Privacy Policy
Last updated: May 19, 2026 • Version 3.0
Sections
CollectionBankingScreeningApplicationsUsageAI ProcessingSharingCookiesSecurityRetentionRightsChildrenInternationalChangesContactAt Ledge Flow LLC ("LedgeFlow", "we", "us", or "our"), we respect your privacy and are committed to protecting the personal data of our Landlord customers, their Residents, and prospective tenants. This Privacy Policy explains how we collect, use, share, and protect your information across our property management, financial, AI, and screening services.
1. Information We Collect
A. Landlord Account Information
- Identity Data: First name, last name, email address, phone number, and company name (optional).
- Authentication Data: Password (hashed and salted), or Google OAuth tokens (email, display name, profile photo URL) when using third-party login.
- Property Data: Addresses, unit details, rent amounts, occupancy status, property photos, and building configurations (multi-unit, co-living, etc.).
- Financial Data: Expense records, income entries, IRS Schedule E categorizations, and transaction history.
- Maintenance Data: Ticket descriptions, photos of issues, contractor details, repair costs, and vendor assignments.
- Lease Data: Lease terms, agreements, and electronic signatures processed through DocuSeal.
B. Resident Information
- Identity Data: First name, last name, email address, and phone number (provided during Landlord-initiated invitation).
- Authentication Data: Password or Google OAuth tokens.
- Payment Data: Bank account or credit/debit card details processed securely through Stripe. LedgeFlow does not store raw card or bank account numbers.
- Lease Data: Signed lease documents, lease terms, and move-in/move-out dates.
- Communication Data: In-app messages with Landlords, maintenance ticket submissions, and support requests.
C. Automatically Collected Information
- Device & Browser Data: IP address, browser type and version, operating system, device identifiers, and screen resolution.
- Usage Data: Pages visited, features used, click patterns, session duration, and referring URLs.
- Location Data: Approximate location derived from IP address (we do not collect precise GPS data).
- Log Data: Server logs including access times, error logs, and API request metadata.
2. Banking & KYC Data
Because LedgeFlow provides banking features via Stripe Treasury, we are required by federal law to verify your identity. This involves the collection of Social Security Numbers (SSN), Employer Identification Numbers (EIN), and government-issued ID copies.
LedgeFlow does not store your full SSN or raw ID documents on our servers. This sensitive data is transmitted directly to Stripe via encrypted channels to meet "Know Your Customer" (KYC) and Anti-Money Laundering (AML) regulations.
- We may store the last four digits of your SSN for identification verification purposes.
- KYC verification status (approved, pending, or rejected) is stored in our database.
- Banking transaction records (deposits, withdrawals, transfers) are retained for financial reporting and regulatory compliance.
- Security deposit escrow records are maintained for the duration of the tenancy plus applicable statutory retention periods.
3. Tenant Screening Data
Tenant screening services are powered by TransUnion (SmartMove). When a screening is requested:
- LedgeFlow facilitates the connection, but TransUnion collects the sensitive applicant data (e.g., full SSN) directly through their secure portal. This data does not pass through LedgeFlow servers.
- The resulting Credit, Criminal, and Eviction reports are stored in our encrypted database so they can be viewed by the authorized Landlord.
- Screening reports are accessible only to the Landlord who requested them and are not shared with other users.
- We comply with the Fair Credit Reporting Act (FCRA) regarding the handling, storage, and disposal of consumer report data.
- Screening reports are retained for the period required by FCRA regulations, after which they are securely deleted.
4. Lead & Application Data
When prospective tenants submit rental applications through LedgeFlow (including through Landlord white-label websites), we collect:
- Application Data: Full legal name, email address, phone number, gross monthly income, estimated credit score, desired move-in date, pet ownership status, Section 8 voucher status, and any additional notes provided by the applicant.
- Pre-Qualification Data: Income verification information used for automated 3x rent pre-qualification screening.
- Communication Records: Correspondence related to the application, including automated drip campaign emails and follow-up messages.
Applicant Rights
Prospective tenants who submit applications have the right to request deletion of their application data. Requests can be submitted to the Landlord directly or to LedgeFlow at support@ledgeflow.com.
5. How We Use Your Data
We use the information we collect for the following purposes:
Service Delivery
Processing rent payments, managing properties, generating Schedule E tax reports, handling maintenance workflows, and facilitating lease signing.
AI-Powered Insights
Our AI agents process your property and financial data to provide cash flow analysis, yield optimization, expense categorization, and operational recommendations.
Communications
Sending transactional emails, rent reminders, late notices, maintenance updates, and in-app notifications via Postmark, SendGrid, and SMS.
Platform Improvement
Analyzing usage patterns to improve features, fix bugs, ensure security, and develop new capabilities that enhance the user experience.
- Legal Compliance: Fulfilling regulatory obligations including tax reporting, AML/KYC requirements, and responding to lawful legal requests.
- Fraud Prevention: Detecting and preventing fraudulent activity, unauthorized access, and abuse of the platform.
- Lead Management: Facilitating the applicant funnel, automated pre-qualification, and follow-up communications on behalf of Landlords.
6. AI & Autonomous Agent Data Processing
LedgeFlow uses AI-powered autonomous agents (powered by Google Gemini) that process your data to perform property management tasks. Understanding how your data is used by these systems is important to us.
What Data AI Agents Access
- Property portfolio data (addresses, units, occupancy, rent amounts).
- Financial records (expenses, income, transaction history, categorizations).
- Maintenance tickets and work order history.
- Resident information (names, lease status, payment history).
- Communication history for context-aware drafting.
How AI Data Is Handled
- AI processing occurs in real-time using your account data. Data is not used to train third-party AI models.
- Conversation logs with the AI Portfolio Agent may be retained to improve response quality and for debugging purposes.
- Financial insights and analytics use anonymized and aggregated transaction data.
- AI agents operate within user-configured autonomy levels. Actions requiring approval will not execute without your confirmation.
Automated Decision-Making
LedgeFlow's AI agents may make automated suggestions or take actions such as categorizing expenses, flagging overdue payments, or drafting communications. These automated processes do not make binding legal or financial decisions without user confirmation. You have the right to review, override, or disable any automated actions through your Settings dashboard.
9. Data Security
LedgeFlow employs industry-standard security measures to protect your data:
- AES-256 Encryption: All property, financial, and personal data is encrypted at rest.
- TLS 1.3: All data transmitted between your device and our servers is protected by transport-layer encryption.
- Tokenization: We never store raw credit card or bank account numbers. All payment data is tokenized through Stripe.
- Firebase Security Rules: Granular access controls ensure users can only access their own data.
- Authentication Security: Passwords are hashed using industry-standard algorithms. We support Google OAuth for secure third-party authentication.
- Screening Report Encryption: Tenant screening reports containing sensitive consumer data are stored with additional encryption layers.
Security Incident Response
In the event of a data breach affecting your personal information, we will notify affected users within 72 hours of discovery, as required by applicable law. Notifications will be sent via email and in-app alerts, and will include details of the breach, data affected, and remediation steps.
10. Data Retention
We retain your personal data only as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as required by law:
- Active Accounts: Data is retained for the duration of your active subscription.
- Closed Accounts: After account cancellation, data is retained for 90 days to allow for reactivation, after which it is permanently deleted.
- Financial Records: Transaction records, expense logs, and tax-related data (Schedule E reports) are retained for a minimum of 7 years to comply with IRS record-keeping requirements.
- Tenant Screening Reports: Retained in accordance with FCRA requirements and securely deleted thereafter.
- Lease Documents: Retained for the duration of the lease term plus any applicable statutory retention period.
- Lead/Application Data: Retained for 2 years from the date of application, or until deletion is requested by the applicant.
- AI Conversation Logs: Retained for up to 12 months for service improvement and debugging purposes.
- Server Logs: Retained for up to 90 days for security and operational purposes.
When data is deleted, we use industry-standard secure deletion methods to ensure it cannot be recovered.
11. Your Rights (CCPA, GDPR & State Privacy Laws)
Depending on your location, you may have the following rights regarding your personal data. We honor these rights regardless of whether your state has enacted specific privacy legislation:
Request a copy of the personal data we hold about you.
Request deletion of your personal data, subject to legal retention requirements.
Receive your data in a structured, machine-readable format.
Request correction of inaccurate or incomplete personal data.
Opt out of the sale or sharing of personal data (we do not sell data).
Exercise privacy rights without receiving discriminatory treatment.
How to Exercise Your Rights
- Submit a request via email to support@ledgeflow.com with the subject line "Privacy Rights Request."
- Use the data export feature in your Settings dashboard for self-service data portability.
- We will verify your identity before processing any request and respond within 30 days (or 45 days for complex requests, with notice).
California Residents (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). In the preceding 12 months, we have collected the categories of personal information described in Section 1 of this policy. We do not sell personal information as defined by the CCPA. You may designate an authorized agent to submit requests on your behalf.
12. Children's Privacy
LedgeFlow is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to promptly delete that information. If you believe a child has provided us with personal information, please contact us at support@ledgeflow.com.
13. International Data Transfers
LedgeFlow is based in the United States. If you access our Service from outside the United States, please be aware that your data may be transferred to, stored, and processed in the United States where our servers and central database are located.
- By using LedgeFlow, you consent to the transfer of your data to the United States.
- We ensure that data transfers comply with applicable data protection laws, including implementing appropriate safeguards where required.
- For EU/EEA users: We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as a legal basis for international data transfers where applicable.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we make material changes:
- We will provide at least 30 days' advance notice via email or in-app notification.
- The "Last Updated" date and version number at the top of this page will be revised.
- The updated policy will be posted on our website.
- Continued use of the Service after the effective date constitutes acceptance of the updated policy.
- Previous versions of this policy are available upon request.
15. Contact Information
For data requests, privacy concerns, or questions about this Privacy Policy, please contact our Privacy Team:
LedgeFlow Privacy Team
Ledge Flow LLC
support@ledgeflow.com
We aim to respond to all privacy-related inquiries within 5 business days.
Submit a Privacy Ticket →