Privacy Policy

Last updated: May 19, 2026 • Version 3.0

At Ledge Flow LLC ("LedgeFlow", "we", "us", or "our"), we respect your privacy and are committed to protecting the personal data of our Landlord customers, their Residents, and prospective tenants. This Privacy Policy explains how we collect, use, share, and protect your information across our property management, financial, AI, and screening services.

1. Information We Collect

A. Landlord Account Information

  • Identity Data: First name, last name, email address, phone number, and company name (optional).
  • Authentication Data: Password (hashed and salted), or Google OAuth tokens (email, display name, profile photo URL) when using third-party login.
  • Property Data: Addresses, unit details, rent amounts, occupancy status, property photos, and building configurations (multi-unit, co-living, etc.).
  • Financial Data: Expense records, income entries, IRS Schedule E categorizations, and transaction history.
  • Maintenance Data: Ticket descriptions, photos of issues, contractor details, repair costs, and vendor assignments.
  • Lease Data: Lease terms, agreements, and electronic signatures processed through DocuSeal.

B. Resident Information

  • Identity Data: First name, last name, email address, and phone number (provided during Landlord-initiated invitation).
  • Authentication Data: Password or Google OAuth tokens.
  • Payment Data: Bank account or credit/debit card details processed securely through Stripe. LedgeFlow does not store raw card or bank account numbers.
  • Lease Data: Signed lease documents, lease terms, and move-in/move-out dates.
  • Communication Data: In-app messages with Landlords, maintenance ticket submissions, and support requests.

C. Automatically Collected Information

  • Device & Browser Data: IP address, browser type and version, operating system, device identifiers, and screen resolution.
  • Usage Data: Pages visited, features used, click patterns, session duration, and referring URLs.
  • Location Data: Approximate location derived from IP address (we do not collect precise GPS data).
  • Log Data: Server logs including access times, error logs, and API request metadata.

2. Banking & KYC Data

Because LedgeFlow provides banking features via Stripe Treasury, we are required by federal law to verify your identity. This involves the collection of Social Security Numbers (SSN), Employer Identification Numbers (EIN), and government-issued ID copies.

LedgeFlow does not store your full SSN or raw ID documents on our servers. This sensitive data is transmitted directly to Stripe via encrypted channels to meet "Know Your Customer" (KYC) and Anti-Money Laundering (AML) regulations.

  • We may store the last four digits of your SSN for identification verification purposes.
  • KYC verification status (approved, pending, or rejected) is stored in our database.
  • Banking transaction records (deposits, withdrawals, transfers) are retained for financial reporting and regulatory compliance.
  • Security deposit escrow records are maintained for the duration of the tenancy plus applicable statutory retention periods.

3. Tenant Screening Data

Tenant screening services are powered by TransUnion (SmartMove). When a screening is requested:

  • LedgeFlow facilitates the connection, but TransUnion collects the sensitive applicant data (e.g., full SSN) directly through their secure portal. This data does not pass through LedgeFlow servers.
  • The resulting Credit, Criminal, and Eviction reports are stored in our encrypted database so they can be viewed by the authorized Landlord.
  • Screening reports are accessible only to the Landlord who requested them and are not shared with other users.
  • We comply with the Fair Credit Reporting Act (FCRA) regarding the handling, storage, and disposal of consumer report data.
  • Screening reports are retained for the period required by FCRA regulations, after which they are securely deleted.

4. Lead & Application Data

When prospective tenants submit rental applications through LedgeFlow (including through Landlord white-label websites), we collect:

  • Application Data: Full legal name, email address, phone number, gross monthly income, estimated credit score, desired move-in date, pet ownership status, Section 8 voucher status, and any additional notes provided by the applicant.
  • Pre-Qualification Data: Income verification information used for automated 3x rent pre-qualification screening.
  • Communication Records: Correspondence related to the application, including automated drip campaign emails and follow-up messages.

Applicant Rights

Prospective tenants who submit applications have the right to request deletion of their application data. Requests can be submitted to the Landlord directly or to LedgeFlow at support@ledgeflow.com.

5. How We Use Your Data

We use the information we collect for the following purposes:

Service Delivery

Processing rent payments, managing properties, generating Schedule E tax reports, handling maintenance workflows, and facilitating lease signing.

AI-Powered Insights

Our AI agents process your property and financial data to provide cash flow analysis, yield optimization, expense categorization, and operational recommendations.

Communications

Sending transactional emails, rent reminders, late notices, maintenance updates, and in-app notifications via Postmark, SendGrid, and SMS.

Platform Improvement

Analyzing usage patterns to improve features, fix bugs, ensure security, and develop new capabilities that enhance the user experience.

  • Legal Compliance: Fulfilling regulatory obligations including tax reporting, AML/KYC requirements, and responding to lawful legal requests.
  • Fraud Prevention: Detecting and preventing fraudulent activity, unauthorized access, and abuse of the platform.
  • Lead Management: Facilitating the applicant funnel, automated pre-qualification, and follow-up communications on behalf of Landlords.

6. AI & Autonomous Agent Data Processing

LedgeFlow uses AI-powered autonomous agents (powered by Google Gemini) that process your data to perform property management tasks. Understanding how your data is used by these systems is important to us.

What Data AI Agents Access

  • Property portfolio data (addresses, units, occupancy, rent amounts).
  • Financial records (expenses, income, transaction history, categorizations).
  • Maintenance tickets and work order history.
  • Resident information (names, lease status, payment history).
  • Communication history for context-aware drafting.

How AI Data Is Handled

  • AI processing occurs in real-time using your account data. Data is not used to train third-party AI models.
  • Conversation logs with the AI Portfolio Agent may be retained to improve response quality and for debugging purposes.
  • Financial insights and analytics use anonymized and aggregated transaction data.
  • AI agents operate within user-configured autonomy levels. Actions requiring approval will not execute without your confirmation.

Automated Decision-Making

LedgeFlow's AI agents may make automated suggestions or take actions such as categorizing expenses, flagging overdue payments, or drafting communications. These automated processes do not make binding legal or financial decisions without user confirmation. You have the right to review, override, or disable any automated actions through your Settings dashboard.

7. Data Sharing & Third Parties

We do not sell, rent, or trade your personal information. We share data only with essential service partners and only to the extent necessary to provide the Service:

StripePayment processing, banking (Treasury), card issuance (Issuing), and KYC verification
Google Cloud / FirebaseSecure data hosting, authentication, cloud functions, and file storage
Google GeminiAI-powered portfolio agent, insights, and autonomous task execution
TransUnion (SmartMove)Tenant credit, criminal, and eviction background checks
DocuSealElectronic lease document signing and storage
TwilioSMS notifications, rent reminders, and transactional communication
Postmark / SendGridTransactional email delivery (rent notices, alerts, receipts)
Google reCAPTCHABot prevention on contact and application forms

SMS Privacy Disclaimer (A2P 10DLC Compliance)

No mobile information or phone numbers will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties or affiliates.

We may also disclose your information in the following circumstances:

  • Legal Requirements: When required by law, subpoena, court order, or governmental regulation.
  • Safety & Security: To protect the rights, safety, or property of LedgeFlow, our users, or the public.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. You will be notified of any such transfer.
  • With Your Consent: We may share data with additional parties when you provide explicit consent.

8. Cookies & Tracking Technologies

LedgeFlow uses cookies and similar technologies to enhance your experience. When you first visit our platform, you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies.

Types of Cookies We Use

EssentialAuthentication, session management, security, CSRF protection
FunctionalUser preferences, theme settings, dashboard layout
AnalyticsUsage patterns, feature adoption, performance monitoring

Google reCAPTCHA: We use Google reCAPTCHA on certain forms to protect against spam and abuse. This service may collect hardware and software information, such as device and application data, and send it to Google for analysis. Use of reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.

Do Not Track: LedgeFlow currently does not respond to "Do Not Track" browser signals. We will update this policy if we adopt a DNT standard in the future.

9. Data Security

LedgeFlow employs industry-standard security measures to protect your data:

  • AES-256 Encryption: All property, financial, and personal data is encrypted at rest.
  • TLS 1.3: All data transmitted between your device and our servers is protected by transport-layer encryption.
  • Tokenization: We never store raw credit card or bank account numbers. All payment data is tokenized through Stripe.
  • Firebase Security Rules: Granular access controls ensure users can only access their own data.
  • Authentication Security: Passwords are hashed using industry-standard algorithms. We support Google OAuth for secure third-party authentication.
  • Screening Report Encryption: Tenant screening reports containing sensitive consumer data are stored with additional encryption layers.

Security Incident Response

In the event of a data breach affecting your personal information, we will notify affected users within 72 hours of discovery, as required by applicable law. Notifications will be sent via email and in-app alerts, and will include details of the breach, data affected, and remediation steps.

10. Data Retention

We retain your personal data only as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as required by law:

  • Active Accounts: Data is retained for the duration of your active subscription.
  • Closed Accounts: After account cancellation, data is retained for 90 days to allow for reactivation, after which it is permanently deleted.
  • Financial Records: Transaction records, expense logs, and tax-related data (Schedule E reports) are retained for a minimum of 7 years to comply with IRS record-keeping requirements.
  • Tenant Screening Reports: Retained in accordance with FCRA requirements and securely deleted thereafter.
  • Lease Documents: Retained for the duration of the lease term plus any applicable statutory retention period.
  • Lead/Application Data: Retained for 2 years from the date of application, or until deletion is requested by the applicant.
  • AI Conversation Logs: Retained for up to 12 months for service improvement and debugging purposes.
  • Server Logs: Retained for up to 90 days for security and operational purposes.

When data is deleted, we use industry-standard secure deletion methods to ensure it cannot be recovered.

11. Your Rights (CCPA, GDPR & State Privacy Laws)

Depending on your location, you may have the following rights regarding your personal data. We honor these rights regardless of whether your state has enacted specific privacy legislation:

Right to Access

Request a copy of the personal data we hold about you.

Right to Deletion

Request deletion of your personal data, subject to legal retention requirements.

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Correction

Request correction of inaccurate or incomplete personal data.

Right to Opt-Out

Opt out of the sale or sharing of personal data (we do not sell data).

Right to Non-Discrimination

Exercise privacy rights without receiving discriminatory treatment.

How to Exercise Your Rights

  • Submit a request via email to support@ledgeflow.com with the subject line "Privacy Rights Request."
  • Use the data export feature in your Settings dashboard for self-service data portability.
  • We will verify your identity before processing any request and respond within 30 days (or 45 days for complex requests, with notice).

California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). In the preceding 12 months, we have collected the categories of personal information described in Section 1 of this policy. We do not sell personal information as defined by the CCPA. You may designate an authorized agent to submit requests on your behalf.

12. Children's Privacy

LedgeFlow is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to promptly delete that information. If you believe a child has provided us with personal information, please contact us at support@ledgeflow.com.

13. International Data Transfers

LedgeFlow is based in the United States. If you access our Service from outside the United States, please be aware that your data may be transferred to, stored, and processed in the United States where our servers and central database are located.

  • By using LedgeFlow, you consent to the transfer of your data to the United States.
  • We ensure that data transfers comply with applicable data protection laws, including implementing appropriate safeguards where required.
  • For EU/EEA users: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as a legal basis for international data transfers where applicable.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we make material changes:

  • We will provide at least 30 days' advance notice via email or in-app notification.
  • The "Last Updated" date and version number at the top of this page will be revised.
  • The updated policy will be posted on our website.
  • Continued use of the Service after the effective date constitutes acceptance of the updated policy.
  • Previous versions of this policy are available upon request.

15. Contact Information

For data requests, privacy concerns, or questions about this Privacy Policy, please contact our Privacy Team:

LedgeFlow Privacy Team

Ledge Flow LLC

support@ledgeflow.com

We aim to respond to all privacy-related inquiries within 5 business days.

Submit a Privacy Ticket →

© 2026 Ledge Flow LLC.