Privacy Policy

This Privacy Policy describes how TenantBinder (“TenantBinder”, “we”, “us”, or “our”) collects, uses, discloses, and retains information in connection with the TenantBinder website, web portal, and mobile applications, together with all related products, features, and services (collectively, the “Service”). This Privacy Policy is incorporated into and forms part of our Terms of Use. By accessing or using the Service, you consent to the practices described in this Privacy Policy; if you do not agree, you must not use the Service.

Any dispute, controversy, or claim arising out of or relating to this Privacy Policy or our data practices is a “Dispute” subject to the Dispute Resolution provisions of the Terms of Use, including the agreement to arbitrate and the class action waiver contained there.

1. Information We Collect

We collect information you provide directly, information generated when the Service is used, and information collected automatically. Depending on how you and the other parties to your agreements interact with the Service, this may include, without limitation:

You represent that all information you provide is true, complete, and accurate. If you provide personal information about any other individual (such as a tenant, landlord, occupant, or guarantor), you do so as the controller of that information: you are solely responsible for having a lawful basis to collect and submit it, and we process it on your behalf solely to provide the Service.

2. How We Use Information

We use the information we collect for any of the following purposes, and for any other purpose disclosed to you at the time of collection or to which you consent:

Where a legal basis is required, we rely on performance of a contract, our legitimate interests (including operating, securing, improving, and promoting the Service), compliance with legal obligations, and consent where applicable law requires it.

3. How We Share Information

We do not sell your personal information for money. We may share information with the following categories of recipients, at any time and to the extent we consider necessary:

4. Text Messages (SMS)

The only text messages we send are one-time verification codes. TenantBinder does not send marketing, promotional, or advertising text messages, does not operate recurring or subscription SMS programs, and does not text you about anything other than a code you asked for.

How the code is requested. A text message is sent only when you, signed in to your own TenantBinder account, start a signing ceremony for a document addressed to you, read and accept the Electronic Records and Signatures Disclosure and Consent — which states that a mobile telephone able to receive SMS is one of the two identity credentials verified during signing — confirm on the “Where we reach you” screen the mobile number the code should go to, and ask us to send it. Each message is the direct result of that request. The mobile number used is the one on the agreement for you, or the one you enter yourself when the agreement holds none; you may correct it before the code is sent.

Frequency and cost. One message per request — normally one per signing, plus any resend you ask for, subject to rate limits we apply. Message and data rates may apply under your mobile plan; we do not charge you for the message. Delivery depends on mobile carriers we do not control, and we do not guarantee that any message will arrive.

Stopping messages. Because each message is a one-time code you request, simply not requesting one stops them. You may also reply STOP to any message to stop text messages from that number, and HELP for help, or contact [email protected]. Stopping text messages does not affect email, and does not close your account — but a signing cannot be completed electronically without the text-message check, because that check is part of how the signature is verified.

We do not share your mobile number, or your consent to receive text messages, with any third party or affiliate for their own marketing or promotional purposes. No mobile information obtained through the text-message verification described here is sold, rented, or shared for such purposes. We disclose the number only to the SMS provider that transmits the message for us, and to the other parties to your agreement to the extent the number forms part of the agreement itself.

What we record. The mobile number, the time a code was sent and its delivery outcome, and the time it was confirmed, are recorded as part of the signing audit trail and retained as described under “Data Retention”. The code itself is stored only as a hash, expires within ten (10) minutes, and can be attempted a limited number of times.

EEA and UK. Where the GDPR or UK GDPR applies, we process the mobile number and the related verification records on the following legal bases: performance of a contract (Article 6(1)(b)) — the two-channel identity check is an essential part of the signing service you asked us to perform; our legitimate interests (Article 6(1)(f)) in preventing fraud and preserving the evidentiary integrity of executed documents; the consent you give in the Electronic Records and Signatures Disclosure for the electronic transaction (Article 6(1)(a)); and compliance with legal obligations (Article 6(1)(c)) where retention of signing evidence is required. Verification codes are not direct marketing and are therefore outside the electronic-marketing consent rules of the ePrivacy Directive and the UK PECR. Our SMS provider acts as a processor on our instructions under a data processing agreement; transfers outside the EEA or the UK rely on the safeguards described under “International Transfers”. You may exercise the rights described under “Your Choices and Rights” and, if you are not satisfied, lodge a complaint with your supervisory authority.

United States. Text messages sent under this section are transactional messages sent at your request. They are not telemarketing, and we do not use automated dialing to send marketing messages. Your consent to receive a verification code is not a condition of any purchase.

Availability. We can send verification codes only to mobile numbers in the countries the Service supports at the time. If we cannot text your number, the signing cannot be completed electronically.

5. Agreement Content and Encrypted Documents

Information entered into agreements is stored and processed to operate the Service — to display, synchronize, negotiate, sign, and deliver your documents — and for the other purposes described in this Privacy Policy. We do not use the contents of your agreements to build advertising profiles and do not sell them.

Documents stored in the encrypted binder are end-to-end encrypted. We hold ciphertext only, do not possess the keys needed to read it, and therefore cannot review, produce, restore, or recover such content — including in response to your own request — if the associated keys are lost. You are solely responsible for safeguarding keys in your control and for keeping your own copies of important documents.

6. Cookies and Similar Technologies

We and our service providers use cookies, local storage, software development kits, and similar technologies to operate the Service (authentication, security, preferences), to collect the usage and device data described above, and for the advertising and measurement activities described in Section 3. Essential technologies cannot be disabled without breaking the Service. You can limit non-essential technologies through your browser or device settings; where applicable law requires, we honor opt-out preference signals such as Global Privacy Control for the activities they cover. Disabling technologies may impair functionality, and we are not responsible for any resulting degradation.

7. Data Retention

We retain information for as long as we consider it necessary for the purposes described in this Privacy Policy, including operating the Service, complying with legal obligations, resolving disputes, enforcing agreements, and maintaining business records, and thereafter for the duration of any applicable limitation periods.

Executed documents are different. Signed agreements, their final executed versions, and the associated signing audit trails have ongoing evidentiary value for every party to them. We may retain them, and the verification records supporting them, for at least seven (7) years from execution — and longer where the nature of the document, a legal obligation, a legal hold, or a dispute warrants it — notwithstanding any account deletion or erasure request. Deleting your account does not delete executed documents or audit trails, and does not remove copies already delivered to other parties.

Residual copies may persist in routine backups for a period after deletion. We may retain and use aggregated, de-identified, or anonymized data indefinitely.

8. Security

We implement technical and organizational measures that we consider reasonable and appropriate for the nature of the information we process. However, no method of transmission over the Internet and no method of electronic storage is completely secure, and we do not promise or guarantee that our security measures cannot be defeated. Transmission of information to and from the Service is at your own risk, and you are responsible for the security of your own devices, credentials, and keys. To the fullest extent permitted by law, we disclaim liability for unauthorized access to or acquisition of information resulting from circumvention of our security measures; the Disclaimer of Warranties and Limitations of Liability in our Terms of Use apply to this Privacy Policy in full.

9. International Transfers

We operate internationally, and information may be transferred to, stored in, and processed in countries other than the one in which you reside, including countries whose data protection laws differ from those of your jurisdiction. By using the Service, you consent to the transfer of your information to such countries. Where applicable law requires a specific transfer mechanism, we rely on available safeguards such as standard contractual clauses.

10. Your Choices and Rights

Depending on where you reside, applicable law may give you rights with respect to your personal information, such as the right to access, correct, delete, or receive a copy of it, to object to or restrict certain processing, or to withdraw consent. We honor such rights to the extent applicable law actually requires; nothing in this Privacy Policy grants rights beyond those provided by applicable law.

To exercise a right, contact us at [email protected]. We may require verification of your identity, and, where an agent submits a request, written proof of authorization. We may decline requests that are unverifiable, manifestly unfounded, excessive, or repetitive, or where an exception applies — including where the information is part of an executed document or signing audit trail retained under the “Data Retention” section, is subject to a legal hold, is end-to-end encrypted content we cannot access, is another user’s information, or must be retained to comply with law, resolve disputes, or enforce agreements. We will respond within the time required by applicable law. Where you request deletion of information another user submitted about you as part of an agreement, we may direct you to that user, who is the controller of that information.

We do not discriminate against you for exercising rights applicable law gives you. You may opt out of marketing communications at any time via the unsubscribe mechanism or by contacting support; transactional and security communications are part of the Service and cannot be opted out of while you maintain an account.

11. US State Privacy Disclosures

For residents of US states with comprehensive privacy laws (including California): the categories of personal information we collect are described in Section 1; the purposes are described in Section 2; the categories of recipients are described in Section 3. We do not sell personal information for money. Our use of advertising, attribution, and measurement tools may constitute “selling” or “sharing” of limited technical identifiers under some state laws; you may opt out as described in our Do Not Sell or Share My Personal Information notice. We do not use or disclose sensitive personal information for purposes other than those permitted by applicable law without the required consent. We do not knowingly process personal information of consumers under 16 for sale or sharing. California’s “Shine the Light” law: we do not disclose personal information to third parties for their own direct marketing purposes. To exercise rights under these laws, or to appeal a refusal, contact [email protected].

12. Children

The Service is intended for users who are at least 18 years old, and we do not knowingly collect personal information from anyone under 18 (or under 13 for the purposes of COPPA). If we learn that we have collected personal information from a child, we will take reasonable measures to delete it. If you believe a child has provided us personal information, contact [email protected].

13. Third-Party Services

The Service may contain links to, or interoperate with, websites and services operated by third parties, including Apple and Google. This Privacy Policy does not apply to third-party websites or services, we are not responsible for their privacy practices, and we encourage you to review their policies. Information you disclose directly to a third party (including to another user outside the Service) is not governed by this Privacy Policy.

14. Changes to This Privacy Policy

We may update this Privacy Policy at any time and for any reason. The updated version will be indicated by the “Last updated” date above and is effective when posted. Your continued use of the Service after the updated Privacy Policy is posted constitutes your acceptance of it. We encourage you to review this Privacy Policy periodically.

15. Contact Us

If you have questions or comments about this Privacy Policy or our data practices, or wish to exercise a privacy right, contact us at [email protected].