Skip to document

Document version: public-privacy-24394f00a4a391c488467aeeb6f4888b

Save a text copy

You can also use your browser’s Print command to save this document as a PDF.

Tenant Cred Privacy Policy

Updated: May 22, 2026

Entity: Tenant Cred LLC ("Tenant Cred," "we," "us," or "our")

Privacy notice contact: privacy@tenantcred.com

Support contact: help@tenantcred.com

What Tenant Cred Is

Tenant Cred is a U.S. rental-verification product for renters and tenants. Tenant Cred helps a renter create and share a tenant-authorized credential that can include verified facts about identity, income signals, and employment.

Tenant Cred uses Plaid to help securely connect to user-authorized financial accounts for verification.

Tenant Cred is not a consumer reporting agency and does not furnish consumer reports. Tenant Cred does not sell, resell, furnish, or otherwise provide Consumer Reports or tenant-screening reports to landlords, property managers, leasing agents, housing providers, or other rental-context recipients for tenant-screening, rental-eligibility screening, or rental decisioning purposes.

For workflows that require credit-related underwriting data, Tenant Cred uses Identity Verification plus Plaid Check Consumer Report products such as CRA Base Report and CRA Income Insights, with tenant or guarantor authorization and FCRA controls. Any separately authorized Consumer Report workflow is limited to the specific credit, underwriting, regulatory, compliance, or related review purpose presented in that workflow, and is not used to furnish Consumer Reports to rental-context recipients for tenant-screening purposes.

Tenant Cred shares tenant-authorized verification results through recipient-specific views. These views are designed to disclose only the approved facts needed for the rental purpose, not raw bank or provider data.

Tenant Cred does not provide recipient decisioning, automated screening conclusions, composite tenant-quality labels, scores, or automated approval/denial recommendations.

Tenant Cred maintains compliance controls for separately authorized Consumer Report workflows and recipient-specific disclosures, including permissible-purpose handling, consumer authorization, report and file access where required, dispute and correction handling, adverse-action support where required, partner certification, and access logging.

Who This Policy Covers

This policy is written for renters and tenants who use Tenant Cred. It also describes how we handle information when a renter authorizes a disclosure to a rental-context recipient, such as a property manager, leasing agent, or other approved recipient.

Tenant Cred currently offers the service only to users in the United States. This policy applies to that U.S. service.

Information We Collect Directly From You

The categories of information Tenant Cred collects directly from you include:

Tenant Cred does not ask you to give Tenant Cred your bank username or password. When a financial-account connection is needed, the connection is handled through Plaid or another approved verification provider.

Information We May Receive Through Plaid

When you choose to connect a financial account or complete identity, income, Consumer Report, account, or payment-source verification through Plaid, Plaid may collect information from you, your device, your financial institution, and other sources as described in Plaid's own privacy materials.

The exact information Tenant Cred receives depends on the Plaid products, accounts, and data scopes you authorize. Tenant Cred processes Plaid-derived information such as:

Not every user will provide or authorize every category. Tenant Cred requests only the data needed for the tenant-authorized rental verification purpose presented to you.

What Plaid Is

Plaid is a third-party provider that helps users connect financial accounts and authorize data sharing with applications like Tenant Cred. If you use Plaid Link, Plaid may ask you to select your financial institution, authenticate with that institution, select accounts, and review consent information about the data being shared and why. In production, Plaid may display Data Transparency Messaging that describes the requested data scopes and use case.

Plaid's privacy policy and related privacy tools apply to Plaid's own handling of your information. Tenant Cred's privacy practices are described in this policy, and Plaid's privacy practices are described in Plaid's own materials.

Financial Data Permissions And Consumer Authorization

Before Tenant Cred requests financial-account data, identity verification, income verification, Consumer Report data, payment-source verification, or a recipient-specific disclosure, Tenant Cred presents a clear notice or authorization flow that explains the product or service you requested, the data categories requested, the reason the data is needed, the expected duration of collection or access, and how you can revoke future access.

Tenant Cred requests only the data needed for the specific tenant-authorized credential, rental verification, payment-source, support, dispute, or underwriting-support purpose presented to you. If Tenant Cred needs additional data categories, additional recipients, or a materially different use case after your original authorization, Tenant Cred requests additional authorization where required before collecting or using that additional information.

Tenant Cred does not ask you for your financial-account credentials. When a Plaid-powered flow is used, Plaid or your financial institution handles the connection and authentication process. Tenant Cred receives the authorized data, verification results, report references, or operational metadata needed for the product or service you requested.

Tenant Cred records authorization details, including the product or data scope requested, purpose shown to you, policy and consent text version, recipient or partner context for the workflow, timestamps, Plaid session or report references, revocation route, deletion route, dispute route, and file-disclosure route.

Why We Use Plaid-Derived Information

Tenant Cred uses Plaid-derived information for limited tenant-authorized purposes, including:

Tenant Cred does not use Plaid-derived data for targeted advertising, unrelated cross-selling, sale of covered data, or unrelated analytics.

Selective Disclosure To Rental-Context Recipients

Tenant Cred shares verification results with a rental-context recipient only when you authorize that recipient. A recipient may include a property manager, leasing agent, or other approved recipient account you authorize.

When you authorize a disclosure, Tenant Cred shares only the approved credential facts or verification results for that recipient and rental purpose. Recipient views may show verified facts, verification badges, named verification results such as income-signal or employment-verification status, source freshness, and limited provenance. These views identify the relevant result without showing raw bank data, raw provider payloads, full transaction feeds, or other sensitive details that are not needed for the authorized rental purpose.

Tenant Cred does not expose raw Plaid payloads, full transaction feeds, account/routing numbers, bank credentials, IDV document images, selfie/liveness artifacts, or internal verification logic, operational rules, or security-sensitive business logic in ordinary recipient-facing credential views.

A recipient-specific disclosure is not the same as giving a recipient live access to your full Tenant Cred credential. A saved disclosure, if allowed by the applicable share settings, is a saved snapshot of what you authorized and what the recipient saved under policy. It does not give the recipient automatic access to future credential updates, future Plaid refreshes, raw provider data, or additional information without a new authorization or approved workflow.

Tenant Cred requires recipients and approved partners to use disclosed information only for the tenant-authorized rental, verification, support, or underwriting purpose. Recipient or partner access is logged, purpose-limited, and subject to expiration, revocation, retention, deletion, and no-onward-sharing controls.

Tenant Cred presents notice and obtains your authorization before initiating Plaid Link, Plaid Identity Verification, Plaid Check CRA Base Report, Plaid Check CRA Income Insights, payment-source verification, or a selective disclosure to a recipient or approved credit/underwriting partner.

For Consumer Report workflows, Tenant Cred asks a tenant or guarantor to connect all relevant financial accounts they own or control and can authorize through Plaid, including accounts at multiple financial institutions, so the requested credential, rental verification, or underwriting-support workflow can use a holistic consumer-authorized account and cash-flow view.

You may request to revoke future Plaid access or future disclosure access by contacting us at help@tenantcred.com or using the in-product controls when available. Revocation generally stops future collection, future refresh, and future recipient access where permitted.

Revocation does not automatically delete records that Tenant Cred must retain or is allowed to retain for legal, fraud-prevention, dispute, audit, security, product-servicing, contractual, or historical disclosure-record purposes. For example, Tenant Cred may retain consent records, revocation records, disclosure manifests, access logs, saved disclosure snapshots, deletion records, and support records where needed to show what you authorized, what was shared, and what actions were taken.

You may request access to information about the categories of information Tenant Cred collects, the reasons for collection, the categories of recipients or vendors with whom information was shared, correction of inaccurate information, deletion where legally and operationally permitted, or help disputing information you believe is inaccurate. If a separately authorized Tenant Cred workflow is subject to consumer-reporting law, additional FCRA file disclosure, reinvestigation, correction, permissible-purpose, user-notice, and adverse-action support obligations may apply.

Tenant Cred will not discriminate against you for exercising privacy rights that apply to you.

Consumer Report Workflows And Rights

Some Tenant Cred workflows may involve Consumer Report information or other information used for a rental, credential, or credit-related underwriting purpose. For those workflows, Tenant Cred maintains additional controls required by applicable law and approved operating procedures.

Where required, you may request access to report or file information Tenant Cred maintains about you, dispute inaccurate or incomplete information, request correction or suppression of inaccurate information, and receive information about the source/provider and support route for the report or data at issue.

Tenant Cred does not make a property manager's, leasing agent's, credit partner's, underwriting partner's, or other recipient's final rental or credit decision. Tenant Cred does not provide Consumer Reports to rental-context recipients for tenant-screening, rental-eligibility screening, or rental decisioning purposes. If a financial institution, credit partner, or underwriting partner makes an adverse decision based in whole or in part on separately authorized Consumer Report information, Tenant Cred supports the legally required notice, report-copy, source, rights-summary, dispute, and correction process where required.

For Consumer Report workflows, Tenant Cred maintains FCRA compliance controls, including permissible-purpose handling, consumer authorization, report and file disclosure routes, dispute and reinvestigation workflows, correction or suppression where appropriate, adverse-action support, and partner-certification controls.

Data Retention

Tenant Cred retains Plaid-derived data and Tenant Cred verification data indefinitely by default. You may submit a deletion request through Tenant Cred's support channel. After verifying your identity and authority, Tenant Cred will delete covered information when required by applicable law or in response to your verified request, except that Tenant Cred may continue to retain information to the extent permitted by law and needed for legitimate service, contractual, legal, audit, security, fraud-prevention, dispute, support, or comparable obligations.

When continued Plaid access is no longer needed or no longer authorized, Tenant Cred removes the relevant Plaid Item where appropriate, subject to legal, fraud-prevention, dispute, audit, product-servicing, security, and contractual exceptions.

Retention rules may differ for authorization records, audit logs, support records, saved disclosure snapshots, product-servicing records, security records, legal holds, backups, and records required by law or contract. Tenant Cred may delete, de-identify, suppress, expire, archive, or restrict records when full deletion is not permitted or is not technically feasible in an active backup or legal-hold context.

How We Share Information

Tenant Cred shares personal information only as needed for the service, with your authorization, or as permitted or required by law. Sharing categories include:

Tenant Cred does not sell Plaid-derived consumer financial data. Tenant Cred does not use Plaid-derived covered data for targeted advertising, unrelated cross-selling, sale of covered data, or unrelated analytics.

Tenant Cred shares Plaid-derived restricted consumer data with vendors only when the vendor is approved for that data category, contractually bound, access-limited, included in the vendor inventory, and subject to retention and deletion duties.

Analytics, Tracking, Logging, Support Tools, And AI Tools

Tenant Cred configures analytics, tracking, logging, support, monitoring, session replay, customer-communications, and AI or automation tools so they do not receive raw Plaid payloads, Consumer Report data, full transaction feeds, bank credentials, account/routing details, IDV document images, selfie/liveness artifacts, restricted identity artifacts, or other sensitive financial data. A tool may receive sensitive financial data only when it is approved for that specific data category, contractually controlled, access-limited, and disclosed or authorized where required.

Tenant Cred does not use Plaid-derived restricted consumer data for advertising pixels, targeted advertising, unrelated analytics, AI model training, or unrelated product development. Operational analytics, if used, are limited to minimized metadata needed to operate, secure, troubleshoot, or improve the product you requested.

Support tickets, logs, analytics events, AI prompts, exports, and ordinary troubleshooting notes are configured to avoid raw sensitive data. Where sensitive information is needed to resolve a support, security, dispute, legal, or compliance issue, Tenant Cred limits access, records the purpose, and retains the information only as allowed by policy.

State Privacy Rights

As provided by applicable law, you may have additional privacy rights. These include the right to know or access categories or specific pieces of personal information, correct inaccurate personal information, delete personal information where permitted, receive information about categories of recipients, opt out of sale or sharing, limit certain uses or disclosures of sensitive personal information, or appeal a rights-request decision.

Tenant Cred does not sell Plaid-derived consumer financial data. Tenant Cred does not use Plaid-derived covered data for targeted advertising, unrelated cross-selling, sale of covered data, or unrelated analytics. Tenant Cred complies with applicable state privacy rights requirements, including rights-request, verification, appeal, authorized-agent, sale, sharing, and sensitive-personal-information requirements where those requirements apply.

To exercise privacy rights that apply to you, contact Tenant Cred using the contact information below. Tenant Cred may need to verify your identity before responding to certain requests.

Security Safeguards

Tenant Cred uses administrative, technical, and physical safeguards designed to protect personal information. These safeguards may include TLS for data in transit, encrypted infrastructure storage, application-layer encryption for restricted consumer data, server-side handling of secrets and long-lived tokens, least-privilege access controls, MFA for systems that handle customer information, logging and monitoring, vulnerability management, incident response, vendor oversight, and secure deletion or de-identification workflows.

Tenant Cred processes live production Plaid-derived consumer financial data only with applicable production controls, evidence, and operational workflows in place.

Tenant Cred keeps public security statements general, accurate, and supported by implemented controls.

No system can guarantee absolute security. If you believe your account or information may have been compromised, contact us at help@tenantcred.com.

Children

Tenant Cred is not directed to children under 18, and Tenant Cred does not knowingly collect personal information from children under 18.

Changes To This Policy

Tenant Cred may update this policy from time to time. If we make material changes, we will update the effective date and provide notice as required by law or appropriate for the change.

Tenant Cred will not use a policy update to retroactively broaden how it uses, shares, retains, analyzes, trains models on, or discloses previously collected personal information without appropriate review, notice, and new authorization where required. If Tenant Cred adds a materially different product, Plaid scope, recipient class, partner use, analytics use, AI use, or data retention purpose, Tenant Cred reviews and updates the policy, consent flow, terms, support scripts, and related product copy before using data for that new purpose.

Tenant Cred assigns an internal owner for this policy and reviews it at least annually and after material changes to products, Plaid scopes, vendors, recipients, state privacy law applicability, retention rules, security controls, or support/dispute workflows.

Contact Us

Questions, privacy requests, deletion requests, correction requests, revocation requests, and disputes may be sent to: