EliteRent

Privacy

Privacy Policy

Draft revision · not yet effective · last edited 2026-07-30

How EliteRent handles the information you and your applicants provide. This is a working draft written so counsel can finalize it — the structure and the facts about what the product does are real; the binding legal language is not yet in place.

Draft — pending legal review

This document is an internal working skeleton, not a binding policy. It has not been reviewed or approved by an attorney and does not take effect until it is. Sections marked TODO · counsel need real legal language before launch. Do not rely on anything here.

1. Who we are

EliteRent is landlord software operated by its owner, a landlord in Cary, North Carolina. It is currently in early access for North Carolina and Florida landlords. EliteRent is software — not a law firm, a bank, or a CPA.

TODO · counselConfirm the legal controller entity (individual vs. LLC), business address, and — for any EU/UK data subjects — whether a representative is required.

2. Information we collect

We collect only what the product needs to do its job:

  • Account details — your name, email, and password credentials (passwords are stored only as a salted hash), plus optional two-factor authentication secrets.
  • Portfolio data you enter — properties, units, tenants, pets, leases, tasks, and the financial fields you record.
  • Bank-connection data — when you connect an account through Plaid, EliteRent receives read-only balances and transactions. It never receives your online-banking password and never moves money.
  • Documents you upload — leases, receipts, insurance, and similar files kept in your document vault.
  • Rental-application data — information applicants submit through your public application links (no applicant accounts are created).
  • Usage & diagnostics — basic telemetry and error/performance monitoring to keep the service reliable.

TODO · counselConfirm the exact field-level inventory (especially any data that could be considered sensitive, e.g. applicant financial details) and whether a cookie/consent banner is required for the telemetry above.

3. How we use it

To operate the service you asked for: watching for rent, keeping your books, generating documents you request, running the AI features you invoke, sending the digests and alerts you enable, and securing your account. We do not sell your data.

TODO · counselConfirm the lawful bases (contract / legitimate interest / consent), any marketing-communication practices, and an explicit "no sale / no cross-context behavioral advertising" statement for state privacy laws.

4. Subprocessors

EliteRent relies on a small set of vendors to run. Each receives only the data needed for its function:

Amazon Web Services

Cloud hosting, database, file storage, and transactional email (SES).

Data shared: All application data at rest and in transit; outbound email content.

Plaid

Secure, read-only bank-account connections and transaction data.

Data shared: Bank-connection tokens and the account/transaction data you link.

Stripe

Subscription billing and payment processing (when billing is enabled).

Data shared: Billing contact and payment details (handled by Stripe, not stored by us).

Amazon Bedrock

AI features: categorization, document extraction, and drafted prose.

Data shared: The specific records you submit to an AI action at the moment you invoke it.

TODO · counselConfirm this is the complete subprocessor list, that a signed DPA is in place with each, the processing regions, and whether a public subprocessor page + change-notice commitment is needed.

5. Data retention

We keep your data while your account is active. Two retention behaviors are already built into the product:

  • Rental applications — 90-day purge. A rental application that is not converted into a tenant is hard-deleted (its records and uploaded files) about 90 days after submission (or after a decline decision). Converted applications are kept as part of the tenant record.
  • Backups. The database is covered by 14 days of automated point-in-time backups, plus a weekly logical export retained in encrypted storage.

TODO · counselSet the retention period for account data after an account is closed, for closed-out financial records (tax/regulatory minimums), and for backups/logs; confirm how the 90-day applicant purge interacts with a deletion request.

6. Security

Data is encrypted in transit and at rest, bank tokens are additionally sealed with application-level encryption, access is least-privilege, and two-factor authentication is available on your account.

TODO · counselHave counsel/security confirm the wording so it neither over-claims nor under-states, and add the breach-notification commitment and timeline.

7. Your choices and rights

You can access and export your data and request deletion of your account. Depending on where you live, you may have additional rights under laws such as the CCPA/CPRA or GDPR.

TODO · counselEnumerate the specific rights, the request/verification process, the response timeline, and the appeal path required by the applicable statutes.

8. Changes to this policy

When this policy is finalized and later updated, we will revise the date at the top and, for material changes, notify account holders.

TODO · counselConfirm the notice mechanism and how prior versions are archived.

9. Contact

Questions about privacy can be sent to privacy@eliterentapp.com.

TODO · counselProvision the privacy@ mailbox (or set the real controller contact) before launch and confirm it here.