Intry Privacy Policy
1. About This Policy
Bytesize LLC, doing business as Intry (‘Intry’, ‘we’, ‘us’) operates a smart building access management platform available at gointry.com and through mobile applications. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with our services.
By accessing or using Intry, you agree to this Policy. Our Compliance Officer is T. Thomas, reachable at [email protected] or [email protected].
2. Information We Collect
Role of Parties
When providing access management services to properties, Intry processes personal data (including access event history) strictly as a Data Processor on behalf of the Property Management Company or Landlord, who acts as the Data Controller. Any inquiries regarding access log retention or property surveillance policies must be directed to your property administration.
Account & Identity Data
Name, email address, nickname, role, property and unit assignment, and authentication provider identifiers (Clerk).
Contact & Communication Data
Phone numbers (including verified status), email addresses, and fallback notification preferences (SMS, voice, WhatsApp).
Building & Access Data
Property address, timezone, unit label, virtual phone number assignments, gate configuration, DTMF/access codes, and access event history including call records, approval/denial actions, and approver identity.
Caller Identification Data
When the caller identification feature is enabled by a property administrator, we may collect speech transcripts and audio recordings of callers seeking entry. Callers are notified before any recording begins.
Device & Push Notification Data
Device platform, push token (Expo/FCM/APNs), device model, OS version, app version, notification preferences, and last active timestamp.
Analytics & Diagnostic Data
Product usage events, session data, error reports, crash logs, and session replay recordings (PostHog, Mixpanel, Sentry, LogRocket). This data may include device/app interaction context. See Section 6 for detail.
Billing Data
Stripe customer, subscription, payment, and invoice identifiers. We do not store full payment card numbers — these are handled directly by Stripe, Inc.
Audit & Security Logs
IP addresses, user agents, request paths, API key usage, and admin impersonation activity for security and compliance purposes.
Integration & Webhook Data
URLs, Slack webhook endpoints, WhatsApp numbers, and email recipients configured by users for notification delivery. Webhook signing secrets are stored encrypted.
3. How We Use Your Information
Providing, operating, and improving the Intry platform and access management services
Routing inbound calls, delivering access approval/denial notifications, and processing entry events
Sending transactional SMS, voice calls, push notifications, and emails related to access events
Authenticating users, verifying sessions, and managing API keys and permissions
Processing subscription billing, invoicing, and payment events via Stripe
Monitoring platform health, diagnosing errors, and conducting security audits
Complying with legal obligations and enforcing our Terms of Service
4. Telephony & SMS Consent
Intry uses Twilio to deliver voice calls, SMS messages, and WhatsApp notifications. By providing your phone number and opting in during onboarding, you consent to receive operational messages related to your property access. Standard carrier message and data rates may apply.
You may opt out of SMS at any time by replying STOP to any Intry message. To reactivate, reply START. These notifications are operational in nature and cannot be fully disabled while your account is active, as they are required for access event delivery.
5. Call Recording & Transcription
When the caller identification feature is enabled by a property administrator, inbound callers may be prompted to state their name, which is recorded and/or transcribed using Twilio’s recording services. Callers are notified via an audio prompt before any recording begins. Recordings are associated with the corresponding access event and are accessible to the resident who received the access request. Recordings are retained for 30 days and then automatically deleted, unless applicable law requires longer retention.
6. Cookies, Analytics & Session Replay
We use the following tools to understand how our platform is used and to improve performance:
PostHog — product analytics, feature flags, pageview tracking, and localStorage/cookie persistence in our admin dashboard
Mixpanel — server-side user behavior analytics and user property tracking
Sentry — error monitoring, crash reporting, and session replay in the mobile app
LogRocket — React Native session replay and diagnostics
Google Tag Manager — present in the admin interface for tag management
7. Subprocessors & Third-Party Vendors
We share data with the following categories of third-party processors to deliver our services. A full Subprocessor List is maintained as a separate document and updated periodically.
Categories include: telephony (Twilio), authentication (Clerk, WorkOS), API management (Unkey), payments (Stripe), push notifications (Firebase/FCM, Apple APNs, Expo), error monitoring (Sentry), analytics (PostHog, Mixpanel, New Relic), session replay (LogRocket), communications (Slack, Resend), mapping (Mapbox, OpenStreetMap), and infrastructure (Railway, Fly.io, PostgreSQL, Cloudflare R2).
8. Data Retention & Deletion
We retain personal data for as long as your account is active or as needed to provide services. Upon account deletion, we will delete or anonymize personal data within 30 days, subject to legal holds. Access event logs are retained for 90 days. Call recordings are retained for 60 days. Billing records are retained for 7 years per applicable tax and financial regulations. Full retention schedules are documented in our Data Retention & Deletion Policy.
9. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or restrict processing of your personal data. California residents have additional rights under CCPA including the right to know what personal information is collected, the right to delete, and the right to opt out of sale (we do not sell personal information). To exercise rights, contact [email protected].
10. Security
We implement industry-standard security measures including encryption of sensitive integration secrets, password hashing, webhook signature validation, rate limiting, API key scope controls, audit logging, and role-based access controls with admin impersonation audit trails.
11. Children
Intry is intended for use by adults (18+) or authorized property managers. We do not knowingly collect personal information from individuals under the age of 18 without verifiable parental consent.
12. Contact
Intry, a trade name of Bytesize, LLC.
1954 Airport Road, #1047, Atlanta, GA 30341
1-866-254-6879