Legal
22.done Privacy Policy
This Privacy Policy explains how Verdant Keep, LLC, an Illinois limited liability company that operates the 22.done service (“22.done,” “we,” “us,” or “our”), collects, uses, protects, shares, retains, and deletes information through the 22.done website and disclosure-packet service (the “Service”). It applies both to website visitors and to users who begin or complete a disclosure session.
1. Information We Collect
Website and technical information. Our hosting and infrastructure providers may receive standard technical information, such as your Internet Protocol address, browser or device type, pages requested, access dates and times, and error or security events.
Session information. The Service collects information entered during a disclosure session, including association and property information, unit and seller information, officer or representative information, assessment and account information, financial information, insurance information, pending claims or litigation, anticipated expenditures, and other disclosure responses.
Uploaded documents. Users may upload declarations, bylaws, rules, financial statements, and other association records. These documents may contain information about unit owners or other individuals.
Generated files. We process user responses and uploaded documents to create disclosure statements, unit-account or paid-assessment letters, exhibits, and downloadable files.
Payment information. Payments are processed through Stripe or another identified payment processor. Complete payment-card details are provided directly to the processor and are not stored by 22.done. We may receive payment status, amounts, transaction identifiers, receipts, and refund information.
Communications. If you contact us, we collect the information contained in your message, including your name, email address, and support request.
Please do not submit Social Security numbers, passwords, medical information, biometric information, complete bank or payment-card numbers, or other sensitive information the Service does not request. Users should remove unnecessary personal information from uploaded documents.
2. How We Use Information
We use information to:
- Create and maintain a disclosure session;
- Organize user responses and uploaded documents;
- Generate and deliver the requested disclosure package;
- Process payments, refunds, and promotional access;
- Provide technical or customer support;
- Diagnose errors and maintain the Service;
- Prevent fraud, misuse, and security incidents;
- Comply with legal obligations and valid legal process; and
- Enforce our Terms of Use.
We do not use Transaction Content for behavioral advertising or to train a generalized artificial-intelligence model.
3. Confidentiality and Disclosure
“Transaction Content” means information entered, uploaded, or generated during a disclosure session. We treat Transaction Content as confidential.
We do not sell or rent Transaction Content, and we do not disclose it for cross-context behavioral advertising. We may disclose information only:
- To hosting, storage, payment, security, support, and other service providers that need the information to perform services for us and are subject to appropriate confidentiality or security obligations;
- When required by law, court order, subpoena, or other valid legal process;
- When reasonably necessary to investigate fraud or a security incident or to protect rights, property, or safety;
- At the user’s direction or with the user’s authorization; or
- In connection with a merger, financing, reorganization, or sale of the Service or business, subject to this Policy or protections that are at least as protective.
Current or planned providers include Render for hosting and Stripe for payment processing.
Uploaded documents are not routinely reviewed by people. Limited access by authorized personnel or service providers may occur when reasonably necessary for support, security, legal compliance, or incident response.
4. Cookies and Website Visitors
The Service does not presently require users to create an account. It uses an essential session cookie containing a random identifier so that responses and documents can be connected to the correct session.
If you open an access link we issued, the Service may set a second essential cookie containing an opaque token, and may record in an administrative log that that token was opened and later used to start a session. The token is not your name. This is so we can tell which issued link was used. It is not advertising or behavioral analytics.
Deleting or disabling the session cookie may prevent the Service from locating an existing session and may make the immediate-deletion control unavailable from that browser.
The public pages of the Service load the Google Ads tag (gtag.js), provided by Google LLC, so that we can measure whether a visit that began with one of our advertisements resulted in a completed purchase. When you arrive from a Google advertisement, Google may set a cookie on this site containing a click identifier, and may record that a purchase page was later reached. This measurement does not transmit to Google the contents of your disclosure responses, your documents, or the name of your association. Google's use of this information is governed by Google's own privacy policy at policies.google.com/privacy. You may block this cookie with browser settings or an ad blocker without affecting your ability to use the Service. We do not use the tag for remarketing or to build audience profiles.
Other than the Google Ads measurement described above, the Service does not use behavioral-advertising cookies. If we later add nonessential analytics, advertising technology, or materially different tracking, we will update this Policy and provide any notice or choice required by law.
5. Seven-Day Retention and Deletion
Transaction Content—including answers, uploaded documents, and generated files—is automatically scheduled for deletion after seven consecutive days of inactivity.
Users may delete Transaction Content sooner by selecting “Delete my data now.” Once deleted, the session and generated materials cannot be restored. Users are responsible for promptly downloading and retaining their completed packages.
Deletion of Transaction Content does not require the immediate deletion of limited administrative information reasonably needed to:
- Document acceptance of the Terms of Use;
- Record a payment or refund;
- Prevent fraud or misuse;
- Resolve a dispute;
- Comply with tax, accounting, or legal obligations; or
- Document that deletion occurred.
Deletion generally removes Transaction Content from active systems. Limited copies may remain temporarily in security logs or backups until overwritten under the applicable provider’s normal retention cycle. Those copies are not used for ordinary business purposes and may be accessed only for security, disaster recovery, legal compliance, or incident response.
6. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, acquisition, alteration, destruction, use, or disclosure. Access is limited to systems, personnel, and service providers with a legitimate need for it.
No Internet transmission or storage system is completely secure, and we cannot guarantee absolute security. Users can reduce risk by submitting only information needed for the transaction, removing unnecessary personal information, using a trusted device and network, downloading the completed package promptly, and deleting the session when finished.
7. Your Choices
During an active session, you may review and revise your responses and may delete Transaction Content using the “Delete my data now” control.
You may also contact us with a privacy question or request. We may need enough information to verify the request and identify the relevant session or administrative record. Because the Service does not use traditional user accounts and Transaction Content is retained only briefly, we may be unable to locate information after the applicable session or cookie has been deleted.
8. Children
The Service is intended for authorized adult representatives of condominium associations. It is not directed to children under 18, and we do not knowingly collect personal information directly from children.
9. Third-Party Services
The Service may rely on or link to third-party services, including Render, Stripe, and public legal or informational websites. Information submitted directly to those services is governed by their privacy terms.
This Policy does not control information after a user downloads a disclosure package and distributes it to a buyer, attorney, lender, title company, unit owner, or other person.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in the Service, technology, service providers, or law. The revised Policy will state its effective date. The version presented when a disclosure session begins will apply to that session unless a change is required by law or the user separately acknowledges the revised Policy.
11. Contact
Customer support for the Service: support@retoolschi.com.
Privacy questions or requests may be directed to Cole Sadkin, LLC at mcole@colesadkin.com on behalf of:
Verdant Keep, LLC
Attn: Privacy—22.done