Privacy Policy
Effective August 9, 2026
Vardis ("we") is property management software operated by Nicholas Redmann, doing business as Vardis, from Florida, USA. This policy says what we collect, why, and what we will never do with it.
What we collect
- Your account: your name, email address, and password. Passwords are stored only as a cryptographic hash — we cannot read them.
- The records you create: properties, units, tenants, leases, rent entries, work orders, notes, and documents you upload. This includes personal information about your tenants that you choose to enter.
- Billing: handled entirely by Stripe. Card numbers never touch Vardis servers. We keep only your subscription status and a Stripe customer reference.
- Technical: IP addresses and sign-in events (to secure accounts and stop abuse), routine server logs, and error reports that are scrubbed of personal data.
- Cookies: one session cookie that keeps you signed in. No advertising cookies, no analytics trackers, nothing that follows you around the web.
Why we collect it
To run Vardis for you, keep accounts secure, bill subscriptions, send transactional email (verification, password resets, invites), and fix problems. That's the list. We don't use your data for advertising, and we won't email you marketing without asking first.
We never sell your data
Not to anyone, not in any form, not "anonymized." We share it only with the services that physically run Vardis — hosting (Railway), file storage and delivery (Cloudflare), billing (Stripe), email delivery (Resend), and error monitoring (Sentry, configured to exclude personal data) — each bound to use it only to provide their service to us; or if the law genuinely requires it; or at your direction (like when you export).
Your tenants' information
You're responsible for having the right to store the tenant information you enter. We use it for exactly one purpose: running the service for you. If a tenant has concerns about their information, they can contact their landlord or us.
Retention and deletion
Inside the app, records are voided, not erased — that audit trail is a core feature, so accidental and malicious deletions can always be traced.
Encrypted database backups are kept on a rolling schedule — daily backups for 30 days and weekly backups for 84 days — so no database backup is more than 84 days old. Backup copies of uploaded documents are kept until you ask us to delete your data.
If you close your account and request deletion: you can take a full export first, we permanently delete your live data and the backup copies of your uploaded documents, and database backups expire on their schedule — fully gone within 84 days.
Security
Passwords are hashed with bcrypt, all traffic is HTTPS, backups are encrypted before they leave the server, and access to production systems is limited to the operator.
Your rights
You can see and export your data from inside the app at any time, correct anything yourself, or email us to close your account and have your data deleted. We answer within 30 days.
Children
Vardis is a business tool and isn't directed at children under 13; we don't knowingly collect their information.
Changes
We'll post any updates here, and email you about material changes.