Founder draft — attorney review required. This document is a working draft and has not been reviewed by counsel. It may change before RentThread launches publicly.

Privacy Policy

RentThread Privacy Policy

DRAFT — DO NOT PUBLISH UNTIL REVIEWED BY COUNSEL, MATCHED TO THE PRODUCTION DATA MAP, AND ALL PLACEHOLDERS ARE REPLACED

Effective: {{EFFECTIVE_DATE}}
Last updated: {{LAST_UPDATED_DATE}}

This Privacy Policy explains how {{LEGAL_ENTITY_NAME}} (“RentThread,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you use RentThread.com and related services that link to this Policy (collectively, the “Service”). It also explains your choices and privacy rights.

1. Privacy summary

RentThread is designed to let people contribute useful apartment information without publicly exposing sensitive residency details.

  • We separate public profiles and Property Aliases from private account ownership.
  • We do not display exact unit numbers, exact private stay dates, verification evidence, email addresses, or the account behind a Property Alias.
  • We do not sell personal information.
  • We do not share personal information for cross-context behavioral advertising or use targeted advertising at launch.
  • We do not give property owners or managers access to Property Alias ownership or verification evidence.
  • We collect and retain only the information reasonably needed for the purposes described here.
  • A Property Alias is publicly separated from your profile, but it is not a guarantee of anonymity against valid legal process.

2. Scope

This Policy applies to the Service and our interactions concerning it. It does not apply to an independently operated property, owner, manager, representative, government agency, linked website, or other third party. Those parties have their own practices and policies.

The Service is intended only for users in the United States who are at least 18 years old.

3. Information we collect

The information collected depends on the features you use.

A. Account and authentication information

  • Email address
  • Authentication identifiers and credential-verification status
  • Account creation, login, recovery, session, and security records
  • Age-eligibility confirmation
  • Terms and policy acceptance records

We do not receive your password in readable form when authentication is handled by our authentication provider.

B. Public profile information

  • Public handle and random public profile identifier
  • Optional avatar and biography
  • Contributions you choose to associate with your public profile
  • Public contribution totals, badges, and visibility settings

Your email, authentication identifier, and private residency information are not part of the public profile.

C. Property Alias information

  • Random Property Alias identifier
  • Property-specific alias display name
  • Public alias badge or status
  • Restricted account-to-alias ownership record
  • Alias rotation, restriction, and integrity history

The ownership record is kept in restricted systems and is not included in public content or public APIs.

D. Property connection and residency information

  • Property identity and address
  • Whether you describe yourself as a current resident, former resident, applicant, guest, employee, representative, or another permitted relationship
  • Broad occupancy period shown according to your settings
  • More precise dates used privately when needed for eligibility or integrity
  • Verification status, method, decision, and limited audit history
  • Information you provide to resolve an exception or appeal

At initial launch, RentThread does not accept leases, government IDs, utility bills, or similar sensitive documents. If document verification is enabled later, we will present an updated Notice at Collection and express consent before upload, restrict access, and follow the evidence-retention rules described below.

E. Contributions and community activity

  • Resident Reports, ratings, answers, questions, discussion posts, replies, edits, and attachments if enabled
  • Votes, saves, follows, accepted answers, subscriptions, and notification preferences
  • Drafts and publication settings
  • Reports, appeals, correction requests, and communications with moderators
  • The public profile, Property Alias, or representative identity you select for a contribution

Published contributions are public and may be indexed by search engines, quoted, copied, or shared by others. Do not include information you do not want made public.

F. Property Representative information

  • Name, work contact information, title, organization, and represented properties
  • Evidence and review records used to verify an organizational relationship
  • Official Responses and correction requests
  • Representative security, permission, and audit records

G. Communications

  • Support, privacy, legal, security, correction, copyright, and other messages
  • Survey or research responses
  • Email delivery, preference, and unsubscribe records

H. Device, network, usage, and security information

  • IP address
  • Browser, device, operating system, and language
  • Dates, times, referring pages, pages and features used, and request identifiers
  • Cookie and similar technology identifiers
  • Approximate region derived from IP; we do not request precise device geolocation at launch
  • Crash, performance, error, fraud, abuse, rate-limit, and security events
  • Signals reasonably needed to detect automated activity, account compromise, coordinated voting, evasion, or other misuse

We do not intentionally record review or message bodies in routine analytics, logs, or session replay.

I. Public and licensed property information

We may collect property names, former names, addresses, management or ownership periods, and other property facts from government records, authorized providers, property representatives, public sources, and user correction submissions. We maintain source and review information where appropriate.

J. Personal health information is not requested

RentThread asks about observable property conditions and property responses—not a person’s diagnosis, symptoms, medication, pregnancy, treatment, disability details, medical records, or medical causation. Do not submit that information about yourself or anyone else in a contribution, report, support message, or ordinary form.

If we encounter personal health information that was not requested, we may restrict, redact, or delete it; limit access while reviewing it; and retain only what is required for security, legal, or documented operational reasons. RentThread does not infer a person’s health condition from property activity, searches, reports, or other behavior.

4. Sources of information

We collect information:

  • Directly from you.
  • Automatically from your browser or device when you use the Service.
  • From other users when they reply, mention, report, or interact with your public content.
  • From verified organization representatives.
  • From vendors working for RentThread, such as authentication, hosting, security, email, analytics, and support providers.
  • From public records and other sources we reasonably believe we may use.
  • From legal, safety, fraud-prevention, or dispute-resolution sources where permitted by law.

5. How we use information

We use personal information to:

  1. Create, authenticate, secure, and support accounts.
  2. Find, create, deduplicate, correct, and maintain persistent property records.
  3. Maintain My Places and evaluate property-connection or residency claims.
  4. Publish contributions using the identity mode you select.
  5. Calculate and display ratings, RentThread Scores, votes, rankings, and community signals under published rules.
  6. Provide questions, discussions, replies, follows, saves, notifications, and preferences.
  7. Verify and administer Property Representatives and Official Responses.
  8. Detect spam, fraud, fake experiences, manipulation, harassment, evasion, security threats, and policy violations.
  9. Review reports, corrections, appeals, copyright notices, and legal requests.
  10. Communicate about transactions, security, moderation, policy changes, support, and optional marketing.
  11. Measure reliability, accessibility, performance, and use of the Service without putting private content into routine analytics.
  12. Debug, maintain, develop, and improve the Service.
  13. Protect the rights, safety, property, and integrity of users, RentThread, and others.
  14. Comply with law, enforce agreements, establish or defend claims, and respond to valid legal process.
  15. Complete a financing, merger, acquisition, reorganization, or transfer subject to appropriate safeguards.

We do not use the Service to make tenant-screening, rental-eligibility, credit, employment, insurance, healthcare, education, or other similarly significant decisions about a person.

6. What is public and what remains private

Public by design

Depending on your settings and actions, the following may be public:

  • Public handle, avatar, biography, and public profile ID
  • Property Alias display identity and qualifying public badge
  • Published Resident Reports, ratings, questions, answers, posts, replies, and edit indicators
  • Public contribution totals and helpful-vote aggregates
  • Property Representative name, organization, represented relationship, and Official Responses
  • Public moderation placeholders or reason labels

Restricted by design

The following are not public:

  • Email, authentication identifier, and account-security information
  • The account or global profile behind a Property Alias
  • Exact unit number and exact private stay dates
  • Verification evidence and internal verification notes
  • Individual voters, saves, follows, and private notification records
  • Drafts and content restricted from publication
  • Reports, moderator notes, integrity signals, and staff-access records
  • Private representative-claim evidence

Current residences are hidden from public profiles by default. You control whether an eligible contribution appears on your public profile, but a public contribution can still reveal contextual information you include in its text.

7. How we disclose information

We may disclose personal information in these circumstances:

A. At your direction or publicly

We publish information you choose to make public and disclose information when you direct us or give consent.

B. Service providers and contractors

We disclose information to providers that perform services for RentThread, such as cloud hosting, database, authentication, email delivery, error monitoring, security, analytics, customer support, and professional services. They may use information only for contracted purposes and must protect it as required by contract and law.

C. Legal process, safety, and rights

We may preserve or disclose information when we reasonably believe disclosure is required by valid law, subpoena, warrant, court order, or other binding process; is needed to address an emergency involving danger of death or serious physical injury; or is reasonably necessary to investigate fraud, security, abuse, or violations and protect legal rights.

We review legal requests for facial validity and scope. When legally permitted and appropriate, we seek to notify the affected user and may challenge an overbroad or defective request. We do not promise notice when prohibited or when an emergency or integrity concern makes notice inappropriate.

D. Business transactions

Information may be reviewed or transferred as part of a proposed or completed financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction. We will require the recipient to handle personal information consistently with applicable law and provide notice when required.

E. Deidentified or aggregated information

We may disclose information that has been reasonably deidentified or aggregated so it is not reasonably linkable to an individual. We do not attempt to reidentify data that we maintain as deidentified, except to test whether our deidentification processes are effective or as permitted by law.

8. Property owners and managers

A property owner, manager, or Property Representative does not receive access merely because of that role to:

  • The account or profile behind a Property Alias
  • Verification evidence
  • Exact private stay dates or unit numbers
  • A list of voters, followers, or saved-item owners
  • Private reports, appeals, integrity signals, or moderator notes

They may see the same public content visible to other users, receive their own representative account information, and submit an Official Response, correction request, policy report, or valid legal request.

9. No sale or targeted advertising

RentThread does not sell personal information for money or other valuable consideration. At launch, RentThread also does not share personal information for cross-context behavioral advertising, use targeted advertising, or profile users in furtherance of decisions that produce legal or similarly significant effects.

If these practices change, we will update this Policy, complete the legal-development change gate, provide required notice and choices before the change takes effect, and obtain consent where required.

10. Cookies and similar technologies

We use strictly necessary technologies for authentication, security, preferences, load balancing, and core functionality. With the choices required by applicable law, we may use limited analytics technologies to understand aggregate use, performance, and errors.

We do not use advertising cookies at launch. The Cookie Notice identifies the categories, purposes, providers, and intended durations of cookies and similar technologies. You can manage optional analytics through the cookie settings control when available. Blocking necessary cookies may prevent account or security features from working.

Where legally required, we recognize supported universal opt-out preference signals, such as Global Privacy Control, for the rights to which those signals apply. Because RentThread does not sell or share personal information for targeted advertising at launch, such a signal should not materially change those practices, but we record and honor it as required.

Some browsers transmit “Do Not Track” signals. There is no single generally accepted response standard. Our practices remain as described in this Policy regardless of a legacy Do Not Track signal.

11. Your choices and controls

Depending on the feature, you can:

  • Edit your public profile and visibility settings.
  • Choose an eligible public profile or Property Alias for a contribution.
  • Keep current properties off your public profile.
  • Edit or request deletion of qualifying content.
  • Change notification and digest preferences.
  • Unsubscribe from marketing email.
  • Review active sessions and change security settings.
  • Request access, correction, deletion, or portability through /privacy/choices or privacy@rentthread.com.

Removing public content does not necessarily remove replies, public references by others, deidentified property-level aggregates, moderation placeholders, legal holds, security records, or copies outside RentThread’s control.

12. U.S. state privacy rights

Depending on where you live and subject to applicable exceptions, you may have rights to:

  • Confirm whether we process your personal information.
  • Access personal information and receive a portable copy.
  • Correct inaccuracies.
  • Delete personal information.
  • Opt out of sale, targeted advertising, or certain profiling.
  • Limit certain uses of sensitive personal information.
  • Withdraw consent for processing based on consent.
  • Appeal a decision concerning a privacy request.
  • Use an authorized agent.
  • Receive equal service without unlawful discrimination for exercising a privacy right.

RentThread offers access, correction, deletion, and portability requests to U.S. account holders even when a particular state law does not require us to do so, subject to reasonable identity verification and legal exceptions.

Submit a request at /privacy/choices or email privacy@rentthread.com. Describe the request and provide the email associated with your account. We will use information already associated with your account and, when necessary, proportionate additional verification. Do not email identity documents unless we specifically provide a secure authorized method.

We will acknowledge, respond, and provide an appeal route within the periods required by applicable law. If we deny a request in whole or part, we will explain the basis when legally permitted. An authorized agent must provide proof of authority, and we may verify the request directly with you.

California notice

For purposes of California law, the categories collected in the preceding 12 months may include identifiers; internet or other electronic network activity; geolocation at an approximate level; user-generated content that may constitute customer-record or protected-class information when voluntarily included; professional information for representatives; and inferences limited to security, integrity, or product preferences. Sensitive personal information may include account credentials, precise property-connection information, private communications with RentThread, and verification information.

We collect these categories from the sources described in Section 4, use them for the purposes in Section 5, and disclose them to the recipient categories in Section 7. We do not sell or share these categories for cross-context behavioral advertising and do not knowingly sell or share personal information of people under 16. The Service is limited to adults.

We use sensitive personal information only for permitted service, security, integrity, legal, and other reasonably expected purposes and not to infer unrelated characteristics. We therefore do not offer a separate right-to-limit link for launch practices. If our practices change, we will add the required notice and control before the change.

California residents may exercise the rights described above, including the right to know, access, correct, delete, opt out of sale/sharing, limit qualifying sensitive-information uses, and receive information about our practices. We honor legally recognized opt-out preference signals. We do not offer a financial incentive for personal information at launch.

Texas notice

Texas residents may request confirmation, access, correction, deletion, and portability and may opt out of targeted advertising, sale, or qualifying profiling. They may appeal a denied request using the same Privacy Choices route and selecting Appeal a privacy decision. RentThread does not sell sensitive personal data or biometric data.

13. Retention

We keep personal information no longer than reasonably necessary for the disclosed purpose, security, legal obligations, dispute resolution, and enforcement. The following is the intended launch schedule; the internal retention standard controls implementation and must match this Policy.

CategoryIntended retention
Account and private profileWhile the account is active; deletion workflow begins after a verified request, subject to the periods below
Public profile and User ContentUntil deleted, deidentified, or removed under user controls/policy; public conversation structure and property aggregates may remain
Terms, consent, and policy acceptanceDuration of the relationship plus 7 years, unless counsel approves a different period
Property Alias ownershipWhile needed to operate or enforce the account; after account/content deletion, only a restricted minimum anti-abuse record for the approved internal period, unless legal hold applies
Private residency claim and derived verification recordWhile the credential/report remains active; then delete precise dates and relationship detail under the internal schedule, retaining only a justified minimum integrity or appeal record
Sensitive verification documentsNot collected at initial launch; if later enabled, successful raw evidence is scheduled for deletion within 72 hours after the final decision, rejected evidence after the 30-day appeal window, and ordinary backup copies within 35 additional days, unless a documented fraud, appeal, legal-hold, or legal basis requires longer
Draft contributionsUntil published or deleted; abandoned drafts automatically deleted after 12 months
Votes, follows, saves, and notificationsUntil removed, the account is deleted, or 24 months after no longer operationally needed
Moderation, report, appeal, correction, and integrity recordsGenerally 3 years after closure; up to 5 years for serious safety, fraud, repeat-abuse, representative, or legal matters
Support and ordinary communicationsGenerally 3 years after closure
Security, access, and technical logsGenerally no more than 180 days for routine logs; shorter when practical and longer only for a documented incident, investigation, or legal obligation
Marketing subscription and suppression recordUntil opt-out; retain the minimum suppression record needed to honor the opt-out
Privacy request recordsGenerally 2 years after completion, or longer where required to demonstrate compliance
Production backupsRolling period no longer than 35 days at launch; deleted information ages out unless restored for disaster recovery and re-deleted

Legal holds, valid preservation demands, fraud investigations, unresolved appeals, safety matters, and legal obligations may extend a period. We document and limit such extensions.

14. Security

We use administrative, technical, and physical safeguards designed for the nature of the information, including access controls, least privilege, multifactor authentication for staff, encryption in transit, restricted private schemas and storage, audit logs, secure development, dependency and secret scanning, monitoring, backups, and incident response.

No method of transmission or storage is completely secure. You are responsible for protecting your account credentials and for avoiding sensitive personal information in public contributions.

Report a suspected security issue privately to security@rentthread.com. Do not exploit a vulnerability, access another person’s data, disrupt the Service, or publicly disclose sensitive details before we have a reasonable opportunity to investigate and remediate.

15. Legal requests and Property Alias privacy

Public anonymity is not absolute. A private party may seek information through a subpoena or court process, and government authorities may use legally authorized process. We may also be required to preserve records before a disclosure decision is made.

Our Legal Request Guidelines explain where process must be served and our general practices. They do not create rights beyond applicable law and do not promise that every user can be notified.

We collect only the alias-ownership and security information needed to operate the Service and do not volunteer it to a property because of criticism. We do not obstruct valid process or destroy information subject to a preservation duty or legal hold.

16. Children

The Service is not directed to anyone under 18, and people under 18 may not create an account or submit personal information. If you believe a minor has provided personal information, contact privacy@rentthread.com. We will investigate and take appropriate deletion or restriction steps.

17. Processing in the United States

The Service is operated for the United States. Information may be processed in U.S. locations where RentThread and its service providers operate. Do not use the Service if your use would require RentThread to offer the Service under another country’s law.

18. Changes to this Policy

We may update this Policy to reflect product, legal, or operational changes. We will post the revision and update the date above. If a change is material, we will provide additional notice and obtain consent when required before applying the change.

19. Contact and appeals

{{LEGAL_ENTITY_NAME}}
{{MAILING_ADDRESS}}
Privacy requests and questions: privacy@rentthread.com
Privacy request portal: /privacy/choices

To appeal a privacy-request decision, select Appeal a privacy decision in the portal or email privacy@rentthread.com with the prior request identifier. We will provide information about further regulator contact where applicable.