Tenant Cred Privacy Policy
Updated: May 22, 2026
Entity: Tenant Cred LLC ("Tenant Cred," "we," "us," or "our")
Privacy notice contact: privacy@tenantcred.com
Support contact: help@tenantcred.com
What Tenant Cred Is
Tenant Cred is a U.S. rental-verification product for renters and tenants. Tenant Cred helps a renter create and share a tenant-authorized credential that can include verified facts about identity, income signals, and employment.
Tenant Cred uses Plaid to help securely connect to user-authorized financial accounts for verification.
Tenant Cred is not a consumer reporting agency and does not furnish consumer reports. Tenant Cred does not sell, resell, furnish, or otherwise provide Consumer Reports or tenant-screening reports to landlords, property managers, leasing agents, housing providers, or other rental-context recipients for tenant-screening, rental-eligibility screening, or rental decisioning purposes.
For workflows that require credit-related underwriting data, Tenant Cred uses Identity Verification plus Plaid Check Consumer Report products such as CRA Base Report and CRA Income Insights, with tenant or guarantor authorization and FCRA controls. Any separately authorized Consumer Report workflow is limited to the specific credit, underwriting, regulatory, compliance, or related review purpose presented in that workflow, and is not used to furnish Consumer Reports to rental-context recipients for tenant-screening purposes.
Tenant Cred shares tenant-authorized verification results through recipient-specific views. These views are designed to disclose only the approved facts needed for the rental purpose, not raw bank or provider data.
Tenant Cred does not provide recipient decisioning, automated screening conclusions, composite tenant-quality labels, scores, or automated approval/denial recommendations.
Tenant Cred maintains compliance controls for separately authorized Consumer Report workflows and recipient-specific disclosures, including permissible-purpose handling, consumer authorization, report and file access where required, dispute and correction handling, adverse-action support where required, partner certification, and access logging.
Who This Policy Covers
This policy is written for renters and tenants who use Tenant Cred. It also describes how we handle information when a renter authorizes a disclosure to a rental-context recipient, such as a property manager, leasing agent, or other approved recipient.
Tenant Cred currently offers the service only to users in the United States. This policy applies to that U.S. service.
Information We Collect Directly From You
The categories of information Tenant Cred collects directly from you include:
- Contact and account information, such as your name, email address, phone number, login information, and account settings.
- Identity information you provide for verification, such as date of birth, address, Social Security number, government-issued ID information, and related government identifier information.
- Rental-context information, such as the property, unit, property manager, leasing contact, share purpose, disclosure settings, and recipient contact information you choose to provide.
- Information you enter, upload, or authorize for credential creation, support, corrections, disputes, deletion requests, or account servicing.
- Consent, authorization, revocation, deletion, disclosure, and access records, including timestamps, policy versions, selected data categories, recipient context, and related audit information.
- Device, usage, log, and security information, such as IP address, browser or device data, request IDs, session identifiers, security events, and similar operational metadata.
Tenant Cred does not ask you to give Tenant Cred your bank username or password. When a financial-account connection is needed, the connection is handled through Plaid or another approved verification provider.
Information We May Receive Through Plaid
When you choose to connect a financial account or complete identity, income, Consumer Report, account, or payment-source verification through Plaid, Plaid may collect information from you, your device, your financial institution, and other sources as described in Plaid's own privacy materials.
The exact information Tenant Cred receives depends on the Plaid products, accounts, and data scopes you authorize. Tenant Cred processes Plaid-derived information such as:
- Identity and contact information, such as account owner name, phone, email, mailing address, and identity-match information.
- Identity verification results, including verification status, document-verification status, selfie or liveness status, fraud-prevention signals, and related evidence references.
- Account ownership and account metadata, such as institution name, account name, account type, account subtype, masked account number, and account-owner match status.
- Account and balance information, if authorized and applicable.
- Account and routing information, only where needed for an approved payment-source or account-verification purpose.
- Income, employment, payroll, direct-deposit, bank-income, or income-provider information, where authorized.
- Plaid Check Consumer Report information, where authorized, such as CRA Base Report data from tenant-owned or guarantor-owned linked accounts, CRA Income Insights, income-stream attributes, cash-flow attributes, account-coverage records, report references, report PDFs if retained, and related report metadata.
- Transaction, recurring-transaction, and payment-history-related information, where authorized, including information used to detect tenant-relevant recurring housing-like payment signals.
- Statements, assets, or other financial records only when the applicable Plaid product is enabled for the requested feature and specifically authorized by you.
- Plaid session, consent, item, account, webhook, error, and operational metadata needed to provide, secure, audit, support, or troubleshoot the service.
Not every user will provide or authorize every category. Tenant Cred requests only the data needed for the tenant-authorized rental verification purpose presented to you.
What Plaid Is
Plaid is a third-party provider that helps users connect financial accounts and authorize data sharing with applications like Tenant Cred. If you use Plaid Link, Plaid may ask you to select your financial institution, authenticate with that institution, select accounts, and review consent information about the data being shared and why. In production, Plaid may display Data Transparency Messaging that describes the requested data scopes and use case.
Plaid's privacy policy and related privacy tools apply to Plaid's own handling of your information. Tenant Cred's privacy practices are described in this policy, and Plaid's privacy practices are described in Plaid's own materials.
Financial Data Permissions And Consumer Authorization
Before Tenant Cred requests financial-account data, identity verification, income verification, Consumer Report data, payment-source verification, or a recipient-specific disclosure, Tenant Cred presents a clear notice or authorization flow that explains the product or service you requested, the data categories requested, the reason the data is needed, the expected duration of collection or access, and how you can revoke future access.
Tenant Cred requests only the data needed for the specific tenant-authorized credential, rental verification, payment-source, support, dispute, or underwriting-support purpose presented to you. If Tenant Cred needs additional data categories, additional recipients, or a materially different use case after your original authorization, Tenant Cred requests additional authorization where required before collecting or using that additional information.
Tenant Cred does not ask you for your financial-account credentials. When a Plaid-powered flow is used, Plaid or your financial institution handles the connection and authentication process. Tenant Cred receives the authorized data, verification results, report references, or operational metadata needed for the product or service you requested.
Tenant Cred records authorization details, including the product or data scope requested, purpose shown to you, policy and consent text version, recipient or partner context for the workflow, timestamps, Plaid session or report references, revocation route, deletion route, dispute route, and file-disclosure route.
Why We Use Plaid-Derived Information
Tenant Cred uses Plaid-derived information for limited tenant-authorized purposes, including:
- Creating, verifying, servicing, and updating your Tenant Cred credential.
- Verifying identity, account ownership, payment-source status, income, employment, direct deposit, recurring income, Consumer Report attributes, ability-to-pay signals, or housing-like payment signals where authorized.
- Turning provider data into Tenant Cred verified facts, badges, status fields, named verification results, freshness indicators, and limited provenance.
- Creating tenant-authorized, recipient-specific verification views.
- Supporting account service, customer support, correction requests, disputes, deletion requests, revocation, fraud prevention, audit, security, compliance, and legal or contractual obligations.
- Improving, maintaining, and troubleshooting the product you requested, using only data that is appropriate for that purpose.
Tenant Cred does not use Plaid-derived data for targeted advertising, unrelated cross-selling, sale of covered data, or unrelated analytics.
Selective Disclosure To Rental-Context Recipients
Tenant Cred shares verification results with a rental-context recipient only when you authorize that recipient. A recipient may include a property manager, leasing agent, or other approved recipient account you authorize.
When you authorize a disclosure, Tenant Cred shares only the approved credential facts or verification results for that recipient and rental purpose. Recipient views may show verified facts, verification badges, named verification results such as income-signal or employment-verification status, source freshness, and limited provenance. These views identify the relevant result without showing raw bank data, raw provider payloads, full transaction feeds, or other sensitive details that are not needed for the authorized rental purpose.
Tenant Cred does not expose raw Plaid payloads, full transaction feeds, account/routing numbers, bank credentials, IDV document images, selfie/liveness artifacts, or internal verification logic, operational rules, or security-sensitive business logic in ordinary recipient-facing credential views.
A recipient-specific disclosure is not the same as giving a recipient live access to your full Tenant Cred credential. A saved disclosure, if allowed by the applicable share settings, is a saved snapshot of what you authorized and what the recipient saved under policy. It does not give the recipient automatic access to future credential updates, future Plaid refreshes, raw provider data, or additional information without a new authorization or approved workflow.
Tenant Cred requires recipients and approved partners to use disclosed information only for the tenant-authorized rental, verification, support, or underwriting purpose. Recipient or partner access is logged, purpose-limited, and subject to expiration, revocation, retention, deletion, and no-onward-sharing controls.
Consent, Revocation, Deletion, Correction, And Disputes
Tenant Cred presents notice and obtains your authorization before initiating Plaid Link, Plaid Identity Verification, Plaid Check CRA Base Report, Plaid Check CRA Income Insights, payment-source verification, or a selective disclosure to a recipient or approved credit/underwriting partner.
For Consumer Report workflows, Tenant Cred asks a tenant or guarantor to connect all relevant financial accounts they own or control and can authorize through Plaid, including accounts at multiple financial institutions, so the requested credential, rental verification, or underwriting-support workflow can use a holistic consumer-authorized account and cash-flow view.
You may request to revoke future Plaid access or future disclosure access by contacting us at help@tenantcred.com or using the in-product controls when available. Revocation generally stops future collection, future refresh, and future recipient access where permitted.
Revocation does not automatically delete records that Tenant Cred must retain or is allowed to retain for legal, fraud-prevention, dispute, audit, security, product-servicing, contractual, or historical disclosure-record purposes. For example, Tenant Cred may retain consent records, revocation records, disclosure manifests, access logs, saved disclosure snapshots, deletion records, and support records where needed to show what you authorized, what was shared, and what actions were taken.
You may request access to information about the categories of information Tenant Cred collects, the reasons for collection, the categories of recipients or vendors with whom information was shared, correction of inaccurate information, deletion where legally and operationally permitted, or help disputing information you believe is inaccurate. If a separately authorized Tenant Cred workflow is subject to consumer-reporting law, additional FCRA file disclosure, reinvestigation, correction, permissible-purpose, user-notice, and adverse-action support obligations may apply.
Tenant Cred will not discriminate against you for exercising privacy rights that apply to you.
Consumer Report Workflows And Rights
Some Tenant Cred workflows may involve Consumer Report information or other information used for a rental, credential, or credit-related underwriting purpose. For those workflows, Tenant Cred maintains additional controls required by applicable law and approved operating procedures.
Where required, you may request access to report or file information Tenant Cred maintains about you, dispute inaccurate or incomplete information, request correction or suppression of inaccurate information, and receive information about the source/provider and support route for the report or data at issue.
Tenant Cred does not make a property manager's, leasing agent's, credit partner's, underwriting partner's, or other recipient's final rental or credit decision. Tenant Cred does not provide Consumer Reports to rental-context recipients for tenant-screening, rental-eligibility screening, or rental decisioning purposes. If a financial institution, credit partner, or underwriting partner makes an adverse decision based in whole or in part on separately authorized Consumer Report information, Tenant Cred supports the legally required notice, report-copy, source, rights-summary, dispute, and correction process where required.
For Consumer Report workflows, Tenant Cred maintains FCRA compliance controls, including permissible-purpose handling, consumer authorization, report and file disclosure routes, dispute and reinvestigation workflows, correction or suppression where appropriate, adverse-action support, and partner-certification controls.
Data Retention
Tenant Cred retains Plaid-derived data and Tenant Cred verification data indefinitely by default. You may submit a deletion request through Tenant Cred's support channel. After verifying your identity and authority, Tenant Cred will delete covered information when required by applicable law or in response to your verified request, except that Tenant Cred may continue to retain information to the extent permitted by law and needed for legitimate service, contractual, legal, audit, security, fraud-prevention, dispute, support, or comparable obligations.
When continued Plaid access is no longer needed or no longer authorized, Tenant Cred removes the relevant Plaid Item where appropriate, subject to legal, fraud-prevention, dispute, audit, product-servicing, security, and contractual exceptions.
Retention rules may differ for authorization records, audit logs, support records, saved disclosure snapshots, product-servicing records, security records, legal holds, backups, and records required by law or contract. Tenant Cred may delete, de-identify, suppress, expire, archive, or restrict records when full deletion is not permitted or is not technically feasible in an active backup or legal-hold context.
How We Share Information
Tenant Cred shares personal information only as needed for the service, with your authorization, or as permitted or required by law. Sharing categories include:
- Plaid, when you use Plaid-powered verification or account-linking flows.
- Hosting, cloud, database, storage, infrastructure, and backup providers.
- Security, monitoring, fraud-prevention, logging, and incident-response providers.
- Customer support, ticketing, communications, and operations providers.
- Analytics providers, limited to minimized operational metadata and only where sensitive data is excluded.
- Tenant-authorized rental-context recipients, such as property managers, leasing agents, or approved recipient accounts.
- Tenant-authorized credit or underwriting partners, including bank partners, only for the authorized purpose and under contractual controls.
- Legal, compliance, accounting, audit, insurance, and professional service providers.
- Verification, screening, or compliance partners that are contractually governed and appropriate for the specific workflow.
- Government, regulator, court, law enforcement, or other parties where required by law, subpoena, legal process, or to protect rights, safety, or security.
- Successors or counterparties in a business transaction, such as a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and legal controls.
Tenant Cred does not sell Plaid-derived consumer financial data. Tenant Cred does not use Plaid-derived covered data for targeted advertising, unrelated cross-selling, sale of covered data, or unrelated analytics.
Tenant Cred shares Plaid-derived restricted consumer data with vendors only when the vendor is approved for that data category, contractually bound, access-limited, included in the vendor inventory, and subject to retention and deletion duties.
Analytics, Tracking, Logging, Support Tools, And AI Tools
Tenant Cred configures analytics, tracking, logging, support, monitoring, session replay, customer-communications, and AI or automation tools so they do not receive raw Plaid payloads, Consumer Report data, full transaction feeds, bank credentials, account/routing details, IDV document images, selfie/liveness artifacts, restricted identity artifacts, or other sensitive financial data. A tool may receive sensitive financial data only when it is approved for that specific data category, contractually controlled, access-limited, and disclosed or authorized where required.
Tenant Cred does not use Plaid-derived restricted consumer data for advertising pixels, targeted advertising, unrelated analytics, AI model training, or unrelated product development. Operational analytics, if used, are limited to minimized metadata needed to operate, secure, troubleshoot, or improve the product you requested.
Support tickets, logs, analytics events, AI prompts, exports, and ordinary troubleshooting notes are configured to avoid raw sensitive data. Where sensitive information is needed to resolve a support, security, dispute, legal, or compliance issue, Tenant Cred limits access, records the purpose, and retains the information only as allowed by policy.
State Privacy Rights
As provided by applicable law, you may have additional privacy rights. These include the right to know or access categories or specific pieces of personal information, correct inaccurate personal information, delete personal information where permitted, receive information about categories of recipients, opt out of sale or sharing, limit certain uses or disclosures of sensitive personal information, or appeal a rights-request decision.
Tenant Cred does not sell Plaid-derived consumer financial data. Tenant Cred does not use Plaid-derived covered data for targeted advertising, unrelated cross-selling, sale of covered data, or unrelated analytics. Tenant Cred complies with applicable state privacy rights requirements, including rights-request, verification, appeal, authorized-agent, sale, sharing, and sensitive-personal-information requirements where those requirements apply.
To exercise privacy rights that apply to you, contact Tenant Cred using the contact information below. Tenant Cred may need to verify your identity before responding to certain requests.
Security Safeguards
Tenant Cred uses administrative, technical, and physical safeguards designed to protect personal information. These safeguards may include TLS for data in transit, encrypted infrastructure storage, application-layer encryption for restricted consumer data, server-side handling of secrets and long-lived tokens, least-privilege access controls, MFA for systems that handle customer information, logging and monitoring, vulnerability management, incident response, vendor oversight, and secure deletion or de-identification workflows.
Tenant Cred processes live production Plaid-derived consumer financial data only with applicable production controls, evidence, and operational workflows in place.
Tenant Cred keeps public security statements general, accurate, and supported by implemented controls.
No system can guarantee absolute security. If you believe your account or information may have been compromised, contact us at help@tenantcred.com.
Children
Tenant Cred is not directed to children under 18, and Tenant Cred does not knowingly collect personal information from children under 18.
Changes To This Policy
Tenant Cred may update this policy from time to time. If we make material changes, we will update the effective date and provide notice as required by law or appropriate for the change.
Tenant Cred will not use a policy update to retroactively broaden how it uses, shares, retains, analyzes, trains models on, or discloses previously collected personal information without appropriate review, notice, and new authorization where required. If Tenant Cred adds a materially different product, Plaid scope, recipient class, partner use, analytics use, AI use, or data retention purpose, Tenant Cred reviews and updates the policy, consent flow, terms, support scripts, and related product copy before using data for that new purpose.
Tenant Cred assigns an internal owner for this policy and reviews it at least annually and after material changes to products, Plaid scopes, vendors, recipients, state privacy law applicability, retention rules, security controls, or support/dispute workflows.
Contact Us
Questions, privacy requests, deletion requests, correction requests, revocation requests, and disputes may be sent to:
- Privacy email: privacy@tenantcred.com
- Support email: help@tenantcred.com