Utility Profit

Utility Profit Connect — privacy policy

Last updated: 2026-10-06. Applies to version 0.10.0 of the browser extension "Utility Profit Connect" for Chrome, Microsoft Edge, Firefox and Safari on the Mac, published by B&Z Homes, Inc. ("Utility Profit", "we").

Who uses this extension

Property managers who already have a Utility Profit partner account (or, for the optional move-out card alone, a sign-in to Utility Profit's move-out tracker) and use AppFolio or, in Chrome, Edge and Firefox, Rent Manager Express or Buildium. It is not for renters and it is not for the general public.

The Safari version

The Safari version, for Safari 18.4 and later on the Mac, is the same extension with less in it. It sends nothing the Chrome version does not, and it differs in these ways:

The Firefox version

The Firefox version, for Firefox 140 and later, is the same extension, move-out card included. It differs in these ways:

What the extension reads

On a tenant page under https://*.appfolio.com/occupancies/… the extension reads what is already on the screen in front of the property manager:

It does not read the tenant type or the lease status, even though they sit in the same blocks — nothing in the extension compares or sends them, so it does not take them.

It also reads from the property manager's own Utility Profit account, signed in as them: the Utility Profit record for the tenant on screen, and the list of tenants Utility Profit holds for their company — name, email address, phone number and address, the same fields their own Utility Profit dashboard shows them. That list is what lets the extension recognise a tenant by email or phone rather than by address alone. It is read from Utility Profit, never sent to it, and it is not kept in readable form: see Matching a tenant.

The extension runs on two other kinds of page.

The first is ours. A content script restricted to https://sunroomrentals.com/utility-profit/* types the property manager's own search term into the Utility Profit dashboard's search box when they arrive there from one of the extension's links. It reads nothing from that page and sends nothing anywhere.

The second is AppFolio's property and unit pages (https://*.appfolio.com/properties/*), for the move-out card, which is on from 0.10.0 and silent unless the property manager is signed in to Utility Profit's move-out tracker in the same browser. Signed out, it draws nothing. Turned off, the extension reads nothing from those pages, draws nothing on them and makes no network request. What it reads, sends and writes is described under The move-out card on property pages below.

Those three — AppFolio tenant pages, AppFolio property pages and the Utility Profit dashboard — and, in Chrome, Edge and Firefox, the Rent Manager Express and Buildium pages in On Rent Manager Express and Buildium are the only pages the extension runs on. The only sites it holds permission for are Utility Profit's own (api.utilityprofit.com and sunroomrentals.com) and Amazon S3, where Utility Profit keeps uploaded files, plus, in Chrome, Edge and Firefox, Utility Profit's move-out tracker (moveout.utilityprofit.com), for the move-out card (since 0.10.0 asked for at install or update; before, only when the property manager turned the card on). It holds none for AppFolio, Rent Manager or Buildium in Chrome and Edge; Firefox grants it access to those sites along with its page scripts (see The Firefox version), and in Safari the property manager allows each AppFolio site so that the extension's page script can run there (see The Safari version).

On Rent Manager Express and Buildium

Since 0.10, in Chrome, Edge and Firefox (not Safari), the same card is drawn on two other property management systems, for anyone signed in to Utility Profit, with nothing to turn on.

Everything this page says about AppFolio's tenant pages holds there too. What is read is compared inside the browser, and the only thing about a tenant that leaves it is the coarse address fragment. The extension writes nothing into Rent Manager or Buildium, clicks nothing there, calls none of their APIs and reads none of their cookies; none of their own page elements is changed, and the card goes when the page changes. Where AppFolio's identifiers travel (to the link service and, except in Firefox, the activity receiver), Rent Manager's company code and tenant id travel instead, and Buildium's account and lease id; an event from before a Buildium page has shown its lease carries the account only. Usage events also say which of the two the page was.

What it sends, and to whom

Every place the extension sends anything, and what goes to each:

There is no other destination. Of what the extension reads about a tenant on an AppFolio, Rent Manager or Buildium page, the only thing that leaves the browser is the coarse address fragment. Of what the property manager types into the card's search box, the only thing that leaves the browser is the same fragment of an address; an email address, phone number or name typed there is compared inside the browser and sent nowhere. The AppFolio subdomain and occupancy id from the page's web address travel as identifiers to the link service and, except in Firefox, the activity receiver. Of what the extension reads on an AppFolio property page, nothing leaves the browser but what the move-out card's usage events say about it: whether the page matched a tracker property and how many (a word and a count), whether it was linked by hand (yes or no), whether the page's AppFolio account was one of the tracker company's (a word), and whether the card found one of AppFolio's sections to sit beside. Nothing of its text or address.

Signing in

The extension needs the property manager's own Utility Profit session. It uses the first of these it finds:

When it finds none of these, or Utility Profit no longer accepts the one it has, the extension popup asks for the phone number and password of their Utility Profit account. Those two values are sent once, over HTTPS, to Utility Profit's own sign-in endpoint (https://api.utilityprofit.com), in exchange for a session token. The password is not stored, not written to disk, and not sent anywhere else. Only the returned session token is kept, in the browser's extension storage on that computer.

The extension also reads the dashboard's session cookie to read the company's tenant list from the dashboard, whichever way it is signed in, and it notices when that cookie is set, so that a property manager who signs in to the dashboard from the card's link is signed in and gets the tenant list straight away rather than on a later page. It reads cookies for api.utilityprofit.com and sunroomrentals.com only — no cookie for AppFolio or any other site.

These are the property manager's own credentials for their own account. The extension never asks for, reads, or transmits a tenant's credentials of any kind.

The optional move-out card has no sign-in of its own, and it does not need the Utility Profit sign-in above. It works only when the property manager is already signed in to Utility Profit's move-out tracker in the same browser: the browser attaches the tracker's own session cookie to the card's requests to the tracker, and the extension does not read that cookie, store it, or ask for a tracker password.

Matching a tenant

The extension shows a Utility Profit record next to a tenant only when it can tell the record belongs to that tenant. It checks, in this order:

A name alone never links a record. At most it lets the extension recommend one for the property manager to confirm.

A match to check. Where the email address or phone number agrees and neither the last name nor the move-in date disagrees, but Utility Profit holds the record at a different address from the page, the card shows the record in full — as it shows a match — but says so ("Not a perfect address match", with the address Utility Profit has) and asks the property manager to confirm it. The same goes for the one record a search finds that agrees in the same way. A record that agrees on the email address or phone number but whose last name or move-in date disagrees may be another person sharing that contact, or an earlier tenancy: it is not shown in full, and at most the card lists it, masked, for the property manager to judge (see Finding a tenant by hand). Until the property manager answers, nothing is saved or shared, nothing is written into AppFolio, and the tenant's uploaded proof does not open. That's them links the record, exactly as described below. Not them is remembered on that computer — the tenancy's id, the Utility Profit record's id and when, nothing else — and the record is not suggested for that tenancy again; it stays in the card's list, marked, so the answer can be changed.

The tenant list the email and phone step compares against is built from the property manager's Utility Profit dashboard session in the same browser: when the browser starts, or the extension is installed or updated, if that session is already there; when the property manager signs in to the dashboard; otherwise on the first tenant page; and again on a tenant page once it is half an hour old. The newest move-ins are read first, a page at a time, for as long as the dashboard can answer a page in time; where it is slow, the list is the company's newest move-ins (at a large company, a couple of hundred) and older records are not read. Signed in through the dashboard, the newest are used as soon as they arrive, and until the rest has arrived a tenant not found among them shows as still loading. Where the list stopped at the newest move-ins, a tenant not in it shows as not among them, with a link to the dashboard's own search, never as having no record. On an API session the address search answers meanwhile, the automatic email and phone step runs only on a list of the whole book, and an open tenant page without a sure match looks again when it lands. A build that ends without a list says so on the pages waiting for it. Signing out of the dashboard stops a build, and nothing that build read is kept. A list that comes back empty is kept only once the dashboard confirms the session is still signed in to that company. Without the list, a tenant whose Utility Profit address differs from AppFolio's can only be found by the searches below, and the card says so, with a link to sign in to the dashboard.

Finding a tenant by hand

When the extension cannot tell, the card on the tenant page searches on its own and lists the Utility Profit records that could be this tenant so the property manager can decide. Each shows the name, the lease start date, how many utilities are set up, and an email and phone masked to their first letter and last four digits — enough to check against the page in front of them. Where one record agrees on the email address or phone number and nothing else disagrees, the card shows it as a match to check (see Matching a tenant); nothing is linked until the property manager confirms. The search sends nothing the automatic check does not already send; at most it searches the street word on its own.

Under the list, a search box takes an address, an email address, a phone number or a full name. An email address, phone number or name typed there is turned into a fingerprint inside the browser and compared with the tenant list's fingerprints; it is not sent anywhere and it is not stored. Without the tenant list these cannot be searched, and the card says so. An address typed there is cut to the same coarse fragment as the page's own — the house number, a directional where the address has one, the first word of the street, and the unit key — before it is sent to Utility Profit; nothing else of it is (signed in through the dashboard, the fragment is compared inside the browser instead and not sent at all). Records found at an address the property manager typed are listed, masked, for them to judge; one is shown in full only if it agrees on the email address or phone number, as above.

If the property manager links a record, the extension stores the Utility Profit record's id against the tenancy's id, and shares that pair with colleagues (see Links shared with colleagues) — no name, no contact details, no address. It can be unlinked from the same place at any time.

The tenant's name, email address, phone number, move-in date, zip code, city and full address line, as read off the AppFolio page, are never transmitted. They are used only inside the browser, to check that a Utility Profit record really belongs to the tenant on screen rather than to a previous occupant at the same address.

The account numbers in AppFolio's utilities table are never transmitted, and the extension does not compare or keep them. The same holds for a policy number on AppFolio's Insurance Coverage card.

Use sidebar only, a switch under Advanced in the extension's popup, stores one preference in this browser's extension-local storage. Inline display remains the default. Sidebar-only removes injected cards, disables form filling, pauses required-utility capture/sync, hides the move-out card, and stops automatic typing into the Utility Profit dashboard search field. It preserves those features' previous preferences so switching back restores them. While it is on, the sidebar says so and offers Turn off; Open sidebar in the popup opens the sidebar whether or not it is on. It does not erase notes or form values already handed to AppFolio, or change existing Utility Profit retention policies.

The current tenant lookup stays available in the browser sidebar. A separate manual search works without AppFolio: the existing address-fragment search and local company-list contact search are reused, and results can be expanded to read utility details without saving a link or filling AppFolio fields. Changing tabs clears the previous displayed result. Rendering trees and the transport's binding tokens are held in memory, not added to persistent storage or analytics. Existing lookup caches, activity logs, and saved links retain their existing retention rules. Chrome adds the sidePanel permission; no tabs, activeTab, scripting, or AppFolio host permission is added. Browsers without the Chrome side-panel API use an extension tab opened from the popup. Sidebar-only does not promise an undetectable extension.

The card on the tenant page

On each AppFolio tenant page the extension adds one card of its own — right above AppFolio's utilities table where the page has one, otherwise below Upcoming Activities (or the nearest card AppFolio shows) — which the property manager can collapse to a single line. It is drawn on every tenant page, whether or not the company uses AppFolio's own resident-obligated utilities. It shows what Utility Profit holds for the tenant: each utility's setup status, the provider, the account number, the service start date, and the name of any proof the tenant uploaded. Since 0.9.27, the card is rendered in an extension-origin frame. AppFolio page scripts cannot directly read that frame's contents under the browser's same-origin rules. Only the frame shell and dimensions enter AppFolio's DOM; customer values and binding capabilities are not placed in its attributes or URL. The host retains session-replay masking attributes. The frame is detectable and removable by the page. This does not prevent screenshots, privileged browser software, or retention of data previously disclosed.

The card only shows. Its one field is the search box (see Finding a tenant by hand), and nothing on it is written into AppFolio: not its notes, its utilities table or that table's Edit dialog. Clicking a proof's name opens the file in a new tab (see Amazon S3 under What it sends, and to whom). Its other controls are the search and the That's them / Not them answers (see Finding a tenant by hand and Matching a tenant), and a link to sign in to the Utility Profit dashboard when the tenant list is missing.

What it writes into AppFolio

The extension writes nothing into AppFolio's utilities table or its Edit dialog, and it never clicks Cancel or Close. It writes nothing at all into Rent Manager or Buildium: there the card has no note or insurance action. Nor does the move-out card: its changes are saved to Utility Profit's move-out tracker, never to AppFolio.

When a property manager links a tenant to a Utility Profit record, or unlinks one, the extension sends that change to Utility Profit's link service, so colleagues signed in to the same Utility Profit company see it too. A link is four identifiers: the partner id, the AppFolio subdomain, the AppFolio occupancy id and the Utility Profit record id. The property manager's own Utility Profit session is the only credential; the service asks Utility Profit who that session belongs to and answers only for that company. If the service is unreachable, the link stays on the computer and is sent at a later check — unless the service already holds a colleague's link for that same tenancy, in which case the colleague's link replaces the one on this computer at a later check.

An unlink the service does not take is kept on the computer — the partner id, the AppFolio subdomain, the occupancy id and a time — and sent again before the extension next reads the shared links, so a refused request does not quietly undo it. The extension also keeps a short note that the tenancy was unlinked here (the subdomain, the occupancy id and a time), so an answer already on its way from the service cannot put the link back; a note older than five minutes no longer does anything and is cleared out the next time a tenancy is unlinked. When the extension cannot name the Utility Profit company at all — signed out, with nothing known from earlier in the session — nothing is queued to send: the service keeps its copy, and a later check puts the link back on this computer.

Signed in through the dashboard alone, the extension has no API session, and the link service needs one, so nothing is sent to the service or read from it. A link made then stays on the computer; if the extension later has an API session, the link is sent at a later check, as one the service could not be reached for is. An unlink made then is not sent and not kept to send later: the service keeps any link it holds for that tenancy, and a check under an API session puts it back on this computer.

The move-out card on property pages

Not in the Safari version. Since 0.10.0 this is on by default and silent when signed out: the card appears only for a property manager signed in to Utility Profit's move-out tracker (https://moveout.utilityprofit.com), Utility Profit's own product for the utility transfers when a tenant moves out, in the same browser. Show the move-out card on property pages in the popup's Advanced section turns it off, and so does Show the card on tenant pages, turned off, which also stops every request the card makes (a card already on an open page stays there, making no request, until that page is reloaded or left). Before 0.10.0 it was off until the property manager turned it on; an update to 0.10.0 turns it on once, including where an earlier version had stored it as off.

On an AppFolio property page the card first asks the tracker for the company's property list, with the browser's own tracker sign-in. Signed out, the tracker refuses, and the card draws nothing at all: no link, no button, no line. The extension then does not ask the tracker again for two minutes, or until the tracker's sign-in cookie changes in the browser (a sign-in or a sign-out there), so a property manager who is not a tracker customer sends the tracker at most one request every two minutes and sees nothing. Signed in, on a page that matches none of the company's properties, it shows one folded line that, opened, offers to link the page to one by hand. Signed in and later signed out while a card is open, the card says so.

The card is drawn only when the extension answers yes to the page's question "is the card on?"; a no, or no answer at all, draws nothing. The page asks again each time the property manager goes to another page within AppFolio, and whenever the switch or the browser's permission changes, so turning the card off takes it off pages already open, without a reload.

Permission. Since 0.10.0 moveout.utilityprofit.com is one of the sites the extension holds, so the browser lists it when the extension is installed or updated to 0.10.0, in the same prompt as Rent Manager Express and Buildium. Before, it was asked for only when the property manager turned the card on. Where the browser has not granted it (Firefox lets a person withdraw a site), the card stays hidden and nothing is requested: the extension checks the permission before every request. Turning the card off no longer hands the permission back; it stops every request instead.

What it reads, from the move-out tracker, as the signed-in property manager and for their own company only:

What the card shows. The move-out details above, including staff names, the email address of whoever completed a transfer, account numbers and notes; under Details, the owner's name, who manages the property, its status and move-out date, and, to a tracker admin, the owners' email addresses, the reminder cadences and the owner's pause date; the team's names, in the lists for choosing who a utility is assigned to (and, for an admin, who manages the property); and the state of the owner's reminder emails, with the actions the signed-in person may take. It receives the signed-in person's own name and role, the company's slug and its AppFolio account names but does not show them; it shows the company's name only where it says the page is not on one of the company's AppFolio accounts (see Only the company's own AppFolio). It does not show the recipient of an owner email. It also receives, and does not show, past move-outs' account numbers, per-utility notes and who completed them (for a past move-out the card shows its date, who it was assigned to, its move-out notes, and each utility's provider, status and where it went), and the phone numbers, websites, portal addresses and steps in the company's provider list (from that list the card offers only names, when a provider is being changed). When the property manager opens Link a property…, it lists the company's properties (address, city, move-out date, and the property code as a filter attribute) inside the card, on the AppFolio page. The provider's phone number is shown as text, and its website or portal address as a link (http or https, as typed into the tracker) that opens that site in a new tab only when the property manager clicks it. So do the card's links to the tracker itself.

The tracker's card routes leave out owner email addresses (except to a tracker admin, as above), login tokens and provider portal logins, and the extension keeps only a fixed list of fields from each answer, trimmed and capped in length, before anything is kept or shown.

Only the company's own AppFolio (since 0.9.24). The tracker names the AppFolio accounts each company uses. Before the extension hands anything of the company's to a property page, it compares the page's AppFolio account (the first part of its web address, as the browser reports it for the tab) with those names, inside the browser. On any other AppFolio account — or on every account, while the tracker names none for the company — the page gets none of the company's properties, move-outs or controls, and nothing can be written from it; the card says only which company the tracker sign-in belongs to and that this AppFolio account is not one of its own, or that the company has not been connected yet. The AppFolio account's name is not sent to the tracker. This keeps a person signed in to one company's tracker from seeing or linking that company's move-outs on another company's AppFolio; what the tracker sends is still only the signed-in person's own company's.

Matching the page. The extension compares the AppFolio property page's headings and text with the company's property list inside the browser. Nothing read from the AppFolio page is sent to the tracker or anywhere else. When nothing matches, the property manager can link the page to a tracker property by hand; that link — the AppFolio page's web address (its host and path) and the tracker record id — is kept in the extension's storage on this computer and is not shared. Unlink on the card removes it, and turning the card off removes every such link.

What it writes, only when the property manager clicks, and only what the tracker allows the signed-in person (the tracker checks every request against its own rules; the ones its dashboard keeps to admins stay admin-only): a utility's status, "straight to next tenant", its account number, notes, provider, who pays, where it goes at move-out or who it is assigned to; a property's notes or move-out notes; a new move-out date; for an admin, the name and email address of the owner or second owner, who manages the property, its status, a corrected move-out date and how often the team and the owner are reminded; a utility to add, or a utility or the whole property to remove (a removal needs a second click to confirm); and the owner's reminder emails: email the owner now (also after a second click), turn their scheduled reminders on, hand the owner's utilities to the team instead, stop them, or resume them. The tracker sends any such email itself, to the address it holds; the extension neither sends it nor sees it. Each request carries exactly one of these fields or actions to the tracker (adding a utility carries its type and where it goes; a removal carries nothing but the record id in its address), as the signed-in property manager, checked against a fixed list of values or cut to a maximum length; saving a change of provider and who pays sends one request for each of the two that changed, for each utility the entry on the card covers (both, on an entry three utilities share, is six requests). It writes nothing into AppFolio.

What it keeps. The company's property list, with the signed-in person's own name and role and the company's slug, name and AppFolio account names, is kept in the browser's memory (chrome.storage.session: never written to disk) and read again from the tracker once it is more than ten minutes old. It stays until the browser closes, the card is turned off, or a new move-out is started, a move-out date changed or a property deleted from the card; signing out of the extension does not remove it. A property's detail is never kept; while the card is open, unfolded and on a visible tab, it is read again every 30 seconds so that colleagues' changes show.

How it sits on the page. Since 0.9.27, the move-out card uses the same extension-origin frame and private runtime transport as the tenant card. Its values are not exposed through an open shadow root on AppFolio. The host still carries session-replay masking attributes. The frame itself remains detectable and removable; information explicitly written into AppFolio becomes visible to AppFolio. The standalone lab preview still uses its original shadow rendering.

Analytics. The card adds its own usage events, under the same rules and the same switch as the rest (see Activity log and usage counts): what it showed (a word such as "match" or "signed out", how many units, whether the page was linked by hand, where the card sat), how reading the property list went (whether it worked, a reason word, whether it came from memory, how many properties, how long it took), a property that could not be read (a reason word and how long), and each save (the kind, the field's name or, for the owner's emails, the action word, a utility's new status word, whether it worked, a reason word, how long it took), plus the switch being turned on or off, whether the browser's permission was granted, and — when a property page keeps taking the card away — one event saying the card stopped drawing itself again (a reason word and how many times it tried). Like every other event they carry the time, the extension version, the random install id and, when the extension knows it, the Utility Profit partner id (not in Firefox). They carry no AppFolio page address or id, and never an address, name, account number, note or anything typed; a status change carries only the new status word. What the card showed, how many units, whether the page was linked by hand and where the card sat all depend on the AppFolio page: words, a count and a yes/no, nothing of its text or address.

Report an issue

The extension popup has a Report an issue button. It builds a diagnostic bundle, copies it to the clipboard, and opens a pre-addressed email; the property manager pastes it in and sends it. Nothing is transmitted automatically — no bundle leaves the computer unless they send that message.

The bundle is built from a fixed allow-list: a field that is not named on that list cannot appear in it, including one added to the extension next week. What it carries is shape — which surfaces the page had, how many rows, which utility types, what the extension's own card said, timings, error codes, and the latest usage events described below. It never carries a value read off the page: no tenant name, email, phone number, move-in date, address line, account number, policy number or note text. The property manager's own typed description of the problem is the one piece of free text in it, and they can read the whole bundle before sending it.

Activity log and usage counts

The extension keeps a log of what it did: builds of the tenant list, each link made by hand, and, for a link or unlink sent to colleagues as it is made, whether it reached them. A line about a link names the tenancy by its AppFolio subdomain and occupancy id and by the Utility Profit record id — no address. It never carries a tenant's name, email address, phone number, account number or note text. The move-out card writes no lines to this log; its usage events are described under The move-out card on property pages.

It also records usage analytics, so Utility Profit can see how the extension is used and where it goes wrong: each tenant page viewed, how the lookup went and why it ended where it did (including whether the tenant list was there and whether a dashboard session was, and, when it did not find the tenant, how many whole months ago the tenant moved in — counted in the browser, capped at 36, never the date), what the card showed and whether it could actually be seen once drawn, each match to check it showed and the property manager's answer, what kind of term was typed into the search box — address, email, phone or name, never the term — and how many records came back, and — when a page keeps taking the card away — one event saying the extension stopped drawing it again (which card, a reason word and how many times it tried), each click on the card and in the popup and what came of it, sign-in changes, settings switched, and errors by kind. Every event is checked against a fixed list before it is recorded: an event may carry only the fields named for it, and every value must be a yes/no flag, a count or a duration (the move-in's age only in whole months, 0 to 36) or an HTTP status code, or a word from that field's own fixed list. There is no field that takes free text, so no name, email address, phone number, address, account number, note or other page text can travel in one; an event carrying anything else is dropped rather than trimmed. Each event is tagged with the time, the extension version, a random id created when the extension is installed, and — when the extension knows it — the Utility Profit partner id; a log line sent to the receiver carries the time, the version and the same random id. Events from a tenant page also carry two page-derived values: the AppFolio subdomain (e.g. kencoapartments) and the occupancy id from the web address, opaque identifiers that tie a question or an error to a page.

Both stay on the computer, and Download activity log in the popup saves them as a file. That file also carries the extension's diagnostics, which can include the street and unit of the last tenant page it looked at; it goes nowhere unless the property manager sends it. By default the events and the log lines — not the diagnostics — are also sent, as they happen, to Utility Profit's activity receiver, which saves validated records in a private PostgreSQL database Utility Profit keeps on Render. The switch Send usage data to Utility Profit in the popup's Advanced section turns that off, unless a company's IT has set it by policy (see Settings a company's IT can set); off means nothing is sent. Only a company's IT can send it somewhere other than Utility Profit's receiver, by that same policy. In Firefox, only the events are sent, without the ids above, and only with the property manager's consent: see The Firefox version.

The Render receiver requires the property manager's current Utility Profit session, sent in an Authorization header, and verifies it with Utility Profit's own API or dashboard. It never stores the session token. For Chrome, Edge and Safari it also stores the verified submitting user id and the source of authentication, for tracing misuse; in Firefox neither user nor company identity is retained in the usage record. The receiver has a separate operator credential for querying records. Records are retained until Utility Profit deletes them; there is no automatic expiry. The existing Google Sheet remains historical data and receives older versions until that receiver is retired.

While signed in, up to 200 unsent records are queued in the browser's extension storage, bound to that sign-in and destination. They are retried on later activity and browser startup; a different user is not used to send them. Opting out clears this forwarding queue. Events collected while signed out remain in local diagnostics and are not sent to the Render receiver.

What it stores

On the property manager's own computer, in the browser's extension storage:

In the browser's memory only, never written to disk and cleared when the browser closes:

The Utility Profit tenant list itself is held only in the extension's working memory and is never written to storage.

Settings a company's IT can set

Chrome, Edge and Firefox only; the Safari version reads no settings from IT. A company that installs the extension on its computers through its browser's enterprise policy can decide five settings for everyone: the extension on or off, sending usage activity on or off, the move-out card on or off, the address usage activity is sent to, and the address of the link-sharing service. A value set this way comes from the browser's managed storage and takes precedence over the property manager's own choice; it is never written into the property manager's own settings, so it ends when the policy does. Where the popup has a control for one of them, that control is greyed out and says it is set by the organization. If the policy turns the move-out card off on a computer that had it on, the extension removes what the card kept and stops every request to the tracker, as when the property manager turns it off. A policy the browser fails to read is treated as no answer: until a read succeeds the property manager's own settings apply, nothing is removed, and the extension asks again. In Firefox, a changed enterprise policy applies at the next Firefox start, and a policy file Firefox cannot parse reads as no policy (see The Firefox version).

What the extension never does

Cookies

The extension reads the Utility Profit session cookies for api.utilityprofit.com and sunroomrentals.com: the Utility Profit API's session cookie, so that a property manager whose browser already holds a Utility Profit API session is not asked for a password; and the dashboard's own session cookie, to confirm that both belong to the same person, to sign the property manager in to the extension when they are signed in to the dashboard (since 0.9.22), to tell one person's dashboard session from the next, and to read the company's tenant list and records from the dashboard. It sends the dashboard's cookie back to the dashboard's own server and nowhere else. The browser tells it when a cookie changes on the sites it has access to; it acts on one notice only — the dashboard's session cookie being set — by building the tenant list, and keeps nothing from the others (Safari's notices do not say which cookie changed: see The Safari version). When the browser starts, and when the extension is installed or updated, it looks for that same cookie and, if it is there, builds the tenant list then. While it reads the list, it looks for the cookie again before each page it asks for, and stops once the cookie has gone. It reads no other cookie, and outside Firefox it holds no permission for AppFolio's, Rent Manager's or Buildium's (see The Firefox version). The extension makes no request to AppFolio of its own, and never sees AppFolio's session cookie. Its requests to Amazon S3 and to the activity receiver carry no cookies at all. With the move-out card on, its requests to the move-out tracker carry the tracker's own session cookie, which the browser attaches; the extension does not read it.

Retention and deletion

Removing the extension from Chrome, Edge or Firefox deletes everything it stored on the computer, including the session token. To end the extension's session without removing it: signed in through the popup, use Sign out there. Otherwise the popup has no Sign out, and the extension uses a session only while the browser holds it: signing out of the dashboard stops it using the dashboard's session, and an API session it found in the browser is dropped within five minutes of the browser dropping it. Sign out in the popup ends only the popup's sign-in, so a property manager who is also signed in to the dashboard stays signed in to the extension through it. Turning the move-out card off deletes what the card kept (the company's property list and the pages linked by hand) and stops every request to the tracker; the tracker sign-in itself belongs to the browser and the tracker, not to the extension.

Removing the extension does not recall what was already sent: links held by the link service (unlinking a tenant while signed in with an API session removes its link for everyone at the company; see Links shared with colleagues), activity lines at Utility Profit's receiver, and values saved to Utility Profit, its move-out tracker or AppFolio. To ask for links or activity lines to be deleted, write to the address below. Records held in the Utility Profit product itself are covered by Utility Profit's main privacy policy, not this one.

Contact

accountmanager@utilityprofit.com

Not affiliated with AppFolio, Rent Manager or Buildium

Utility Profit Connect is built by B&Z Homes, Inc. It is not affiliated with, endorsed by, or sponsored by AppFolio, Inc., or by the makers of Rent Manager or Buildium. "AppFolio", "Rent Manager" and "Buildium" are used only to describe the software the extension works alongside.