Intry Privacy Policy

1. About This Policy

Bytesize LLC, doing business as Intry (‘Intry’, ‘we’, ‘us’) operates a smart building access management platform available at gointry.com and through mobile applications. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with our services.

By accessing or using Intry, you agree to this Policy. Our Compliance Officer is T. Thomas, reachable at [email protected] or [email protected].

 

2. Information We Collect

Role of Parties

When providing access management services to properties, Intry processes personal data (including access event history) strictly as a Data Processor on behalf of the Property Management Company or Landlord, who acts as the Data Controller. Any inquiries regarding access log retention or property surveillance policies must be directed to your property administration.

Account & Identity Data

Name, email address, nickname, role, property and unit assignment, and authentication provider identifiers (Clerk).

Contact & Communication Data

Phone numbers (including verified status), email addresses, and fallback notification preferences (SMS, voice, WhatsApp).

Building & Access Data

Property address, timezone, unit label, virtual phone number assignments, gate configuration, DTMF/access codes, and access event history including call records, approval/denial actions, and approver identity.

Caller Identification Data

When the caller identification feature is enabled by a property administrator, we may collect speech transcripts and audio recordings of callers seeking entry. Callers are notified before any recording begins.

Device & Push Notification Data

Device platform, push token (Expo/FCM/APNs), device model, OS version, app version, notification preferences, and last active timestamp.

Analytics & Diagnostic Data

Product usage events, session data, error reports, crash logs, and session replay recordings (PostHog, Mixpanel, Sentry, LogRocket). This data may include device/app interaction context. See Section 6 for detail.

Billing Data

Stripe customer, subscription, payment, and invoice identifiers. We do not store full payment card numbers — these are handled directly by Stripe, Inc.

Audit & Security Logs

IP addresses, user agents, request paths, API key usage, and admin impersonation activity for security and compliance purposes.

Integration & Webhook Data

URLs, Slack webhook endpoints, WhatsApp numbers, and email recipients configured by users for notification delivery. Webhook signing secrets are stored encrypted.

 

3. How We Use Your Information

  • Providing, operating, and improving the Intry platform and access management services

  • Routing inbound calls, delivering access approval/denial notifications, and processing entry events

  • Sending transactional SMS, voice calls, push notifications, and emails related to access events

  • Authenticating users, verifying sessions, and managing API keys and permissions

  • Processing subscription billing, invoicing, and payment events via Stripe

  • Monitoring platform health, diagnosing errors, and conducting security audits

  • Complying with legal obligations and enforcing our Terms of Service

 

4. Telephony & SMS Consent

Intry uses Twilio to deliver voice calls, SMS messages, and WhatsApp notifications. By providing your phone number and opting in during onboarding, you consent to receive operational messages related to your property access. Standard carrier message and data rates may apply.

You may opt out of SMS at any time by replying STOP to any Intry message. To reactivate, reply START. These notifications are operational in nature and cannot be fully disabled while your account is active, as they are required for access event delivery.

 

5. Call Recording & Transcription

When the caller identification feature is enabled by a property administrator, inbound callers may be prompted to state their name, which is recorded and/or transcribed using Twilio’s recording services. Callers are notified via an audio prompt before any recording begins. Recordings are associated with the corresponding access event and are accessible to the resident who received the access request. Recordings are retained for 30 days and then automatically deleted, unless applicable law requires longer retention.

 

6. Cookies, Analytics & Session Replay

We use the following tools to understand how our platform is used and to improve performance:

  • PostHog — product analytics, feature flags, pageview tracking, and localStorage/cookie persistence in our admin dashboard

  • Mixpanel — server-side user behavior analytics and user property tracking

  • Sentry — error monitoring, crash reporting, and session replay in the mobile app

  • LogRocket — React Native session replay and diagnostics

  • Google Tag Manager — present in the admin interface for tag management

 

7. Subprocessors & Third-Party Vendors

We share data with the following categories of third-party processors to deliver our services. A full Subprocessor List is maintained as a separate document and updated periodically.

Categories include: telephony (Twilio), authentication (Clerk, WorkOS), API management (Unkey), payments (Stripe), push notifications (Firebase/FCM, Apple APNs, Expo), error monitoring (Sentry), analytics (PostHog, Mixpanel, New Relic), session replay (LogRocket), communications (Slack, Resend), mapping (Mapbox, OpenStreetMap), and infrastructure (Railway, Fly.io, PostgreSQL, Cloudflare R2).

 

8. Data Retention & Deletion

We retain personal data for as long as your account is active or as needed to provide services. Upon account deletion, we will delete or anonymize personal data within 30 days, subject to legal holds. Access event logs are retained for 90 days. Call recordings are retained for 60 days. Billing records are retained for 7 years per applicable tax and financial regulations. Full retention schedules are documented in our Data Retention & Deletion Policy.

 

9. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or restrict processing of your personal data. California residents have additional rights under CCPA including the right to know what personal information is collected, the right to delete, and the right to opt out of sale (we do not sell personal information). To exercise rights, contact [email protected].

 

10. Security

We implement industry-standard security measures including encryption of sensitive integration secrets, password hashing, webhook signature validation, rate limiting, API key scope controls, audit logging, and role-based access controls with admin impersonation audit trails.

 

11. Children

Intry is intended for use by adults (18+) or authorized property managers. We do not knowingly collect personal information from individuals under the age of 18 without verifiable parental consent.

 

12. Contact

Intry, a trade name of Bytesize, LLC.
1954 Airport Road, #1047, Atlanta, GA 30341

1-866-254-6879

[email protected]