Last updated August 21, 2026
Privacy Policy
This Privacy Policy describes how TenantBinder (“TenantBinder”, “we”, “us”, or “our”) collects, uses, discloses, and retains information in connection with the TenantBinder website, web portal, and mobile applications, together with all related products, features, and services (collectively, the “Service”). This Privacy Policy is incorporated into and forms part of our Terms of Use.
Who we are. TenantBinder is run by one person, not a company. The controller of the personal data described here — the person who decides why and how it is handled — is the owner of TenantBinder, acting as a private individual. There is no company behind the Service and no registered office, so there is no postal address we can give you. Write to [email protected]. That address reaches the controller directly, and it is the address for every request described in this Policy.
Any dispute, controversy, or claim arising out of or relating to this Privacy Policy or our data practices is a “Dispute” subject to the Dispute Resolution provisions of the Terms of Use, including the agreement to arbitrate and the class action waiver contained there.
1. Information We Collect
We collect information you provide directly, information generated when the Service is used, and information collected automatically. Depending on how you and the other parties to your agreements interact with the Service, this may include, without limitation:
- Account and identity data: name, legal name used for signing, email address, phone number, password or other credentials, account identifiers, and account settings;
- Agreement data: information entered into or generated around rental agreements and related documents — property details, lease terms, rent and deposit amounts, names and contact details of landlords, tenants, occupants, guarantors, and representatives, negotiation history, approvals, change requests, and comments;
- Signing and verification data: one-time verification codes sent to your email and phone and the fact and time of their confirmation, drawn signature images, consent records, document hashes, IP addresses, device identifiers, and server-side timestamps forming the audit trail of each signing ceremony;
- Uploaded content: documents and files you store with the Service. Certain documents are end-to-end encrypted; we hold only ciphertext and associated metadata (file names as stored, sizes, timestamps) and cannot read their contents;
- Purchase data: subscription status, product identifiers, and transaction metadata received from the Apple App Store or Google Play. Payment is processed by Apple or Google under their own terms; we do not collect or store your payment card details;
- Communications: correspondence with our support and the contents of messages you send us;
- Usage and device data (collected automatically): IP address, device and operating system characteristics, application version, language, log and diagnostic data, crash reports, feature usage, screens viewed, actions taken, and similar analytics events, collected directly and through analytics tools and similar technologies.
You represent that all information you provide is true, complete, and accurate. If you enter someone else’s details — a tenant, a landlord, an occupant, a guarantor — we are the controller of that information too, not you and not us on your behalf. You are still responsible for the details you enter being correct, and for having a reason to enter them. When you invite a tenant, we tell them by email that you gave us their details and how to reach us about it.
2. How We Use Information
We use the information we collect for any of the following purposes, and for any other purpose disclosed to you at the time of collection or to which you consent:
- to provide, operate, maintain, and improve the Service, including creating, negotiating, signing, and delivering agreements between the parties;
- to verify signer identity, generate and preserve signing audit trails, and maintain the evidentiary integrity of executed documents;
- to create, administer, and secure accounts, and to communicate with you about the Service, including transactional, technical, and security notices you cannot opt out of;
- to send marketing and product communications where permitted by law (you may opt out of marketing communications at any time);
- to analyze usage, monitor performance, debug, and develop new products and features;
- to detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Use;
- to comply with legal obligations, enforce our agreements, and establish, exercise, or defend legal claims;
- in aggregated, de-identified, or anonymized form for any purpose, without restriction — such data is not personal information and this Privacy Policy does not apply to it.
Where the law asks us to name a ground for what we do, these are the grounds, purpose by purpose:
- Creating, negotiating, signing, and delivering agreements — performance of a contract. This is the Service you asked us for, and it cannot be done without this information;
- Verifying a signer’s identity and keeping the signing record — performance of a contract, and a legitimate interest in the record holding up later. A signature is worth little if nobody can show afterwards who signed it and when;
- Running and securing accounts, and sending transactional messages — performance of a contract. You cannot have an account, or be told what happened to your agreement, without them;
- Keeping executed documents and their audit trails — a legitimate interest in evidence, and a legal obligation where one applies. Every party to a signed agreement may need to prove years later what it said;
- Product analytics and install attribution — consent. You give it in the app, and you withdraw it with the switch in Settings; nothing is sent from the app before you agree;
- Recording that a purchase, a renewal or a refund went through — a legitimate interest in knowing that paying for the app works. Our server sends those few events by itself, so the switch in the app does not cover them;
- Marketing messages — consent. You give it when you ask for them, and you withdraw it with the unsubscribe link in any of them;
- Answering a legal request — a legal obligation. Where a law, a court, or an authority requires us to produce something, we have no choice about it.
3. How We Share Information
We do not sell your personal information for money.
These are the companies that actually receive personal data when you use the Service. We have no data-processing contract with any of them beyond the terms each of them publishes for its own service, and we do not claim otherwise.
- Amplitude — product analytics events and a user identifier, in its European data region. The app sends its events only if you agreed to analytics in the app. Our server sends Amplitude a short list of subscription events of its own — a purchase, a renewal, a refund, the end of a paid period — under the same user identifier, and the switch in the app does not stop those;
- AppsFlyer — install attribution: device and advertising identifiers, and the fact of an install. Only if you agreed to analytics in the app. We never disclose the contents of your agreements or documents to it, or to any other advertiser. To the extent this counts as a “sale” or “sharing” under applicable state law, you may opt out as described in our Do Not Sell or Share My Personal Information notice;
- Postmark — every email we send: your address and the contents of the message;
- Twilio Verify, with Telnyx as a fallback — verification text messages: your phone number and the code;
- Cloudflare — every request to our website and to our servers passes through it, including everything the app sends and receives, so it sees your IP address, what you asked for, what your browser or phone says about itself, and the contents of the request;
- Our hosting provider in France — everything the Service stores, at rest;
- Apple and Google — purchases and refunds, and delivery of push notifications. If you sign in with your Apple or Google account, they also see that you signed in to TenantBinder, and they pass us the name and email address held on that account;
- DigiCert, Sectigo, Apple, and FreeTSA — a document’s hash, and nothing else, so that a signed document carries a trusted timestamp.
We also share information in these situations:
- Other parties to your agreements. The Service exists to share agreement data between the parties: landlords, tenants, and their representatives see the agreement content, party names and contact details, statuses, signatures, and audit information relevant to their agreement. Executed documents are delivered to every party;
- Professional advisors, such as lawyers, auditors, accountants, and insurers, in connection with the services they provide to us;
- Authorities and other parties where we believe in good faith that disclosure is appropriate: to comply with a law, regulation, subpoena, court order, or other legal process; to respond to a lawful request; to enforce our Terms of Use; to protect the rights, property, or safety of TenantBinder, our users, or others; or to detect, prevent, or address fraud, security, or technical issues;
- Successors. In connection with, or during negotiations of, any merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our business or assets, information may be disclosed and transferred as a business asset;
- Affiliates — our current and future parents, subsidiaries, and companies under common control.
4. Text Messages (SMS)
The only text messages we send are one-time verification codes. TenantBinder does not send marketing, promotional, or advertising text messages, does not operate recurring or subscription SMS programs, and does not text you about anything other than a code you asked for.
How the code is requested. A text message is sent only when you, signed in to your own TenantBinder account, start a signing ceremony for a document addressed to you, read and accept the Electronic Records and Signatures Disclosure and Consent — which states that a mobile telephone able to receive SMS is one of the two identity credentials verified during signing — confirm on the “Where we reach you” screen the mobile number the code should go to, and ask us to send it. Each message is the direct result of that request. The mobile number used is the one on the agreement for you, or the one you enter yourself when the agreement holds none; you may correct it before the code is sent.
Frequency and cost. One message per request — normally one per signing, plus any resend you ask for, subject to rate limits we apply. Message and data rates may apply under your mobile plan; we do not charge you for the message. Delivery depends on mobile carriers we do not control, and we do not guarantee that any message will arrive.
Stopping messages. Because each message is a one-time code you request, simply not requesting one stops them. You may also reply STOP to any message to stop text messages from that number, and HELP for help, or contact [email protected]. Stopping text messages does not affect email, and does not close your account — but a signing cannot be completed electronically without the text-message check, because that check is part of how the signature is verified.
We do not share your mobile number, or your consent to receive text messages, with any third party or affiliate for their own marketing or promotional purposes. No mobile information obtained through the text-message verification described here is sold, rented, or shared for such purposes. We disclose the number only to the SMS provider that transmits the message for us, and to the other parties to your agreement to the extent the number forms part of the agreement itself.
What we record. The mobile number, the time a code was sent and its delivery outcome, and the time it was confirmed, are recorded as part of the signing audit trail and retained as described under “Data Retention”. The code itself is stored only as a hash, expires within ten (10) minutes, and can be attempted a limited number of times.
EEA and UK. Where the GDPR or UK GDPR applies, we process the mobile number and the related verification records on the following legal bases: performance of a contract (Article 6(1)(b)) — the two-channel identity check is an essential part of the signing service you asked us to perform; our legitimate interests (Article 6(1)(f)) in preventing fraud and preserving the evidentiary integrity of executed documents; the consent you give in the Electronic Records and Signatures Disclosure for the electronic transaction (Article 6(1)(a)); and compliance with legal obligations (Article 6(1)(c)) where retention of signing evidence is required. Verification codes are not direct marketing and are therefore outside the electronic-marketing consent rules of the ePrivacy Directive and the UK PECR. Transfers outside the EEA or the UK rely on the safeguards described under “International Transfers”. You may exercise the rights described under “Your Choices and Rights” and, if you are not satisfied, lodge a complaint with your supervisory authority.
United States. Text messages sent under this section are transactional messages sent at your request. They are not telemarketing, and we do not use automated dialing to send marketing messages. Your consent to receive a verification code is not a condition of any purchase.
Availability. We can send verification codes only to mobile numbers in the countries the Service supports at the time. If we cannot text your number, the signing cannot be completed electronically.
5. Agreement Content and Encrypted Documents
Information entered into agreements is stored and processed to operate the Service — to display, synchronize, negotiate, sign, and deliver your documents — and for the other purposes described in this Privacy Policy. We do not use the contents of your agreements to build advertising profiles and do not sell them.
Documents stored in the encrypted binder are end-to-end encrypted. We hold ciphertext only, do not possess the keys needed to read it, and therefore cannot review, produce, restore, or recover such content — including in response to your own request — if the associated keys are lost. You are solely responsible for safeguarding keys in your control and for keeping your own copies of important documents.
6. Cookies and Similar Technologies
We and our service providers use cookies, local storage, software development kits, and similar technologies to operate the Service (authentication, security, preferences), to collect the usage and device data described above, and for the advertising and measurement activities described in Section 3. Essential technologies cannot be disabled without breaking the Service. You can limit non-essential technologies through your browser or device settings. Disabling technologies may impair functionality, and we are not responsible for any resulting degradation.
7. Data Retention
We retain information for as long as we consider it necessary for the purposes described in this Privacy Policy, including operating the Service, complying with legal obligations, resolving disputes, enforcing agreements, and maintaining business records, and thereafter for the duration of any applicable limitation periods.
Executed documents are different. Signed agreements, their final executed versions, and the associated signing audit trails have ongoing evidentiary value for every party to them. We may retain them, and the verification records supporting them, for at least seven (7) years from execution — and longer where the nature of the document, a legal obligation, a legal hold, or a dispute warrants it — notwithstanding any account deletion or erasure request. Deleting your account does not delete executed documents or audit trails, and does not remove copies already delivered to other parties.
Residual copies may persist in routine backups for a period after deletion. We may retain and use aggregated, de-identified, or anonymized data indefinitely.
8. Security
We implement technical and organizational measures that we consider reasonable and appropriate for the nature of the information we process. However, no method of transmission over the Internet and no method of electronic storage is completely secure, and we do not promise or guarantee that our security measures cannot be defeated. Transmission of information to and from the Service is at your own risk, and you are responsible for the security of your own devices, credentials, and keys. To the fullest extent permitted by law, we disclaim liability for unauthorized access to or acquisition of information resulting from circumvention of our security measures; the Disclaimer of Warranties and Limitations of Liability in our Terms of Use apply to this Privacy Policy in full.
9. International Transfers
The servers that run TenantBinder are in France, so that is where your data is stored. The United Kingdom recognises the EEA as giving adequate protection, so data from the UK is covered by that finding. Getting to those servers is a separate matter: a request does not always stay inside the EEA on the way.
Some of the companies listed in Section 3 handle data outside the EEA — Amplitude keeps ours in its European region, but Cloudflare, Postmark, Twilio, Telnyx, AppsFlyer, Apple, and Google do not. Cloudflare is the one every single request goes through, at whichever of its locations around the world is nearest to you. Each of them publishes its own transfer terms; we have not negotiated a separate transfer agreement with any of them, and we are telling you that rather than implying one exists.
10. Your Choices and Rights
Depending on where you reside, applicable law may give you rights with respect to your personal information, such as the right to access, correct, delete, or receive a copy of it, to object to or restrict certain processing, or to withdraw consent. We honor such rights to the extent applicable law actually requires; nothing in this Privacy Policy grants rights beyond those provided by applicable law.
To exercise a right, contact us at [email protected], or write to the controller directly at [email protected]. We may require verification of your identity, and, where an agent submits a request, written proof of authorization. We may decline requests that are unverifiable, manifestly unfounded, excessive, or repetitive, or where an exception applies — including where the information is part of an executed document or signing audit trail retained under the “Data Retention” section, is subject to a legal hold, is end-to-end encrypted content we cannot access, is another user’s information, or must be retained to comply with law, resolve disputes, or enforce agreements. We will respond within the time required by applicable law.
Getting a copy of your data. Open Settings in the app and use “Export my data”. It answers with a JSON file holding the rows that name you.
Complaining. If you are in the EEA or the UK and you are not happy with how we handle your data, you can complain to your country’s data protection authority. You do not have to come to us first.
Taking back your agreement to analytics. The app sends analytics only after you agree to it. Turn the analytics switch off in Settings and the app stops sending it. The subscription events our server records, named in Section 3, carry on, because they never ran on your agreement in the first place.
We do not discriminate against you for exercising rights applicable law gives you. You may opt out of marketing communications at any time via the unsubscribe mechanism or by contacting support; transactional and security communications are part of the Service and cannot be opted out of while you maintain an account.
11. US State Privacy Disclosures
For residents of US states with comprehensive privacy laws (including California): the categories of personal information we collect are described in Section 1; the purposes are described in Section 2; the categories of recipients are described in Section 3. We do not sell personal information for money. Our use of advertising, attribution, and measurement tools may constitute “selling” or “sharing” of limited technical identifiers under some state laws; you may opt out as described in our Do Not Sell or Share My Personal Information notice. We do not use or disclose sensitive personal information for purposes other than those permitted by applicable law without the required consent. We do not knowingly process personal information of consumers under 16 for sale or sharing. California’s “Shine the Light” law: we do not disclose personal information to third parties for their own direct marketing purposes. To exercise rights under these laws, or to appeal a refusal, contact [email protected].
12. Your Rights Where You Live
The European Economic Area and the United Kingdom (GDPR, UK GDPR). You can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to erase it, ask us to stop or to limit what we do with it, ask for it in a form you can take elsewhere, object to processing we base on a legitimate interest, and take back any consent you have given. Write to [email protected]. If you are not happy with the answer, you can complain to your country’s data protection authority.
We have not appointed a representative under Article 27 of the GDPR for the European Union, and none under the UK GDPR for the United Kingdom. There is no local representative to write to. Write to [email protected].
Brazil (LGPD). You can ask us to confirm that we handle your personal data, to show you what we hold, to correct it, to make it anonymous or delete it, to give it to you in a form you can take elsewhere, and to tell you who we share it with. You can also take back any consent you have given. Write to [email protected].
India (DPDP). You can ask to see the personal data we hold about you, ask us to correct or complete it, ask us to erase it, and name someone to act for you if you cannot act yourself. If something goes wrong, write to [email protected] — that is our grievance route, and the same person reads it and answers it.
13. Children
The Service is intended for users who are at least 18 years old, and we do not knowingly collect personal information from anyone under 18 (or under 13 for the purposes of COPPA). If we learn that we have collected personal information from a child, we will take reasonable measures to delete it. If you believe a child has provided us personal information, contact [email protected].
14. Third-Party Services
The Service may contain links to, or interoperate with, websites and services operated by third parties, including Apple and Google. This Privacy Policy does not apply to third-party websites or services, we are not responsible for their privacy practices, and we encourage you to review their policies. Information you disclose directly to a third party (including to another user outside the Service) is not governed by this Privacy Policy.
15. Changes to This Privacy Policy
We may update this Privacy Policy at any time and for any reason. The updated version will be indicated by the “Last updated” date above and is effective when posted. Where a change needs your agreement, we will ask you for it. We encourage you to review this Privacy Policy periodically.
16. Contact Us
If you have questions or comments about this Privacy Policy or our data practices, or wish to exercise a privacy right, contact us at [email protected].