Smartlage

Legal

Privacy Policy

This policy covers both the Smartlage website and the Smartlage iPhone app. Last updated 7 August 2026.

Summary

  • We never see your lock codes, access codes or Schlage account password.
  • The app talks to your lock and to Apple’s services; we do not run a lock server.
  • We use three processors: Firebase Analytics, RevenueCat and Mixpanel.
  • The website has no accounts, no cookies and no newsletter capture.

Who we are

Smartlage (“we”) publishes this website and the Smartlage iPhone app. We are an independent developer and are not affiliated with, endorsed by, or sponsored by Allegion plc or Schlage. For any privacy request, contact privacy@smartlage.com.

The website

The website has no accounts, no login and no comment system. We do not ask for your email address and we do not run a newsletter. On-site search runs entirely in your browser against content already loaded with the page — search terms are never sent to a server. We do not use cookies, local storage or session storage; your light or dark mode choice lives in memory for the current visit only. Our hosting provider records standard request logs (IP address, user agent, requested URL, timestamp) for security and reliability, retained for a short period by that provider and not used to build a profile of you.

The iPhone app

Data that stays on your device

Lock names, access codes, guest schedules, activity history and any credentials you enter are stored on your device and in your own iCloud/Keychain where you have enabled it. We do not transmit or store them on our servers, and we cannot read them.

Data we or our processors receive

  • Usage and diagnostics — screens viewed, features used, taps on key actions, crashes and errors, app version, iOS version, device model, coarse region and language.
  • Purchase data — subscription status, transaction identifiers, renewal and cancellation events, and a pseudonymous app user ID. Payment card details go to Apple only; we never receive them.
  • Support correspondence — anything you choose to send us by email, including diagnostic logs you attach yourself.

Analytics events are keyed to a randomly generated pseudonymous identifier, not to your name, email address or Apple ID. We do not use IDFA and we do not run ad tracking or the App Tracking Transparency prompt.

Processors we use

Google Firebase Analytics and Crashlytics

Purpose: aggregate product analytics and crash reporting. Data: pseudonymous installation ID, event names and parameters, device model, OS version, app version, coarse location derived from IP, crash stack traces. Provider: Google LLC / Google Ireland Limited. IP addresses are used to derive coarse location and are not stored by us. See Google’s Firebase privacy documentation.

RevenueCat

Purpose: managing in-app subscriptions and entitlements, and validating App Store receipts. Data: pseudonymous app user ID, Apple receipt and transaction identifiers, subscription status, product identifiers, country, device and app version. Provider: RevenueCat, Inc. See the RevenueCat privacy policy.

Mixpanel

Purpose: product analytics — understanding which flows people complete and where they get stuck, so we can fix them. Data: pseudonymous distinct ID, event names and properties, screen views, app and OS version, coarse region. We have Mixpanel configured so that IP addresses are not used for precise geolocation. Provider: Mixpanel, Inc. See the Mixpanel privacy policy.

Apple also provides us with aggregate App Store analytics and, if you opt in on your device, crash and usage data. That data is aggregated by Apple and is not linked to you by us.

What we do not do

  • We do not sell or rent personal data, and we do not share it for advertising.
  • We do not use third-party advertising SDKs or cross-app tracking.
  • We do not upload your lock codes, guest codes or lock activity to our servers.
  • We do not require an account to use the app’s core features.

Legal bases (EEA/UK)

  • Contract — processing purchase and entitlement data through RevenueCat so we can deliver the subscription you bought.
  • Legitimate interests — pseudonymous analytics and crash reporting to keep the app working and improve it, balanced against your interests and limited to non-identifying data.
  • Consent — where consent is required in your jurisdiction for analytics, we rely on the choice you make in the app’s privacy settings.

International transfers

Firebase, RevenueCat and Mixpanel are US-based providers and may process data in the United States. Transfers rely on the European Commission’s Standard Contractual Clauses and the providers’ own transfer frameworks.

Retention

Analytics events are retained for up to 14 months and then deleted or aggregated. Purchase records are retained for the life of the subscription plus the period required for tax and accounting. Support emails are retained for up to 24 months. On-device data is deleted when you delete the app.

Your choices and rights

  • Turn analytics off in the app under Settings → Privacy; the app remains fully usable.
  • Delete the app to remove all on-device data, including codes and schedules.
  • Request access, correction, deletion, a copy of your data, or object to processing by emailing privacy@smartlage.com. Include your RevenueCat app user ID (Settings → About) so we can find your records. We respond within 30 days.
  • Manage or cancel subscriptions in the App Store; refunds are handled by Apple.
  • California residents may exercise CCPA/CPRA rights via the same address. We do not sell or share personal information as those terms are defined.

Children

The app is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

Security

Data in transit uses TLS. Sensitive on-device values are stored in the iOS Keychain. Access to processor dashboards is limited to the developer and protected with two-factor authentication.

Changes

Material changes will be posted on this page with a new “last updated” date, and announced in the app when they affect what we collect.