Legal
How we handle resident, visitor and website data.
What we collect, what we never do, and who it is shared with — covering the platform and our public website, and saying clearly where the two differ.
Privacy Policy
Effective date: October 1, 2026
Maximum.Community is operated by CMJPEJ, LLC. We provide visitor management and security software to residential communities and the security companies that serve them.
Your community — its board, its property manager, or its security provider — decides how the service is used and who sees what. This policy covers both the platform itself and our public website at maximum.community, and says clearly where the two differ.
What we collect
- Your account: name, email, phone number and unit, given either by you or by your community when your account is created.
- Visitors you invite: the name, phone number and vehicle details you enter, and the passes you create for them.
- Gate activity: pass scans and check-ins, with the time, the entrance, and who or what processed them. A guard device may attach approximate location to a scan for the community’s records. Location never decides whether someone gets in.
- License plates, at communities that use camera-based entry.
- What you send us: messages to your community office, work orders, and incident reports.
- Notification delivery: a push token and your device model, so alerts you asked for can reach your phone.
- Sign-in with Google or Apple, if you choose it: we receive an account identifier and email address from that provider to match you to the account your community created. We receive nothing else and never post or share anything back.
What we do not do
We do not sell or rent personal information. We do not run advertising networks inside the apps or the platform, we never use resident or visitor information to advertise anything, and nothing we use follows you to other websites. We do count visits to our public website, which is described under Our public website below.
Our public website
This part applies to maximum.community, the pages describing our services.
- We count visits with Clicky, a third-party web-analytics service. When you open a page, your browser sends the visit to Clicky and it records it for us. This is a change from our previous approach, where the counting software ran on a server we own; what Clicky collects and how long it keeps it is set out in Clicky’s own privacy policy, which applies alongside ours.
- A visit records the pages you open and when, the site or search that sent you, links you follow away from the site and files you download from it, your browser, device and screen size, your language, your IP address, and the approximate location — country, and often region and city — worked out from that address. A cookie set by this site lets us tell a returning reader from a new one.
- We use this only to understand how the site is used. We do not sell it and we do not use it to advertise to you. Because Clicky records it for us, it is held by Clicky under their terms as well as ours; we do not add it to the resident, guard or visitor records the rest of this policy describes.
- If you send us an enquiry, we get the name, community, state, email and phone number you typed, and we use them to reply and to follow up about our services. A form submission does not put you on a marketing list — we ask separately for that.
None of this touches any community’s records. Reading these pages does not identify you as a resident of anywhere, and we make no attempt to connect website visits to resident accounts.
If you are in the EU, the EEA or the UK, we ask first. Nothing is loaded and nothing is recorded until you accept, accepting and declining are one click each, and closing the notice without answering is not an answer, so nothing is counted and you will be asked again next time. If you decline, the site behaves exactly as it does for everyone else; nothing on it depends on being counted.
Your choice about being counted
Anyone can change this at any time, wherever they are and whatever they chose before. The choice is stored in this browser, so it applies to the browser you make it in.
You can also clear this site’s stored data in your browser, which erases the choice entirely and makes us ask again, or write to [email protected].
Analytics inside the apps
The mobile resident and guard apps do not count which screens you use. Our web platform at app.maximum.community counts page visits with Clicky, the same third-party service used on this website, and the limit we set ourselves holds: counting, never content. Pages that carry something private in their address — a resident or incident id, or an access token in a pass, guest-list or entry-panel link — are stripped of it before the visit is counted, so a message, an incident report, a plate read, a visitor record or an access credential is never sent to an analytics system.
That is a statement about analytics and not about everything the apps do. They still send technical information to the companies that run parts of the service for us, including hosting, push notification delivery, and crash and error reporting when something goes wrong. Those are covered under Who sees your information below.
Text messages
Where your community has switched texting on, we send texts about visitor passes and your community’s notices from the community’s number. Message frequency varies, and message and data rates may apply. Reply STOP to stop, START to start again, or HELP for help. We do not share mobile information with third parties or affiliates for their marketing or promotional purposes, and we never share text-messaging opt-in data or consent with anyone.
Who sees your information
- Your community: entry records are visible to its authorized staff and its contracted security provider, according to their role.
- Companies that run parts of the service for us — hosting, push notifications, email, SMS where a community has switched it on, speech-to-text for intercom calls where a community records them, and crash and error reporting. They handle the data only to provide the service.
- Your community’s access-control provider, where the community uses a phone as a key. When you open a door that way, your location is sent to them to confirm you are actually at the door — a check that stops a copied key being used from somewhere else. Your name and email are sent when your key is first issued.
- Anyone we are legally required to give it to, in response to a valid legal request.
Keeping it safe
Data is encrypted in transit. Sign-in credentials are held in the phone’s own secure storage. Access follows your role, sensitive records are access-logged, and our apps check that requests come from a genuine, unmodified app rather than a script pretending to be one.
How long we keep it
Sign-in history, security logs and access-control records are kept for 24 months and then deleted automatically. We chose that period deliberately, and it is the same one we apply to website visit records.
Gate and visitor activity is kept as long as your community’s record-keeping needs it. We are extending the same automatic 24-month limit to cover these records, and this page will say so plainly once that is in place rather than describing it in advance. Some communities arrange a different period for their own records; yours can tell you which applies to it. If you ask us to remove specific records sooner, we do that with your community by hand.
Deleting something removes it from the live service. Backups are taken regularly and age out on their own schedule, so a deleted record can persist in backup media for a period after it is gone from the service. We do not restore individual records from a backup once they have been deleted. Website visit records are the exception with a fixed limit: 24 months, then deleted automatically, as described above.
Your choices
Notification preferences are in the app. To see, correct or delete your information, contact your community office or write to [email protected]. Where a deletion request touches community security records, we work with your community, which may be required to keep some of them.
Children
The service is not aimed at children under 13. Accounts are issued only by communities, to their residents and staff.
Changes
If we change this policy materially, we will update this page and the date at the top.
Contact
CMJPEJ, LLC — [email protected]