Privacy Policy
Last updated: August 26, 2026
Effective: August 26, 2026
This Privacy Policy describes how Asteroid Property Management, Inc. d/b/a Ender (“Ender”, “we”, “us”, or “our”) collects, uses, discloses, and protects information in connection with all websites, applications, APIs, communication tools, and related products and services made available by Ender, including at https://ender.com (collectively, the “Service”).
This Privacy Policy is incorporated into and forms part of the Ender Terms of Service (the “Terms of Service”). Capitalized terms not defined here have the meanings given in the Terms of Service. By accessing or using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, you may not access or use the Service.
If you or your organization has a separately executed written agreement with Ender (e.g., a Data Processing Agreement) that expressly governs data protection, that agreement will control to the extent of any direct conflict with this Privacy Policy.
1. Data Definitions and Roles
For clarity, the following definitions apply:
“Customer” means the entity or person that has a direct contractual relationship with Ender for use of the Service.
“Customer Content” means data, records, documents, files, messages, calls, audio, video, images, attachments, workflows, configurations, and any other content that you or your Users submit to or store in the Service.
“Service Data” means operational and technical data generated by or relating to the Service, such as logs, usage metrics, device information, timestamps, session data, error reports, and interaction traces (including actions taken by Users and Agents).
“Personal Data” means information that identifies or is reasonably capable of identifying a particular natural person.
“Derived Data” means aggregated, anonymized, de-identified, pseudonymized, obfuscated, or otherwise transformed data derived from or based on Customer Content and/or Service Data that does not reasonably identify an individual natural person or a specific property and does not include real-world PII.
Unless otherwise set out in a separate Data Processing Agreement: (a) for most Personal Data within Customer Content, Customer is the “controller” (or similar role) and Ender acts as a “processor” or “service provider” on Customer’s behalf; and (b) Ender is an independent controller/owner of Service Data and Derived Data to the extent created or processed for its own legitimate purposes as described in this Privacy Policy and the Terms of Service.
2. Data Collection and Categories
2.1 Personal Data You Provide
We may collect Personal Data such as:
Name, email address, phone number, mailing address;
User role and organization;
Government identifiers where required for payments (e.g., SSN, EIN);
Payment and billing information (primarily handled by processors).
2.2 Usage and Interaction Data
We collect Service Data, including:
IP address, device and browser characteristics, operating system;
Session information, access times, pages/screens viewed;
Logs of actions taken in the Service (e.g., record changes, approvals, messages sent, calls initiated, assignments, configuration changes);
Metadata relating to messages, calls, or other actions (e.g., timestamps, participants, channels);
Contents of chats, text messages, emails, and other communications sent or received through the Service, including conversations with AI assistants;
Where enabled, recordings or transcripts of certain calls or sessions.
Where calls or sessions are recorded or transcribed, we or the applicable Customer will provide notice and obtain any consent required by applicable call-recording and communications laws before recording begins.
2.3 Location Data
If you enable location services, we may collect and process location data for security, fraud prevention, routing, compliance, or workflow features. You can disable location access through your device settings, but some features may not function.
2.4 Cookies and Similar Technologies
We use cookies, pixels, and similar technologies for session management, security, preferences, analytics, and advertising/remarketing, as further described below.
2.5 Business Verification Information
As described in the Terms of Service, to enable payment, payout, disbursement, or funds-movement features, Ender and/or our payment processors may collect business and ownership information for identity verification, fraud prevention, risk management, and compliance purposes, including legal entity details, federal tax identification numbers (EIN or other TIN), authorized representative information, and beneficial owner information (which may include name, date of birth, address, and government identifier). Ender may collect, use, and disclose this information solely to the extent necessary to provide payment functionality, satisfy processor/network rules, and comply with applicable law.
We use government identifiers and other sensitive Personal Data only for the purposes described in this Privacy Policy (such as identity verification, payments, screening, security, fraud prevention, and legal compliance), and never for advertising or marketing.
2.6 Categories of Personal Data (State Law Disclosures)
Depending on how you and your organization use the Service, the categories of Personal Data we collect include: identifiers (e.g., name, email address, phone number, mailing address, IP address, account identifiers); government identifiers (e.g., SSN, EIN, where required for payments, verification, or screening); commercial and financial information (e.g., payment and billing information, transaction and ledger records); internet or other electronic network activity (e.g., usage logs, device and browser information, session data); approximate geolocation data (where enabled); audio and electronic information (e.g., chat, text message, and email content; call recordings and transcripts, where enabled); professional or employment-related information (e.g., role and organization); and inferences derived from the foregoing. We collect these categories from you, from your organization and its Users, from your devices, and from our Service Providers, for the purposes described in Sections 3.1 through 3.5, and we disclose them to the categories of recipients described in Sections 5 and 12. We retain each category as described in Section 3.6. We do not sell Personal Data for monetary consideration; as described in Sections 3.4 and 9, our use of advertising cookies may constitute “sharing” or “targeted advertising” under certain state laws, and you may opt out as described in Section 14 (Your Privacy Rights). Text messaging originator opt-in data and consent are excluded from all such sharing (see Section 6.4).
3. Use of Data; AI Training; Obfuscation; Derived Data Rights; Retention
3.1 Use of Customer Content
We use Customer Content to:
Provide, operate, configure, and support the Service;
Execute workflows you configure (e.g., communications, payments, tasks, approvals, accounting entries);
Troubleshoot and resolve issues;
Comply with contractual and legal obligations.
3.2 Use of Service Data
We use Service Data to:
Operate, secure, monitor, and improve the Service;
Detect, prevent, and investigate security incidents, abuse, fraud, or misuse;
Measure performance, reliability, and engagement;
Develop new features, models, and services (with any AI/ML training conducted as described in Section 3.3).
3.3 AI Training and Model Improvement
Subject to applicable law and any conflicting written agreement: (a) We may use de-identified and/or aggregated forms of Customer Content and Service Data (including logs of messages, calls, and actions taken within Ender’s ecosystem) to train, fine-tune, evaluate, and improve AI models and Agents and to develop new AI features. (b) Such use will rely on techniques such as aggregation, masking, and de-identification designed so that the data used for these purposes does not reasonably identify a natural person. (c) Where we rely on de-identified data, we will maintain and use it only in de-identified form, will not attempt to re-identify it (except as permitted by law to test the effectiveness of our de-identification processes), and will contractually require any recipients of such data to comply with these same commitments. (d) Where the Service is provided to an agency or instrumentality of the U.S. Government, Government data (as defined in Section 20.3 of the Terms of Service) will not be used to train AI/ML models and systems without explicit written authorization from the ordering activity contracting officer. Section 20.3 (AI/ML Model Training Restrictions) of the Terms of Service governs and controls over this Privacy Policy with respect to Government data.
3.4 Ender’s Right to Create Derived Data; No Sale of Customer Content
(a) We reserve the right to transform Customer Content and Service Data into Derived Data using industry-standard and evolving de-identification, aggregation, and obfuscation methodologies. (b) Customer Content and Personal Data remain Customer’s data. Ender will not sell Customer Content or Personal Data for monetary consideration, and will not disclose Customer Content to third parties except as necessary to provide the Service, comply with law, or as otherwise permitted in this Privacy Policy and the Terms of Service. Our use of analytics, advertising, and remarketing technologies described in Section 9 may be considered a “sale” or “sharing” of Personal Data, or “targeted advertising,” as those terms are defined under certain state privacy laws; you may opt out as described in Section 14 (Your Privacy Rights), and text messaging originator opt-in data and consent are excluded from any such “sale” or “sharing” (see Section 6.4). (c) Any sharing or commercialization is limited to Derived Data that is highly obfuscated and does not reasonably identify an individual person or specific property.
3.5 Ender’s Ownership, Retention, and Monetization of Derived Data
(a) Derived Data is owned by Ender. (b) We may retain Derived Data permanently (subject to applicable law). (c) We may use, share, license, publish, disclose, sell, assign, or otherwise commercialize Derived Data for purposes such as benchmarking, analytics, research, product development, and AI training (subject, for Government data, to Section 3.3(d)), provided Derived Data does not include Personal Data or real-world PII and does not reasonably identify, or enable re-identification of, an individual person or specific property.
3.6 Retention of Customer Content and Personal Data
We retain Customer Content and Personal Data for as long as: (a) your account is active or as needed to provide the Service; (b) required by law, regulation, or court order; or (c) reasonably necessary for legitimate business purposes (e.g., audit, security, fraud prevention, dispute resolution, accounting, tax). We may maintain certain records (e.g., system logs, financial records, legal holds, and audit trails) for longer periods as required or permitted by law or contract.
3.7 Cloned/Replicated Environments
We may replicate production data into QA, staging, or development environments to test and improve the Service. Such environments are subject to security and access controls and may apply masking or de-identification to reduce exposure of Personal Data.
3.8 No Obligation to Return or Destroy Derived Data
Upon termination of your account and/or deletion of Customer Content, we have no obligation to delete or return Derived Data.
4. Security Program; SOC 1, SOC 2, and FedRAMP Alignment
4.1 Security Program
We maintain an information security program with administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Customer Content and Personal Data, including least-privilege access, continuous logging/monitoring, vendor risk management, secure SDLC controls, and encryption in transit and at rest. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. In the event of a breach of security affecting Personal Data, we will notify affected Customers and individuals as required by applicable law.
4.2 SOC 1 and SOC 2 Alignment
Our internal controls are designed to align with relevant SOC 2 Type 2 Trust Services Criteria (e.g., security, availability, confidentiality). We are also actively pursuing one or more SOC 1 (SSAE 18\) examinations addressing controls relevant to our Customers’ internal control over financial reporting, such as payment processing, ledgering, reconciliation, and disbursement controls. We may undergo independent assessments over defined periods. Any formal reports, if and when available, may be provided under separate confidentiality terms. Nothing in this Privacy Policy is a representation that any particular examination has been completed or that any report has been issued unless expressly stated in a separate written agreement.
4.3 FedRAMP Alignment
For systems and environments supporting U.S. federal or similarly regulated customers, we implement controls designed to align with relevant FedRAMP baselines (e.g., Low or Moderate), including access management, continuous monitoring, secure configuration, encryption, incident response, and supply-chain controls, as applicable to the in-scope environments. Nothing in this Privacy Policy is a representation that any particular environment is formally authorized under FedRAMP unless expressly stated in a separate written agreement.
5. Service Providers and Subprocessors
We may engage third-party service providers (“Service Providers” or “Subprocessors”) for infrastructure, communications, analytics, payments, support, and other services. These may include, without limitation:
SMS, voice, and email providers (e.g., Twilio, Mailgun, similar platforms);
Payment processors and ACH networks (e.g., Stripe, Dwolla, Moov, banks);
Cloud hosting, storage, logging, and observability;
Support and ticketing tools.
Service Providers may process Personal Data and Customer Content as necessary to perform their services and are generally bound by contractual obligations to protect data and use it only for authorized purposes. Their use of your information is governed by their own terms and privacy policies. We do not store full payment card numbers. A current list of our material Subprocessors is available upon written request to support@ender.com.
Where Stripe payment features are used (debit and credit card payments, including application fee and rent payments), your payment information is processed by Stripe, Inc. If you receive payments processed through Stripe, you authorize us to collect and share with Stripe information about you and your business and related transaction information, as further described in the Terms of Service. Stripe’s use of your personal information is governed by the Stripe Privacy Policy, available at https://stripe.com/privacy.
Where Dwolla payment features are used, you authorize us to collect and share with Dwolla, Inc. your personal information, including full name, date of birth, Social Security number, physical address, email address, and financial information, as further described in the Terms of Service, and you are responsible for the accuracy and completeness of such data. Dwolla’s use of your personal information is governed by Dwolla’s Privacy Policy, available at https://www.dwolla.com/legal/privacy.
Where Moov payment features are used, you authorize us to collect and share with Moov Financial, Inc. your personal information, including full name, date of birth, Social Security number (where required for identity verification), physical address, email address, and financial information, as further described in the Terms of Service, and you are responsible for the accuracy and completeness of such data. Moov’s use of your personal information is governed by the Moov Privacy Policy, available at https://moov.io/legal/privacy-policy/.
6. SMS and Text Message Communications
6.1 Consent Requirement
We may send text notifications, alerts, reminders, or marketing messages via SMS. We send such messages only with the level of consent required by applicable law and carrier rules: replies within a conversation that an individual initiates, recurring informational or service messages with affirmative opt-in consent, and marketing messages only with prior express written consent. We maintain records of consent as required by applicable law, including the Telephone Consumer Protection Act (TCPA). Program terms for conversational and AI assistant messaging, including with prospects, are set out in the Ender Chat and AI Assistant Terms.
6.2 Opt-Out Rights
Users may withdraw consent and opt out of receiving text messages at any time by replying “STOP” to any message or by contacting us directly. We will promptly honor all valid opt-out requests and update our records accordingly.
6.3 User Responsibility
You are responsible for ensuring that any phone numbers you submit to the Service (including those belonging to residents, prospects, vendors, or other third parties) have valid consent to receive SMS communications where legally required. You agree not to use the Service to send messages in violation of applicable laws or regulations.
6.4 Restrictions on Use
Notwithstanding anything else in this Privacy Policy, all categories of information described in this Privacy Policy exclude text messaging originator opt-in data and consent; this information will not be shared with, sold to, rented to, or transferred to any third parties or affiliates for marketing or promotional purposes. We use mobile telephone numbers, text messaging opt-in data, and SMS consent records only to deliver the messages you have requested, to honor opt-outs, and to comply with applicable law.
7. Background Checks and Consumer Reports
7.1 Use of Consumer Reporting Agencies
We may use third-party consumer reporting agencies, such as TransUnion, to conduct background screening or verification when necessary in connection with the Service (for example, for applicant screening, identity verification, or compliance purposes).
7.2 Information Sharing
When we use such services, we share only the minimum personal information necessary to obtain a consumer report. Such reports are obtained and used in accordance with applicable laws, including the Fair Credit Reporting Act (FCRA) where required.
7.3 User Rights
You acknowledge that you may have certain rights under applicable law with respect to consumer reports obtained about you, including the right to dispute inaccurate information. TransUnion’s Privacy Notice is available at https://www.transunion.com/privacy/transunion.
8. Data Classification and Internal Handling
We apply internal data classification and handling requirements (e.g., Restricted/Confidential, Internal Use, Public) to guide baseline controls. We may exchange Internal Use or Confidential/Restricted information over secure collaboration tools where appropriate, subject to access controls and need-to-know principles.
9. Analytics, Tracking, and Remarketing
We may use tools such as FullStory, Google Analytics, and similar services to analyze usage and improve the Service. These tools may use cookies and similar technologies to collect Service Data. Some of these tools use session replay technology that captures how you interact with the Service (such as clicks, scrolls, page views, and form interactions), with masking applied to sensitive fields. We may also use remarketing or targeted advertising tools to show ads based on your interactions with the Service, subject to applicable law. You can manage cookie preferences through your browser, and certain analytics or advertising services may provide their own opt-out mechanisms. Residents of certain states may also opt out of targeted advertising and the “sale” or “sharing” of Personal Data as described in Section 14 (Your Privacy Rights).
10. Do Not Track and Opt-Out Preference Signals
Our Service does not currently respond to browser “Do Not Track” signals. You may use other privacy controls (e.g., browser settings, extensions) to manage tracking technologies. However, where required by applicable law, we honor recognized opt-out preference signals, such as the Global Privacy Control (GPC), as a request to opt out of the sale or sharing of Personal Data or targeted advertising for that browser or device.
11. Children’s Privacy
The Service is not directed to children, and we do not permit individuals under 18 to create accounts or use the Service as account holders. We do not knowingly collect Personal Data directly from children under 13.
Notwithstanding the foregoing, Customers and adult Users may provide to the Service limited Personal Data about minors in their household or under their care (for example, a resident’s child’s name and date of birth) solely for legitimate property-management, tenancy, eligibility, compliance, safety, or operational purposes (e.g., household composition, certifications, leasing records, or emergency contact context). By submitting such information, you represent and warrant that you are the child’s parent or legal guardian, or otherwise have lawful authority and any required consents to provide the information to Ender and to permit Ender to process it as described in this Privacy Policy and the Terms of Service.
We process minors’ information only as Customer Content on Customer’s instructions and for the purposes above, apply data-minimization principles, and do not use such information to target children with marketing. We do not disclose minors’ Personal Data to third parties except as necessary to provide the Service, comply with law, or as otherwise permitted in this Privacy Policy and the Terms of Service.
If we learn that we have collected Personal Data directly from a child under 13 without verifiable parental consent, we will delete it as required by law. Parents or legal guardians who believe their child’s information has been provided to Ender without proper authority may contact support@ender.com to request access, correction, or deletion, subject to applicable law and our verification procedures.
12. Disclosure of Data; Business Transfers
We may disclose Personal Data and Customer Content: (a) to Service Providers as described above; (b) to comply with legal obligations, lawful requests, or government/regulatory authorities; (c) to protect and defend the rights, property, or safety of Ender, our customers, or the public; (d) to investigate and prevent potential violations of law or the Terms of Service; (e) in connection with a merger, acquisition, sale of assets, financing, reorganization, bankruptcy, or similar transaction, subject to confidentiality obligations and required notices; or (f) with your consent or at your direction.
13. International Data Transfers
We may process and store information in the United States and other countries with different data protection laws. By using the Service, you consent to these transfers, subject to safeguards required by applicable law.
14. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights under applicable privacy laws (including, for example, the California Consumer Privacy Act as amended, the Texas Data Privacy and Security Act, and similar laws in other states):
Access / Know. The right to confirm whether we process your Personal Data and to obtain a copy of it, including in a portable format.
Correction. The right to correct inaccurate Personal Data.
Deletion. The right to request deletion of your Personal Data, subject to legal exceptions.
Opt-Out. The right to opt out of (i) targeted advertising, (ii) the “sale” or “sharing” of Personal Data as those terms are defined under applicable law, and (iii) certain profiling in furtherance of decisions that produce legal or similarly significant effects.
Sensitive Data. The right to limit certain uses of sensitive Personal Data. As described in Section 2.5, we use sensitive Personal Data only for purposes permitted by applicable law, such as providing the Service, verification, security, and compliance, and not for advertising.
Non-Discrimination. The right not to receive discriminatory treatment for exercising your privacy rights.
How to exercise your rights. You (or an authorized agent, where permitted by law) may submit a request by emailing support@ender.com. We may need to verify your identity, and the identity of any authorized agent, before responding, and we will respond within the timeframes required by applicable law. If we deny your request, you may appeal our decision by replying to our response with the subject line “Privacy Appeal.” If your appeal is denied, you may contact the Attorney General in your state.
Requests relating to data we process for Customers. For most Personal Data in Customer Content (for example, prospect, resident, applicant, or vendor records managed by a property manager or owner), Ender acts as a service provider or processor on behalf of the relevant Customer. If you are a prospect, resident, applicant, vendor, or other individual whose data is managed by one of our Customers, please direct your request to that Customer (typically your property manager or landlord), who controls that data. We will assist our Customers in responding to verified requests as required by law, and where appropriate we will forward requests we receive to the relevant Customer.
Cookies and opt-out preference signals. You can manage cookies through your browser settings, and we honor recognized opt-out preference signals such as the Global Privacy Control where required by applicable law (see Sections 9 and 10).
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice and update the “Last updated” date. The revised Privacy Policy becomes effective on the date stated in the notice. Your continued use after the effective date constitutes acceptance. If you do not agree, you must stop using the Service.
16. Contact
Asteroid Property Management, Inc. d/b/a Ender
Attn: Legal / Privacy
816 Congress Ave, Suite 700, Austin, TX 78701
Website: https://ender.com
Email: support@ender.com
Phone: +1 (737) 232-9168