CasitanaBack

Privacy Policy

Last updated: August 2026

1. Who we are

CASITANA is operated by Forward Thinking, a company providing property management software for rental property owners in Europe. Our platform helps landlords track finances, bookings, documents and maintenance tasks for their rental properties.

For questions about this policy, contact us at: privacy@casitana.com

2. What data we collect

We collect only the data necessary to provide our service:

  • Account data: your name, email address, and password (stored as a bcrypt hash — we never see your plain-text password).
  • Property data: property names, addresses, financial transactions, booking records, and documents you upload.
  • Payment data: billing is processed entirely by Stripe. We store only your Stripe customer ID and subscription status — never your card details.
  • Usage data: server logs, page visits, and error reports for debugging and service improvement.
  • Session cookies: a single session cookie to keep you logged in. It expires when you close your browser or log out.

3. How we use your data

  • To provide, operate and maintain the CASITANA platform.
  • To process payments via Stripe.
  • To send transactional emails (account confirmation, password reset, subscription receipts).
  • To provide customer support when you contact us.
  • To improve our product based on aggregated, anonymised usage patterns.

We do not sell your data. If you allow marketing cookies, measurement data about your visit to our public marketing pages is shared with our advertising providers, Google and Meta — see section 7. We share nothing with advertisers otherwise, and we do not use your data for any purpose other than operating and improving the service.

4. Legal basis (GDPR)

Under the General Data Protection Regulation (GDPR), we process your data on the following legal bases:

  • Contract performance: to deliver the service you subscribed to.
  • Legitimate interest: to maintain security, prevent fraud, and improve the platform.
  • Legal obligation: to retain financial records as required by applicable law.
  • Consent: for any marketing communications (which you may withdraw at any time).

5. Data sharing and third parties

We use the following third-party processors:

  • Stripe — payment processing (privacy policy at stripe.com/privacy).
  • Railway — cloud hosting and database infrastructure.
  • Cloudflare R2 — file and document storage.
  • Resend — transactional email delivery.
  • Anthropic PBC — AI receipt scanning. The receipt image or PDF itself is sent to the model, which reads the amount, date, supplier name and category back out of it. This happens only for a receipt you attach on a plan that includes scanning, and nothing the model returns is kept beyond the transaction you save.
  • Sentry (functional.sentry.io) — error monitoring and performance tracking to improve application reliability. Session capture runs only if you allow analytics cookies.
  • Google (Tag Manager, Google advertising products) — advertising measurement and personalisation on our public marketing pages, only if you allow marketing cookies. Tag Manager is the container through which our advertising tags, including Meta’s below, are loaded.
  • Twilio Inc. — WhatsApp business messaging (phone numbers, message content).
  • Meta Platforms (WhatsApp Business) — message delivery. Part of the service; not related to cookies or advertising consent.
  • Meta Platforms (advertising pixel) — advertising measurement on our public marketing pages, only if you allow marketing cookies. A separate use from WhatsApp message delivery above.
  • SES Hospedajes (Spanish Ministry of Interior) — guest registration data as required by Royal Decree 933/2021.

All processors are contractually bound to protect your data and comply with GDPR.

6. Data retention

We retain different categories of data for specific periods based on legal requirements and operational necessity:

  • Read notifications: 90 days
  • Scheduled WhatsApp messages: 30 days after delivery
  • Automation logs: 90 days
  • Guest registration data (SES): 3 years, as required by Royal Decree 933/2021
  • Audit logs: 1 year

Upon account deletion request, all personal data is permanently removed, except data that we are legally required to retain (e.g. guest registration records under Royal Decree 933/2021, financial records under Código de Comercio, Art. 30).

7. Cookies and similar technologies

We group cookies and similar technologies into three categories. You choose which optional categories to allow the first time you visit, and you can change that choice at any time.

  • Essential — always on. A session cookie keeps you signed in, a CSRF token protects against cross-site request forgery, and a language preference cookie (casitana_locale) stores your chosen language for one year. These cannot be switched off, because the platform does not work without them.
  • Analytics — off unless you allow it. Measures which pages people use and where they run into difficulty. This includes error-triggered session capture through Sentry, a third-party service: when something goes wrong, a recording of what happened on the page is captured so we can diagnose it. Text and form inputs are masked in those recordings.
  • Marketing — off unless you allow it. Google advertising products and Meta’s advertising pixel, both loaded through Google Tag Manager, used to measure which advertisements and referrals bring people to Casitana and to show you our advertisements on other sites. Neither is enabled unless you allow this category.

We use Google Consent Mode. On our public marketing pages this means the Google Tag Manager container loads before you have made a choice, in a state where advertising and analytics storage are denied; your choice is then applied to it. That applies to every advertising tag in the container, Meta’s included. The container is not loaded at all inside the customer portal, or on the pages guests reach through a registration or contract link.

8. Your rights (GDPR)

As an EU resident, you have the right to:

  • Access: request a copy of your personal data.
  • Rectification: correct inaccurate data.
  • Erasure: request deletion of your account and data (“right to be forgotten”).
  • Portability: receive your data in a machine-readable format.
  • Objection: object to processing based on legitimate interest.
  • Restriction: request that we limit how we use your data.

To exercise any of these rights, email privacy@casitana.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.

9. Security

We use industry-standard security measures including HTTPS encryption in transit, bcrypt password hashing, and isolated database access controls. No method of electronic storage is 100% secure; we work continuously to protect your data and will notify you promptly in the event of a breach.

10. Changes to this policy

We may update this policy when our practices change or when required by law. We will notify active users by email at least 14 days before material changes take effect. Continued use of the service after that date constitutes acceptance.

Questions? Contact us at privacy@casitana.com or visit our contact page.