Security and data handling

How Hometrace protects inspection data

Hometrace uses authenticated accounts for private inspector work, gives report recipients inspection-scoped access, limits support access to authorized administrators with time-limited and logged sessions, and uses named service providers for hosting, storage, communications, and payments. Hometrace does not claim that any system is risk-free, and this page does not assert a security certification.

Who it is for

For inspectors evaluating where business and client data goes

Inspection software holds property details, photos, findings, recipient information, and business records. This page summarizes the controls and responsibilities Hometrace documents today without turning implementation details into broader guarantees.

Private work requires access

Inspectors use a Hometrace account for their workspace. Client and agent links are tied to the intended recipient and provide access to the inspection content that recipient is allowed to see.

Support access is restricted

The Privacy Policy limits account access for support to authorized administrators. Those sessions are time-limited and logged, with password and payment details outside the permitted support workflow.

Full card details stay with Stripe

Stripe handles subscription and inspection-payment card data. Hometrace receives identifiers and high-level payment metadata rather than full card details.

How it works

How access and service providers fit together

Hometrace separates the inspector workspace, intentional recipient sharing, operational service providers, and exceptional support access.

  1. The inspector signs in

    Private inspection setup, field work, templates, reports, contacts, and business settings sit inside the authenticated Hometrace workflow.

  2. The inspector chooses recipients

    Clients and agents receive individual access only after the inspector adds them to an inspection and sends or publishes the relevant materials.

  3. Named providers operate the service

    The current Privacy Policy lists Vercel for hosting, Neon and Postgres for database services, Amazon Web Services for file storage, Stripe for payments, Twilio for SMS, and Resend for email.

  4. Authorized support can troubleshoot

    When support requires account-level context, a limited administrator may use a temporary logged session. The Privacy Policy describes the purpose and boundaries of that access.

What to know

Security is a shared responsibility, not a blanket promise

Hometrace documents current product controls and service-provider roles, but no online service can promise zero risk. Inspectors also control credentials, recipient lists, public site content, report delivery, and the client data they choose to collect.

  • This page does not claim SOC 2, ISO 27001, HIPAA, PCI, or another certification or compliance status.
  • Hometrace does not publish a universal fixed retention period; the Privacy Policy describes retention while an account is active and as needed for legal obligations.
  • Inspectors are responsible for protecting their account credentials, obtaining appropriate client consent, and removing recipients who should no longer have inspection access.
  • Inspector websites and booking pages are intentionally public surfaces, while reports and inspector workspaces follow their own sharing and access rules.