This Privacy Notice explains how Tenantly LLC (West Virginia, USA) ("we", "us", "our"), the operator of Tenantly ("the Service"), collects, stores, protects, shares, and deletes personal data — including the highly sensitive financial documents that landlords and applicants upload. We act as the data controller for landlord (customer) account data, and as a service provider / processor acting on the landlord's instructions when we analyze applicant documents submitted through the Service.
This page is maintained by Tenantly LLC and describes our current practices. It is not a certification, audit report, or independent verification.
1. Exactly What Data We Collect
1.1 Landlord (customer) account data
- Name, email address, and authentication identifier. Passwords are never stored in plaintext — they are stored as salted hashes by our authentication provider.
- Properties, units, leases, tenant records, notes, maintenance tickets, complaints, and messages you create in the Service.
- Subscription and credit balance, plan status, and billing metadata.
1.2 Applicant and tenant data
- Identity and contact — name, email address, phone number where provided.
- Uploaded financial documents — bank statements, pay stubs, offer/employment letters, and other supporting records the applicant or landlord uploads. These documents routinely contain account numbers, transaction histories, balances, employer names, and pay amounts.
- Data extracted from those documents — verified income, deposit cadence, average balances, NSF and overdraft counts, expense patterns, affordability ratio, employer summary, risk score, fraud signals, and report narrative.
- Background-check data — where an applicant expressly consents, identity information they submit (name, date of birth, current address, SSN) is transmitted directly to our consumer-reporting partner. We do not retain raw SSN values after submission.
- Rent payment records — charge amounts, due dates, payment status, payment method type and last four digits, and receipt numbers. We never receive or store full card or bank account numbers.
1.3 Technical data
- IP address, browser and device identifiers, pages viewed, actions taken, timestamps, and error/diagnostic logs.
- Strictly necessary cookies and local storage used to keep you signed in. We do not use third-party advertising cookies or ad-tech trackers.
What we do not collect: we do not ask for, and do not knowingly use, protected characteristics (race, color, national origin, religion, sex, familial status, disability, or any other class protected by federal, state, or local law) in generating reports or scores.
2. Where Your Data Is Stored
- Uploaded documents are stored in a private, non-public object-storage bucket. There is no public URL: every read is authorized server-side and served through short-lived, expiring signed links scoped to a single file.
- Structured data (accounts, reports, leases, payments) is stored in a managed PostgreSQL database operated by our infrastructure provider (Supabase, running on Amazon Web Services) in data centers located in the United States.
- Backups are managed by that provider, encrypted, and retained on the provider's rolling backup schedule.
- Payment data is stored by Stripe, Inc. on Stripe's PCI-DSS Level 1 certified infrastructure — not by us.
3. Encryption and Security Measures
- In transit — all traffic to and from the Service, and between the Service and every subprocessor, is encrypted with TLS 1.2 or higher. The site is served over HTTPS only.
- At rest — database volumes, object storage, and backups are encrypted at rest using AES-256 by our infrastructure provider.
- Access control — every table enforces row-level security. A landlord can only read rows tied to their own account; a tenant can only read rows tied to their own lease. Applicant upload links are single-purpose, token-gated, and expiring.
- Secrets — API keys and signing secrets are held in an encrypted secret store, injected only into server-side code, and never exposed to the browser.
- Least privilege — privileged (RLS-bypassing) database access is limited to specific server functions that verify the caller first, and is never available from client code.
- Monitoring — server errors, authentication events, and payment webhooks are logged and reviewed.
No system is perfectly secure. These are the controls we operate today; they are not a warranty against every possible attack.
4. Who Can Access Your Data
- The landlord who requested the screening — sees the applicant's report and any documents submitted to their account.
- The applicant or tenant — sees their own uploads, lease, balance, payments, and receipts through their own account.
- Authorized Tenantly personnel — a small number of administrators may access production data only where necessary to operate the Service, investigate a support request, or respond to a security incident. Access is credentialed and logged.
- Subprocessors — as listed in Section 5, strictly to perform the function described.
- We do not sell personal data, and we do not share it with data brokers, advertisers, or for cross-context behavioral advertising.
5. Subprocessors, Including AI Providers
- Supabase / Amazon Web Services — database, object storage, and authentication hosting (United States).
- Cloudflare — edge delivery and application hosting.
- Lovable AI Gateway — the routing layer through which our document-analysis and support-assistant requests are sent to the model provider.
- Google (Gemini models) — the AI model provider that currently performs document analysis, report generation, property-fit scoring, and support-assistant replies. Document contents and extracted text are transmitted to this provider solely to produce the output the landlord requested.
- TransUnion Rental Screening Solutions, Inc. (SmartMove) — an FCRA-regulated consumer reporting agency. Where an applicant consents, identity data is transmitted to produce the requested consumer report. Tenantly is not itself a consumer reporting agency.
- Stripe, Inc. — payment processing for subscriptions and for landlord rent collection via Stripe Connect. Stripe is an independent controller for the payment data it collects.
- Transactional email provider — delivery of invites, receipts, and notifications (recipient email address and message contents only).
We may change model or infrastructure providers as the Service evolves. Material changes to this list will be reflected here. If you require advance notice of subprocessor changes or a data processing agreement (DPA), contact us through the Service.
6. AI Processing and Model Training
- Your data is not used to train AI models. We do not train, fine-tune, or otherwise build models on customer or applicant data, and we send analysis requests to our AI provider under terms that exclude the submitted content from provider model training.
- No long-term retention by the model provider.Requests are processed to return a response; the provider does not retain the content for its own product development. Providers may hold content briefly for abuse monitoring under their own terms.
- Human review. Tenantly staff do not routinely read uploaded documents. Access occurs only for the operational reasons in Section 4.
- AI output is informational only. Reports, scores, and recommendations are decision-support information. The landlord makes every leasing decision and is solely responsible for compliance with the Fair Housing Act, the FCRA, and applicable state and local law. See our Terms.
7. Retention Periods
- Uploaded financial documents — retained while the associated application is active, and automatically deleted when the landlord deletes the application. Landlords and applicants can delete individual documents at any time from the dashboard. Documents that are not deleted sooner are removed within 24 months of upload.
- Generated reports and extracted data — retained with the application record and deleted when the application is deleted.
- Background-check identity input — SSN is not retained after submission to the consumer reporting agency. The resulting report is retained by the CRA under its own retention rules.
- Account, lease, and payment records — retained while the account is active and for up to 7 years after closure where required for tax, accounting, and legal-defense purposes.
- Logs and diagnostics — typically retained up to 90 days.
- Backups — deleted data persists in encrypted backups until those backups age out (generally within 30 days).
8. How Deletion Works
- Self-service — delete an individual document, an application, or a lease from your dashboard. Deleting an application removes its documents and generated report.
- Account deletion — request account deletion from your account settings, through the support channels in the Service, or by email at support@betenantly.com.
- Applicant requests — an applicant may request deletion of their documents. Because the landlord controls the screening record, we will forward the request to the landlord and honor it where we are permitted to act.
- Timeline — we action verified deletion requests within 30 days. Copies in encrypted backups are purged as those backups expire.
- Exceptions — we may retain limited records where required by law, to resolve disputes, or to enforce our agreements.
9. Data Breach Procedures
- Detection and triage — suspected incidents are triaged immediately on discovery; we contain the issue, revoke or rotate affected credentials, and preserve logs for investigation.
- Assessment — we determine what data categories and which individuals are affected, and whether the incident is likely to create a risk of harm.
- Notification — where a breach affects personal data we hold, we notify affected landlords without undue delay and within 72 hours of confirming the breach, and we notify regulators and affected individuals where required by applicable state breach-notification law or the GDPR/UK GDPR. Notices describe what happened, the data involved, the steps taken, and recommended actions.
- Landlord obligations — where Tenantly acts as your processor, you remain responsible for any notifications you owe to your applicants or tenants; we will provide the information you reasonably need to make them.
- Remediation — every confirmed incident results in a post-incident review and corrective controls.
- Reporting a vulnerability — if you believe you have found a security issue, contact us through the support channels in the Service, or by email at support@betenantly.com, and describe the issue rather than accessing other users' data.
10. Legal Bases for Processing
- Contract performance — creating accounts, processing uploads, generating reports, collecting rent.
- Consent — applicant consent for background checks and for submitting documents through a screening link.
- Legitimate interests — security, fraud prevention, service reliability, and de-identified product improvement.
- Legal obligation — tax, accounting, and regulatory requirements.
11. Your Rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data, to object to processing, to withdraw consent, and to be free from discrimination for exercising these rights. California residents have rights under the CCPA/CPRA, including the right to know, delete, and correct, and to opt out of sale or sharing — we do not sell or share personal data as those terms are defined. To exercise any right, contact us through the support channels in the Service or by email at support@betenantly.com; we verify requests before acting and respond within the period required by applicable law. You may also complain to your state attorney general or data-protection authority.
12. International Transfers
Personal data is processed in the United States. If you access the Service from outside the U.S., your data will be transferred there. Where required, we rely on appropriate safeguards, such as Standard Contractual Clauses, with our processors.
13. Children
The Service is not intended for children under 18 and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
14. Changes
We may update this Privacy Notice from time to time. Material changes will be communicated through the Service or by email, and the "last updated" date above will change.
15. Contact
Controller: Tenantly LLC (West Virginia, USA). For privacy questions, deletion requests, a DPA, or to report a security concern, contact us through the support channels listed in the Service or by email at support@betenantly.com. See also our Terms and Refund Policy.