Skip to main content

RentCafe Privacy Statement

By using RentCafe.com (RentCafe ILS) or any property websites powered by RentCafe (RentCafe Portal) (collectively, “RentCafe”), you acknowledge you have read and understand the latest version of the RentCafe Privacy Policy (posted at https://resources.yardi.com/legal/rentcafe-privacy-policy/), which describes RentCafe’s privacy practices and will be updated from time to time. The property may have its own Privacy Policy that describes the property’s privacy practices.


PRIVACY POLICY

This privacy policy (the “Privacy Policy” or “Policy”) of Property Management Company (“Company,” “we,” “us,” or “our”) describes our privacy practices regarding personal information we collect, including from persons (“you” or “your”) who access our property’s RentCafe Portal website or our related mobile applications that may be available for download (collectively, the “Site”). To access the Privacy Policy of RentCafe, please visit: https://resources.yardi.com/legal/rentcafe-privacy-policy/.

PURPOSE. The purpose of this Privacy Policy is to inform you about the types of personal information we gather about you, including personal information gathered when you visit the Site, and personal information we may receive from third parties or affiliates in addition to that online information, how we may use that information, whether we disclose that information to anyone, and the choices you have regarding our use of, and your ability to correct, the information.  This Policy does not cover information that is exempted from privacy policy notification requirements, including information about employees, contractors, job applicants and information processed exclusively in the context of a business person acting in a business capacity.

THE SITE IS NOT INTENDED FOR CHILDREN AND COMPANY DOES NOT KNOWINGLY SOLICIT OR COLLECT PERSONAL INFORMATION ON THE SITE
FROM CHILDREN UNDER THE AGE OF 13. IF COMPANY LEARNS THAT A CHILD UNDER THE AGE OF 13 HAS SUBMITTED PERSONALLY IDENTIFIABLE INFORMATION TO COMPANY THROUGH THE SITE, IT WILL TAKE REASONABLE MEASURES TO DELETE SUCH INFORMATION FROM ITS RECORDS AND TO NOT USE SUCH INFORMATION FOR ANY PURPOSE (EXCEPT WHERE NECESSARY TO PROTECT THE SAFETY OF THE CHILD OR OTHERS, AS REQUIRED BY LAW, OR AS MAY OTHERWISE BE REQUIRED BY LAW).

YOUR CONSENT AND POLICY CHANGES. PLEASE READ THIS ENTIRE PRIVACY POLICY CAREFULLY. BY USING THE SITE, YOU EXPRESSLY CONSENT, WITHOUT QUALIFICATION, TO THE COLLECTION, USE AND DISCLOSURE OF INFORMATION, INCLUDING PERSONAL INFORMATION, AS DESCRIBED IN THIS PRIVACY POLICY. IF YOU DO NOT AGREE TO THE TERMS OF THIS PRIVACY POLICY, YOU ARE NOT AUTHORIZED TO USE THE SITE.

Company may amend this Privacy Policy from time to time. We will post those changes on the website or update the Privacy Policy date below.  In certain cases, you will be notified via email or by a notice on our website. 

PERSONAL INFORMATION COLLECTED IN THE PAST 12 MONTHS

We collect, process and store various types of Personal Information.  For purposes of this Policy, “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.  It does not include de-identified or aggregate information, or public information lawfully available from governmental records.

Personal Information we collect may include:  your name, email addresses, postal addresses, postal codes, user Internet Protocol (IP) addresses, social security/insurance number, driver’s license number, prior addresses, monthly rent paid at prior residences, employers, job titles, income, telephone numbers, credit card information, bank account information and routing numbers, date of birth, gender, age, marital status, user name and password (if you choose to become a registered user of the Site or our products and services), emergency contact information, information about your pets, information about your vehicles including license plate numbers, biometric information or biometric identifiers (if you choose to schedule a self-guided tour and/or use our identity verification services), when a smart device is on or off; when a door is locked, unlocked, opened, or closed; the unit with which the door is associated (if you choose to use Smart Home or the Home IQ Device(s) or Home IQ Hub), and other information either desirable or necessary to provide quality services to our residents and visitors.  We may also collect information about you such as your use of the Site and communication preferences.

Your Personal Information may be retained for as long as you use the Site or our products and services. Retention periods may be extended if we are required to preserve your personal information because of litigation, investigations and other similar proceedings, or if a longer retention period is required or permitted by applicable law.

We do not and will not sell your Personal Information.

Additional Information about How We Collect and Share your Personal Information

With respect to each of the categories of data above, we may also collect and share Personal Information with third parties to comply with legal obligations; when we believe in good faith that an applicable law requires it; at the request of governmental authorities or other third parties conducting an investigation; to detect and protect against fraud, or any technical or security vulnerabilities; to respond to an emergency; with contracted service providers; or otherwise to protect the rights, property, safety, or security of our business, third parties, visitors to our websites and mobile apps, or the public. With respect to biometric information or biometric identifiers, we may disclose such data to our technology service providers for the purpose of verifying your identity. We may also share Personal Information with any person to whom we transfer any of our rights or obligations under any agreement, or in connection with a sale, merger or consolidation of our business or other transfer of our assets, whether voluntarily or by operation of law, or who is otherwise deemed to be our successor or transferee.

PERSONAL INFORMATION WE WILL CONTINUE TO COLLECT

We will continue to collect the same categories of Personal Information listed above, for the same purposes. 

USE OF COOKIES AND OTHER TECHNOLOGIES. Like many other website operators, Company may use cookies to customize content specific to your interests and track your use of the Site. “Cookies” are text files that are placed on your computer and may be used to store your personal information. In addition to cookies, Company may use other now known or later developed technologies, to assist Company in observing the behavior of users
visiting the Site. These technologies access individual user information but the information is used only to compile aggregated statistics about the Site’s usage.

Our service providers may use cookies and those cookies may be stored on your computer when you visit our website.

This Site uses Lead Attribution or Marketing Attribution to assess the conversions of different channels that generate leads.

This Site uses Google Analytics (and in the future may use other similar sites or services), a web analytics service provided by Google, Inc. (“Google”), to
better assist Company in understanding how the Site is used. Google Analytics will place cookies on your computer that will generate information that we select about your use of the Site, including your computer’s IP address. That information will be transmitted to and stored by Google. The information will be used for the purpose of evaluating consumer use of the Site, compiling reports on Site activity for Company’s use, and providing other services relating to Site activity and usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. The use of cookies by Google Analytics is covered by Google’s privacy policy: https://www.google.com/policies/privacy/.

You can choose to delete existing cookies, allow or block cookies, and set preferences for certain websites in your browser’s settings. Please note you may not be able to use the full functionality of the Site if you choose to block all cookies.

EMAIL AND TEXT MANAGEMENT. You may receive emails and texts from Company for a variety of reasons. We respect your desire to manage email and text correspondence. If you have an account with Company on the Site, you can select your preferences through your account settings. You can also manage your receipt of certain types of communication by following the instructions included in the email we send you. Please note that, even if you unsubscribe from certain email correspondences, we may still need to email you with information relating to your unit, the management of the property, and other important transactional or administrative information. 

THIRD-PARTY WEBSITES. This Privacy Policy applies solely to information collected by Company. This Privacy Policy does not apply to other websites that are accessible through this Site, including but not limited to any third-party websites.

ACCESSING, REVIEWING AND CHANGING YOUR CONTACT INFORMATION. As an account holder, you can see, review and change most of your contact information associated with your Account Profile by logging into your account and editing your Account Profile.  For assistance, you may contact us using one of the methods listed below. With some exceptions, you have the right to see what Personal Information we hold about you. We can help you identify what records we might have about you. We may need to confirm your identity before providing you with this access, and if we cannot verify your identity with the degree of certainty required, we will not be able to respond to your request.  If we cannot give you access, we will tell you within 45 days of receipt of your request and provide you with a reason, as best we can, as to why we cannot give you access.

PERSONAL INFORMATION OF MINORS. Our Sites are not directed to minors under the age of 16 and we do not knowingly collect Personal Information from minors.  We may collect Personal Information of minors, provided by parents or guardians, in connection with the application and rental of a unit, or the provision of property management services.  We do not sell the Personal Information of minors.

CALIFORNIA RESIDENTS’ RIGHTS. The California Consumer Privacy Act (CCPA) may apply to California residents whose Personal Information is collected by landlords of a certain size or that meet other criteria. If the CCPA applies to us, California residents may request to know about Personal Information collected about them and request deletion of that Personal Information. These rights are subject to certain exceptions, including without limitation, for Personal Information subject to the Fair Credit Reporting Act and the Gramm-Leach-Bliley Act.  If we are subject to the CCPA, you can learn more about these rights and our processes for consumer requests by contacting us using one of the methods listed below. If you exercise any of the rights afforded to you by the CCPA, we will continue to treat you fairly.

Right to request disclosure of information we have collected about you

If the CCPA applies to us and to your information, you can submit a request to us for the following personal information we have collected: 

  •  

    • The categories of personal information we’ve collected about you.

  •  

    • The categories of sources from which we collected the personal information.

  •  

    • The business or commercial purposes for which we collected or sold the personal information.

  •  

    • The categories of third parties with which we shared the personal information.

  •  

    • The specific pieces of personal information we collected about you.

  •  

    • The categories of personal information (if any) that we have sold about you, the categories of third parties to which we sold that information, and the category or categories of personal information sold to each third party.

  •  

    • The categories of personal information that we disclosed about you for a business purpose. 

Our responses to any of these requests will cover the 12-month period preceding our receipt of the request.

Right to request the deletion of personal information we have collected from you 

Upon request, we will delete the personal information we have collected about you that is covered by the CCPA, unless a relevant exception to the right to deletion applies.

Do Not Track

“Do Not Track” is a privacy preference that users can set in certain web browsers.  We do not respond to browser or do not track signals.

INTERNATIONAL TRANSFER OF INFORMATION. To facilitate global operations, we may store, transfer and access Personal Information we collect (as described above) or you submit on the Site around the world, including the United States, Canada and other countries in which we or our service providers have operations.

ACCESSIBILITY.  We are committed to ensuring that our communications are accessible to people with disabilities.  To make accessibility-related requests or report barriers, please contact us using one of the methods below.

ACCEPTABLE USE. You agree you will not modify, tamper with, reverse engineer, decompile, or otherwise attempt to discover the source code for, any Site or related hardware or software associated with the Site.

CONTACTING US.

If you have questions regarding this Privacy Policy or use of information collected, please contact your property manager using the Contact Us form.

Canada. To the extent it is applicable, this policy is made under the Personal Information Protection and Electronic Documents Act. There are some rare exceptions to the commitments set out above.

For more general inquiries, the Information and Privacy Commissioner of Canada oversees the administration of the privacy legislation in the private sector. The Commissioner also acts as a kind of ombudsman for privacy disputes. The Information and Privacy Commissioner can be reached at:

Address: 112 Kent Street, Ottawa, ON K1A 1H3 
Phone: (613) 995-8210
Toll-free: (800) 282-1376
Facsimile: (613) 947-6850
TTY: (613) 992-9190
Website: www.priv.gc.ca/en/

Updated:  July 24, 2023

 

ARCADIA MANAGEMENT SERVICES CO.

AUTOMATED LICENSE PLATE RECOGNITION (ALPR) USAGE AND PRIVACY POLICY FOR MANAGED PROPERTIES

ALPR Data Custodian: Director of Information Technology

Email: [email protected]

Public Policy URL: https://www.woodsapartments.com/privacypolicy

1. ALPR POLICY & SCOPE

1.1 Purpose. Arcadia Management Services Co. (the “Company”) manages commercial, residential and mixed-use properties. At certain managed properties, the Company deploys, administers, accesses, or operates or intends to operate, one or more automated license plate recognition (“ALPR”) cameras systems (“ALPR System”). The ALPR System utilizes cameras and various processes to capture and store digital images of vehicle license plates entering or exiting the property. The ALPR System uses software recognition algorithms to identify license plate characters and creates a searchable computerized database resulting from the data collected by cameras located at the property. ALPR System data (“ALPR Data”) includes license plate number information as well as the date, time and location when the image or information was collected.

The purpose of this Automated License Plate Recognition Usage and Privacy Policy (the “Policy”) is to detail the Company’s use of the ALPR System, and how we use, access, process, share, store, maintain, collect, secure, and retain the ALPR Data that is within the Company’s possession or control, in compliance with all applicable federal, state, and local laws, including California Civil Code sections 1798.90.5 through 1798.90.55.

1.2 Applicability of ALPR Policy. The Policy applies to ALPR Data collected or hosted on the Company’s behalf at an ALPR enabled property for which the Company manages. This Policy does not govern an ALPR System operated exclusively by a property owner, tenant, law enforcement agency, or other third party where the Company does not administer that system and has no authority to access, use, or share its ALPR Data. If the Company later receives access to a third-party system, that access will be approved, documented, and brought within this Policy before use.

1.3 Availability of this Policy. This Policy is available to the public in writing upon request to the Director of Information Technology at [email protected]. The Company will also post the current Policy on the Company’s website at the Public Policy URL identified above. The posted version will identify its effective date and supersede prior versions.

2. ALPR DATA USAGE

2.1 Data Collection. A property managed by the Company that utilizes an ALPR System may collect the license plate image, vehicle image, plate number and state of issuance, date, time, camera location, and available vehicle characteristics such as color and make.

2.2 Authorized Use of ALPR Data. The Company utilizes the ALPR System to capture, analyze, and store ALPR data for the following authorized purposes: (1) managing vehicular access and parking at properties managed by the Company; (2) deterring and investigating theft, vandalism, vehicle break-in, trespassing, and other criminal activity occurring at properties managed by the Company; (3) identifying vehicles associated with a reported crime or a reported incident at a managed property; (4) protecting the safety and security of occupants, visitors, employees, and tenants; (5) responding to a safety or security incident at a managed property; and (6) providing ALPR Data to a law enforcement agency, consistent with this Policy, in support of an official and lawful investigation or in response to an imminent theat.  

2.3 Restricted Uses. The Company does not make the ALPR System or ALPR Data available to individuals for any personal or non-commercial purpose. The Company does not sell ALPR Data. The Company only uses the ALPR System to collect license plate data from vehicles in areas of the property open to public view, such as entrances, exits, and parking area. ALPR Data shall not be used by the Company to harass, intimidate, or discriminate against any individual or constitutionally protected group.

3. OPERATION OF ALPR SYSTEM & ALPR DATA

3.1 Management of the ALPR System. The Company remains responsible for implementing this Policy for ALPR Data within its possession or control. A written agreement with each service provider that hosts, processes, maintains, or administers an ALPR System will require the provider, as applicable, to use ALPR Data only to perform contracted services; maintain reasonable security and access controls; maintain required access records; follow the Company’s configured retention and deletion rules; provide prompt notice of suspected unauthorized access, use, or disclosure; prohibit sale and unauthorized secondary use; restrict onward disclosure; and cooperate with audits, incident response, and legal compliance.

The ALPR System deployed at a property managed by the Company is installed and hosted by independent third-party service providers, which perform collection, storage, security, retention, and deletion functions on the Company’s behalf under written agreement. The Company does not delegate, and the service provider does not assume, the Company’s obligations under applicable laws, including California Civil Code sections 1798.90.51 through 1798.90.53. The Company remains responsible for compliance as to ALPR Data within its possession or control and ensures through written agreements that each service provider implements security procedures and privacy practices consistent with this Policy and applicable law.

3.2 Authorized Users. Authorized users with access to ALPR Data include employees and contractors with an operational need to oversee the ALPR System. Access to configure, operate, or administer the ALPR System is restricted to individuals holding the following job titles or roles, or their designated backups, who have completed the training described below: (1) Director of Commercial Property Management; (2) Director of Residential Property Management; (3) Assistant property managers, and security or risk-management personnel, limited to the Company’s properties for which they have assigned responsibility; (4) Legal, compliance, or audit personnel, for a specific legal, compliance, audit, claim, or incident-response purpose; (5) Information technology or information-security personnel; and (6) Independent contractors performing a specific function. Authorized users are responsible for complying with this Policy and may have their access suspended or revoked for any misuse.

Each Authorized User must have a unique individual account. Credentials may not be shared. Multi-factor authentication must be used where supported. Access will be reviewed periodically and promptly suspended or revoked when the business need ends, the user changes roles or separates, or misuse is suspected.

3.3 Access. Access to ALPR data is limited to personnel with a documented operational need. The Company’s Authorized Users, as identified in Section 3.2, may query data in the ALPR System. Logins and queries by Authorized Users are recorded and monitored, and the record includes: (1) the username of the person who accessed the ALPR Data and, as applicable, the organization or entity with which that person is affiliated; (2) the date and time of access; (3) the purpose of the query; and (4) the license plate number or other data elements used in the query. Any employee who becomes aware of unauthorized access or misuse of ALPR information shall immediately notify the Data Custodian as identified in Section 3.4.

A record containing the same information is maintained for every instance in which the Company accesses or provides access to ALPR Data, including access by a law enforcement agency user under Section 4.3 and access by service-provider personnel under Section 4.1. Where the record is generated and held by the Company’s service provider, the Company’s written agreement with that provider requires the provider to create and retain that record and to make it available to the Company on request.

3.4 Data Custodian. The Director of Information Technology is the official custodian and head administrator responsible for implementing this Policy. The Data Custodian approves Company users, defines permission levels, approves law enforcement sharing, confirms retention settings, oversees training, reviews audits and incidents, and coordinates legal and privacy compliance. A documented backup may perform these functions when the Data Custodian is unavailable, but the Data Custodian retains oversight responsibility.

3.5 Training. Each Authorized User must complete training before being granted access to the ALPR System or ALPR data. Training is designed to protect and safeguard individual privacy and to ensure compliance with applicable laws, and covers, at a minimum: (1) the terms of this Policy and the authorized and restricted uses in Section 2; (2) permissible query purposes and the obligation to record a purpose for each query; (3) the prohibition on personal or harassing use, and on sharing credentials; (4) data security practices; and (5) recognizing and immediately reporting suspected unauthorized access, misuse, or a security incident. A record of all completed training, including the date and the name of each authorized user trained, is maintained by the Company. The Data Custodian or their designee is responsible for the development and implementation of training requirements for all Authorized Users, and assumes responsibility for the implementation of this Policy.

3.6 Company Operator and End-User Status. The Company may act as an ALPR operator, as an ALPR end-user, or as both, as those terms are defined in Civil Code section 1798.90.5. Where the Company operates an ALPR System, the obligations of Civil Code section 1798.90.51 apply. Where the Company or its personnel access or use an ALPR System the obligations of Civil Code section 1798.90.53 apply. This Policy governs the Company’s own collection, access, use, sharing, and retention of ALPR Data.

3.7 Monitoring and Compliance. The Data Custodian or their designee monitors the ALPR System to ensure the security of ALPR Data and compliance with this Policy and applicable  laws. Monitoring consists of: (1) review of the ALPR System access and query logs; (2) review of Authorized Users and permissions to access ALPR data; (3) confirmation of retention and deletion settings; (4) confirmation of sharing confirmation and approved law enforcement agency list; (5) review of training records. Monitoring is performed at least annually and promptly upon any report of suspected unauthorized access or misuse.

 

4. ALPR DATA SHARING AND DISCLOSURE

4.1 Service-Provider Access. The Company’s designated service-provider and approved contractors may access or process ALPR Data as reasonably necessary to provide, secure, maintain, troubleshoot or improve the contracted services, comply with the law, or respond to a security or technical issue.

4.2 General Restrictions & Process. The Company will not sell, rent, or exchange ALPR Data. Sharing, transfer, or disclosure is permitted only for an authorized purpose, through a process described in this Policy. Except for legally compelled disclosures, sharing must be approved by the Data Custodian or occur through a sharing configuration approved in advance by the Data Custodian.

4.3 Law Enforcement Sharing. The Company may enable match-based sharing for an ALPR System at one or more properties. Where the Company has enabled match-based sharing for a covered ALPR System, an authorized user of an approved law enforcement agency may query the ALPR Data by entering a license plate, vehicle characteristic, or other criteria into the ALPR System. The Company’s service provider acts as the technical intermediary, comparing the criteria against ALPR Data available under the Company’s sharing configuration and, if a match exists, returning responsive ALPR Data to the agency. A Company employee does not separately review or approve each agency query.

Match-based sharing is enabled only for law enforcement agencies on an approved agency list maintained by the Data Custodian. An agency is added only by documented approval of the Data Custodian, and sharing is not enabled on a default, portfolio-wide, or open basis. An authorized law enforcement agency may use shared ALPR Data only for official and lawful investigations, a response to an imminent threat to life or serious bodily injury, or another documented public-safety purpose consistent with this Policy. Each approved agency must require its users to record a case number or a documented public-safety purpose for every query, and must confirm that its users are bound by the agency’s own ALPR usage and privacy policy and by applicable law.

ALPR Data made available under this Section may be used only for the authorized purposes described in this Policy. The Company requires each approved agency to agree to that limitation as a condition of being added to the approved agency list.

4.4 Company Disclosure of ALPR Data. The Company may make a case-specific disclosure of the minimum necessary ALPR Data: (a) to a law enforcement or governmental agency responding to a documented request related to a specific crime, emergency, or material safety incident; (b) in response to a valid subpoena, warrant, court order, or other legally compelled process; or (c) to a property owner, insurer, legal counsel, or approved security provider where reasonably necessary to investigate or respond to a specific incident, claim, threat, or legal obligation involving a property managed by the Company. Except where disclosure is legally compelled, the Data Custodian or their designee must approve the disclosure in advance. Each disclosure is documented, including the recipient, the date, the ALPR Data disclosed, and the basis for the disclosure.

5. RETENTION & SECURITY

5.1 Data Storage & Retention. ALPR Data is stored in the databases of the Company’s service providers. ALPR Data in the Company’s possession or control is retained for thirty (30) days from the date of capture, after which it is automatically and permanently deleted from the ALPR System in the ordinary course, unless retention beyond that period is necessary as described below.

The Company may preserve or export the minimum ALPR Data reasonably necessary for a specific active investigation, incident, insurance claim, litigation hold, subpoena, warrant, court order, or other legal obligation, in which case it will be retained only until the applicable legal process, investigation, or hold concludes. Each preservation is documented by the Data Custodian, including the ALPR Data preserved, the reason for preservation, and the date. The Data Custodian or their designee reviews each open preservation no less than quarterly and, upon determining in consultation with legal counsel that the underlying investigation, claim, hold, or legal process has concluded, causes the preserved ALPR Data to be permanently deleted. The Data Custodian is responsible for confirming, at least annually, that ALPR Data is retained consistent with this Policy.

5.2 Security and Monitoring. The Company shall implement and maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of ALPR Data. These safeguards are designed to protect ALPR Data from unauthorized access, destruction, use, modification, or disclosure, including: (1) role-based access controls limiting ALPR System access to individuals identified in this Policy; (2) obtaining unique login credentials for each authorized user; and (3) logging each instance in which ALPR Data is accessed.

5.3 Data Verification. The Company shall take reasonable measures to help ensure the accuracy of ALPR Data and to correct data errors, including periodic verification that the ALPR System's plate-recognition algorithm is functioning within the manufacturer’s stated accuracy parameters. The Company tests each ALPR System at least annually for accuracy and documents the results.

5.4 Periodic Audits. The Company will conduct periodic audits of ALPR System access logs to confirm that all access to and use of ALPR Data is consistent with this Policy, including retention and destruction practices and any sharing or transfer of ALPR Data. The audit shall be performed by the Data Custodian or their designee at least annually. Audit findings should be documented by the Data Custodian.

5.5 Incident Response. The Company will promptly investigate any suspected unauthorized access, use, modification, destruction, or disclosure of ALPR Data. Where required by California law, notifications shall be provided in accordance with applicable data breach statutes. Questions regarding this Policy or alleged misuse of the ALPR Data should be directed to the Data Custodian.

5.6 Notice at the Property. The Company will post conspicuous signage at vehicular entrances at each property where an ALPR System is deployed.

6. POLICY REVIEW & AMENDMENTS

6.1. Policy Review. The Data Custodian will review this Policy at least annually and whenever there is a material change to law, technology, vendor terms, data collection, retention, or sharing practices.

6.2 Changes to this Policy. This Policy may be amended from time to time to account for new policies, procedures, or changes in the law. Any amended version will be made publicly available in writing and, where applicable, posted on the Company’s website.