Last updated August 15, 2026
Privacy Policy
This Privacy Policy describes how TenantBinder (“TenantBinder”, “we”, “us”, or “our”) collects, uses, discloses, and retains information in connection with the TenantBinder website, web portal, and mobile applications, together with all related products, features, and services (collectively, the “Service”). This Privacy Policy is incorporated into and forms part of our Terms of Use. By accessing or using the Service, you consent to the practices described in this Privacy Policy; if you do not agree, you must not use the Service.
Any dispute, controversy, or claim arising out of or relating to this Privacy Policy or our data practices is a “Dispute” subject to the Dispute Resolution provisions of the Terms of Use, including the agreement to arbitrate and the class action waiver contained there.
1. Information We Collect
We collect information you provide directly, information generated when the Service is used, and information collected automatically. Depending on how you and the other parties to your agreements interact with the Service, this may include, without limitation:
- Account and identity data: name, legal name used for signing, email address, phone number, password or other credentials, account identifiers, and account settings;
- Agreement data: information entered into or generated around rental agreements and related documents — property details, lease terms, rent and deposit amounts, names and contact details of landlords, tenants, occupants, guarantors, and representatives, negotiation history, approvals, change requests, and comments;
- Signing and verification data: one-time verification codes sent to your email and phone and the fact and time of their confirmation, drawn signature images, consent records, document hashes, IP addresses, device identifiers, and server-side timestamps forming the audit trail of each signing ceremony;
- Uploaded content: documents and files you store with the Service. Certain documents are end-to-end encrypted; we hold only ciphertext and associated metadata (file names as stored, sizes, timestamps) and cannot read their contents;
- Purchase data: subscription status, product identifiers, and transaction metadata received from the Apple App Store or Google Play. Payment is processed by Apple or Google under their own terms; we do not collect or store your payment card details;
- Communications: correspondence with our support and the contents of messages you send us;
- Usage and device data (collected automatically): IP address, device and operating system characteristics, application version, language, log and diagnostic data, crash reports, feature usage, screens viewed, actions taken, and similar analytics events, collected directly and through analytics tools and similar technologies.
You represent that all information you provide is true, complete, and accurate. If you provide personal information about any other individual (such as a tenant, landlord, occupant, or guarantor), you do so as the controller of that information: you are solely responsible for having a lawful basis to collect and submit it, and we process it on your behalf solely to provide the Service.
2. How We Use Information
We use the information we collect for any of the following purposes, and for any other purpose disclosed to you at the time of collection or to which you consent:
- to provide, operate, maintain, and improve the Service, including creating, negotiating, signing, and delivering agreements between the parties;
- to verify signer identity, generate and preserve signing audit trails, and maintain the evidentiary integrity of executed documents;
- to create, administer, and secure accounts, and to communicate with you about the Service, including transactional, technical, and security notices you cannot opt out of;
- to send marketing and product communications where permitted by law (you may opt out of marketing communications at any time);
- to analyze usage, monitor performance, debug, and develop new products and features;
- to detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Use;
- to comply with legal obligations, enforce our agreements, and establish, exercise, or defend legal claims;
- in aggregated, de-identified, or anonymized form for any purpose, without restriction — such data is not personal information and this Privacy Policy does not apply to it.
Where a legal basis is required, we rely on performance of a contract, our legitimate interests (including operating, securing, improving, and promoting the Service), compliance with legal obligations, and consent where applicable law requires it.
3. How We Share Information
We do not sell your personal information for money. We may share information with the following categories of recipients, at any time and to the extent we consider necessary:
- Other parties to your agreements. The Service exists to share agreement data between the parties: landlords, tenants, and their representatives see the agreement content, party names and contact details, statuses, signatures, and audit information relevant to their agreement. Executed documents are delivered to every party;
- Service providers, such as hosting and infrastructure providers, content delivery and security networks, email and SMS delivery providers, analytics providers, crash reporting tools, and customer support tools, in each case to perform services on our behalf;
- App store and platform providers (Apple, Google) in connection with distribution, billing, and refunds;
- Advertising, attribution, and measurement partners, which may process limited technical data — advertising and device identifiers, click identifiers, IP address, and ad interaction and conversion events — to help us promote the Service and measure advertising performance. We never disclose the contents of your agreements or documents to advertisers. To the extent such processing is a “sale” or “sharing” under applicable state law, you may opt out as described in our Do Not Sell or Share My Personal Information notice;
- Professional advisors, such as lawyers, auditors, accountants, and insurers, in connection with the services they provide to us;
- Authorities and other parties where we believe in good faith that disclosure is appropriate: to comply with a law, regulation, subpoena, court order, or other legal process; to respond to a lawful request; to enforce our Terms of Use; to protect the rights, property, or safety of TenantBinder, our users, or others; or to detect, prevent, or address fraud, security, or technical issues;
- Successors. In connection with, or during negotiations of, any merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our business or assets, information may be disclosed and transferred as a business asset;
- Affiliates — our current and future parents, subsidiaries, and companies under common control.
4. Text Messages (SMS)
The only text messages we send are one-time verification codes. TenantBinder does not send marketing, promotional, or advertising text messages, does not operate recurring or subscription SMS programs, and does not text you about anything other than a code you asked for.
How the code is requested. A text message is sent only when you, signed in to your own TenantBinder account, start a signing ceremony for a document addressed to you, read and accept the Electronic Records and Signatures Disclosure and Consent — which states that a mobile telephone able to receive SMS is one of the two identity credentials verified during signing — confirm on the “Where we reach you” screen the mobile number the code should go to, and ask us to send it. Each message is the direct result of that request. The mobile number used is the one on the agreement for you, or the one you enter yourself when the agreement holds none; you may correct it before the code is sent.
Frequency and cost. One message per request — normally one per signing, plus any resend you ask for, subject to rate limits we apply. Message and data rates may apply under your mobile plan; we do not charge you for the message. Delivery depends on mobile carriers we do not control, and we do not guarantee that any message will arrive.
Stopping messages. Because each message is a one-time code you request, simply not requesting one stops them. You may also reply STOP to any message to stop text messages from that number, and HELP for help, or contact [email protected]. Stopping text messages does not affect email, and does not close your account — but a signing cannot be completed electronically without the text-message check, because that check is part of how the signature is verified.
We do not share your mobile number, or your consent to receive text messages, with any third party or affiliate for their own marketing or promotional purposes. No mobile information obtained through the text-message verification described here is sold, rented, or shared for such purposes. We disclose the number only to the SMS provider that transmits the message for us, and to the other parties to your agreement to the extent the number forms part of the agreement itself.
What we record. The mobile number, the time a code was sent and its delivery outcome, and the time it was confirmed, are recorded as part of the signing audit trail and retained as described under “Data Retention”. The code itself is stored only as a hash, expires within ten (10) minutes, and can be attempted a limited number of times.
EEA and UK. Where the GDPR or UK GDPR applies, we process the mobile number and the related verification records on the following legal bases: performance of a contract (Article 6(1)(b)) — the two-channel identity check is an essential part of the signing service you asked us to perform; our legitimate interests (Article 6(1)(f)) in preventing fraud and preserving the evidentiary integrity of executed documents; the consent you give in the Electronic Records and Signatures Disclosure for the electronic transaction (Article 6(1)(a)); and compliance with legal obligations (Article 6(1)(c)) where retention of signing evidence is required. Verification codes are not direct marketing and are therefore outside the electronic-marketing consent rules of the ePrivacy Directive and the UK PECR. Our SMS provider acts as a processor on our instructions under a data processing agreement; transfers outside the EEA or the UK rely on the safeguards described under “International Transfers”. You may exercise the rights described under “Your Choices and Rights” and, if you are not satisfied, lodge a complaint with your supervisory authority.
United States. Text messages sent under this section are transactional messages sent at your request. They are not telemarketing, and we do not use automated dialing to send marketing messages. Your consent to receive a verification code is not a condition of any purchase.
Availability. We can send verification codes only to mobile numbers in the countries the Service supports at the time. If we cannot text your number, the signing cannot be completed electronically.
5. Agreement Content and Encrypted Documents
Information entered into agreements is stored and processed to operate the Service — to display, synchronize, negotiate, sign, and deliver your documents — and for the other purposes described in this Privacy Policy. We do not use the contents of your agreements to build advertising profiles and do not sell them.
Documents stored in the encrypted binder are end-to-end encrypted. We hold ciphertext only, do not possess the keys needed to read it, and therefore cannot review, produce, restore, or recover such content — including in response to your own request — if the associated keys are lost. You are solely responsible for safeguarding keys in your control and for keeping your own copies of important documents.
6. Cookies and Similar Technologies
We and our service providers use cookies, local storage, software development kits, and similar technologies to operate the Service (authentication, security, preferences), to collect the usage and device data described above, and for the advertising and measurement activities described in Section 3. Essential technologies cannot be disabled without breaking the Service. You can limit non-essential technologies through your browser or device settings; where applicable law requires, we honor opt-out preference signals such as Global Privacy Control for the activities they cover. Disabling technologies may impair functionality, and we are not responsible for any resulting degradation.
7. Data Retention
We retain information for as long as we consider it necessary for the purposes described in this Privacy Policy, including operating the Service, complying with legal obligations, resolving disputes, enforcing agreements, and maintaining business records, and thereafter for the duration of any applicable limitation periods.
Executed documents are different. Signed agreements, their final executed versions, and the associated signing audit trails have ongoing evidentiary value for every party to them. We may retain them, and the verification records supporting them, for at least seven (7) years from execution — and longer where the nature of the document, a legal obligation, a legal hold, or a dispute warrants it — notwithstanding any account deletion or erasure request. Deleting your account does not delete executed documents or audit trails, and does not remove copies already delivered to other parties.
Residual copies may persist in routine backups for a period after deletion. We may retain and use aggregated, de-identified, or anonymized data indefinitely.
8. Security
We implement technical and organizational measures that we consider reasonable and appropriate for the nature of the information we process. However, no method of transmission over the Internet and no method of electronic storage is completely secure, and we do not promise or guarantee that our security measures cannot be defeated. Transmission of information to and from the Service is at your own risk, and you are responsible for the security of your own devices, credentials, and keys. To the fullest extent permitted by law, we disclaim liability for unauthorized access to or acquisition of information resulting from circumvention of our security measures; the Disclaimer of Warranties and Limitations of Liability in our Terms of Use apply to this Privacy Policy in full.
9. International Transfers
We operate internationally, and information may be transferred to, stored in, and processed in countries other than the one in which you reside, including countries whose data protection laws differ from those of your jurisdiction. By using the Service, you consent to the transfer of your information to such countries. Where applicable law requires a specific transfer mechanism, we rely on available safeguards such as standard contractual clauses.
10. Your Choices and Rights
Depending on where you reside, applicable law may give you rights with respect to your personal information, such as the right to access, correct, delete, or receive a copy of it, to object to or restrict certain processing, or to withdraw consent. We honor such rights to the extent applicable law actually requires; nothing in this Privacy Policy grants rights beyond those provided by applicable law.
To exercise a right, contact us at [email protected]. We may require verification of your identity, and, where an agent submits a request, written proof of authorization. We may decline requests that are unverifiable, manifestly unfounded, excessive, or repetitive, or where an exception applies — including where the information is part of an executed document or signing audit trail retained under the “Data Retention” section, is subject to a legal hold, is end-to-end encrypted content we cannot access, is another user’s information, or must be retained to comply with law, resolve disputes, or enforce agreements. We will respond within the time required by applicable law. Where you request deletion of information another user submitted about you as part of an agreement, we may direct you to that user, who is the controller of that information.
We do not discriminate against you for exercising rights applicable law gives you. You may opt out of marketing communications at any time via the unsubscribe mechanism or by contacting support; transactional and security communications are part of the Service and cannot be opted out of while you maintain an account.
11. US State Privacy Disclosures
For residents of US states with comprehensive privacy laws (including California): the categories of personal information we collect are described in Section 1; the purposes are described in Section 2; the categories of recipients are described in Section 3. We do not sell personal information for money. Our use of advertising, attribution, and measurement tools may constitute “selling” or “sharing” of limited technical identifiers under some state laws; you may opt out as described in our Do Not Sell or Share My Personal Information notice. We do not use or disclose sensitive personal information for purposes other than those permitted by applicable law without the required consent. We do not knowingly process personal information of consumers under 16 for sale or sharing. California’s “Shine the Light” law: we do not disclose personal information to third parties for their own direct marketing purposes. To exercise rights under these laws, or to appeal a refusal, contact [email protected].
12. Children
The Service is intended for users who are at least 18 years old, and we do not knowingly collect personal information from anyone under 18 (or under 13 for the purposes of COPPA). If we learn that we have collected personal information from a child, we will take reasonable measures to delete it. If you believe a child has provided us personal information, contact [email protected].
13. Third-Party Services
The Service may contain links to, or interoperate with, websites and services operated by third parties, including Apple and Google. This Privacy Policy does not apply to third-party websites or services, we are not responsible for their privacy practices, and we encourage you to review their policies. Information you disclose directly to a third party (including to another user outside the Service) is not governed by this Privacy Policy.
14. Changes to This Privacy Policy
We may update this Privacy Policy at any time and for any reason. The updated version will be indicated by the “Last updated” date above and is effective when posted. Your continued use of the Service after the updated Privacy Policy is posted constitutes your acceptance of it. We encourage you to review this Privacy Policy periodically.
15. Contact Us
If you have questions or comments about this Privacy Policy or our data practices, or wish to exercise a privacy right, contact us at [email protected].