Privacy Policy

Effective September 2, 2026

Version 2026-09-02. This Privacy Policy explains what information CommonKeep collects, why, and how it is used. CommonKeep was founded by Nicole Luckey and operates the Service described in our Terms of Service. By using CommonKeep, you agree to the practices described here.

1. Who is responsible for your data

CommonKeep is the independent product and service responsible for the personal information you enter. Nicole Luckey founded CommonKeep. CommonKeep is built and operated using technology, hosting, and infrastructure provided by Base44, along with other service providers described below. CommonKeep is not owned or operated by Base44, and Base44 did not create the CommonKeep concept; Base44 provides the platform and infrastructure CommonKeep uses today. This disclosure does not imply that CommonKeep will always use Base44 — CommonKeep may change technology, hosting, or service providers as described in the Terms.

2. Information CommonKeep collects and why

Account information.

Your primary email address (used to sign in) and name are used to create and identify your account. Authentication — including sign-in sessions and your password — is handled by the platform that operates the Service; CommonKeep does not store or have access to your password. You may also add a phone number and a profile photo to your account.

Additional contact identities.

You may add additional email addresses or phone numbers to your account (for example, a work email) so that invitations sent to those addresses can be matched to you. Verified additional emails are used for invitation matching; phone numbers can be saved but SMS verification is not yet available, so unverified phones are not used for matching. Verification codes for these identities are stored server-side only and are not returned to the client.

Environment membership and access.

To provide shared access, CommonKeep stores environment membership information: which users belong to an environment, their roles (owner, admin, or member), display emails, and any folder- or resource-specific access you grant. This is used to show members their environments and to enforce who can see or manage what.

Invitations.

When you invite someone, CommonKeep stores the recipient email (or a shareable token), the scope of the invitation (environment, a single resource, or a folder), the role offered, and the invitation status. This is used to deliver and track invitations and to match accepted invitations to the right account.

Manual People (contacts without accounts).

You may create "Manual People" records — name, email, phone, and notes — for people who do not have CommonKeep accounts, so you can assign or reserve resources to them and track resource use. This information is entered by you; CommonKeep uses it only within the environment where you created it. You are responsible for having the lawful authority to provide information about another person.

Resource and activity information.

You enter information about the resources you manage — names, descriptions, categories, locations, condition, value, contact details, rules, photos, quantities, and units — and the activities around them: reservations, assignments, returns/check-outs, issues, condition history, and maintenance/inspection records. This is used to provide the organizing, tracking, and sharing features of the Service.

Billing information.

For paid subscriptions, CommonKeep stores a Stripe customer identifier and subscription details (plan, billing cycle, status, and renewal dates) on the relevant environment. Payment-card data is processed by Stripe; CommonKeep does not collect or store full card numbers or banking credentials.

Feedback and quote requests.

If you submit feedback or a support message, CommonKeep stores your message, subject, type, and the email associated with your account. If you request a quote, CommonKeep stores the details you provide (name, email, phone, and your use case or needs); quote requests are visible only to CommonKeep administrators.

Technical and security information.

The platform that operates the Service may collect technical information necessary to run, secure, and maintain the Service, such as authentication session data and service logs. Depending on the platform's infrastructure, this may also include information such as IP addresses or device and browser details; CommonKeep does not independently control or verify all platform-level technical collection. CommonKeep may also record limited analytics events (for example, that a feature was used) to understand and improve the Service.

Information from other users.

You may receive information about yourself from other CommonKeep users rather than directly from you — for example, an invitation sent to your email, or a Manual Person record another member created about you so they can assign or reserve a resource to you.

3. How information is used

  • to provide, operate, and maintain your account and environments;
  • to organize, share, reserve, assign, and track resources and related activities;
  • to manage membership, access, and invitations;
  • to match invitations to the correct account (including verified additional emails);
  • to process subscriptions and billing through Stripe;
  • to communicate with you about your account, security, and service changes;
  • to prevent fraud, abuse, and security issues; and
  • to improve and develop the Service.

4. Service providers

CommonKeep uses service providers to operate the Service:

  • Base44 provides the technology platform, hosting, and infrastructure used to build and operate the Service. Your data is processed and stored through Base44's infrastructure as a processor/service provider for CommonKeep.
  • Stripe processes subscription payments. Stripe handles payment-card data; CommonKeep receives and stores only the customer and subscription identifiers and billing status needed to manage your plan.

CommonKeep may use other service providers for functions such as email delivery and analytics, each limited to what is necessary for their function.

5. Sharing of information

CommonKeep shares your information only as needed to operate the Service (including with the service providers above), among members within the environments you participate in (as you control), to respond to legal obligations, to protect rights and safety, and in connection with a legitimate business reorganization or transfer as described in the Terms.

CommonKeep does not sell your personal information. CommonKeep does not engage in targeted advertising or rent personal information to third parties for their own marketing.

6. Retention and deletion

CommonKeep keeps your information for as long as your account is active and as needed to provide the Service. When you request account deletion through Settings, CommonKeep deletes the CommonKeep-managed data associated with your account: environments you solely own along with the data within them; your own reservations and assignments in environments you belong to but do not own; your membership in those environments; and pending invitations you sent. To protect other members, CommonKeep will not delete an environment you own that still has other members. CommonKeep does not remove the underlying platform-managed login account, which may need to be removed separately. Shared Environment operational history that legitimately belongs to other members is preserved. These deletions are subject to legally permitted retention and backups as described in the Terms.

CommonKeep deletes or de-identifies applicable personal data within a reasonable period, except information that may or must be retained for legal obligations, security, fraud prevention, billing and accounting, disputes, backups, or other legally permitted purposes. CommonKeep does not promise a specific deadline for residual copies that exist only in routine platform backups, because that timeframe depends on platform-level backup retention that CommonKeep does not solely control.

7. Security

CommonKeep takes reasonable measures to help protect your information, including access controls, row-level restrictions on shared data, and keeping sensitive verification data server-side. However, no service can guarantee perfect security, and CommonKeep does not make an absolute guarantee that information will never be exposed. You should not store highly sensitive information in CommonKeep (see the Terms).

8. Your privacy rights

Depending on where you live, you may have rights to access, correct, or delete your personal information, to object to or restrict certain processing, to withdraw consent, and to request portability of your data. You can manage much of your information directly in Settings, and account deletion is available in Settings → Data & Privacy. A self-service in-app data export is not currently available; if you would like a copy of your data, contact CommonKeep as described below. To exercise other rights, contact CommonKeep as described below. CommonKeep may need to verify your identity before responding.

9. Children

CommonKeep accounts are only for people who are at least 18 years old. CommonKeep is not directed to children as account users, and people under 18 may not create CommonKeep accounts. However, an authorized adult user may enter limited operational and contact information about a person under 18 as a "Manual Person" — for example, to assign or reserve a resource to that person — when the adult user has the lawful authority to provide that information. The adult user is responsible for having appropriate authority to provide information about a minor and for ensuring that use is appropriate. CommonKeep should not be used to store highly sensitive information about minors. If you believe information about a minor has been entered without appropriate authority, contact CommonKeep so it can be reviewed.

10. Changes to this Privacy Policy

CommonKeep may update this Privacy Policy over time and will provide reasonable notice of material changes where appropriate. The effective date above reflects the current version.

Contact

You can contact CommonKeep about these Terms or privacy questions through the Help & Support page (no account required).