Privacy Policy
Last updated: May 2026
By using DepositBack and submitting information through our intake form, you expressly consent to the collection, use, and sharing of your information as described in this Privacy Policy for the purposes of providing the DepositBack service.
1. Information We Collect
We collect the following information when you use DepositBack:
- Personal information: name, email address, phone number, current mailing address
- Rental information: rental property address, move-in/move-out dates
- Landlord information: landlord name, mailing address, property management company
- Deposit information: deposit amount, amount returned, dispute details
- Payment information: processed securely by Stripe; we do not store credit card numbers
2. How We Use Your Information
We use your information to:
- Generate and send your demand letter via certified mail
- Send you email notifications about your order status and delivery tracking
- Process payments and refunds
- Respond to your support requests
- Improve our service
3. Third-Party Services
We share your information with the following third-party services as necessary to provide our service. These third parties process your data solely on our behalf as service providers, not for their own independent purposes:
- Stripe: payment processing. See Stripe's Privacy Policy.
- PostGrid: certified mail printing and delivery. Your name, address, and landlord's address are shared to fulfill the mailing. See PostGrid's Privacy Policy.
- Resend: transactional email delivery. Your email address is shared to send notifications. See Resend's Privacy Policy.
- Supabase: database hosting. Your data is stored securely in a Supabase-hosted PostgreSQL database.
- Plausible Analytics (optional, opt-in only): a privacy-respecting, cookieless analytics service used to measure aggregate site usage. See Plausible's Privacy Policy.
- Google Analytics 4: aggregate site-usage analytics provided by Google. Runs by default in cookieless ping mode (Google Consent Mode v2); cookies are set only after you click "Accept" in our cookie banner. IP addresses are anonymized. See Google's Privacy Policy.
- Microsoft Clarity: behavioral analytics provided by Microsoft that captures aggregate metrics such as heatmaps, scroll maps, and session activity to help us understand how visitors use our pages and improve the service. Clarity automatically masks sensitive form inputs (passwords, payment fields). Runs without cookies by default; cookies are set only after you click "Accept" in our cookie banner. For more information about how Microsoft collects and uses your data, see the Microsoft Privacy Statement.
4. Data Retention
We retain your order data for as long as your account is active or as needed to provide our service. Order records are kept for a minimum of 3 years to support any potential legal proceedings. You may request deletion of your data by contacting us (see below).
5. Data Security
We implement reasonable security measures to protect your personal information, including encrypted data transmission (HTTPS), secure database access controls, and secure payment processing through Stripe. However, no method of transmission over the internet is 100% secure.
6. Your Rights (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA):
- Right to know: You can request what personal information we collect, use, and disclose.
- Right to delete: You can request deletion of your personal information.
- Right to correct: You can request correction of inaccurate personal information.
- Right to opt out of sale/sharing: See the dedicated section below.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise any of these rights, contact us at support@depositback.co. We will respond within 45 days.
7. Do Not Sell or Share My Personal Information
DepositBack does not sell your personal information, and does not share your personal information with third parties for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act / California Privacy Rights Act. We have not done so in the preceding 12 months and have no plans to do so.
The only parties with whom we share your information are the service providers listed in Section 3, each of whom processes your data solely on our behalf for the purpose of fulfilling your order. Because we do not sell or share personal information, there is no opt-out to submit; however, you may still contact us at support@depositback.co to confirm this status or to exercise any other privacy right.
8. Cookies and Analytics
We use a small number of strictly necessary cookies to operate the service — for example, a session cookie and a cookie that records your cookie-consent choice. These do not identify you across sites and are not used for advertising.
We use analytics tools to understand how visitors interact with our service so we can improve it.
These include Plausible Analytics (cookieless by design), Google Analytics 4
(running in Google's cookieless ping mode by default under Consent Mode v2; IP anonymization enabled),
and Microsoft Clarity (which records heatmaps, scroll maps, and behavioral metrics
with sensitive form inputs automatically masked). By default these services run in a privacy-respecting
mode that does not set tracking cookies. If you click "Accept" in our cookie banner, the services
are permitted to set cookies for more granular measurement. If you click "No thanks," they continue
in their cookieless mode. You can change your choice at any time by clearing the
db_cookie_consent cookie in your browser.
We do not use advertising cookies, cross-site behavioral advertising cookies, or fingerprinting. Microsoft Clarity does capture session activity for heatmaps and product improvement purposes; sensitive form fields are masked and you can opt out of all analytics via the cookie banner or the "Do Not Sell or Share" mechanism above.
9. Children's Privacy
DepositBack is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Last updated" date at the top of this page.
11. Contact
For questions about this privacy policy or to exercise your privacy rights, contact us at support@depositback.co.