SpotHOA

Built to be trusted

How SpotHOA handles your community’s data, money, and continuity. No certifications we don’t hold and no security theater: just what is actually true about how the product works.

Your data stays isolated
Every HOA's data is partitioned by HOA, and that isolation is enforced by an automated test suite that runs on every change, not just by convention. Data is encrypted in transit (TLS) and hosted in the United States.
The money never touches us
Dues and assessments flow directly through your HOA's own Stripe account (Stripe Connect). SpotHOA never holds, pools, or routes your funds. Your treasurer keeps control of the bank connection, and the dues amount lands in your balance untouched.How this protects against embezzlement
You own your data, and you can leave
Export the full ledger, document vault, member list, and meeting records as CSV and PDF at any time, on Free or Pro. Cancel in one click. If you delete the account, there is a 14-day grace period before anything is purged. No contracts, no lock-in.
Support access is read-only and logged
When our team needs to look at your account to help, that access is read-only and every session is logged. We do not quietly edit your community's records.
Privacy in plain language
Our privacy policy discloses every subprocessor and exactly how data is handled, written to be read by a volunteer board, not a lawyer. We honor data-access and deletion requests.Read the privacy policy
We operate in the open
A live status page shows real-time uptime, and a public feature-request board shows exactly what we are building. We ship most customer requests in roughly a week.System status
Built to survive board turnover
Every dues payment, vote, and violation is a permanent, timestamped, append-only event. When the board changes, the next board inherits the full history on day one. No tribal knowledge, no lost paperwork.
Security reports are welcome
Found a vulnerability? Tell us directly at hello@spothoa.com and we will respond quickly. A machine-readable disclosure channel is published per RFC 9116, and we ask for a reasonable window to fix an issue before it is shared publicly.security.txt

Questions about how we handle your data?

Ask us anything. If the answer is “we don’t do that,” we will say so.