Membershine Privacy Policy

This privacy policy discloses the privacy practices for this product.

Effective date: 8/5/2026

Membershine, Inc (“Membershine,” “we,” “us,” or “our“), which also does business as “HOA Start,” provides software that helps homeowners associations, community associations, and property managers run their communities. This Privacy Policy explains how we collect, use, share, and protect personal information across our websites and applications.

This policy replaces any prior privacy policy published at hoastart.com. It is published at hoastart.com and membershine.com and linked from within our applications.

A note on our two platforms. We currently run two systems at the same time:

  • Our legacy platform (the current HOA Start application), which most communities use today.
  • Our new Membershine platform, which we are rolling out to replace it.

This single policy covers both. Where a practice applies to only one of them, we say so.

1. Who We Are and How This Policy Works

Our customers are the HOAs and management companies that subscribe to our service. The people whose information we handle are mostly the homeowners, residents, board members, committee members, and property managers who use the service.

Because of this structure, we play two different roles depending on the data:

  • For most member and community data, we act as a service provider / processor on behalf of the HOA. The HOA (our customer) decides what information to collect and how to use it, and is the party responsible for that data. We handle it only to provide our service and following the HOA’s instructions.
  • For account, billing, and product-usage data that we collect for our own business purposes (for example, running your login, billing our customers, securing the platform, and improving the service), we act as the party responsible for that data (a “business” under California law, or a “controller“).

How members should direct requests. If you are a homeowner or resident and you want to see, correct, or delete your information, you can contact us (see Section 12), but in many cases we will need to work with your HOA to complete your request, because the HOA controls that data.

2. Scope

This policy applies to:

  • Our web applications and dashboards (legacy and new platforms).
  • Our mobile app (legacy platform).
  • Public community websites that HOAs run through our platform.
  • Our websites at hoastart.com and membershine.com.
  • Our communications with you (email, and — on the legacy platform — text messages and push notifications).

This policy does not cover:

  • Websites, products, or services operated by a third party, even if we link to them.
  • What your HOA or property manager does with your information outside of our platform.

3. Personal Information We Collect

The exact information collected depends on your community and how your HOA has set up its account. In general, we may collect the following.

3.1 Information you or your HOA provide

  • Contact and identity details: name, email address, phone number.
  • Address details: physical, mailing, and billing addresses.
  • Property details: your lot, unit, or property number, and property address type (physical, billing, or mailing).
  • Profile photo / avatar: a photo you or your HOA upload. On the new platform, avatar images may be stored in a publicly accessible location and served over the internet.
  • Location information (legacy platform only): approximate geographic coordinates (latitude and longitude) associated with a member’s community record.
  • Custom fields defined by your HOA (legacy platform only): your HOA can create its own free-form fields to track information about members and households. Because your HOA defines these fields, they may contain a wide range of information — for example, emergency contacts, vehicle or pet information, dates, or other notes. We do not control what an HOA chooses to collect in these fields.
  • Vendor and payee information: for vendors and payees an HOA works with, we may store business contact details and tax identification numbers, including an Employer Identification Number (EIN), for accounting and tax-reporting purposes (legacy platform).
  • Member-created content (mostly legacy platform): messages, community wall / newsfeed posts, comments, photos, event and calendar entries, amenity reservations, form and survey responses, support requests, and similar content you create in the community.
  • Consent and agreement flags: records of your communication preferences (such as opting into or out of email, text, address mail, member directory listing, digests, or chat) and your acceptance of terms.

3.2 Information we collect automatically

  • Login and session data: authentication tokens used to keep you signed in.
  • Local browser storage: on the new platform, the dashboard stores items in your browser’s local storage (for example, your preferences, selected community/organization, saved filters, and theme).
  • Device, log, and usage data: technical logs and telemetry about how the service is used, which may include IP address, browser and device information, timestamps, and activity within the app.
  • Cookies and similar technologies: see Section 8.

3.3 Information we do not collect in standard fields

We do not collect the following in our standard, built-in fields:

  • Social Security numbers (SSNs).
  • Dates of birth.
  • Government-issued identification numbers (such as driver’s license or passport numbers).
  • Biometric information.

Important exception: because HOAs can create their own free-form custom fields (Section 3.1, legacy platform), it is possible for an HOA to enter sensitive information into a custom field. We do not request or intend to collect that information, and we discourage HOAs from placing sensitive identifiers in free-form fields.

4. Payment and Financial Information

We use trusted payment processors to handle payments. We do not store full payment card numbers or full bank account numbers on our systems.

  • Card payments are processed by Stripe. We store only a payment token, the card brand, and the last four digits.
  • Bank / ACH payments are processed by Stripe and, on the legacy platform, by Plaid for linking bank accounts. We store only a token and limited identifying details such as the bank name and the last four digits.

When you enter payment details, they are transmitted to our payment processor for secure handling.

5. How We Collect Information

We collect information in these ways:

  • When an account is created — by you or by your HOA on your behalf.
  • When your HOA enters or imports data — HOAs and property managers can add or bulk-import member and property records.
  • When you fill out forms, surveys, or requests in the platform.
  • When you upload files or photos (see Section 6).
  • When you make or receive payments.
  • Automatically, through logs, cookies, and local browser storage, as you use the service (see Sections 3.2 and 8).

6. Uploaded Files and the Document Center

Our platform lets HOAs and members upload and store files — for example, governing documents, meeting minutes, photos, form attachments, receipts, and profile photos. On the legacy platform this includes a Document Center with per-file and per-folder permissions.

Uploaded files are stored using Microsoft Azure cloud storage. Access to files is controlled by the permission settings your HOA configures. As noted in Section 3.1, profile/avatar images on the new platform may be stored in a publicly accessible location.

Please do not upload sensitive personal information (such as SSNs or financial account numbers) into documents or custom fields unless your HOA specifically requires it and has authority to collect it.

7. Communications

Depending on your platform and preferences, we may send you:

  • Transactional messages — such as account invitations, password resets, invoice and payment notifications, and other messages needed to operate the service. These are part of the service and are generally not optional while you have an active account.
  • Marketing and bulk messages (legacy platform) — such as community email blasts, digests, and newsletters. These are sent based on your HOA’s settings and your consent flags. You can opt out of marketing/bulk emails at any time using the unsubscribe link in the email or by updating your preferences, without affecting transactional messages. Marketing emails include a valid postal address and unsubscribe mechanism consistent with the CAN-SPAM Act.
  • Text messages / SMS (legacy platform) — sent through Twilio, only where you have opted in to text messaging. Message and data rates may apply. You can opt out by replying STOP, or get help by replying HELP, or by updating your preferences.
  • Text messages / SMS (sales and marketing) — if you submit an inquiry through our website and check the box consenting to text messages, we may text you about your inquiry and about our products, services, and events. These are sent through Salesmsg. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP, or get help by replying HELP. Consent to receive texts is not a condition of purchase. See Section 9 for how we handle your opt-in data.
  • Push notifications (legacy platform only) — delivered through OneSignal to the mobile app. You can turn these off in your device settings.

We use SendGrid to send email on both platforms. Our systems keep logs of messages sent, which may include the recipient and message content.

8. Cookies and Similar Technologies

We use a small number of technologies to keep the service working and to remember your settings.

  • Sessions and login tokens. We use authentication tokens (JWTs) to keep you signed in. On the legacy platform these are held in your browser’s session storage; on the new platform, login context is stored in your browser’s local storage.
  • Local storage (new platform). The dashboard saves preferences such as your active community/organization, saved filters, and theme in your browser’s local storage.
  • Web fonts (new platform). Our new dashboard loads fonts from Google Fonts. When it does, your device’s IP address is shared with Google in order to deliver the fonts.
  • Analytics on public community websites (legacy platform). An HOA can choose to add Google Analytics to its public community website. When an HOA enables this, Google Analytics may set cookies and collect usage data from visitors to that community site. This is configured by the HOA, not by Membershine.

You can control or disable cookies through your browser settings. Because some of these technologies (such as login tokens and local storage) are necessary for the service to function, blocking them may prevent parts of the service from working.

9. How We Share Information

We share personal information only as described here. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Our audit found no advertising networks or data brokers among our service providers.

We share information with:

  • Your HOA / community association and its authorized administrators and managers. This is the core of the service — your HOA controls your member record and can see the information associated with it.
  • Other community members, but only where you or your HOA have opted your information into a member-visible feature, such as a member directory (see Section 15).
  • Service providers (sub-processors) who perform functions on our behalf, listed in Section 10.
  • Legal and safety recipients — when we reasonably believe disclosure is required to comply with a law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Membershine, our customers, or others.
  • In a business transfer — if we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy.

Text messaging consent

Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the Text Message services.

In plain terms: if you give us permission to text you, we do not pass that phone number or your consent record to anyone else for their own use. The only parties who receive it are the messaging platform and carriers that deliver the message on our behalf.

10. Service Providers (Sub-Processors)

We work with the third-party service providers below. Each receives only the information needed to perform its function, and is required to protect it. “Legacy” and “New” show which platform uses each provider.

Service providerWhat they do for usPlatform
StripePayment processing (cards and ACH/bank), including Stripe ConnectLegacy + New
PlaidLinking bank accounts for ACH paymentsLegacy
Auth0User login, identity, and password managementNew
SendGridSending email (transactional and, on legacy, marketing/bulk)Legacy + New
TwilioSending text messages (SMS)Legacy
SalesmsgSending and receiving sales/marketing text messages (SMS) to website inquiries who opted in; syncs contact and message activity with HubSpotMarketing/Sales
HubSpotCRM — stores website inquiry contacts, message activity, and consent flagsMarketing/Sales
OneSignalMobile push notificationsLegacy
Intuit QuickBooks OnlineAccounting sync (customer and financial data)Legacy
LobAddress verification and autocomplete onlyNew
Microsoft AzureCloud hosting, file/document storage, databases, job queues, and system telemetryLegacy + New
GoogleWeb fonts (fonts CDN); and Google Analytics where an HOA configures it on its public community websiteNew (fonts); Legacy (customer-configured analytics)

We may update this list as our providers change.

Note on address mailing:

Lob is used today only for address verification/autocomplete. If physical mail (letters, postcards, checks) is enabled in the future, member names and addresses would be sent to a print/mail vendor, and this policy will be updated to reflect that.

11. How Long We Keep Information (Retention)

We keep personal information for as long as your community keeps an active account with us, and for a reasonable period afterward to meet our legal, accounting, tax, dispute-resolution, and record-keeping needs.

Please be aware:

  • Account and community data is retained for the life of the HOA’s account and for a period afterward.
  • Financial and payment records may be kept longer where required by tax and accounting laws.
  • System logs, audit records, and email logs are retained for operational, security, and compliance purposes.

When we no longer need personal information, we take reasonable steps to delete or de-identify it. Note that some deletion is handled by marking records inactive rather than permanent erasure (see Section 12).

12. Your Privacy Rights

Depending on where you live, you may have some or all of the rights below. We honor these rights for California residents under the CCPA/CPRA, and we extend comparable rights to residents of other U.S. states with applicable privacy laws (for example, Virginia, Colorado, Connecticut, and Texas). Where you are located outside the United States, we provide rights aligned with those principles, but this policy does not represent a claim of full compliance with the EU/UK GDPR.

Your rights may include:

  • The right to know / access — to request the categories and specific pieces of personal information we hold about you, how we collect it, why we use it, and with whom we share it.
  • The right to delete — to request deletion of your personal information, subject to legal exceptions (for example, we may need to keep certain financial or transaction records).
  • The right to correct — to request that we fix inaccurate personal information. You can also update much of your profile information directly in the app.
  • The right to opt out of the sale or sharing of personal information — we do not sell or share your personal information for cross-context behavioral advertising, so there is nothing to opt out of. If this ever changes, we will update this policy and provide an opt-out.
  • The right to non-discrimination — we will not deny you service, charge you a different price, or provide a different quality of service because you exercised your privacy rights.

How to exercise your rights

  • Submit a request by emailing legal@membershine.com.
  • We handle requests manually. We do not yet offer a self-service download-all-my-data or one-click delete tool. Our team will process your request by hand.
  • Verification. To protect your information, we will take reasonable steps to verify your identity before acting on a request. We may ask you to confirm details we already have on file.
  • HOA-controlled data. Because your HOA controls much of your member data (see Section 1), we may need to route your request to your HOA or ask for its involvement to complete it.
  • Response time. We will respond within about 45 days. If we need more time, we will tell you and may extend the period as allowed by law (generally up to a total of 90 days).
  • Authorized agents. You may use an authorized agent to submit a request on your behalf. We may ask the agent for proof of authorization and may ask you to verify your identity directly.
  • Appeals. If we decline your request, you may appeal by replying to our decision or emailing legal@membershine.com with the word “Appeal.” We will review and respond as required by applicable state law.

A note on deletion.

In some cases we delete information by marking it inactive rather than permanently erasing it, and some records (such as financial and audit records) are retained where the law allows or requires. We will explain what we can and cannot delete when we respond to your request.

13. Information for California Residents (California Civil Code § 1789.3)

Under California Civil Code Section 1789.3, California residents are entitled to the following consumer-rights notice:

  • The Membershine sites and services are provided by Membershine, Inc, P.O. Box 7209, Fishers, IN 46038.
  • Fees, if any, for use of the services are as described on our Pricing and Plans page.
  • To file a complaint, or to receive further information about use of the services, contact us in writing at Membershine, Inc, Legal Department, P.O. Box 7209, Fishers, IN 46038, or by email at legal@membershine.com (Subject: “California Resident Request”).
  • You may also contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs in writing at 400 R Street, Suite 1080, Sacramento, CA 95814, or by telephone at (916) 445-1254 or (800) 952-5210.

14. Children’s Privacy

Our service is not directed to individuals under the age of 18, and creating an account requires you to be 18 years of age or older. The service is intended for use by adults — homeowners, residents, board and committee members, and property managers. We do not knowingly collect personal information from individuals under 18. If you believe someone under 18 has provided us personal information, please contact legal@membershine.com and we will take appropriate steps to remove it.

15. Where Your Information Is Processed

Membershine is based in the United States, and we store and process personal information in the United States using Microsoft Azure data centers. Our services are offered only to residents of the United States, Canada, and Mexico. If you access the service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your location.

16. Public Community Websites and Member Directories

  • Member directories. Some communities offer a member directory that lets residents see one another’s contact details. Directory listing is based on an opt-in setting. If you do not want your information shown to other members, you can opt out through your preferences or by asking your HOA.
  • Public community websites. HOAs can publish public-facing community websites through our platform. Your HOA controls what content appears on its public site and whether to enable tools such as Google Analytics (see Section 8). Information your HOA chooses to make public on a community website may be viewable by anyone on the internet.

17. How We Protect Information (Security)

We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including:

  • Encryption in transit (secure HTTPS/TLS connections) and encryption at rest for stored data.
  • Tokenized payments — we rely on established payment processors and do not store full card or bank account numbers.
  • Access controls — access to personal information is limited to those who need it to operate and support the service, and is governed by the permission settings your HOA configures.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify affected parties and regulators as required by law.

18. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will change the “Effective date” at the top, and, if the changes are significant, we will provide a more prominent notice (such as an in-app message or email). Your continued use of the service after an update means you accept the updated policy.

19. Contact Us

If you have questions about this policy or your privacy, contact us: