Built to be trusted
How SpotHOA handles your community’s data, money, and continuity. No certifications we don’t hold and no security theater: just what is actually true about how the product works.
- Your data stays isolated
- Every HOA's data is partitioned by HOA, and that isolation is enforced by an automated test suite that runs on every change, not just by convention. Data is encrypted in transit (TLS) and hosted in the United States.
- The money never touches us
- Dues and assessments flow directly through your HOA's own Stripe account (Stripe Connect). SpotHOA never holds, pools, or routes your funds. Your treasurer keeps control of the bank connection, and the dues amount lands in your balance untouched.How this protects against embezzlement →
- You own your data, and you can leave
- Export the full ledger, document vault, member list, and meeting records as CSV and PDF at any time, on Free or Pro. Cancel in one click. If you delete the account, there is a 14-day grace period before anything is purged. No contracts, no lock-in.
- Support access is read-only and logged
- When our team needs to look at your account to help, that access is read-only and every session is logged. We do not quietly edit your community's records.
- Privacy in plain language
- Our privacy policy discloses every subprocessor and exactly how data is handled, written to be read by a volunteer board, not a lawyer. We honor data-access and deletion requests.Read the privacy policy →
- We operate in the open
- A live status page shows real-time uptime, and a public feature-request board shows exactly what we are building. We ship most customer requests in roughly a week.System status →
- Built to survive board turnover
- Every dues payment, vote, and violation is a permanent, timestamped, append-only event. When the board changes, the next board inherits the full history on day one. No tribal knowledge, no lost paperwork.
- Security reports are welcome
- Found a vulnerability? Tell us directly at hello@spothoa.com and we will respond quickly. A machine-readable disclosure channel is published per RFC 9116, and we ask for a reasonable window to fix an issue before it is shared publicly.security.txt →
Questions about how we handle your data?
Ask us anything. If the answer is “we don’t do that,” we will say so.