Privacy Policy

Effective date: Oct. 1, 2026

This policy explains how Konjo Story ("Konjo Story," "we," "us"), operated by Konjo Solutions, collects, uses and protects information when you use the Konjo Story application at konjostory.com and its subdomains (the "Service").

Konjo Story is a business tool for multifamily property management companies and their marketing partners. Our customers are organizations (for example, property management companies), and the people who use the Service are their authorized staff and partners ("Users").

1. Information we collect

Account information. A User's name, email address, organization, role and property assignments. Passwords are stored only in hashed form by our authentication provider. We never see or store passwords in readable form.

Property and business data. Information our customers provide about their properties, such as property names, addresses, unit types, occupancy, targets, marketing events, notes and ILS package details.

Aggregated leasing and marketing metrics. Counts and totals such as leads, tours, applications, signed leases, move-ins, marketing spend, impressions and clicks, by property, date and marketing source.

Imported reports. Customers can upload or email reports (CSV or Excel), for example from their property management software.

  • We extract only the aggregated metrics the customer has mapped.

  • Columns that appear to contain personal information about prospects or residents (such as names, phone numbers or email addresses) are ignored and never loaded.

  • The original file is kept for a limited period so the customer can review the import, then deleted automatically. The default is 30 days, and each customer can set it between 1 and 365 days.

Emailed-report records. When a report is emailed to an import address, we record the sender address, subject, time received, attachment names and the email authentication results (SPF, DKIM, DMARC). We use these to confirm the report came from an approved sender.

Data from connected services. When an organization administrator connects a Google or Meta account, we receive the reporting data described in section 3.

Usage and security records. We keep an audit trail of changes (who changed what, and when). Our hosting providers also keep standard server logs (such as IP address, browser type and request time) for security and troubleshooting.

Cookies. We use only the cookies needed to keep you signed in and to remember basic preferences, such as the selected organization. We do not use advertising or third-party tracking cookies in the Service.

What we do not collect

Konjo Story does not store prospect-level or resident-level personal information. We do not store prospect names, phone numbers, email addresses, messages or application details. Leasing activity is stored only as aggregated counts.

2. How we use information

We use information to:

  • provide the Service: dashboards, reports, imports and alerts

  • control access, so each User sees only the organizations and properties they are authorized for

  • send service emails, such as invitations, password resets and import notifications

  • keep the Service secure, prevent misuse and troubleshoot problems

  • comply with legal obligations

We do not sell personal information. We do not use customer data for advertising, and we do not use it to train artificial intelligence models.

3. Google and Meta data

With an organization administrator's permission, Konjo Story can connect read-only to the following services:

  • Google Analytics

  • Google Search Console

  • Google Ads

  • Google Business Profile

  • Meta (Facebook and Instagram)

What we access:

  • performance and reporting data, such as sessions, search impressions and clicks, ad spend, impressions, clicks and conversions

  • business profile performance and reviews, with their rating, date, text and response status

We do not store reviewers' names or profile information.

How we use it: only to show reporting and insights for the properties that organization manages, inside that organization's Konjo Story account. It is not shared with other customers.

Google API Services. Konjo Story's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We use Google user data only to provide and improve the user-facing features described above.

  • We do not transfer it to others except as needed to provide the Service, comply with law, or as part of a merger or acquisition with notice to users.

  • We do not use it for advertising.

  • We do not allow humans to read it except with the customer's permission, for security purposes, or to comply with law.

Disconnecting. An organization administrator can disconnect a Google or Meta connection in Konjo Story at any time. You can also remove Konjo Story's access from your Google Account (myaccount.google.com/permissions) or Meta Business settings. When a connection is removed, we stop collecting new data and delete the stored access credentials. Customers can ask us to delete previously collected data (see section 7).

Meta data deletion. To request deletion of data received from Meta, email pilot@konjosolutions.com with the subject "Data deletion request". We will confirm and complete the request within 30 days.

4. How information is shared

We share information only:

  • within your organization, with Users authorized to see it according to their role and property assignments

  • with service providers that host or operate the Service for us, under contracts that limit their use of the data:

    • Supabase: database, authentication and file storage (United States)

    • Vercel: application hosting

    • Resend: sending and receiving service email

  • when required by law, or to protect the rights, safety and security of our Users and the Service

  • in a business transfer, such as a merger or acquisition, with notice to affected customers

5. Data security

  • Data is encrypted in transit (HTTPS) and at rest.

  • Access is enforced at the database level, so each organization's data is isolated from every other organization.

  • Access keys for connected services are stored encrypted and are used only by our servers.

  • Changes to important records are logged.

No system is perfectly secure. We will notify affected customers of a security incident as required by law.

6. Data retention

  • We keep customer data for as long as the customer's account is active, or as needed to provide the Service.

  • Original imported files are deleted automatically after the customer's retention period (30 days by default).

  • When a customer closes their account, we delete or de-identify their data within 90 days, except where we must keep it longer by law.

7. Your choices and rights

  • Users can view and update their name and email in their account.

  • Organization administrators can manage Users, disconnect connected services, and request export or deletion of their organization's data.

  • Depending on where you live, you may have rights to access, correct, delete or receive a copy of your personal information. To make a request, email pilot@konjostory.com. If your information was provided by your employer (our customer), we may refer your request to them.

8. Children

The Service is for business use and is not directed to children under 16. We do not knowingly collect their information.

9. Changes to this policy

We may update this policy. We will post the new version here with a new effective date and, for significant changes, notify customer administrators by email.

10. Contact

Konjo Solutions, PO Box 301, Hudson, OH 44236 Email: pilot@konjostory.com