Table of Contents
RentFlow360 is property management software. Landlords, property managers, and their teams use it to run buildings; tenants, applicants, owners, and vendors use it to deal with those landlords and managers. Most of the personal information in the platform was entered by a customer about somebody else, and that single fact shapes almost everything below.
| Question | Short answer | Section that covers it |
|---|---|---|
| Who is responsible for my information? | Kips Reality L.L.C, for our own use of it. For information a landlord or property manager entered about you, they are responsible and we act on their instructions. | Our Two Roles: Controller and Processor |
| What do you collect? | Identity and contact details, account and role information, property and lease records, application and screening information, payment and bank details, documents, messages, and technical records of how the Services are used. | Personal Information We Collect |
| Do you collect Social Security numbers? | Yes, where screening, identity verification, or tax reporting requires one. They are encrypted at the field level, with keys held outside the database, before they are stored. | Sensitive Personal Information |
| Do you sell my information? | No. We do not sell or share personal information as California law defines those words, we run no advertising trackers, and we honor the Global Privacy Control signal. | We Do Not Sell or Share Personal Information |
| Who else sees it? | The people the customer has authorized, and the service providers listed on our security page who process data on our behalf. | How We Disclose Personal Information |
| Is my rent payment history sent to a credit bureau? | Not unless you switch it on yourself. With it on, and where the managing organization has the integration configured, completed rent payments are furnished to Experian RentBureau. | Rent Reporting to Consumer Reporting Agencies |
| Does AI read my documents? | Four features send content to an AI provider: listing copy, price suggestions, a fair-housing language check, and utility-bill extraction. Separately, a proof-of-income document can be read by a document-extraction service where a customer enables verification. No decision about a person is made automatically. | Automated Features, Scoring, and AI Assistance |
| How long do you keep it? | For as long as the account relationship lasts, then thirty days after termination so records can be retrieved, then deletion from active systems — except records we are obliged to keep, principally financial and signed ones. | Data Retention |
| What can I ask for? | Access, correction, deletion, a portable copy, and limits on certain uses. Account holders can export and delete from inside the app without asking us at all. | Your Privacy Rights |
| How do I reach a person? | support@rentflow360.com | Contact Us and Privacy Requests |
Two things a summary cannot do. It cannot tell you which of us holds your information — if a landlord entered it, your request usually has to start with them, and the fourth section explains how to tell. And it cannot carry the qualifications, which is where the substance of a privacy policy actually lives. Find the section that covers your situation and read that one properly.
Kips Reality L.L.C ("Kips Reality", "RentFlow360", "we", "us", "our") operates the RentFlow360 property management platform. This Privacy Policy explains what personal information the platform collects, why we hold it, who we give it to, how long it stays, and what you can require of us.
What it covers
This policy applies to the RentFlow360 marketing site, the web application, our application programming interfaces, the public rental application pages, the public and embedded document signing pages, the email and SMS messages the platform sends, and our support channels. Together those are the "Services".
What it does not cover
It does not describe what a landlord, property manager, or employer does with information about you outside RentFlow360. Their own privacy practices are theirs, and this policy neither states nor constrains them.
It does not govern the third parties named throughout this document. Stripe, Plaid, Experian, Checkr, Onfido, Twilio, Resend, Postmark, Cloudinary, Sentry, Vercel, and our AI provider each publish their own privacy notice, and their independent handling of information is governed by those notices rather than this one.
It is also not a contract. Your commercial relationship with us is governed by the Terms of Service. This policy describes conduct, and where the two documents genuinely conflict on a privacy question, this one wins.
Defined terms
"Personal information" means information that identifies, relates to, describes, or can reasonably be linked with an identifiable individual. Some laws call the same thing "personal data"; we use the two interchangeably. "Customer" means the organization or person holding a RentFlow360 subscription. "You" means whoever is reading — a customer, a member of a customer's team, a tenant, an applicant, an owner, a vendor, or a visitor to our site.
Reading it
This document is long because a short one would answer nothing. Each section carries a one-line summary under its heading, the table of contents at the top jumps straight to any section, and the search box filters sections by title. If you came here for one answer, find the section and read only that.
By using the Services you acknowledge that this policy describes how information is handled. Where the law requires consent rather than notice, we ask for consent separately and this policy does not stand in for it.
RentFlow360 is operated by Kips Reality L.L.C, a limited liability company organized in the State of Washington, United States. Kips Reality L.L.C is the entity responsible for the personal information described in this policy and the entity you contract with when you subscribe.
Kips Reality L.L.C, trading as RentFlow360 Washington State, United States Email: support@rentflow360.com
We publish an email address rather than a street address because email is the channel we monitor. If you need a postal address for a formal legal notice, a regulatory filing, or service of process, write to support@rentflow360.com and we will provide it.
Every question, complaint, and rights request described in this policy goes to that same address. There is one queue and no form to complete first. Our mail provider rejects mail sent to an address we have not created, so we publish only addresses that are known to work rather than the tidy-looking aliases a policy usually lists.
What we build
RentFlow360 is a multi-tenant platform for residential property management. It handles properties and units, leases and renewals, rental applications and screening, rent collection and accounting, maintenance and vendor work, utility billing and allocation, documents and electronic signatures, owner reporting, and the messaging that runs between all of those. Six kinds of account use it — system administrators, property managers, tenants, vendors, agents, and owners — and what any one person can see is decided by the role their organization gave them.
What we are not
We are not a bank, an escrow agent, a consumer reporting agency, a debt collector, a real estate brokerage, or an advertising network. We do not take custody of rent. We do not decide who gets a tenancy. We do not sell data, and we have no business model that would reward us for doing so — we are paid by subscription, by the customer, for the software.
Several sections below exist to mark exactly where our responsibility ends and a customer's begins. That line matters more in property management than in most software, because the person the data is about is very often not the person who bought the product.
This is the most consequential section in the policy, because it determines who has to answer your request.
Where we are the controller
We decide the purposes and the means of processing — we are the "controller", and in California terms the "business" — for:
- account and profile information for the people who use the platform: names, email addresses, phone numbers, roles, and authentication data;
- subscription, billing, and plan information for our customers;
- security, authentication, and audit records the platform generates;
- correspondence with our support team;
- technical records of how the Services are used, including server logs and error diagnostics;
- information about visitors to our marketing site and people who ask us for a demonstration or a quote.
For all of that, this policy is the complete description of what happens, and you can bring a request straight to us.
Where we are the processor
For the operating records a customer creates inside their own workspace — tenants, applicants, leases, ledgers, maintenance tickets, documents, messages, screening orders, owner statements — the customer is the controller and we are the "processor", which California law calls a "service provider". They decide what to collect, why, how long to keep it, and who on their team may see it. We process it on their documented instructions and under our contract with them.
In practice that means:
- We do not decide whether you are screened, whether your application succeeds, what rent you are charged, whether a notice is served, whether a deposit is withheld, or whether your rent payment history is furnished to a credit bureau.
- We do not repurpose a customer's operating records. We do not market to their tenants, build a profile of you for our own commercial purposes, sell anything derived from their data, or use it to train models.
- We cannot always act alone. If a property manager entered information about you, correcting or deleting it can cut across their own legal obligations — a landlord has record-keeping duties we are not entitled to override — so the right route is usually to ask them.
How to tell which applies to you
Ask who typed it in. If you created your own account and gave us the information yourself, we are the controller for it. If it exists because a landlord, property manager, or employer put it there, they are the controller and we are acting for them.
Some information is both. Your email address is a login credential we control and a tenant contact detail your property manager controls. Where that is the case, we handle our copy under this policy and pass anything touching their copy to them.
If you write to us anyway
Do. Send it to support@rentflow360.com whatever the answer to the question above. Where we are the processor we will identify the responsible customer, forward your request to them without delay, and tell you that we have. Where we can act directly without cutting across that customer's obligations — unsubscribing you from our own marketing, correcting your login details, closing a duplicate account — we will simply do it rather than route you in a circle.
Property management software holds information about people who never chose it. This section names them, because a policy written only for the buyer leaves everyone else guessing.
| Who | How their information arrives | Who controls it |
|---|---|---|
| Customers and their staff | They create accounts, subscribe, and configure the workspace | We do, for account and billing data |
| Tenants and residents | A property manager adds them, or they accept an invitation and create a login | The customer, mostly; we control their login credentials |
| Rental applicants | They complete a public application form, or a manager enters it for them | The customer who received the application |
| Guarantors, co-signers, occupants, and emergency contacts | An applicant or tenant names them on a form | The customer who received the form |
| Property owners | A manager records them for accounting, or they are given an owner login | The customer, for the accounting record; we control the login |
| Vendors and contractors | A manager adds them to run work orders and pay invoices | The customer |
| Agents and brokers | Invited into an organization by a manager | The customer |
| Website visitors and prospects | They browse the marketing site or ask for a demonstration | We do |
| Signers of documents | They receive a signing link by email and complete it | The customer who sent the envelope, for the document; we control the signing audit trail |
Two of those deserve a note.
People who never had an account. A guarantor named on an application, an occupant listed on a lease, or an emergency contact has often never heard of RentFlow360. Their information is in the platform because somebody else supplied it. The rights in this policy apply to them, and a request from someone in that position is a valid request even though we have no account to match it against — we will verify identity through the customer who holds the record.
Signers. A signing link carries its own audit trail: who opened it, from what network address, when, and what they agreed to. That trail exists to make a signature provable, so it is deliberately more detailed than ordinary usage logging, and it is retained with the document rather than expiring with a session.
Employment and job applications
If you apply for a job at Kips Reality L.L.C, we handle your application under a separate recruitment notice provided at the point of application, not under this policy.
What we collect depends entirely on which parts of the platform you or your organization use. A tenant who pays rent by card and never files a maintenance ticket leaves a much smaller record than an applicant who completes screening. The table below is the full set; almost nobody generates all of it.
| Category | What it includes | Where it comes from | Can you decline? |
|---|---|---|---|
| Identity | Legal name, preferred name, date of birth where a service requires it, government identification details where identity verification is enabled | You, or the customer who entered it | Not if you want the service that requires it |
| Contact | Email address, telephone number, mailing address, unit and property address | You, or the customer | No — the platform cannot notify you otherwise |
| Account and access | Username, hashed password, role, organization membership, two-factor settings and encrypted authenticator secret, session and token version, notification preferences | Generated when you register or are invited | No, while you hold an account |
| Property and tenancy | Property and unit records, lease terms, rent and deposit amounts, occupancy dates, renewal history, move-in and move-out records, inspection findings and photographs | The customer | Not by us; ask the customer |
| Application and screening | Employment and income details, rental history, references, declared pets and vehicles, uploaded supporting documents, screening authorization, screening outcomes | You, on an application form | Yes — you can decline to apply |
| Financial | Bank account and routing numbers for payees, payment amounts and dates, payment method type and processor tokens, invoice and ledger entries, taxpayer identification numbers where tax reporting requires them | You, the customer, or a payment provider | Only by not transacting |
| Documents | Leases, notices, applications, addenda, identification documents, maintenance photographs, inspection reports, signed records and their audit trails | You or the customer, by upload or by generating them in the platform | Not for documents a tenancy requires |
| Communications | In-platform messages, email and SMS we send you and delivery results, support tickets and their contents, feedback | You and the customer | Transactional messages, no; marketing, yes |
| Maintenance | Requests, descriptions, photographs, access instructions and entry notes, vendor assignments, work orders, costs | You or the customer | No, if you want the repair |
| Utility | Meter readings, consumption data, provider bills and the amounts allocated to a unit, connected utility account identifiers | The customer, uploaded bills, or a connected utility provider | Ask the customer |
| Technical | Described in full in the next section but one | Generated automatically | Not while using the Services |
| Inferences | Tenant retention and risk scores derived from payment, maintenance, and lease history | Calculated by the platform | Not currently |
Information you are asked for but do not have to give
Some fields are genuinely optional: an avatar, a preferred name, a secondary phone number, notes on a maintenance ticket, marketing preferences. Leaving them blank costs you nothing.
Information we ask you not to give us
The platform has no field for health conditions, disability, race, ethnicity, religion, union membership, sexual orientation, immigration status, biometric identifiers, or precise geolocation, and we do not ask for any of them. Information of that kind can still reach us if somebody types it into a free-text box or uploads a document containing it — a doctor's note attached to an accommodation request is the common example. Please do not supply it unless it is genuinely necessary for the request you are making, and if you are a customer, please do not solicit it.
Information we never collect
We do not collect full payment card numbers, card security codes, or online banking credentials. Those are captured by Stripe and Plaid in their own interfaces and never traverse our servers. We hold tokens that let us request a payment; we do not hold the instrument.
Some of what the platform holds is treated as "sensitive personal information" under California law and as a regulated identifier under several federal and state statutes. We collect four categories of it, each tied to a function that cannot be performed without it.
| Category | Why it is collected | When |
|---|---|---|
| Social Security numbers and other taxpayer identification numbers | Tenant screening requires one to match a credit file; IRS information returns, including Form 1099, require one for owners, vendors, and payees | Only when screening is ordered or a tax filing obligation arises |
| Government-issued identification numbers and identity documents | Identity verification on rental applications, where a customer has enabled it | Only where that feature is switched on |
| Financial account information, including bank routing and account numbers | Rent collection by ACH, owner distributions, vendor payments, and utility payee records | Only for the accounts a user chooses to add |
| Account credentials and security information, including authenticator secrets | Authentication and two-factor authentication | While you hold an account |
How they are protected
Social Security numbers, taxpayer identification numbers, and bank routing and account numbers are encrypted at the field level with AES-256-GCM before they are written to the database, using keys held outside the database and outside our codebase. Passwords are stored only as salted hashes and are never recoverable, by us or by anyone else. Two-factor authenticator secrets are encrypted with a separate key from the one that protects financial fields.
How they are limited
We use sensitive personal information only for the function that required it, and for the security, fraud-prevention, and record-keeping purposes that necessarily attach to it. We do not use it to infer characteristics about you, we do not use it for marketing, we do not disclose it to advertising networks or data brokers, and we do not sell it.
Where a screening report or an identity check is ordered, the identifier is transmitted to the consumer reporting agency or verification provider that performs it and is not retained by us beyond what the record of the transaction requires.
Your right to limit
California residents may direct a business to limit its use of sensitive personal information to what is necessary to provide the service. Our use is already limited to that, so the right changes nothing about what we do — but the control exists in the app under Account, then Privacy, and exercising it is recorded. The California section below explains the right in full.
Using the Services generates technical records. Most of them exist for security and for diagnosing failures, and they are the reason we can tell an outage from an attack.
Request and device data. Network address, browser type and version, operating system, device type, language, and time zone. Approximate location — city or region at best — can be inferred from a network address; we do not collect precise or device-level location, and the platform asks for no location permission.
Usage data. Pages and screens viewed, features used, timestamps of access, referring page, and the outcome of actions you take.
Authentication and security events. Sign-in attempts and their result, failed-password counts and lockouts, two-factor challenges, token refreshes and revocations, password and email changes, and role changes. Repeated failed sign-ins are rate-limited by network address, which requires holding that address briefly.
Audit records. Changes to leases, properties, journal entries, listings, approvals, and signing envelopes are recorded with the account that made them and the time. Audit history is visible inside the app and can be exported, because a record nobody can inspect is not much of a control.
Application errors. When something fails, a diagnostic report is sent to our error monitoring provider. Personal data is redacted before the report leaves our process; what remains is the stack trace and the technical shape of the request.
Signing audit trails. A signing envelope records who opened it, when, from what network address, what they saw, and what they agreed to, along with a cryptographic hash of the finished document. That trail is what makes a signature evidentially useful, and it is retained with the document.
What we do not do
We run no advertising trackers, no cross-site tracking, no fingerprinting, no session replay, and no third-party marketing pixels — none of these appear anywhere in the platform or on the marketing site. Analytics on our public pages is cookieless, is not tied to an identity, and switches itself off entirely when your browser sends a Global Privacy Control or Do Not Track signal.
We use cookies for one purpose: keeping you signed in securely. There are no advertising cookies, no analytics cookies, and no third-party tracking cookies anywhere in the platform or on the marketing site.
| Name | Purpose | Lifetime | Type |
|---|---|---|---|
| token | Your signed-in session. Sent with each request so the server knows who you are | 15 minutes | Strictly necessary |
| refreshToken | Obtains a new session token without making you sign in again. It lasts seven days while "Keep me signed in" is on, and expires when you close the browser if you turn that off | 7 days, or the browser session | Strictly necessary |
| SSO flow cookie | Holds the state of a single sign-on exchange while your identity provider authenticates you, and guards against request forgery during it | Minutes, then cleared | Strictly necessary |
All three are HTTP-only, meaning no script on the page can read them, and are marked Secure on any encrypted connection. Signing out clears them and revokes the underlying session on the server, so the tokens are dead even if a copy survives somewhere.
Local storage
The application uses your browser's local storage to remember interface preferences and to cache lists you have already loaded, so a page you return to renders immediately rather than blank. It stays on your device, is not transmitted to us, and clearing your browser data removes it.
Analytics
Our public marketing pages use Vercel Analytics for page views, web vitals, and a small number of button-level events that tell us which parts of the site are used. It sets no cookies, does not follow you between sites, and is not linked to a person or an account. If your browser sends a Global Privacy Control or Do Not Track signal, the analytics code does not arm at all — nothing is recorded, rather than recorded and discarded.
There is no analytics inside the signed-in application.
Why there is no cookie banner
A consent banner exists to obtain permission for cookies that are not necessary to run the service. We do not set any, so there would be nothing for you to consent to and a banner would be theatre. If that ever changes, the banner appears before the cookie does.
Controlling cookies yourself
Your browser can block or delete cookies. Blocking the three above will stop you being able to sign in, because they are the mechanism by which signing in works.
Information reaches us from third parties when you, or the organization managing your tenancy, connects one of them. What we receive depends on which service it is, and in every case is narrower than what the provider itself holds.
| Source | What comes back to us |
|---|---|
| Stripe | Payment status, amount, currency, date, method type, the last four digits and brand of a card, payout and refund records, dispute notices, and processor identifiers |
| Plaid | Account and institution names, account type, masked account numbers, balances where a check is run, ownership details for verification, payroll or bank-derived income data where income verification is used, and an access token. Your bank login is entered on Plaid and never reaches us |
| Amazon Textract | The figures read off a proof-of-income document you uploaded, returned as structured fields |
| Checkr | The status and outcome of a background or credit screening you authorized, and the report where the ordering customer is entitled to receive it through the platform |
| Onfido | The result of an identity document check, and the check's status. Document images are captured by Onfido |
| Experian | Confirmation of whether a furnished rent payment record was accepted |
| Resend, Postmark, and our SMTP provider | Delivery, bounce, and complaint results for the emails the platform sends |
| Twilio | Delivery status for SMS messages, and inbound replies such as a STOP keyword |
| Utility providers, through UtilityAPI or Green Button | Meter and consumption data, billing periods, and amounts for accounts a customer has connected |
| Identity providers, on single sign-on | The identity assertion your employer's provider sends: name, email address, and the attributes they choose to release |
| Email inbound processing | Utility bills forwarded to a dedicated address by a customer, including whatever the bill itself contains |
We do not buy personal information from data brokers, we do not enrich or append profiles from commercial datasets, and we do not receive information from advertising networks.
Information other users give us about you
The largest single source of information about a tenant, an applicant, a guarantor, or an emergency contact is another person: the property manager who entered it, or the applicant who named you. Customers are responsible under our Terms for having the right to supply it and for giving you any notice your jurisdiction requires. We are the recipient of that information, not its author, which is why a correction request often has to go back to whoever wrote it.
| Purpose | What this covers |
|---|---|
| Running the Services | Creating and authenticating accounts; managing properties, units, leases, and renewals; processing applications; collecting and reconciling rent; posting to the ledger; producing invoices, statements, and reports; handling maintenance and vendor work; allocating utility costs; generating, delivering, and storing documents and signatures |
| Communicating | Sending notices, reminders, receipts, alerts, and responses to your requests, in the channels your organization and your preferences allow |
| Supporting you | Answering questions, investigating faults, and reproducing problems you report |
| Billing our customers | Managing subscriptions, invoices, plan changes, dunning, and tax on our own fees |
| Securing the platform | Authenticating users, rate-limiting and locking out repeated failures, detecting fraud and abuse, investigating incidents, and maintaining audit records |
| Improving the product | Diagnosing errors, measuring performance, understanding which features are used, and testing changes — using aggregated or technical data wherever it will answer the question |
| Complying with law | Meeting tax, accounting, consumer reporting, landlord-tenant, and record-keeping obligations, and responding to lawful requests |
| Establishing and defending rights | Enforcing our agreements, resolving disputes, and preserving evidence where a claim is threatened or foreseeable |
What we do not do with it
We do not sell it. We do not share it for cross-context behavioral advertising. We do not disclose it to data brokers. We do not use one customer's operating data to market to another, and we do not market to a customer's tenants on our own account. We do not use customer content to train artificial intelligence models, and our AI provider does not use content sent through its interface to train its models either.
Aggregated and de-identified use
We produce aggregated and de-identified statistics — occupancy patterns, payment timeliness distributions, feature usage — and use them for product development, capacity planning, and benchmarking. Information in that form does not identify anyone, we maintain it in that form, and we do not attempt to re-identify it except where the law requires us to test whether de-identification held.
The platform includes features that generate text, suggest numbers, or score records. This section says exactly what they are, because vague reassurance on this subject is worth nothing.
Features that send content to an AI provider
Four features call an external artificial intelligence provider. Each is initiated by a user, and each is off unless the organization has the feature configured.
| Feature | What is sent | What comes back |
|---|---|---|
| Listing description | The property and unit attributes you have entered | Draft marketing copy for you to edit or discard |
| Price suggestion | Property attributes and comparable listing data from your own workspace | A suggested rent range |
| Fair-housing language check | The listing text you wrote | Flags on wording that may breach fair housing rules |
| Utility bill extraction | The bill document you uploaded, which typically contains the service address, account number, and amounts | Structured figures for the billing period, for you to confirm |
Under our provider's commercial terms, content sent through its interface is not used to train its models. We do not send tenant records, screening results, identification documents, or payment details to a generative AI provider, and no such call is made without a user action.
Document data extraction
Separately from the four features above, where a customer has enabled applicant verification, an uploaded proof-of-income document — typically a pay stub — is sent to Amazon Textract, which reads the figures printed on it and returns them as fields. It is a document-reading service rather than a generative one: it extracts what is on the page and produces no opinion about the applicant. Where a customer has enabled income verification through Plaid instead, payroll or bank-derived income data is retrieved from the source you authorize. Both are described in the rental applications section.
Scoring calculated inside the platform
The platform computes a tenant retention score for an active lease from payment history, maintenance activity, and the state of the lease itself. It produces component scores, a composite, and a low, medium, or high banding, and it is shown to the managing organization as an operational prompt about which residents may be at risk of leaving.
It is calculated by arithmetic on that organization's own records. No external provider is involved, no data from outside the workspace is used, and it plays no part in tenant screening, in an application decision, or in anything a prospective resident is subject to.
What is never automated
No decision that produces a legal or similarly significant effect on a person is made by the platform without a human being making it. RentFlow360 does not decide whether an application is accepted or refused, whether a lease is renewed, whether a deposit is withheld, whether a notice is served, or whether anyone is reported to a bureau. Every one of those is a decision by the landlord or property manager, and the Terms of Service place that responsibility on them explicitly.
We also do not claim these features are accurate. A generated description, a suggested price, an extracted figure, and a risk band are all drafts requiring human judgment, and the person acting on one is responsible for checking it. Nothing in this policy authorizes using an automated output to make a housing decision that discriminates against a protected class — the fair housing section below is not decorative.
Your rights over automated processing
If a decision affecting you was influenced by any of the above, you may ask us what the platform produced and how it was derived. Where the decision was the customer's, we will pass the request to them and tell you we have. Residents of jurisdictions with a right to opt out of profiling for significant decisions may exercise it under the rights sections below.
A rental application is the single richest collection of personal information the platform handles, and it is collected by the landlord or property manager, not by us.
What an application collects
Identity and contact details, date of birth, current and previous addresses with dates, employment and income details, references, declared pets, vehicles, and occupants, guarantor or co-signer details, and any documents the manager asks you to upload — pay stubs, bank statements, or identification. Where screening is ordered, it also collects your Social Security number and your written authorization to obtain a report.
Uploaded application documents are scanned for malware where the customer has that scanning configured. Where the scanner cannot be reached, an upload is refused rather than accepted unscanned, unless the customer has deliberately chosen the opposite.
Verifying what an application says
Where a customer has enabled verification, three optional checks may run against what you submitted, each one only if they have configured it:
- Income and employment, through Plaid, using payroll or bank-derived income data from the account you authorize. You choose whether to connect it.
- Documents, through Amazon Textract, which reads the figures off a pay stub or proof-of-income document you uploaded and returns them as fields for the manager to see alongside the file.
- Identity, through Onfido, which checks an identity document you supply.
None of these three decides anything. They produce evidence that a human being then weighs.
Who runs the screening
Screening reports are produced by third-party consumer reporting agencies, currently Checkr for background and credit screening and Onfido for identity verification, and only where the customer has enabled and configured them. Your identifiers are transmitted to that agency to produce the report. We are a conduit for the order and the result.
RentFlow360 is not a consumer reporting agency. We do not compile or evaluate consumer information for the purpose of furnishing consumer reports, we do not score applicants, and we do not recommend or influence any tenancy decision.
Who is responsible for what
The customer ordering the report is the end user of it under the Fair Credit Reporting Act. They are responsible for having a permissible purpose, for obtaining your authorization before ordering, for giving you the disclosures the law requires before and after, and for delivering an adverse action notice if they refuse, condition, or increase the cost of a tenancy because of what a report said.
Two of those notices are generated by the platform and carry the identity and contact details of the consumer reporting agency, because both federal law and Washington law require the agency to be named. Under RCW 59.18.257, a Washington landlord must tell you before you apply what screening they conduct, which agency they use, what criteria they apply, and what the fee covers. Under section 615(a) of the Fair Credit Reporting Act, an adverse action notice must name the agency, state that it did not make the decision, and tell you of your right to a free copy of the report and to dispute what it contains.
Disputing what a report says
If a report is wrong, the agency that produced it is who must correct it, and the notice you received names them. We cannot amend a consumer report and neither can your landlord. If the error is in what was submitted rather than in the report — a misspelled name, a wrong date of birth — tell the landlord or manager who submitted it, and tell us at support@rentflow360.com if they do not act.
If you do not get the tenancy
Your application information stays in the customer's workspace, subject to their retention decisions and the record-keeping obligations that fair housing law imposes on them. You may ask them to delete it; where the law entitles you to deletion and they instruct us to carry it out, we do.
Positive rent reporting can help a resident build a credit history from payments they were already making. It is also a disclosure to a consumer reporting agency about you, so it is set out here in full rather than folded into a list.
When it happens
Two things must both be true before anything is furnished about you. The organization managing your tenancy must have configured the Experian integration with its own credentials, and you must have turned reporting on for yourself. It is off unless you switch it on, under Account, then Privacy, and the date you agreed is recorded with the setting.
Where either is missing — which is the default state — nothing is transmitted, and the payment record is marked as skipped inside the platform.
What is transmitted
When a rent invoice is settled in full, the following is sent to Experian RentBureau:
- your first and last name;
- your email address;
- the property address, city, state, and postal code;
- the amount paid and the currency;
- the date the payment was due and the date it was paid;
- whether the payment was on time or late, and if late, by how many days.
Nothing else goes with it. Your Social Security number, bank details, application file, and correspondence are not part of the furnished record, and partial payments and unconfirmed self-reported payments are excluded.
What it means for you
Experian is a consumer reporting agency. A furnished rent record can appear in a consumer report about you and be seen by anyone with a permissible purpose to pull one. A record of late payment can affect your credit file in the same way any other furnished delinquency can.
Your rights over a furnished record
Under the Fair Credit Reporting Act you may dispute the accuracy of a furnished record with Experian directly, and with the furnisher. To dispute what was furnished about your tenancy, write to support@rentflow360.com with the property address and the payment dates in question. We will check the record against the underlying payment, correct it if it is wrong, and tell you what we found.
Turning it off
To stop it, switch it off in Account, then Privacy. Nothing further is furnished from that point. Turning it off does not withdraw records already furnished — those are held by Experian under its own rules, and correcting or disputing one goes through the route above.
If you cannot reach the setting, or you believe something was furnished while it was off, write to support@rentflow360.com with the property address and we will check the record against the underlying payment and tell you what we find.
Payments made through the platform — rent, deposits, fees, and our own subscription charges — are processed by Stripe. When you enter a card or bank account, the details are collected by Stripe in a field they control and are transmitted to them. We do not receive or store full card numbers, security codes, or online banking credentials.
What we hold
A processor token that lets us request a payment against a method you have authorized, the method's type, the brand and last four digits where it is a card, the amount, currency, date, and status of each transaction, refunds, chargebacks and disputes, payout records, and the ledger entries that follow from all of it. Payment metadata of that kind is encrypted at the field level using keys held outside the database.
Where a bank account is added manually rather than through a provider, the routing and account numbers are encrypted at the field level before storage with the same protection applied to Social Security numbers.
What Stripe does with it
Stripe is a payment processor and a controller in its own right for the transaction data it holds. It uses that data to process the payment, to meet its own anti-money-laundering, sanctions, and fraud obligations, and as described in its privacy policy. Its identity verification of a customer receiving funds is its process, not ours.
Money
We do not hold, invest, or take custody of funds. Money moves from the payer to the account the recipient connected, on the processor's schedule and subject to the processor's terms, including any holds or reversals it applies. RentFlow360 is not a bank or an escrow agent.
Fraud checks
Payments are subject to the processor's fraud screening, and the platform enforces its own limits, including a maximum single-transaction amount. A payment can be declined or held on those grounds. Where that happens, the reason available to us is passed on to the person who attempted it.
The platform can verify and use a bank account through Plaid, which specializes in connecting financial accounts. This happens only when you choose to connect one.
What you enter, and where
Your online banking credentials are entered inside Plaid's own interface. They are never transmitted to RentFlow360, never stored by us, and cannot be recovered from anything we hold.
What we receive
An access token that authorizes us to make specific requests about the account you connected, together with account and institution names, account type, a masked account number, and, where verification requires it, balance and ownership details. We use them to confirm the account is real and yours, to set up ACH payments, and to check that funds are available before a debit where the customer has enabled that check.
Where a rental application uses income verification, and only if you authorize it at that point, Plaid also returns payroll or bank-derived income information — employer, income amounts, and pay frequency — which is used to verify what the application states and for nothing else.
What we do not do with it
We do not read your transaction history for any purpose beyond the verification and payment functions above, we do not analyze your spending, we do not sell or share financial data, and we do not use it for marketing or credit decisions.
Disconnecting
You can remove a connected account in the app at any time. When you do, and whenever you exercise the deletion right described later in this policy, the platform archives the payment method, stops any automatic payment relying on it, and revokes the underlying authorization with Plaid so that our access to the account ends rather than merely being hidden from view. Records of payments already made remain, because they are accounting records.
Plaid's own role
Plaid is an independent controller of the data it collects from your financial institution and publishes its own end-user privacy policy, which sets out what it retains and the rights you have directly against it. Read it before connecting an account; it governs the part of this flow that we do not see.
The platform includes electronic signing for leases, addenda, notices, and other documents. By signing, you and the other participants consent to transact electronically, and electronic signatures and records satisfy the requirements of the federal ESIGN Act and state law under UETA.
What the signing record contains
For each participant: name, email address, the signature and any initials applied, the date and time of each action, the network address it came from, the sequence of documents shown, consent to transact electronically, and any authentication step completed before access was granted. For the document: its content, its version history, and a cryptographic hash of the final signed file.
That record is more detailed than ordinary usage logging, and deliberately so. Its purpose is to make a signature provable years later, and a record that omits how, when, and by whom a document was signed cannot do that.
Access to signed documents
A signing link is a limited, time-bound credential sent to a named recipient. Anyone holding the link can open the envelope it addresses, so links should not be forwarded. Signed documents and their audit trails are available to the organization that sent the envelope and to the participants, and can be exported together.
Notarization
Where an organization enables the optional notary feature, only a cryptographic hash of the finished document is published to an external ledger, along with the time it was recorded. A hash is a fingerprint; it proves that a document you already hold has not been altered, and it cannot be reversed to reveal the document, its contents, or the identities of the people who signed it. No document content and no personal information is published. The feature is disabled by default.
Retention
Signed documents and their audit trails are retained with the tenancy record they belong to, for as long as the customer requires them and for as long as the law obliges either of us to keep them. Because a signature record exists to be evidence, it survives the deletion of the account that created it — the retention and deletion sections below explain what that means in practice.
What we do not verify
We do not verify that a signer is who they say they are, and we do not review a document for legal sufficiency. Confirming identity, confirming authority to sign, and confirming that a document does what it should are the sender's responsibilities under our Terms.
Where a property allocates utility costs to units, the platform holds the data that allocation is calculated from.
Where it comes from
Three routes. A manager uploads a provider bill, or forwards it to a dedicated inbound email address the organization provisions. A manager enters meter readings. Or the organization connects a utility account through UtilityAPI or Green Button Connect, both of which use the provider's own authorization flow, so the utility account credentials are entered at the provider and not with us.
What it contains
Service addresses, utility account identifiers, billing periods, consumption figures, bill amounts, and the amounts allocated to each unit or resident. Where a bill is uploaded as a document, everything printed on that bill comes with it, and where the extraction feature is used, the document is sent to our AI provider as described in the automated features section.
Who sees it
Consumption and allocation data is visible to the managing organization, and each resident sees the amounts allocated to their own unit. Utility usage can reveal patterns of occupancy, which is a reason we neither sell nor analyze it beyond producing the allocation the tenancy requires.
Disconnecting
A customer can disconnect a utility integration at any time, which ends future collection. Bills, readings, and allocations already produced remain, because they are the support for charges already made.
A maintenance request typically includes a description of the problem, photographs, the unit and property, your contact details, when you are available, and how a technician should get in — a lockbox code, a note that a key is with a neighbor, a warning about a dog.
Who it is shared with
The managing organization sees the request. Where a vendor or contractor is assigned, they see what they need to do the work: the address, the fault, the photographs, the access instructions, and a contact number. They do not see your lease, your payment history, your application, or anything about other residents.
Photographs and free text
Photographs of an interior show what is in it. A description written in a hurry can mention a household member, a health circumstance, or a reason you need the repair urgently. That content is stored as written and is visible to the people above, so include what the repair needs and leave out what it does not.
Access records
Entry notes, scheduled visits, completion records, costs, and invoices are retained with the property record. Inspections carry the same kind of content: findings, photographs, dates, and the identity of whoever performed them.
Vendors as recipients
A vendor engaged by a customer is that customer's contractor, not ours. What the vendor does with a work order after receiving it is governed by their arrangement with the organization that hired them. Vendors who hold RentFlow360 accounts are bound by our Terms, which forbid using platform data for anything other than the work.
Transactional messages
The platform sends messages that are part of the service: rent reminders and receipts, invoice and statement notices, lease and renewal notices, maintenance updates, signing requests, application status, security alerts such as a new sign-in or a password change, and two-factor codes. These are how a tenancy is administered, and while you can often choose the channel, you cannot switch them off and keep the account — a rent reminder that never arrives is a problem for both of us.
Email is delivered through Resend, with Postmark as a second route if the first fails, or through our own SMTP provider. Delivery, bounce, and complaint results come back to us so we can tell whether a notice arrived.
SMS
Where a customer has enabled SMS and you have provided a mobile number, the platform sends notifications by text through Twilio. Message and data rates from your carrier may apply. Reply STOP to any message to stop them; the opt-out is recorded and honored. Reply HELP for assistance. Your number is used for notifications and account security, is not sold, and is not used for marketing by us.
In-app notices
Notifications inside the application follow the preferences on your profile, and are the channel of last resort when email and SMS are both unavailable.
Our marketing
Marketing email comes only from us to customers and to people who asked to hear from us, never from us to a customer's tenants. Every marketing message carries an unsubscribe link that works, and unsubscribing has no effect on the transactional messages above.
Recorded correspondence
Support conversations are retained so that the next person you speak to knows what the last one said. If you send us a document to illustrate a problem, it is retained with that conversation, so please redact anything the question does not require.
If you visit our marketing site, request a demonstration, start a trial, book a setup call, or subscribe to updates, we collect what you tell us: your name, work email address, phone number if you give one, the organization you represent, the size of your portfolio if you say, and the content of your enquiry. Alongside it we hold the technical records described earlier and the cookieless analytics described in the cookies section.
We use it to answer you, to run the trial, to set up the account, and to tell you about the product. That is the whole list.
We do not buy prospect lists, we do not append data from brokers to what you gave us, we do not run advertising pixels, and we do not build behavioral profiles for targeting. If you never become a customer, we keep your enquiry while a conversation is live and for a reasonable period afterwards in case you come back, and you can ask us to delete it sooner at support@rentflow360.com.
Referrals
If a customer refers you to us, we receive your name and contact details from them and use them once, to make the introduction. The referrer is responsible for having your agreement to pass them on.
| Recipient | What they receive | On what basis |
|---|---|---|
| Authorized users within a customer's organization | Whatever their role permits — a property manager sees the tenancies they manage, a vendor sees the work order, a tenant sees their own record, an owner sees their properties | The customer's configuration of roles and permissions |
| Service providers acting for us | Only what their function requires, listed in the next section | Written contract, limited to providing the service to us |
| Third parties you or the customer connect | The data that integration is for: a screening order, a payment, a utility connection, a syndicated listing | Your or the customer's instruction to connect it |
| Professional advisers, auditors, and insurers | What a specific engagement requires | Our own legitimate interests and legal obligations, under confidentiality |
| Authorities, courts, and parties to a legal process | What a valid legal request compels, or what is necessary to establish or defend a claim | Law, described in its own section below |
Personal information may also transfer as part of a corporate transaction, which has its own section.
Within an organization
Role and organization boundaries are enforced by the platform rather than by convention: a request can only read or write inside the organization on the caller's own session, and the organization is never taken from the request itself. That is what stops one customer's workspace from being reachable by another. What a colleague can see inside a single organization is a configuration decision by that organization, and if you think somebody there sees too much, they are the ones who can change it.
What never leaves
We do not disclose personal information to advertising networks, data brokers, or list vendors, and we do not make it available for anyone else's marketing. There is no exception to this and no setting that turns it on.
We use third-party providers to run parts of the platform. Each is engaged under a written contract that limits them to processing data for the service they provide to us, requires confidentiality and appropriate security, and forbids using the data for their own purposes.
| Function | What reaches the provider |
|---|---|
| Application hosting and infrastructure | Requests to the platform and the data they carry |
| Database and file storage | The records and documents the platform holds |
| Payment processing | Card and bank details, amounts, and billing contacts |
| Bank account verification | Account metadata and authorization tokens; the bank login happens at the provider |
| Background and credit screening | The applicant identifiers a report requires, when a report is ordered |
| Identity verification | Identity document images and check results, where enabled |
| Document data extraction | A proof-of-income document uploaded with an application, where verification is enabled |
| Utility account connection | The utility account a customer authorizes, and the billing and usage history it returns |
| Address geocoding | The address or search text being looked up, with no account or person attached to it |
| Rent reporting | The furnished payment record described in its own section, where enabled |
| Transactional email | Recipient addresses and message contents |
| SMS | Recipient numbers and message contents |
| Image hosting and delivery | Listing and property images |
| Error monitoring | Stack traces and request context, with personal data redacted before it is sent |
| AI-assisted features | The listing text, property attributes, or utility bill described in the automated features section |
The current named list
The providers behind each of those functions are named, with what each one receives, on our security page. That list is maintained as the authoritative one and is updated when a provider is added or removed, which is why this policy points at it rather than duplicating it — two lists in two places drift, and the stale one is always the one somebody reads.
Sub-processing and location
Providers may use their own infrastructure providers. Each remains responsible to us for its subcontractors. Our providers are predominantly United States-based; some operate globally and may process data outside the United States, which the international transfers section covers.
Changing a provider
We may add or replace providers as the platform changes. When we do, the security page list changes with it. Customers on negotiated agreements that include advance notice of subprocessor changes receive that notice under those agreements.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Those two phrases have specific statutory meanings, which is why the plain-English version is not enough on its own. Under the California Consumer Privacy Act as amended, "sale" covers disclosing personal information to a third party for monetary or other valuable consideration, and "sharing" covers disclosing it for advertising targeted across different businesses or sites. Several other state laws define "sale" the same broad way, and some define targeted advertising separately.
Measured against those definitions rather than the everyday one:
- We have not sold or shared personal information in the twelve months preceding the date of this policy, and we do not do so now.
- We do not have, and have never had, an arrangement with a data broker, list vendor, or advertising network.
- We run no advertising or cross-site tracking technology, so there is nothing on our pages capable of transmitting information to an advertising partner.
- We do not sell or share the personal information of anyone we know to be under sixteen. We do not knowingly collect it at all.
- We do not disclose personal information to our service providers for any purpose other than performing the service they were engaged for, which is why those disclosures are not sales.
We honor the Global Privacy Control signal as an opt-out request, and the app carries an opt-out control under Account, then Privacy, notwithstanding that we have nothing to opt out of. Both exist so that the position is verifiable rather than merely asserted, and so that the control is already there if the answer ever changes. If it does, this section changes first, the date on this policy moves, and the change is announced before it takes effect.
Protecting data in transit and at rest
All traffic to RentFlow360 is served over HTTPS, and plain HTTP requests are redirected to it.
The most sensitive fields we hold — Social Security and taxpayer identification numbers, and bank routing and account numbers for owners, collection accounts, and utility payees — are encrypted at the field level with AES-256-GCM before they are written, using keys held outside the database and outside the codebase. Two-factor authenticator secrets and payment metadata are encrypted with their own separate keys. Passwords are stored only as salted hashes.
Full card numbers never reach our servers: card and bank credentials are collected by Stripe and Plaid directly, and we hold tokens rather than instruments.
Access control
Every account holds exactly one role. Every membership write goes through a single enforcement path rather than being left to each caller, and every interface gates on that role before it touches data. Data is partitioned by organization: a request can only read or write within the organization on the caller's own session, and the organization is never taken from the request itself. An automated guard suite scans every route on every continuous integration run to keep both of those properties true, because a rule enforced only by review is a rule that eventually is not enforced.
Alongside that:
- two-factor authentication using an authenticator app, available on every account;
- single sign-on through OIDC or SAML for organizations on the Enterprise plan;
- server-side session revocation: signing out invalidates every session, with a fifteen-minute ceiling on access tokens already issued, rather than ending only the browser you used;
- rate limiting and account lockout after repeated failed sign-ins;
- malware scanning of uploaded application documents where a customer has it configured;
- staff access to production limited to what a role requires, and access to a customer's workspace only for support, at the customer's request or where necessary to investigate a fault or a security incident.
Monitoring and auditability
Changes to leases, properties, journal entries, listings, approvals, and signing envelopes are recorded with the account that made them and when. Application errors are captured centrally with personal data redacted before it leaves the process, so failures are diagnosed without exporting customer records into a monitoring tool. Privacy actions — an export, a deletion, a change to a privacy preference — are recorded as their own audit events.
What we do not claim
This section is worth more if you can trust the paragraphs above it, so here is what is not true, stated by us rather than discovered later:
- We are not SOC 2 certified. We have not been through the audit, so we do not claim the report and do not use the badge.
- We have not commissioned a third-party penetration test. Security work here has been internal review and automated checking, and we would rather say that than let the word "tested" do work it has not earned.
- We do not claim blanket encryption at rest for the whole database. We describe field-level encryption of specific columns because that is what we do. Database-level encryption is a hosting-layer control we are working through with our provider.
- We do not offer customer-managed encryption keys, data residency selection, or on-premise deployment.
- No system is impenetrable. We cannot guarantee absolute security, and any policy that does is overstating what software can do.
Most account compromises we see anywhere in this industry begin with a reused password or a shared login, not with a flaw in the software.
- Use a password you use nowhere else, and a password manager to hold it.
- Turn on two-factor authentication. It is available on every account, takes a minute, and defeats the entire class of attack that starts with a leaked password.
- Do not share logins. Give each person their own account with the role they need — shared credentials destroy the audit trail and outlive the person who left.
- Sign out on shared or public devices, and use the revoke-everywhere option if you think a session is loose.
- Do not forward signing links or invitations. Anyone holding one can act on it.
- Keep your email address current. It is how a password reset and every security alert reaches you.
- Treat unexpected requests for credentials or payment changes as suspicious. We will never ask for your password, and a change of bank details arriving by email is the oldest fraud in property management.
If something is wrong
Write to support@rentflow360.com immediately if you believe an account has been accessed without permission, if you see records that should not be visible to you, or if you receive a platform message you cannot account for. Include what you saw and when. If you believe you have found a vulnerability, our security page sets out how to report it and what we commit to in return.
If we become aware of unauthorized access to, or disclosure of, personal information we hold, we investigate immediately, work to contain it, and take steps to prevent it recurring.
Where notification is required by law, we notify. For information we control, we notify affected individuals and any regulator entitled to be told, within the deadline the applicable statute sets. For information we process on a customer's behalf, we notify the customer without undue delay and give them the detail they need to meet their own notification obligations, because in that situation they are the ones who must decide what their residents are told and they hold the relationship.
Our notice will say what happened, what categories of information were involved, what we have done about it, and what you can do to protect yourself. We would rather tell you something incomplete promptly than something polished late.
We do not publish a blanket promise of a fixed notification window here. The deadlines that bind us are set by statute and vary by jurisdiction and by circumstance, and a shorter number invented for a policy page would not change any of them.
If you believe an incident has occurred, tell us at support@rentflow360.com. Reports of suspected vulnerabilities are covered on our security page.
We keep personal information for as long as it is needed for the purpose it was collected for, and then for as long as the law or a legitimate business need requires. In property management those periods are longer than people expect, because tenancy records are financial records.
| Record | How long it is kept |
|---|---|
| Account and profile | For the life of the account. After termination, thirty days so records can be retrieved, then removal from active systems |
| Customer workspace data — properties, leases, tenancies, tickets, documents | For the life of the subscription, then the same thirty-day retrieval window, then removal from active systems |
| Financial and accounting records — ledger entries, invoices, payments, statements, tax records | Seven years, and longer where a specific tax or accounting obligation requires it. These survive account closure |
| Signed documents and signing audit trails | For the life of the agreement they evidence and the limitation period that follows it. In Washington, an action on a written contract may be brought within six years |
| Screening authorizations and adverse action records | For the period the Fair Credit Reporting Act and applicable state law require of the customer who ordered the report. The report itself is held by the consumer reporting agency |
| Rent records furnished to a consumer reporting agency | The furnished record is held by the agency under its own retention rules. Our record that it was furnished stays with the payment |
| Security and audit logs | For the life of the account, because their purpose is answering questions long after the event |
| Error diagnostics held by our monitoring provider | On the provider's standard schedule, currently ninety days |
| Support correspondence | While a conversation is live and for a reasonable period afterwards |
| Marketing and prospect records | Until you unsubscribe or ask us to delete them, and periodically reviewed for people who never responded |
| Backups | Residual copies may persist in backups until those backups age out on their normal schedule |
What drives a period
The type of record, whether the account is still active, the customer's own instructions, statutory record-keeping duties, limitation periods for claims, tax obligations, and whether a dispute or a legal hold is in play. A legal hold overrides everything else in this section for the records it covers, and lasts as long as the matter does.
How deletion actually happens
Records are removed when they are asked for, when a customer closes an account and the retrieval window passes, or when a record is no longer needed for the purpose it was collected for. We do not operate a global automatic purge on a fixed clock, and we are not going to describe one we do not run. If you want something gone sooner than the table above, ask — the next section explains what we can and cannot remove.
Account holders can delete their personal data from inside the application, under Account, then Privacy. It requires an explicit typed confirmation, because it cannot be undone.
What deletion does
Your name is replaced with a placeholder, your email address with a non-routable address that cannot receive mail, and your phone number and profile image are removed. Two-factor authentication and its stored secret are removed. Marketing, notification, and transactional consents are cleared. Every session and refresh token is revoked immediately, and outstanding password reset tokens are destroyed, so the account cannot be used again.
It also ends our access to your money. Stored payment methods are archived, any automatic payment relying on them is stopped, and every bank authorization obtained through Plaid is revoked with the provider, so the platform's ability to reach your account is withdrawn rather than merely hidden.
What survives it, and why
Deletion does not erase the transactions of a tenancy. Ledger entries, invoices, payments, and statements remain, along with the leases and signed documents they relate to, because they are the financial and legal record of an agreement between other parties and are subject to record-keeping obligations that are not ours to waive. What changes is that they no longer carry your identifying details.
We also retain what we must to complete a transaction already under way, to comply with law, to detect and prevent fraud, to exercise or defend a legal claim, and to keep our security and audit records intelligible.
If your landlord holds the record
Where a property manager entered information about you, deleting it is their decision, subject to their own obligations. Ask them first, and tell us at support@rentflow360.com if you do not get an answer — we will pass the request on and confirm that we have.
Deleting a whole organization
When a customer terminates, their workspace is retained for thirty days so they can retrieve their records, then removed from active systems. Residual copies may persist in backups until those backups age out on their normal schedule. A customer who wants an earlier or a more thorough removal should write to us, and we will confirm what can and cannot go.
Which rights you hold depends on where you live and which law applies. Rather than repeat the list under every statute below, here is the full set with what each one means in practice here.
| Right | What it means with us |
|---|---|
| Know and access | Ask what we hold about you, where it came from, why we have it, and who we have given it to. Account holders can export their own data without asking |
| Correct | Have inaccurate information fixed. Most profile fields are editable in the app; a tenancy record entered by a landlord usually has to be corrected by them |
| Delete | Have your information removed, subject to the records described in the previous section |
| Portability | Receive a copy in a structured, machine-readable format. The in-app export produces JSON |
| Opt out of sale or sharing | Available, though we do not sell or share |
| Limit use of sensitive information | Available. Our use is already limited to providing the service |
| Opt out of profiling for significant decisions | Available where a state law provides it. We make no automated significant decisions |
| Restrict or object to processing | Available where the law provides it, for example under the GDPR |
| Withdraw consent | Where processing rests on consent, withdraw it at any time. It does not undo what was lawful before |
| Non-discrimination | We will not deny service, charge a different price, or give you a worse experience for exercising a right |
| Appeal | If we refuse a request, ask us to reconsider. See the next section |
| Complain to a regulator | You may lodge a complaint with your state attorney general or supervisory authority. We would rather you told us first |
The qualification that applies to all of them
If your information is in the platform because a landlord, property manager, or employer put it there, we are the processor and they are the controller. We will pass your request to them, tell you we have, and act on their instruction. That is not a way of avoiding the request; it is what the law requires when the data is not ours to decide about, and it is explained in full in the fourth section of this policy.
Self-service controls
Signed-in account holders do not need to ask us for most of these. Under Account, then Privacy, you can export your data, request deletion, opt out of sale, limit the use of sensitive information, restrict processing, and turn rent reporting to a credit bureau on or off. Each action is recorded as an audit event with the time it happened.
How to submit a request
Email support@rentflow360.com. Tell us what you want — access, correction, deletion, a copy, an opt-out, or a limit — and give us enough to find you: the name and email address associated with the record, and where a tenancy is involved, the property address. There is no form, and there is no charge.
Account holders can also do most of it themselves in the app under Account, then Privacy, which is faster than writing to us.
How we verify it is you
We match what you give us against what we hold. For a signed-in account holder, being signed in is the verification. For someone without an account — a former applicant, a guarantor, an emergency contact — we ask for enough detail to match the record confidently, and the sensitivity of the request sets how much: deleting a record or releasing a copy of one requires more confidence than unsubscribing from an email.
We ask only for what verification needs, we do not create an account for you in order to answer, and information supplied for verification is used for that and then discarded.
If we cannot verify you to the standard the request requires, we will say so and explain what would satisfy us rather than simply refusing.
Authorized agents
You may use an agent. We require written authorization signed by you, or a power of attorney, and we may contact you directly to confirm. An agent submitting on behalf of many people must still establish authority for each.
How long we take
We acknowledge requests promptly and respond within the period the applicable law allows: forty-five days under most United States state privacy laws, extendable once by a further forty-five days where the request is complex, and one month under the GDPR, extendable by two further months. We will tell you if we need an extension and why, before the first period runs out.
We do not publish a single global response time, because the deadlines are set by the statute that applies to you and inventing a shorter number here would not change them.
If we refuse
We will tell you why, and under which exception. You may appeal by replying to that decision or writing to support@rentflow360.com with "Appeal" in the subject. An appeal is reviewed by someone who was not responsible for the original decision, and we respond within the period the applicable law sets — sixty days in most states that provide the right. If we uphold the refusal, we will tell you how to complain to your attorney general or supervisory authority.
Requests we cannot fulfill
We will refuse, in whole or in part, where fulfilling would require us to breach a legal obligation, would compromise the privacy or rights of someone else, concerns records a customer controls and has instructed us to retain lawfully, would undermine our security or fraud prevention, or where an exception in the applicable statute applies. Where only part of a request is affected, we do the rest of it.
This section applies if you are a California resident and the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to our processing of your information. Terms used here have the meanings given in that statute.
Categories of personal information
In the twelve months preceding the date of this policy, we have collected the following statutory categories. "Sold or shared" is included as its own column because it is the question the statute exists to answer.
| Statutory category | Do we collect it? | Source | Business purpose | Disclosed to | Sold or shared |
|---|---|---|---|---|---|
| A. Identifiers | Yes — name, postal address, email, phone, account identifiers, network address | You, the customer, our providers | Running the Services, communicating, security | Authorized users, service providers | No |
| B. Customer records (Cal. Civ. Code 1798.80) | Yes — name, address, telephone, bank account and payment details, employment and income on applications | You, the customer | Tenancy administration, payments, screening | Authorized users, payment and screening providers | No |
| C. Protected classification characteristics | Not collected deliberately. Date of birth is collected where a service requires it, and a free-text field or uploaded document may contain more | You, the customer | Only the function that required the field | Authorized users | No |
| D. Commercial information | Yes — rent and payment history, invoices, transactions, subscription records | Generated by use | Accounting, billing, reporting | Authorized users, service providers | No |
| E. Biometric information | No | — | — | — | No |
| F. Internet or network activity | Yes — pages viewed, features used, log and diagnostic data | Generated automatically | Security, diagnostics, product improvement | Service providers | No |
| G. Geolocation data | Coarse only, inferred from network address. No precise geolocation | Generated automatically | Security and fraud prevention | Service providers | No |
| H. Audio, electronic, visual information | Yes — uploaded photographs and documents, including maintenance and inspection images | You, the customer | Maintenance, inspections, records | Authorized users, vendors assigned to the work | No |
| I. Professional or employment information | Yes, on rental applications — employer, position, income | You | Screening and application assessment | The customer, screening providers | No |
| J. Education information | No | — | — | — | No |
| K. Inferences | Yes — tenant retention and risk scores derived from payment, maintenance, and lease history | Calculated by the platform | Operational reporting to the managing organization | Authorized users of that organization | No |
| Sensitive personal information | Yes — Social Security and taxpayer identification numbers, government identification, financial account details, account credentials | You, the customer | Screening, tax reporting, payments, authentication | Screening, verification, and payment providers | No |
Sale, sharing, and sensitive information
We have not sold or shared personal information in the preceding twelve months, and we do not sell or share the personal information of consumers we know to be under sixteen. We use and disclose sensitive personal information only for the purposes permitted by section 1798.121(a) — providing the service requested, security, and the other enumerated business purposes — so the right to limit its use does not restrict anything we currently do. The control is provided anyway, under Account, then Privacy.
Your California rights
You have the right to know what we collect and how we use it, to access the specific pieces we hold, to have inaccurate information corrected, to delete, to a portable copy, to opt out of sale or sharing, to limit the use of sensitive personal information, and to be free from retaliation for exercising any of them. Exercising a right will not cause us to deny you service, charge you a different price, or provide you with a lower quality of service.
How to exercise them
Email support@rentflow360.com, or use the controls under Account, then Privacy. We honor the Global Privacy Control as a valid opt-out request. The verification, agent, timing, and appeal mechanics are in the previous section and apply to California requests.
Notice at collection
This policy, together with the notices shown where information is collected, is our notice at collection. Where an applicant is asked for a Social Security number, the reason is stated at that point. Where a customer collects information from you inside their own workspace, they are responsible for the notice their collection requires.
Shine the Light
California Civil Code section 1798.83 permits residents to request details of personal information disclosed to third parties for their direct marketing purposes. We make no such disclosures, so there is nothing to report, but the request may be sent to support@rentflow360.com.
Kips Reality L.L.C is organized in Washington State, and the platform implements several Washington-specific requirements. It is worth being precise about which ones, because Washington's privacy landscape is often described inaccurately.
Washington has no comprehensive consumer privacy statute of the kind Virginia, Colorado, or Connecticut have enacted. A resident of Washington therefore does not have a general statutory right of access or deletion under Washington law. What Washington does have, and what applies here:
- The My Health My Data Act, which regulates consumer health data and provides rights over it. It is covered in the next section.
- The Washington Consumer Protection Act (RCW 19.86), under which a materially misleading statement in a privacy policy is itself actionable. That is one reason this document says plainly what we do not do.
- RCW 59.18.257, which requires a landlord to disclose, before an applicant pays a screening fee, what they will screen, which consumer reporting agency they use, what criteria they apply, and what the fee covers. The platform generates that notice with the agency's name and address in it.
- RCW 19.255 and RCW 42.56.590, Washington's data breach notification requirements, which govern when and how we and our customers must notify affected Washington residents.
What we do regardless
We extend the substance of the rights in this policy — access, correction, deletion, a portable copy, and the opt-outs — to Washington residents as a matter of practice rather than because a Washington statute compels it. Write to support@rentflow360.com and we will handle your request exactly as we would one from a state with a comprehensive law.
If Washington enacts a comprehensive privacy statute, this section will be rewritten to describe the rights it creates, and the date at the top of this policy will move.
A growing number of states have comprehensive consumer privacy laws. Where one applies to us and to you, we honor the rights it creates.
| State | Statute | Rights it provides |
|---|---|---|
| Virginia | Consumer Data Protection Act | Access, correct, delete, portability, opt out of targeted advertising, sale, and profiling, appeal |
| Colorado | Colorado Privacy Act | The same, plus recognition of a universal opt-out signal |
| Connecticut | Data Privacy Act | The same, plus recognition of a universal opt-out signal |
| Utah | Consumer Privacy Act | Access, delete, portability, opt out of targeted advertising and sale |
| Texas | Data Privacy and Security Act | Access, correct, delete, portability, opt-outs, appeal, universal opt-out signal |
| Oregon | Consumer Privacy Act | The above, plus a right to a list of specific third parties data was disclosed to |
| Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island | Respective consumer data protection acts | Access, correct, delete, portability, and opt-out rights, with variations by state |
| Nevada | SB 220 | Opt out of the sale of covered information |
Rights and effective dates vary, and more states join the list each year. Rather than track every variation in this document, our position is simpler: if a state grants you a right listed anywhere in this policy, exercise it and we will honor it, without arguing about thresholds.
Universal opt-out signals
Several of these statutes require recognition of a browser-level opt-out. We honor the Global Privacy Control signal, and treat Do Not Track the same way on our public pages. Nothing needs to be enabled for this to work.
Exemptions worth knowing about
Two exemptions frequently apply to information in this platform, and you should know they exist rather than discover them in a refusal letter:
- Business-to-business and employment contexts. Most state laws apply to a "consumer" acting in a personal capacity, not to someone acting for their employer. Information about a property manager acting in their professional role often falls outside them. California is the exception; its law covers both.
- Financial and consumer reporting data. Information regulated by the Gramm-Leach-Bliley Act or the Fair Credit Reporting Act is exempt from most state privacy statutes, because those federal regimes govern it instead. Screening and payment data frequently sits there.
Where an exemption applies, we will tell you which one and why, and we will still do whatever we can outside it.
Washington's My Health My Data Act, Nevada's SB 370, and Connecticut's health data provisions regulate "consumer health data" — information linked to a person that identifies their past, present, or future physical or mental health status. They define it broadly, and a reasonable reading catches things that do not look medical.
RentFlow360 is not a health platform. We do not collect consumer health data, we provide no field for it, we do not ask for it, we do not infer it, and we do not sell it. We have never sold consumer health data and would need your written authorization to do so, which we will not seek.
How it can reach us anyway
Property management touches health at the edges. A reasonable-accommodation request may explain a disability. A maintenance ticket may say why a repair is urgent. A supporting document uploaded with an application may be a medical letter. In each case the information arrives inside free text or an attachment, entered by you or by a property manager.
When that happens, the information is stored, used, and disclosed exactly as the record containing it is — it is visible to the same authorized users, retained on the same schedule, and protected by the same controls. It is never used for advertising, profiling, or any purpose other than handling the request it came with, and it is never sold.
Please do not send it
If a request can be made without a diagnosis, make it without one. If a landlord needs supporting documentation for an accommodation, ask what they actually require; usually it is confirmation that a need exists, not the underlying condition. Customers should not solicit health information through the platform beyond what the accommodation process genuinely requires, and fair housing law constrains what they may ask in any case.
Your rights over it
Where a state consumer health data law applies to you, you may ask us to confirm what we hold, to tell you who it was shared with, and to delete it. Write to support@rentflow360.com and identify the record — the property, the ticket, or the application — so we can find it. Where the record belongs to a customer's workspace, we will act on their instruction and tell you we have passed it on.
The Health Insurance Portability and Accountability Act applies to covered entities — health plans, clearinghouses, and providers who transmit health information electronically — and to the business associates who handle protected health information for them. A software vendor does not become a business associate merely by selling software to an organization that happens to be in healthcare; the relationship and the access to protected health information are what matter.
RentFlow360 is not offered as a HIPAA-compliant platform. We have not represented it as one, and nothing in this policy or on our site should be read that way.
Unless we have signed a Business Associate Agreement with you, you must not use the Services to create, receive, maintain, or transmit protected health information subject to HIPAA. That includes senior housing operators, healthcare-affiliated landlords, and any organization whose residents' health information would travel with a tenancy record.
If you need HIPAA-regulated processing, contact support@rentflow360.com before putting any such information into the platform. Where we enter into a Business Associate Agreement, that agreement governs the permitted uses, disclosures, and safeguards for the information it covers, and its terms take precedence over this policy for that information.
The Gramm-Leach-Bliley Act governs how financial institutions handle "nonpublic personal information", and the Federal Trade Commission's Safeguards Rule requires those institutions to protect it. Whether the Act reaches a particular property management arrangement depends on the activities of the organization involved.
Our position is straightforward regardless of how that question resolves for any given customer:
- Financial account information — bank routing and account numbers, payment tokens, transaction records, and taxpayer identification numbers — is used only to move money the parties intended to move, to keep the books that record it, and to meet tax and record-keeping obligations.
- It is never used for marketing, never disclosed to advertising networks or data brokers, and never sold.
- The sensitive fields are encrypted at the field level before storage, as described in the security section.
- Where a customer is subject to the Act and we process nonpublic personal information for them, we do so as their service provider, under contract, on their instructions, and we will enter into whatever additional terms their obligations require.
Where a payment provider is the financial institution in a transaction — which is the usual arrangement, since Stripe and Plaid handle the instruments — that provider's own privacy notice governs the data it holds and the choices it must offer you.
State privacy laws generally exempt information regulated by this Act. That exemption is one of the reasons a deletion request touching payment records may be answered in part rather than in full, and where that is the reason, we will say so.
The Fair Housing Act and its state and local equivalents prohibit discrimination in housing on the basis of race, color, religion, sex, disability, familial status, and national origin, with many jurisdictions adding source of income, sexual orientation, gender identity, age, marital status, military status, and criminal history restrictions.
Nothing in this policy authorizes using RentFlow360 or any information obtained through it to discriminate. That is a term of our Terms of Service, not merely a sentiment here.
What this means for the data
We do not collect protected characteristics, we provide no field for them, and we do not infer them. No feature scores, ranks, or filters applicants, and the scoring the platform does perform applies to existing tenancies and plays no part in an application. Our AI-assisted features include a fair-housing language check specifically to flag wording in a listing that may breach these rules — a check, not a guarantee, and a listing remains the publisher's responsibility.
Where responsibility sits
The landlord or property manager decides who is screened, what criteria apply, how advertisements are worded, whom they are shown to, whether an application succeeds, and how the decision is recorded. Those are their decisions and their legal obligations. RentFlow360 does not make, recommend, or influence them.
If you believe you have been discriminated against
Contact the organization involved, and if that does not resolve it, the United States Department of Housing and Urban Development or your state or local fair housing agency. If you believe our software contributed to it — a form that asked something it should not, or a generated output that reflected bias — tell us at support@rentflow360.com. That is a defect we want reported, and we will investigate it as one.
The Services are intended for adults and for businesses. We do not knowingly collect personal information directly from children under thirteen, and we do not direct any part of the Services to them. Accounts require an adult, and an application requires legal capacity to enter a tenancy.
Minors do appear in property records, because households contain children: a lease may list an occupant who is a minor, and a maintenance photograph may show a family home. That information is entered by an adult — a tenant or a property manager — as part of administering a tenancy. It is treated as part of the tenancy record, is visible only to the authorized users of that record, and is never used for marketing, profiling, or advertising.
We do not sell or share the personal information of anyone we know to be under sixteen, and we do not knowingly collect it in the first place.
If you believe a child has provided personal information to us directly, or that a child's information is in the platform without appropriate authority, write to support@rentflow360.com and we will investigate and delete what the law requires us to delete.
RentFlow360 is built for, sold in, and operated from the United States. The payment, screening, tax, and landlord-tenant functions are built to United States rules, and we do not market or offer the Services in the European Economic Area, the United Kingdom, or Switzerland.
Our systems and our primary service providers are located in the United States, and information you give us is processed there. Some providers operate globally and may process limited data — message delivery, error diagnostics, content delivery — outside the United States on their own infrastructure.
If you access the Services from outside the United States, you are doing so on your own initiative and your information will be transferred to and processed in the United States, whose privacy laws differ from those of your country and may offer less protection than you are used to.
Visitors from the EEA, the UK, and Switzerland
Our public website is reachable from anywhere, so a person in Europe may visit it or write to us. Because we do not offer goods or services to people in those territories and do not monitor their behavior, we have not appointed an Article 27 representative and do not hold ourselves out as being established there. We would rather say that than imply a compliance apparatus that does not exist.
That said, if you are in one of those territories and we hold personal data about you, we will honor the substance of the rights in the next two sections on request. Write to support@rentflow360.com.
Where the General Data Protection Regulation or the United Kingdom GDPR applies to personal data we hold, the following rights are available, and we will handle a request under them exactly as described in the rights-mechanics section above.
| Right | What you can require |
|---|---|
| Access | Confirmation of whether we process your data, a copy of it, and the supplementary information Article 15 requires |
| Rectification | Correction of inaccurate data, and completion of incomplete data |
| Erasure | Deletion, where one of the Article 17 grounds applies and no exemption does |
| Restriction | That we hold data without further processing while a dispute about its accuracy or our grounds is resolved |
| Portability | A structured, commonly used, machine-readable copy of data you gave us, where processing is by consent or contract and carried out by automated means |
| Objection | That we stop processing based on legitimate interests, including profiling. An objection to direct marketing is absolute |
| Automated decisions | Not to be subject to a decision based solely on automated processing with legal or similarly significant effects. We make none |
| Withdraw consent | At any time, where processing rests on consent, without affecting the lawfulness of what came before |
| Complain | To your supervisory authority, or in the United Kingdom the Information Commissioner's Office |
We respond within one month, extendable by two further months for complex or numerous requests, and we will tell you before the first month expires if we need the extension. There is no charge unless a request is manifestly unfounded or excessive.
Where we act as a processor for a customer, we will refer your request to them as controller and tell you we have done so.
Where the GDPR, the UK GDPR, or a comparable law requires a lawful basis, ours are as follows.
| Processing | Lawful basis |
|---|---|
| Creating and running an account, delivering the Services, and taking payment for them | Performance of a contract with you, or steps taken at your request before entering one |
| Administering a tenancy on a customer's instructions | The customer's own lawful basis, usually performance of their contract with you or their legitimate interests. We act as processor |
| Security, fraud prevention, rate limiting, and audit logging | Legitimate interests — protecting the platform and everyone on it |
| Diagnostics, error monitoring, and product improvement | Legitimate interests — keeping the service working and making it better, using aggregated or technical data where that will do |
| Marketing to business contacts | Legitimate interests, or consent where the law requires it. Withdrawable at any time |
| Tax, accounting, consumer reporting, and record-keeping obligations | Compliance with a legal obligation |
| Establishing, exercising, or defending legal claims | Legitimate interests, and where relevant a legal obligation |
| Responding to lawful requests from authorities | Compliance with a legal obligation |
| Processing that requires it, such as certain special-category data arriving in a free-text field | Consent, or another Article 9 condition where one applies |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you may object at any time on grounds relating to your particular situation. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
Personal information collected through the Services is stored and processed in the United States. Our hosting, database, and file storage are United States-based.
Some of the service providers described earlier operate internationally, and a limited set of data may be processed outside the United States in the course of what they do: email and SMS delivery to an international recipient, content delivered from a network edge close to the reader, or error diagnostics processed on a provider's global infrastructure.
Where a transfer of personal data out of the European Economic Area or the United Kingdom occurs and the receiving country has no adequacy decision, the transfer is made on the basis of the European Commission's Standard Contractual Clauses, or the United Kingdom International Data Transfer Addendum, as incorporated into our contracts with the provider concerned. Copies of the relevant terms are available on request at support@rentflow360.com.
We do not offer data residency selection. If your organization requires data to remain in a particular jurisdiction, RentFlow360 is not currently able to guarantee that, and we would rather tell you now than be discovered later.
Global Privacy Control. We honor it. When a browser sends the GPC signal, we treat it as a valid opt-out of sale and sharing for that browser, and, for a signed-in account, we record the opt-out on the account so that it persists across devices. The action is logged as a privacy event with its source. On our public pages, GPC also prevents the analytics code from arming at all.
Do Not Track. There has never been an agreed standard for what a site should do when a browser sends DNT, which is why most policies say they ignore it. We treat it the same way we treat GPC on our public pages: if your browser sends it, analytics does not run.
Neither signal affects the cookies that keep you signed in. Those are strictly necessary, there is nothing to opt out of, and honoring an opt-out by signing you out would be an odd reading of your intentions.
The Services link to and integrate with services we do not operate. Once information reaches one of them, that provider's privacy policy governs it, not ours.
Integrations a customer switches on
Payments, bank verification, screening, identity verification, rent reporting, accounting exports, utility connections, and single sign-on all send data to the provider concerned when the customer enables them. Each is described in its own section above. Enabling one is the customer's decision; where the data is about you and the customer is the controller, it is their decision to make and their responsibility to have a basis for it.
Listing syndication
Where an organization connects a listing distribution channel, the platform sends the listing to it: the property address, unit details, rent, availability, description, photographs, and the contact details the customer nominated for enquiries. Listings are marketing material and are meant to be public. Tenant, applicant, and financial records are never part of a syndication feed.
Enquiries from public listings
If you contact a landlord through a listing on a third-party site, that site handles your enquiry under its own policy before anything reaches us, and what arrives here becomes part of that landlord's records.
Links
Our marketing pages and some in-app content link out. A link is not an endorsement, and we do not control what is on the other end. Read the destination's own policy before giving it anything.
If you administer properties through RentFlow360, you are the controller of the records you create, and the following are yours rather than ours.
- Have the right to submit the information. Every tenant, applicant, guarantor, occupant, emergency contact, owner, and vendor record you enter is personal information about someone who did not sign your subscription.
- Give people the notices their jurisdiction requires at the point you collect from them, including screening disclosures before an application fee is taken and adverse action notices when a decision goes against an applicant.
- Obtain any consent the law requires, including for text messages, screening, and any collection that goes beyond what a tenancy needs.
- Configure access properly. Give each person their own account and the narrowest role that lets them do their job, and remove accounts when people leave. What your colleagues can see inside your workspace is your configuration, not our default.
- Collect only what you need, and do not solicit protected characteristics, health information, or immigration status through free-text fields.
- Answer requests from your residents. Where we receive one about your records, we will pass it to you, and responding is your obligation as controller.
- Tell us about a legal hold that affects records in your workspace before a retention period would otherwise remove them.
- Keep your own retention decisions lawful. You choose what stays in your workspace; the obligations attaching to that choice are yours.
Data processing terms
Our processing of personal information on your behalf is governed by our agreement with you, which incorporates the description in this policy. If your compliance program requires a separate data processing agreement, standard contractual clauses, a subprocessor notification commitment, or security terms beyond those described here, write to support@rentflow360.com; those are available on a negotiated agreement.
If Kips Reality L.L.C is involved in a merger, an acquisition, a financing, a reorganization, a sale of assets, an insolvency, or a similar transaction, personal information may be reviewed by prospective counterparties under confidentiality obligations, and may be transferred as part of the transaction.
Three commitments apply if that happens:
- Personal information disclosed for diligence is limited to what the exercise genuinely requires and is disclosed under a confidentiality agreement. Wherever aggregated or de-identified information will answer the question, that is what is provided.
- A successor takes the information subject to this policy. If it intends to handle it materially differently, you will be told before the change takes effect, and given whatever choice the applicable law provides.
- Where notice or consent is required by law, it will be given or obtained.
A transfer of this kind does not enlarge anyone's rights over your information. The successor stands in our shoes; it does not acquire permissions we never had.
We disclose personal information to authorities, courts, and other parties where we reasonably believe disclosure is required by law or necessary to protect rights or safety. We also apply the following, which are the parts a policy usually leaves out.
- We require valid legal process. We ask for the specific instrument the law requires for the data sought, and we do not treat an informal request from an official as an instrument.
- We read what is asked for. We object to or seek to narrow requests that are overbroad, defective, or that reach further than the matter requires, and we produce only what the request actually compels.
- We notify where we can. If a request covers a customer's workspace, our first step is to tell that customer so they can respond or object, unless we are legally prohibited from telling them or there is an emergency involving a risk of death or serious injury. Where a prohibition expires, we tell them then.
- Emergency requests are answered where there is a genuine and immediate risk to life or of serious harm, limited to what is necessary to address it.
- We keep a record of what was requested, by whom, under what authority, and what was produced.
We may also disclose information where necessary to establish or exercise our legal rights, to defend against claims, to enforce our Terms, or to investigate suspected fraud, abuse, or a security incident.
The platform reflects what users and customers put into it. We do not independently verify the accuracy of a tenancy record, an application, a maintenance note, or a contact detail, and inaccurate information in a record can have real consequences — a notice sent to the wrong address, a payment credited to the wrong ledger, a screening ordered against the wrong identifiers.
- Your own profile is editable in the app. Keep your email address and phone number current.
- A record a landlord or manager entered is corrected by them. Ask them directly, and tell us at support@rentflow360.com if you get nowhere.
- A consumer report is corrected by the agency that produced it, and the notice you received names them. We cannot amend a report.
- A furnished rent record is checked against the underlying payment by us, on request, as described in the rent reporting section.
Where we correct something at your request, we will tell you what we changed, and where the incorrect version was disclosed to someone else recently, we will notify them where the law requires it and where it is reasonably possible.
This policy is published as a web page so it can be read by a screen reader, magnified, translated by a browser, and linked to section by section. Every section is expanded by default rather than hidden behind a control, because a disclosure that requires forty clicks to read is not much of a disclosure.
If you need this policy in another format — plain text, large print, or a PDF — write to support@rentflow360.com and we will send one. If you encounter an accessibility problem anywhere in the Services, tell us at the same address; we treat it as a defect, not a preference.
We update this policy when the platform changes, when a new law applies to us, or when something here turns out to be less clear than it should be.
When we update it, we change the "Last updated" date at the top and the effective date at the end. Those two dates are enforced by an automated check in our codebase: if the content of this document changes and the date does not move, our build fails. That check exists because a legal page that changes silently is worse than one that never changes at all.
Material changes — a new category of information, a new purpose, a new class of recipient, or anything that would narrow your rights — are announced before they take effect, by email to account holders or a notice in the application, and where the law requires consent we ask for it rather than assuming it.
Minor changes — clarifications, corrections, a renamed provider, a rewritten sentence — take effect when published, with the date moved.
Continuing to use the Services after an updated policy takes effect means the updated policy applies to that use, to the extent the law permits. If you disagree with a change, you may stop using the Services and, where you hold an account, delete your data as described above.
We do not remove old versions from our records. If you want to know what this document said on a particular date, ask at support@rentflow360.com.
Kips Reality L.L.C (RentFlow360) Washington State, United States Email: support@rentflow360.com
Write to that address for anything in this policy: a question, a rights request, a correction, a complaint, an appeal, a request for our postal address, or a request for a copy of our transfer terms. Requests from customers, tenants, applicants, owners, vendors, and people with no account at all are all handled at the same address.
What to include
Tell us what you want and give us enough to find you. For a rights request that usually means the name and email address on the record, and where a tenancy is involved, the property address and, if you know it, the organization managing it. For an appeal, put "Appeal" in the subject and include our earlier response.
What happens next
We acknowledge, verify you to the extent the request requires, and respond within the period the applicable law allows — the timing, verification, and appeal mechanics are set out in the rights section above. Where the request concerns records a customer controls, we forward it to them and tell you we have.
If you are not satisfied
Tell us, and we will look again. You are also entitled to complain to your state attorney general, or to your supervisory authority if you are covered by European or United Kingdom law. We would rather hear it first and fix it.
Security reports
Suspected vulnerabilities go to the address on our security page, which sets out what we ask of researchers and what we commit to in return.
Nothing in this policy waives or limits a privacy right or protection that cannot lawfully be waived. If a provision here conflicts with a mandatory requirement of a law that applies to you, that requirement governs to the extent of the conflict, and the rest of this policy continues to apply.
If a provision is held unenforceable, it is severed and the remainder stands.
Our not enforcing a provision on one occasion is not a waiver of it on another.
Where this policy grants you more than a statute requires, we mean it: the wider commitment applies, and we will not argue that a narrower statutory floor displaces something we chose to promise.
This Privacy Policy is effective as of August 22, 2026, and replaces all previous versions.
| Version | What changed |
|---|---|
| August 22, 2026 | Substantially expanded. Added: the controller and processor distinction as a standalone section; rent reporting to Experian RentBureau, with the exact fields furnished; the AI-assisted features, document extraction, income verification, and the retention scoring model, named individually; a cookie table; a retention table; a full CCPA category disclosure; state-by-state rights; consumer health data; fair housing; GLBA; a statement of where the Services are and are not offered; and a security section that lists what we do not have as well as what we do. Removed a claim to backup procedures that our security page had already withdrawn |
| August 19, 2026 | Named Kips Reality L.L.C as the responsible entity, added the Sensitive Personal Information disclosure covering Social Security and taxpayer identification numbers, and set Washington as the governing jurisdiction |
| June 23, 2026 | The previous published version |
Earlier versions are retained in our records. To see what this document said on a particular date, write to support@rentflow360.com.