Security and data handling
How Hometrace protects inspection data
Hometrace uses authenticated accounts for private inspector work, gives report recipients inspection-scoped access, limits support access to authorized administrators with time-limited and logged sessions, and uses named service providers for hosting, storage, communications, and payments. Hometrace does not claim that any system is risk-free, and this page does not assert a security certification.
Who it is for
For inspectors evaluating where business and client data goes
Inspection software holds property details, photos, findings, recipient information, and business records. This page summarizes the controls and responsibilities Hometrace documents today without turning implementation details into broader guarantees.
Private work requires access
Inspectors use a Hometrace account for their workspace. Client and agent links are tied to the intended recipient and provide access to the inspection content that recipient is allowed to see.
Support access is restricted
The Privacy Policy limits account access for support to authorized administrators. Those sessions are time-limited and logged, with password and payment details outside the permitted support workflow.
Full card details stay with Stripe
Stripe handles subscription and inspection-payment card data. Hometrace receives identifiers and high-level payment metadata rather than full card details.
How it works
How access and service providers fit together
Hometrace separates the inspector workspace, intentional recipient sharing, operational service providers, and exceptional support access.
The inspector signs in
Private inspection setup, field work, templates, reports, contacts, and business settings sit inside the authenticated Hometrace workflow.
The inspector chooses recipients
Clients and agents receive individual access only after the inspector adds them to an inspection and sends or publishes the relevant materials.
Named providers operate the service
The current Privacy Policy lists Vercel for hosting, Neon and Postgres for database services, Amazon Web Services for file storage, Stripe for payments, Twilio for SMS, and Resend for email.
Authorized support can troubleshoot
When support requires account-level context, a limited administrator may use a temporary logged session. The Privacy Policy describes the purpose and boundaries of that access.
What to know
Security is a shared responsibility, not a blanket promise
Hometrace documents current product controls and service-provider roles, but no online service can promise zero risk. Inspectors also control credentials, recipient lists, public site content, report delivery, and the client data they choose to collect.
- This page does not claim SOC 2, ISO 27001, HIPAA, PCI, or another certification or compliance status.
- Hometrace does not publish a universal fixed retention period; the Privacy Policy describes retention while an account is active and as needed for legal obligations.
- Inspectors are responsible for protecting their account credentials, obtaining appropriate client consent, and removing recipients who should no longer have inspection access.
- Inspector websites and booking pages are intentionally public surfaces, while reports and inspector workspaces follow their own sharing and access rules.
Product evidence
Read the policies and access workflow
These maintained documents are the source of truth for collected data, service providers, support access, customer responsibilities, and recipient delivery.