Loading

Effective Date: July 24, 2026

DoorVault Connect builds and refreshes your DoorVault portfolio from a property manager owner portal you are already authorized to use. This notice covers the extension's data handling for RentManager, Buildium, and AppFolio.

What DoorVault Connect handles

On a supported owner portal, the extension reads the portal URL and page title or organization label, active portal cookies, and a limited set of local browser-storage entries whose names indicate session, authentication, or account context. These items may include identifiers for your DoorVault account, owner account, property manager, tenant, company, user, or portal location.

RentManager may require cookies from both the visible owner portal domain and its paired API-session domain. DoorVault Connect excludes known advertising and analytics cookies and storage, unrelated preferences, page-body content, form entries, messages, clicks, and keystrokes. It never asks for or reads your portal password.

Because the supported portal URL and its browser storage are handled, Chrome classifies this narrowly scoped behavior as web-history, website-content, authentication, and potentially personally identifiable data. DoorVault Connect does not request access to your general Chrome browsing history or to unrelated websites.

How the data is used

The extension sends the supported portal URL, organization label, and active portal session over HTTPS to DoorVault. DoorVault verifies the provider, encrypts the portal session at rest, and uses it to retrieve the properties, statements, documents, income, expenses, invoices, and transaction records already booked in your owner portal.

This information is used only to provide and secure the PM portal connection, portfolio import, and refresh you requested. It is not used for advertising, lending, creditworthiness, profiling, or an unrelated purpose.

Storage and retention

  • A scoped DoorVault API token is stored in Chrome local storage until it expires, is replaced, or the extension is removed. It is never stored in Chrome sync.
  • A one-time onboarding handoff is stored in Chrome session storage for up to 10 minutes and removed after successful use.
  • Portal cookies and browser storage are held only in request memory by the extension and are never saved in Chrome extension storage.
  • A supported portal host and last-refresh time are stored locally to prevent duplicate refreshes within 10 minutes.
  • DoorVault stores the portal session encrypted server-side until it is replaced, expires, or you disconnect that portal. Imported portfolio records follow your DoorVault account's retention and deletion controls.

Sharing and Limited Use

The extension sends this data only to DoorVault. DoorVault may use contracted infrastructure providers to process or store data on DoorVault's behalf, as described in the full DoorVault Privacy Policy. DoorVault does not sell extension data or send it to advertising networks, data brokers, or unrelated third parties.

DoorVault Connect's use of information complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Human access is prohibited except when you explicitly authorize support to inspect specific data, when needed for security or legal obligations, or for aggregate and de-identified internal operations permitted by that policy.

Your control

You can remove DoorVault Connect from Chrome at any time. You can also disconnect a PM owner portal from DoorVault in Settings → Integrations → PM Portal Auto-Sync. Disconnecting clears the stored portal session and stops future refreshes; you can manage imported records through your DoorVault account controls.

Contact

Questions about DoorVault Connect privacy can be sent to [email protected].


© 2026 DoorVault