neighborPOP

Privacy policy

Plain language on purpose. Effective August 19, 2026. neighborPOP is a product of Hivetivity Inc., a Delaware corporation based in Milton, Georgia.

Who does what with your data

Your HOA provides its member directory (names, emails, phone numbers, home addresses) so the community can run. Legally and practically, your HOA owns and controls that data; Hivetivity Inc. processes it only on the HOA's behalf and only to operate neighborPOP. If you want your information corrected or removed, your HOA's board is the fastest path, and we help them do it. If you contact us directly at the address below, we respond within 30 days.

When you contact us, that part is ours

Member data belongs to the association, but the details you hand us are a different thing, and we should be plain about it. When you start a trial, ask us to call you, or email us, we keep your name, email address, phone number, the community you named, and how you heard about us. For that information Hivetivity Inc. is the controller, not a processor: it is ours to look after, and the decisions about it are ours to answer for.

We use it to set up your community, to get in touch about neighborPOP, and to work out which of our own pages actually help. We do not sell it, we do not rent it, we do not hand it to advertisers, and nothing automated calls or texts you. If you never become a customer we keep it for two years and then delete it, and if you would rather we deleted it sooner, ask at the address below and we will, without asking you why.

What we store

The directory your HOA provides, plus what the platform produces: maintenance requests and their photos, documents the board uploads, community email history, approval records, and sign-in and delivery logs. Payment details, when billing begins, are handled by Stripe; card numbers never touch our systems.

What we never do

We never sell personal data. We never share it outside your community's operations except with the infrastructure providers below. Inside your community's portal there are no trackers at all. No advertising pixels, no analytics scripts, no third-party cookies, nothing that reports what a resident looked at to anybody. That is not a setting; there is no code in the portal that could do it.

Our own marketing pages, the ones at neighborpop.com that you are reading now, are different and we would rather say so than be caught at it. We run ads, and on these public pages we measure whether they work: a first-party cookie of ours records which ad or link brought you here so that if you later start a community we know which one earned it, and we use the advertising platforms' own measurement tools. None of that follows you into the portal, and none of it is tied to a resident. Our own server also keeps a count of the pages requested on these marketing pages, including by the search engines and AI assistants that index us. It records the page, the browser or crawler that asked, the network it came from and the country, and it sets nothing on your device.

Email

We send two kinds: updates you asked for (sign-in codes, request tracking, receipts) and community announcements your board writes. Announcements identify the sender, include our postal address, and carry a working unsubscribe link honored immediately and automatically, as the CAN-SPAM Act requires. Updates about your own requests continue regardless, because you asked for those.

AI processing

Email sent to a community's intake address is read by an AI model to classify it and draft a record for a human to review. Two providers do that reading: Anthropic (the Claude models), reached through Cloudflare's AI Gateway, and Cloudflare Workers AI, which handles classification and stands in whenever the Anthropic route is unavailable. Both process in the United States.

What they receive is the text of the thing being worked on: the body of an inbound email, or the details of a work order we are drafting a message about. Neither is given your directory, and your email is not used to train anyone's models. We keep a record that a model call happened and which model answered; we do not keep the content of the request.

Where data lives, and who touches it

Everything is stored on Cloudflare's US infrastructure. Three companies process your community's information on our behalf, and no others:

That is the whole list. Each acts under its own data terms, none of them sells your information, and we do not hand your community's data to anyone else. If that list ever changes, this page changes with it.

In transit, everything travels over HTTPS. At rest, it sits on Cloudflare's encrypted storage. Sign-in uses a one-time code sent to an address already in your directory rather than a password, so there is no password of yours for us to lose.

Children

neighborPOP is for adults managing communities. It is not directed at children under 13 and we do not knowingly collect their information.

California and other state privacy laws

At our current size, laws like the CCPA do not yet apply to us. We honor their spirit anyway: ask to see, correct, or delete your data and we will, subject to your HOA's role as the data's controller.

If something goes wrong

If a breach affects your community's data, we notify the affected HOA promptly with what we know and what we are doing, and comply with applicable notification laws.

Cookies, and the short list of them

Signed in, one cookie holds your session so the portal knows it is you. That is the only cookie the portal sets.

On these marketing pages, if you arrived from an ad or a tracked link, one more cookie of ours remembers which one for ninety days. It holds a click identifier and nothing about you, and its only job is telling us which of our own pages and ads are worth the money.

These same public pages also run measurement tags from Google Analytics and Meta, which set their own cookies to count visits and tell us whether an ad worked. Decline all of it by blocking cookies for this site; nothing here stops working. And none of it exists inside your community's portal, which sets exactly one cookie, the one that keeps you signed in.

Found a security problem?

Tell us and we will fix it. Email hello@neighborpop.com with "Security" in the subject and it goes straight to the person who wrote the code. We aim to reply within two business days.

We will not threaten you for reporting something in good faith. Please give us a reasonable chance to fix it before telling the world, do not run tests against a real community's data, and use the demo community instead, where every name and figure is invented. There is no bounty; there is a genuine thank you and a fast fix.

Leaving

A community can export its data at any time. On departure we delete what remains after a 30-day grace window, and residual copies age out of encrypted backups within 90 days.

Changes and questions

If this policy changes materially, community admins get an email before it takes effect. Questions: hello@neighborpop.com or Hivetivity Inc., Milton, Georgia.