Who we are
Urbero is a rental-operations platform for New York City brokerages and landlords, available at urbero.com and its subdomains, including the app, the resident portal, and the public listing pages we host for our customers (together, the “Service”). Urbero is operated by Odd Pair Ventures LLC, a New York limited liability company. When we say “Urbero,” “we,” or “us” in this policy, we mean Odd Pair Ventures LLC.
This policy explains what information we collect, how we use it, who we share it with, and the choices you have. It covers everyone who touches the Service: brokerage and landlord teams who use Urbero for work, residents who use the resident portal, and visitors to our website and to listing pages we host.
The two roles we play
Urbero handles personal information in two distinct capacities, and your rights differ depending on which applies to you:
- Data we control. When you create an Urbero account, contact us, visit our website, or submit an inquiry on a listing page, we decide how that information is used. For this data, Urbero is the responsible party and this policy governs directly.
- Data we process for our customers. Brokerages and landlords use Urbero to manage their rental records — including information about their tenants, applicants, and guarantors or co-signers. They enter and control that data; we store and process it on their behalf and on their instructions. If you are a tenant, applicant, or guarantor and have questions about the records your building’s management keeps about you, the right first stop is your management company or brokerage. We support them in responding, but they decide.
Information we collect
Account and profile information. When brokerage or landlord staff sign up, our authentication provider, Clerk, collects a name, email address, and password — or, if you sign in with Google, the name, email, and profile photo your Google account shares. Inside Urbero, your account carries your role, an optional phone number, an optional avatar, and your product preferences (theme, layouts, notification settings).
Workspace data our customers enter. The point of Urbero is rental operations, so customers enter buildings, units, leases and lease documents, rent and payment history, photos and videos, deal records, comments, team chat messages and attachments, showing appointments (which may include a prospect’s name and contact details), and client search profiles agents keep for their renters.
Tenant and guarantor records. Customers enter information about their tenants — and about applicants and guarantors or co-signers on a lease: name, email, phone number, date of birth, employer and income information, emergency contacts, notes, and — where a tenancy involves a housing voucher or rental subsidy — the program, administering agency, case number, and related details. We treat voucher and subsidy information as sensitive: it is never displayed on any public page, never included in exports to third parties, and case numbers are redacted from our internal logs. New York City law prohibits discrimination based on lawful source of income, and Urbero is built to keep this information internal.
Resident portal. If you use the resident portal, we collect your email address to send you a one-time sign-in link, and we store the maintenance issues you report and the messages you exchange with your management team.
Website visitors and inquiries. If you submit the contact form we collect your name, email, and message, along with campaign parameters (UTM tags) if you arrived from a link that carried them. If you inquire about a listed apartment on a listing page we host, we collect the name, email, phone number, and message you submit, and we deliver that inquiry to the landlord’s team and the unit’s listing agent so they can respond.
Information collected automatically. We use PostHog for product analytics: page views, feature usage, and — in production — session replays that help us find where the product is confusing. Session replay is configured to mask everything typed into any form field. Our servers keep operational logs (scrubbed of email addresses and phone numbers before storage) and record IP addresses transiently for rate limiting and abuse prevention.
Public records. Urbero enriches building pages with New York City public records — HPD registrations, violations, PLUTO lot data, ACRIS filings, and similar datasets. These may include the names of building owners and registered agents as they appear in the public record. This is government-published information about properties, not data collected from you.
How we use information
- To provide, secure, and maintain the Service.
- To operate our customers’ workflows: recording leases, tracking renewals, sending the notifications they configure, and hosting their listing pages and resident portals.
- To send transactional email and, for staff who add a phone number and turn on text notifications, transactional SMS (see “Text messages” below).
- To respond to inquiries and support requests.
- To understand product usage and improve Urbero, using analytics as described above.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
- To comply with law and enforce our terms.
We do not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising. There is no advertising on Urbero.
Who we share information with
Your organization. Urbero is a team product. What your colleagues see is governed by role: brokerage admins see their brokerage’s buildings, agents see the buildings and units assigned to them, landlords see their own portfolios, and residents see only their own lease. Tenant records are visible to the brokerage or landlord team that manages the tenancy.
Service providers. We use a small set of vendors to run Urbero, each limited to the purpose listed:
- Clerk — sign-in and account security for staff accounts (including Google sign-in).
- Google — if you choose to sign in with Google.
- Resend — sending email on our behalf.
- Twilio — sending text messages on our behalf.
- Amazon Web Services — hosting, database, and file storage, in United States data centers.
- Inngest — scheduling and running background jobs (reminders, digests, notifications).
- PostHog — product analytics, session replay, and server log storage.
- Smarty — validating building addresses and apartment rosters (we send building addresses, not personal data).
- CARTO / OpenStreetMap — map imagery; when you view a map inside the app your browser fetches map tiles from CARTO’s servers.
- New York City and federal open-data services (NYC Open Data, NYC GeoSearch, FEMA, HUD) — we query these with building addresses and lot numbers to retrieve public records; no personal data is sent.
Payments. If and when paid plans are billed through the Service, payments will be handled by a dedicated payment processor (such as Stripe). Urbero does not store full payment card numbers.
Legal. We may disclose information if required by law, subpoena, or legal process, or to protect the rights, safety, or property of Urbero, our customers, or others.
Business transfers. If Urbero is involved in a merger, acquisition, or sale of assets, personal information may transfer as part of that transaction; this policy would continue to apply until updated.
Text messages
SMS notifications are optional and off by default. Staff users receive texts only if they add a phone number to their account and turn on the SMS channel in their notification settings. Message frequency varies with your settings and account activity; message and data rates may apply. Reply STOP to any message to stop receiving texts, or turn the channel off in settings; reply HELP or email hello@urbero.com for help. No mobile information, SMS opt-in data, or consent information is ever shared with or sold to third parties or affiliates for marketing or promotional purposes. Text messaging opt-in data is used solely to deliver the notifications you asked for.
Cookies and similar technologies
We use cookies and browser storage for the Service to function:
- Authentication cookies set by Clerk keep staff signed in; a separate session cookie (
urbero_tenant_uid) keeps residents signed in to the resident portal. - Preference cookies and browser storage remember your theme and interface layout choices (for example,
urbero_themeand saved table layouts). - Analytics identifiers set by PostHog help us understand product usage, as described above.
- A short-lived internal cookie supports our own staff when assisting a customer account.
We do not use advertising cookies. Some browsers send “Do Not Track” signals; there is no common standard for them and, like most services, we do not currently respond to them. You can control cookies through your browser settings; blocking authentication cookies will prevent sign-in.
How long we keep information
Urbero is a system of record for regulated housing, and parts of it are deliberately built never to rewrite history: lease records, rent-change history, unit status history, comments, and the audit trail of who changed what are append-only. We retain this data for as long as the owning customer maintains their account, because it is the business record our customers rely on — including for New York rent-regulation compliance, where historical rent and lease data has long-term legal significance.
Other data follows the life of its purpose: account profiles last while the account exists; inquiries and contact-form submissions are kept while being worked and can be deleted on request; server logs and analytics data age out on our providers’ standard schedules. If you unsubscribe from tenant emails, we keep your email address on a suppression list — retaining that one datum is how we make sure we don’t email you again.
Your choices and rights
- Email. Every non-essential tenant-directed email includes an unsubscribe link; using it stops future non-essential email to that address immediately. Staff can adjust notification channels in settings.
- Text messages. Reply STOP, or turn off the SMS channel in settings.
- Access, correction, deletion. You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it, by emailing hello@urbero.com. We will respond within the time required by applicable law. Where the law provides exceptions — for example, records we must retain for legal compliance, security, or the integrity of append-only lease history — we will tell you what we can and cannot do, and why.
- Tenant records. If your request concerns records your building’s management keeps in Urbero, we will refer it to them and support their response, since they control that data.
We will never discriminate against you for exercising a privacy right.
Security
All traffic to the Service is encrypted in transit with TLS. Our databases run in a private network with no direct internet access and are encrypted at rest, with automated backups. Uploaded files live in private storage accessible only through short-lived signed links. Access inside the product is governed by role-based permissions, sensitive fields are redacted from logs, and session replays mask everything typed into forms. No system is perfectly secure, and we cannot guarantee absolute security — but we build with the assumption that this data matters.
Children
The Service is a professional tool and is not directed to children. It is intended for users 18 and older, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact hello@urbero.com and we will delete it.
Changes to this policy
When we change this policy, we will update the “Last updated” date at the top of this page, and for material changes we will give notice in the product or by email before the change takes effect. Continued use of the Service after a change takes effect means the updated policy applies.
Contact
Odd Pair Ventures LLC (operating as Urbero) · hello@urbero.com. We’re based in New York, and we read everything sent to that address.