WHERE IDEAS FIND PEOPLE.
HATCHING POINT / STUDIO
A WORLD IN THE MAKING
LocatorDesk

Privacy, in practical terms

Privacy Policy

How LocatorDesk handles account information, local CRM records, provider requests, purchases, reminders, and support messages.

Last updated July 25, 2026

The short version

LocatorDesk is a local-first customer relationship workspace operated by Hatching Point LLC ("Hatching Point," "we," "us," or "our"). Lead records, renter preferences, notes, activities, properties you add, and message drafts stay in an account-scoped file on your device. They are not uploaded to our hosted account service.

An account is required to authenticate the app and use eligible live-provider features. Those features send only the information needed to complete the apartment or commute request. LocatorDesk contains no third-party advertising, does not sell personal information, and does not use CRM content for cross-app tracking.

Information stored on your device

The local LocatorDesk workspace can include information that you enter, paste, import, or create, such as:

  • Lead names, phone numbers, email addresses, social handles, lead sources, and consent or opt-out status.
  • Renter budgets, move-in timing, bedrooms, pets, requested areas, amenities, and commute preferences.
  • Notes, inbound inquiry text, follow-up dates, activity history, message drafts, and shortlist choices.
  • Property and unit details, source and verification dates, URLs, specials, and commission notes.
  • Business identity, broker-approved disclosure text, reminder choices, and other app preferences.

The file is separated by signed-in account and uses iOS file protection. Local follow-up notifications are scheduled by iOS on your device. LocatorDesk does not operate cloud sync for these CRM records. Your operating system or device-backup settings may independently include app data in a backup, subject to Apple's controls and retention practices.

You are responsible for having a lawful business reason, appropriate consent, and any required broker approval before entering another person's information. Avoid recording sensitive information that is not needed for the renter's requested service.

Account and hosted-service information

Account information

LocatorDesk uses Convex Auth for identity, account access, and hosted sessions. Convex processes your email address, a unique account identifier, one-time sign-in codes, session information, and security metadata needed to authenticate and protect the service. We use Resend only to deliver the one-time sign-in email you request. Resend receives the destination email address, the sign-in message, and delivery metadata needed to transmit that email. The app stores its renewable session securely in the iOS Keychain.

Service operations

The Convex-hosted backend handles authenticated account, entitlement, apartment-search, and commute operations. When you call a live apartment or commute feature, we retain limited operational metadata: your account identifier, the provider and operation used, whether the call succeeded, failed, or was rate-limited, whether an apartment response came from cache, a non-content error code or upstream status, and a timestamp. We do not put request bodies, response bodies, renter text, or commute destinations in these usage records.

Subscription status

Apple processes App Store payments. To verify access to LocatorDesk Pro, we may receive and store the product identifier, original and latest transaction identifiers, Apple environment, expiration, revocation, and last verification time, linked to your LocatorDesk account. We do not receive your full payment-card details.

Temporary migration and rollback

When the Convex-backed TestFlight build is released to testers, limited legacy account and entitlement records may be copied from Supabase to Convex. We use the verified account email to match the records and preserve account continuity. This migration does not upload the local CRM workspace described above.

A restricted Supabase copy is retained only for migration validation and rollback during the 14 days following that TestFlight cutover. After the 14-day window, we decommission Supabase for LocatorDesk once migration validation is complete. If validation is not complete at day 14, the copy remains restricted to migration and rollback and is decommissioned as soon as validation completes.

Live apartment and commute features

Apartment inventory

If you run a live apartment search, the app sends the search criteria you choose—such as city and state, postal code, coordinates and radius, rent range, bedroom count, or result limit—to our authenticated service. The service passes the necessary criteria to RentCast and returns normalized listing information. We may keep a short-lived cache of normalized apartment results to reduce repeat provider calls. The cache is not labeled with your account identifier and expires automatically.

Commute estimates

If you request commute estimates, the app sends the selected property's coordinates and the destination addresses or coordinates you entered, along with travel mode and timing needed for the request. Our service passes those values to Google Routes and returns distance and duration information. We do not intentionally persist commute request or response payloads in our database or apartment cache.

Provider data can be incomplete, estimated, delayed, or wrong. Use it as a research aid and verify material property and route details before anyone relies on them.

Drafts, reminders, feedback, and support

Message drafts

LocatorDesk prepares message drafts on your device from the information in your local workspace. It does not automatically send a text, email, direct message, or other outreach. You decide whether to edit, copy, share, or discard a draft.

Notifications

If you enable reminders, iOS schedules generic follow-up notifications locally. You can turn notifications off in LocatorDesk or iOS Settings. We do not use notifications for advertising profiles.

Feedback and support

Sending feedback or contacting support is optional. If you use the in-app feedback form, we receive your feedback category and message, any email address you choose to provide, app version, device model, operating- system version, and locale. If you email us, we receive your email address and whatever you include. Please do not include renter records or other sensitive client information in a support request.

How we use information

  • Authenticate accounts, maintain sessions, and protect the service from fraud or abuse.
  • Provide requested apartment-search and commute features.
  • Verify subscription access, enforce reasonable quotas, and restore eligible features.
  • Diagnose failures, maintain service reliability, and understand aggregate operational demand.
  • Respond to support, privacy, security, and legal requests.
  • Comply with applicable law and enforce our Terms of Use.

Where privacy law requires a legal basis, processing is based on performing our contract with you, our legitimate interests in operating and protecting LocatorDesk, compliance with legal obligations, or your consent where applicable.

When information is disclosed

We disclose information only as reasonably necessary in these circumstances:

  • Service providers: Convex, including Convex Auth, for identity and the hosted backend; Resend only to deliver requested one-time sign-in emails; Apple for App Store purchases and platform services; RentCast for an apartment search you request; Google Routes for a commute estimate you request; Supabase only for the temporary migration and rollback period described above; and our hosting and feedback providers for delivery, security, and support.
  • Legal and safety: when required by applicable law or legal process, or when reasonably necessary to protect users, the public, our rights, or the integrity of the service.
  • Business transfer: in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and notice where required.
  • At your direction: when you choose to export or share local information through iOS.

Third-party services handle information under their own terms and privacy notices. You can review the policies for Convex, Resend, Apple, RentCast, and Google. During the temporary rollback period, you can also review the policy for Supabase.

Retention and deletion

  • Local CRM information remains on your device until you delete records, reset the workspace, delete the account in the app, or remove the app, subject to device-backup behavior.
  • Account and active entitlement records remain while your account is open. In-app account deletion disables account access and invalidates active sessions immediately, then schedules user-linked authentication, service, quota, usage, and entitlement records for deletion in bounded batches. Failed batches are retried until the purge completes.
  • Provider-usage metadata for an open account is scheduled for deletion after 90 days. Account deletion schedules that metadata for earlier purge with the other user-linked records.
  • The restricted legacy Supabase copy follows the 14-day migration and rollback process described above. During that window, contact support after an account-deletion request if you want confirmation that corresponding legacy records have also been removed.
  • Normalized apartment cache entries expire after their short configured lifetime and are removed through service cleanup.
  • Commute request and response payloads are not intentionally retained in our database.
  • Support correspondence is retained only as long as reasonably needed to resolve the request, maintain business records, prevent abuse, and meet legal obligations.

Deletion from active systems may not immediately remove information from encrypted backups, security records, or records we must keep for legal reasons. Apple and other independent providers control their own records and deletion processes.

Your choices and privacy rights

  • Edit or delete local leads, properties, drafts, and related records inside LocatorDesk.
  • Export a local backup before deleting information.
  • Turn off local reminders and notification permission.
  • Choose whether to use live apartment or commute features.
  • Delete local data separately or delete your LocatorDesk account from Settings.
  • Contact us to request access, correction, or deletion of personal information we control.

Depending on where you live, you may have additional rights, including to appeal a privacy-request decision. We may need to verify your identity before completing a request. We will not discriminate against you for exercising an applicable privacy right.

Security, transfers, and children

We use reasonable technical and organizational safeguards designed to protect information, including authenticated provider routes, server-side credentials, account-scoped local files, iOS Keychain session storage, and limited operational logging. No storage or transmission system can be guaranteed completely secure.

Our providers may process information in the United States and other places where they operate. Privacy laws in those locations may differ from those where you live.

LocatorDesk is a professional business utility and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided account or support information to us.

Changes and contact

We may update this policy when LocatorDesk, our providers, or applicable requirements change. We will update the date above and provide additional notice when required. Questions and privacy requests can be sent to support@hatchingpoint.com.

Hatching Point LLC