local-first PDF tools with a server-backed property operations platform. Client-side PDF tools are designed to process files in your browser by default. Accounts, organizations, properties, jobs, contacts, compliance records, reminders, invoices, activity history, connected integrations, Ask Expoalb and the Vault use server-side services as described below.
Information we collect and store
- Account and profile information, such as email address, display name, workspace preferences, authentication and legal-acceptance records.
- Organization information, membership, roles, enabled workspaces and onboarding settings.
- Property-operation records you create or import, including properties, units, jobs, visits, schedules, reminders, contacts, transactions, notes and related workflow records.
- Files, photos, evidence and document metadata you explicitly upload to server-backed features such as the Vault.
- Compliance and government-record data associated with properties, including records obtained from public agency sources and your related case/workflow information.
- Invoice and accounting-workflow records, including data an authorized organization imports from a connected accounting provider such as Intuit QuickBooks Online.
- Security, audit and service-operation information such as selected activity events, access decisions, usage counters, timestamps and technical request information used for security or legal-acceptance evidence.
- Communication preferences, including reminder-email settings and an opt-in choice for product updates.
Local-first PDF tools
Expoalb's client-side PDF tools are designed to process the selected file in your browser without uploading the file to Expoalb merely to perform the tool operation. Server-backed features are different: if you intentionally save a file to the Vault, attach evidence, import it into a server workflow, or use another feature that clearly requires storage or server processing, that data is handled by the corresponding server service. See How files are handled for feature-specific details.
How we use information
- Provide, secure, maintain and troubleshoot Expoalb.
- Organize property, job, document, compliance, scheduling, accounting and team workflows you request.
- Import, match and display records from customer-directed integrations you authorize.
- Send transactional notices, reminders, invitations, recovery messages and other service communications.
- Process subscriptions, billing status and customer-requested billing actions.
- Generate audit history and investigate abuse, security incidents, ownership disputes or support issues.
- Send product-update email only when the account preference is opted in.
Intuit QuickBooks data
When an authorized organization connects Intuit QuickBooks Online, Intuit may transfer data to Expoalb according to the permissions approved in Intuit's OAuth consent flow. Depending on the enabled Expoalb feature, this can include company identifiers and accounting records such as customers, contact details, invoices, invoice identifiers, items and related metadata made available through the QuickBooks Online API.
Expoalb uses QuickBooks-originated data to provide the connected organization's requested accounting and property-operations workflows, including import, reconciliation, matching and hierarchy filing. Expoalb does not sell QuickBooks data, use it for unrelated advertising, or use it to train a shared/general Expoalb AI model.
OAuth credentials and tokens are handled server-side. Access and refresh tokens are encrypted before database storage and are not exposed through normal customer-facing status responses. Connection management is restricted to authorized organization roles.
When an organization disconnects QuickBooks, Expoalb attempts to revoke Intuit authorization and stops future API access. Imported Expoalb records may remain when they are part of the organization's operational history and are then governed by Expoalb's normal export, retention and deletion controls. Users can also manage third-party access through Intuit or QuickBooks.
Ask Expoalb and AI processing
When you use Ask Expoalb or another AI-assisted workflow, Expoalb may send your request and a limited set of relevant record context needed to resolve it to Anthropic's commercial API. QuickBooks-originated information is only included when needed to perform an authorized workflow for that same customer organization. Expoalb does not use customer property or QuickBooks records to train an Expoalb-owned shared generative model. Do not place information into an AI request that your organization is not authorized to process through that feature.
Service providers and integrations
Depending on the features you use, Expoalb relies on providers including:
- Vercel — hosting, application runtime and deployment delivery.
- Supabase — authentication, database and server-backed file storage.
- Stripe — subscription and payment processing.
- Resend — transactional and configured email delivery.
- Anthropic — AI processing when you invoke an AI-assisted feature.
- Intuit QuickBooks — customer-directed accounting data exchange only after an authorized organization connects the integration.
See the Subprocessor & service-provider list for a feature-level summary. Expoalb may also retrieve public property or compliance information from government and public-data sources. Those records remain subject to the source agency's own terms, availability and accuracy.
Organization sharing and external shares
Records in a shared organization can be available to other authorized organization members according to Expoalb's membership and access rules. If you deliberately create an external share, the recipient can access the subject of that share according to the permissions, expiry and revocation state you selected. Treat active share links as sensitive access links.
Data export
Signed-in users can request a JSON export from Account settings. The export is limited to records the signed-in account is authorized to access in its current organization. Document download links included in the export expire after one hour. Expoalb intentionally excludes bearer-style access tokens, OAuth secrets and payment-processor identifiers from the portability file.
Deletion and retention
Account deletion requires a recent sign-in and explicit confirmation. If the account has an active Expoalb subscription, Expoalb attempts to cancel it before destructive deletion proceeds. Eligible private Expoalb records and stored files are then removed. Shared-organization records may require ownership or responsibility to be transferred before the account can be deleted. Imported integration records may be retained where they are part of shared organization workflows, accounting references, audit history or legal/business records until the organization deletes them through supported controls. Stripe, Intuit and other providers may retain records under their own financial, fraud-prevention, security or legal obligations. Expoalb does not represent account deletion as instantaneous removal from every provider backup or legally required record system.
Cookies and local storage
Expoalb currently uses necessary browser storage and cookies for functions such as authentication, security and product state. See the Cookie Notice for the current implementation.
Your choices and requests
Account settings provide controls for available exports, deletion and email preferences. Organization owners or admins control certain organization settings and connected integrations. You may disconnect a supported integration in Expoalb and may also revoke third-party access through the provider. For a privacy request, correction question or issue that cannot be handled in the product, contact us using the address below. Rights can vary based on applicable law and the role Expoalb plays for the data.
Contact
Privacy questions or requests: sales@expoalb.com