Privacy Notice
There are two relationships here and they are not the same. For an operator's own account we decide what we collect. For that operator's tenants, the operator decides and we process it on their behalf.
Version 2026-09-20.4
Whose information this is about
Operators and their staff — the people who sign up and use the console. We decide what we collect about them, and this notice describes it.
Tenants — the people who rent units from an operator. Their information reaches us because their operator put it there, or because they used that operator's storefront or tenant portal. The operator decides what is collected and how long it is kept; we handle it on the operator's instructions. If you are a tenant, the operator you rent from is the right first point of contact about your own information.
What we hold
Depending on which parts of the product an operator uses:
- Account details for operator staff: name, email address, password (stored only as a scrypt hash, never as the password itself), role, and the record of sign-ins.
- Facility and unit records, rates, hours, photographs and published website copy.
- Tenant records: name, contact details, addresses, the units they rent, their rentals, invoices, payments and account balance, and any notes or custom fields the operator has chosen to keep.
- Payment information: the brand, last four digits and expiry of a saved card and the payment provider's own reference. Full card numbers and bank details are held by the payment provider and never reach this platform.
- Messages sent and received — emails and text messages, their content, and their delivery outcome — together with the record of who agreed to be texted, what wording they were shown and when.
- Signed rental agreements, including the exact text signed, the typed signature, the time and the IP address it was signed from.
- Gate activity at facilities with a connected gate system: codes issued and revoked, and entry and exit events.
- Technical records: IP address, browser user-agent and timestamps against sign-ins, agreement signatures and consent records, plus an audit log of consequential actions taken in the console.
Why we hold it
To run the service an operator has asked us to run: to bill and collect rent, to send the receipts and notices an operator configures, to publish their storefront, to take online move-ins, to open and close gates, and to keep the audit trail an operator needs when something is questioned later.
We do not sell personal information, we do not use it for advertising, and we have added no advertising tracker to any page of this product. Our own public marketing pages on storageunitos.ai use Google Analytics to count visits; no storefront, console or portal page does. The cookies section below lists everything a page does store in a browser, including that and the payment provider's own fraud checks at checkout, so that the two statements can be read against each other.
Who else sees it
We use a small number of service providers to run the product. Each one below was confirmed against the place in the product's source code where it is actually called:
- Stripe — Card and bank payments. Tenant payments are direct charges on the operator's own connected Stripe account, so card details go to Stripe and are never stored here — this platform keeps only the card brand, last four digits and Stripe's own reference.
- Resend — Sending and receiving email — receipts, notices, invitations and sign-in links.
- Telnyx — Sending and receiving text messages, and providing the phone numbers they are sent from.
- Railway — Hosting for the application and its database.
- Railway (custom domains) — Registering an operator's own storefront hostname so that it resolves and gets a TLS certificate. Only when that integration is switched on.
- Amazon Web Services (S3) — object storage — Holding uploaded images and the private company document vault. THIS deployment uses Amazon S3 in the US West (Oregon) region, with the document vault in a private bucket that is not readable from the public internet. The same code can talk to any S3-compatible provider — Cloudflare R2, a self-hosted MinIO — when one is configured, so a DIFFERENT deployment of this software may hold its files elsewhere; this notice describes ours.
- Amazon Web Services (Simple Notification Service) — The notification topic the gate integration receives hardware events through. Only when that integration is switched on.
- OpenTech Alliance (INSOMNIAC CIA) — Gate access control — issuing and revoking a tenant's gate code at the facilities that use OpenTech hardware. Only when that integration is switched on.
- Intuit (QuickBooks Online) — Accounting sync, for operators who connect their QuickBooks company. Only when that integration is switched on.
- Anthropic — Reading an operator's own export from a previous storage-management system during a data import, to work out which column means what. Only when that integration is switched on.
- Google (Google Analytics) — Counting visits to our own public marketing pages on storageunitos.ai — never an operator's storefront, the tenant portal or the console. Loaded only after consent where the visitor's browser reports a European time zone; see the cookies section. Only when that integration is switched on.
- Sentry (Functional Software, Inc.) — Error tracking. When something breaks in our API, our background worker, the operator console, an operator's storefront or the tenant portal, the exception and its stack trace are sent so we can find and fix it. When you are signed in, the report is tagged with your account's id — never your name, email or anything you typed — so we can find it from a support conversation. Any web address in one has its query string removed and any single-use credential in its path masked before it leaves the browser or server, and we collect no session replay and no performance trace. Only when that integration is switched on.
Each entry above was confirmed against a call site in the product's source. The list has not been through a privacy review, and it does not yet name each provider's own legal entity, contracting terms or processing locations.
Cookies and other browser storage
Every cookie we set ourselves is a sign-in cookie. There is one for the operator console, one for the tenant portal, and one for the platform administration area that only our own staff can sign in to. A fourth is set only during a single sign-on round trip, holds the state of that one sign-in, and expires within ten minutes. A fifth is set on your company's own console address only while a Google or single sign-on you started there completes on ours: it holds a random value that lets that address recognise the same browser coming back, carries nothing about you, and expires within ten minutes or as soon as it is used. A sixth is set on ours during that same round trip to tie its two halves together; it too carries nothing about you and expires within ten minutes or as soon as it is used. A seventh is set only when you choose to sign up or rent with a Google account: for the ten minutes it takes to finish that form it holds the name and email address Google confirmed, so we can fill them in for you, and it is removed as soon as the form is submitted. All of them are sent only over HTTPS in production and none is readable by page scripts. A deployment running our newer sign-in stack sets a second console session cookie alongside the first.
One page sets cookies we do not control. A storefront checkout loads Stripe's own payment library, so that a card number goes to Stripe and never to us, and that library sets cookies of its own when it loads — including an identifier for the device that lasts about a year, which Stripe uses to detect fraud on the payment. Those are set and read by Stripe and not by us, and Stripe's own privacy policy governs them. This happens on the checkout part of an operator's storefront; it does not happen on the console or on the pages you are reading now.
We set nothing for advertising and nothing that follows anyone across other websites. One analytics script runs, and only on our own public marketing pages at storageunitos.ai — the home page, pricing, feature and legal pages, and this notice: Google Analytics, which sets its own cookies (named _ga and _ga_ followed by an identifier, lasting up to two years) to tell a returning browser from a new one and count page views. A bar at the foot of those pages tells you so. If your browser reports a European time zone, nothing from Google loads until you press Accept, and Reject is offered beside it; elsewhere the bar is a notice and the script runs. Either way your answer is kept for a year in one first-party cookie named suos_consent, which holds only the word granted or denied, and the Cookie settings link in the footer lets you change it. A browser that sends the Global Privacy Control signal is treated as having declined. It is not loaded on any operator's storefront, on the tenant portal, or in the console, and the information it collects for us is aggregate — pages, referrers, rough location by IP, browser and device — which we use only to understand how people find and read about the product. Google's own privacy policy governs what Google does with what its script collects. The Stripe cookies above are the fraud checks on a payment, not advertising.
Separately from cookies, the console keeps a few things in your own browser that are never sent to us: your light or dark preference, which facility you last had selected, which navigation menu you left open and — if you use single sign-on — your workspace name. Two screens that retry a payment or a refund also keep a reference for that attempt in the tab's own storage — one when refunding the platform's own invoice to an operator, a second when refunding an individual tenant's payment — so that pressing the button again cannot take the money twice; the browser discards each one when the tab closes.
This section is an enumeration, not a summary: it is meant to list every cookie and stored item the product sets, and each was read out of the source rather than recalled. If you find one it does not name, that is a mistake in this notice.
Keeping it safe
Passwords are stored as scrypt hashes. Credentials for an operator's connected third-party systems — gate hardware, a previous provider's portal — are encrypted at rest with AES-256-GCM. Traffic is served over HTTPS.
Each operator's data is separated from every other operator's, and the console enforces that on every request rather than relying on the interface not to show it.
How long we keep it
Records are kept for as long as the account exists. Financial records, signed agreements and consent records are deliberately not destroyed when something is deleted in the console — a deletion marks the row rather than removing it — because those records are the evidence of what happened, and an operator being unable to produce them is a worse outcome than keeping them.
When an account ends, there are 30 days in which an operator can still export their data. After that we delete it, within a further 60 days. Backups age out on their own schedule rather than being edited, so a copy can persist in a backup for a short period after that.
The exception is the evidence described above — signed agreements, payments, consent records and acceptances of our terms. Those are kept for as long as they may be needed to answer a question about the event they record, because destroying them would remove the only proof it happened.
Who is responsible, and how to reach us
The service is provided by Storage Unit OS, LLC, a limited liability company registered in Idaho, at 140 E 100 S, Burley, ID 83318. Questions about this notice, or about information we hold, go to support@storageunitos.ai.
For an operator’s own account we decide what we collect, and this notice describes it. For a tenant’s information the operator decides, and we hold it on their behalf — which is why a tenant asking about their own record is directed to their operator rather than to us.
Your choices
A tenant can stop marketing email by using the unsubscribe link on it, and can stop text messages by replying STOP to any of them. Both are honoured by the platform itself and not only by the operator.
For anything else about a tenant's own record — seeing it, correcting it, or asking for it to be deleted — the operator holds that decision, and the request should go to them.
Still to be settled in this document
These are deliberately blank rather than filled in with text that would only look finished.
- Which privacy laws we are treating as applying, and how requests under them are handled and within what time.
- Where each provider listed above stores data, and the data-processing terms agreed with each of them. Object storage is answered in that list; the others are not written down yet.
- Whether a data-processing agreement is offered to operators, and on what terms.