The fine print · Effective October 1, 2026

Privacy Policy

What we collect, why, who helps us process it, and how you stay in control — for landlords, for the tenants they manage, and for anyone just visiting.

Every section opens with a Plain English summary — the same way our agent explains your leases. The full text below it is what governs.

Never sold

No data sales, no ads, no cross-site tracking, no training AI models on your files.

Cards never touch us

Stripe handles payment details end to end. We store your plan and status, nothing more.

Tenants protected

Landlords control their tenant records; we process them only on the landlord's instructions.

Export & delete anytime

CSV export on every plan. Deletion requests honored within 30 days.

1The short version

Plain English

We collect what's needed to run a property management service, use it only for that, sell it to no one, and hand it back or erase it when you ask.

This policy covers everyone the Service touches: landlords and their teams, tenants and applicants invited by a landlord, and visitors to our website. It explains what we collect, why, who helps us process it, and the rights you have. LetsGoLandlord is operated by Tidal Equity Partners LLC, a Florida limited liability company — reachable anytime through our private support form.

Three commitments up front: we never sell or rent personal information, we never use your content to train AI models, and we never show ads.

2What we collect

Plain English

Your account details, the property records and documents you put in, subscription status from Stripe, and the basic technical logs every website has.

Account data. Name, email, and a password (stored only as a secure hash by our authentication provider). Optional two-factor authentication settings.

Content you add. Properties, units, tenants, leases, ledgers, maintenance tickets, inspections, and the documents and photos you upload or import. This is the heart of the Service and it belongs to you.

Billing data. Payments are processed by Stripe. Card numbers never touch our servers — we store only your Stripe customer reference, plan, and subscription status.

Technical data. Standard server logs (IP address, browser type, pages requested) via our hosting provider, used for security and debugging. We also keep our own record of which pages are opened and for how long, to improve the product — see the analytics section for exactly what that holds and how long we keep it.

Optional integrations. If you connect Telegram, we store your chat ID to send alerts. If you connect a bank through Plaid (where available), we receive account names and transactions for the accounts you choose — your bank credentials go to Plaid, never to us.

3If you're a tenant or applicant

Plain English

Your landlord controls the records they keep about you — we process them on the landlord's behalf. Ask your landlord about corrections; ask us anytime about security.

Landlords use the Service to keep records about their tenants and applicants — contact details, leases, payment history, maintenance requests, and application information the landlord chooses to collect. For those records, your landlord is the data controller and we are the processor: we store and process them on the landlord’s instructions and don’t use them for anything else.

To correct or remove records your landlord keeps, contact your landlord — the law generally governs what they must retain. For questions about how we protect the data itself, submit a privacy support request. If you create a tenant portal login, the account-data promises in this policy apply to you directly.

4How we use data

Plain English

To run the product you signed up for, email you the things you asked for, keep the lights on, and keep intruders out. That's the whole list.

We use personal data to:

  • provide and operate the Service you signed up for;
  • run AI features you trigger (see the AI section below);
  • send transactional email — invites, alerts, digests, receipts, security notices;
  • answer support requests;
  • secure the Service, prevent abuse, and debug problems;
  • meet legal obligations (tax, accounting, lawful requests).

We do not sell or rent personal data, run third-party advertising, track you across other websites, or use your content to train AI models.

5AI processing

Plain English

When you ask the agent to read a lease, that document goes to our AI provider to produce your result — and may not be used to train their models.

AI features run only when you (or automation you configured) trigger them. The document or data involved is sent to our AI provider, Anthropic, over an encrypted connection through their business API — under terms that do not permit using your content to train their models. The result (extracted fields, a draft, a summary) is stored in your account like anything else you create, with confidence labels where accuracy matters.

6Who we share data with

Plain English

Only the vendors below, each doing one job for us under contract — plus the rare legal demand, which we'll tell you about unless we're legally barred.

We share personal data only with the service providers that run parts of the product, each bound by contract to use it solely for that purpose:

ProviderWhat they do for youWhen
SupabaseDatabase, authentication, and file storageAlways — it's where your account lives
VercelApplication hosting, server logs, and page-view counts on the public marketing pagesAlways — it serves the site
StripePayments, subscriptions, and sales taxWhen you subscribe
AnthropicAI document reading and draftingWhen you use an AI feature
ResendTransactional email deliveryWhen the app emails you or your invitees
Google MapsProperty photos and address lookupsWhen a property address is shown or verified
TelegramOptional instant alertsOnly if you connect Telegram
PlaidOptional bank feeds (bank credentials never touch us)Only if you connect a bank
ImprovMXRoutes email you send to our support addressWhen you email support

Beyond that: we disclose data if the law compels us (and will notify you unless legally prohibited), and if LetsGoLandlord is ever acquired or merged, your data transfers with the same commitments and you’ll be notified first.

7Bank connections (Plaid)

Plain English

Your bank login goes to Plaid, never to us. We receive only the transactions you authorize, use them only to reconcile your ledger, and cut off access the moment you disconnect.

Where bank feeds are available, we use Plaid Inc. to connect the accounts you choose. When you use Plaid Link, you provide your credentials directly to Plaid — never to us — and you grant us and Plaid the right to access and transmit your financial information as described here. Data you share with Plaid is governed by the Plaid End User Privacy Policy.

We receive transaction data (dates, amounts, descriptions) and account metadata (institution, account name, last-four mask), and we use it for exactly one thing: reconciling deposits against the rent ledgers in your account. When you disconnect a bank — or a feed pauses itself for inactivity — we revoke our access at Plaid and delete the access token. Transactions already imported stay in your ledger unless you delete them.

8Cookies

Plain English

Session cookies to keep you signed in, two random ids for our own site analytics, and — on the public marketing pages only, when we're running ads — the Meta (Facebook) Pixel and the Google tag.

Our own cookies are first-party — set by us, readable only by us, and never shared with another company.

Session cookies keep you signed in and the Service secure.

Analytics cookies (lgl_vid, lgl_sid) hold two random identifiers — no name, no email, nothing derived from you — so we can see how the site is used: which pages get opened, in what order, and for how long. That’s how we find the places where our own product confuses people. See the analytics section below for exactly what gets recorded and for how long.

Advertising measurement (marketing pages only). When we run ads, the public marketing pages and the signup page load the Meta (Facebook) Pixel and the Google tag (for Google Ads) so we can tell whether an ad worked. Meta and Google may set their own cookies there and receive the pages you viewed on our public site — see the analytics section for the exact boundary. Neither tag ever runs inside the signed-in product, the tenant portal, the owner portal, or any magic-link page.

9Product analytics

Plain English

We record which pages get opened, in what order, and for how long — ourselves, on our own servers. Three third-party scripts (Vercel's page-view counter, the Meta Pixel, and the Google tag) run on the public marketing pages only. IP addresses are deleted after 30 days. We never track your tenants.

We measure how our own website and app are used, so we can find the steps where people get stuck. That measurement runs entirely on our own servers — no Google Analytics, and nothing about your use of the signed-in product leaves our infrastructure.

Three third-party scripts run on the public marketing pages and the signup page, and nowhere else:

  • Vercel Web Analytics, our hosting provider’s page-view counter. It receives the page opened, the page you arrived from, your approximate country, and whether you were on a phone or a computer. It sets no cookies and does not follow you to other sites.
  • The Meta (Facebook) Pixel, for ad measurement: it tells us an ad click turned into a visit or a signup.
  • The Google tag, for Google Ads: the same job as the pixel — did an ad click turn into a visit or a signup — and Google may use the public pages you viewed to show our ads to you again elsewhere (remarketing).

All three share one boundary, enforced in code: a page view inside the app, the tenant or owner portal, a rental application, or any magic-link page is never sent to any of them.

What a page view records. The page’s template (for example /leases/[id] — never the record id itself), when it was opened, how long it was open, the page you arrived from, any campaign tag in the link, whether you were on a phone or a computer, your browser, your approximate country and region, and your IP address. Once you are signed in, your account is recorded alongside it.

Your IP address is deleted after 30 days, while the rest of the record — which is not tied to a name — is kept for up to a year so we can compare one season with another.

We do not do this to tenants. The tenant portal, the property-owner portal, rental applications, and every magic link (maintenance requests, e-signature, renewals, inspection scheduling) are excluded from analytics entirely — ours and every third-party script’s. Those pages belong to people who came here because a landlord sent them, and their movements are not ours to study.

We never sell this data. The only sharing with advertising companies is the Meta Pixel and the Google tag described above — public marketing pages and signup only, so we can measure our own ads — and what each collects is governed by Meta’s and Google’s own privacy policies. Your account data, your ledger, and everything you do inside the product are never shared with advertisers and never used to follow you onto other websites. Ask us and we will tell you what is held against your account, or delete it.

10How we protect it

Plain English

Encrypted in transit and at rest, walled off per organization at the database level, with optional 2FA on your account.

Traffic is encrypted in transit (TLS 1.2+); databases and file storage are encrypted at rest (AES-256), and bank access tokens get an additional layer of application-level AES-256-GCM encryption. Every organization’s data is isolated with database-level row security — the same query physically cannot return another organization’s records. Access by our systems follows least-privilege principles, and you can add two-factor authentication to your account (required before connecting a bank).

No system is perfectly secure. If a breach affects your personal data, we’ll notify you without undue delay and tell you what happened, what was involved, and what we’re doing about it.

11How long we keep it

Plain English

While your account is active, we keep it. Cancel and it's paused but fully exportable for 90 days — we warn you before the deadline, then permanently delete it. Reactivate within that window and nothing is lost. Ask for deletion sooner and it's gone within 30 days.

We keep your data while your account is active. If you cancel — or a trial or paid subscription lapses — your account is paused and read-only, and everything stays visible and exportable. We keep it for 90 days, email you a reminder before the deadline, and then permanently delete the organization and all of its data. Reactivate any time within that 90-day window and it all comes back exactly where you left it.

When you request deletion sooner, we remove your personal data from active systems within 30 days; copies in encrypted backups expire on a rolling schedule shortly after. We retain what the law requires us to keep (for example, billing records for tax purposes) for the legally required period only.

12Your rights and choices

Plain English

See it, export it, fix it, or delete it — one email, answered within 30 days, no hoops.

Wherever you live, we extend the same rights to everyone: ask us to access, export, correct, or delete your personal data by submitting a privacy support request. We’ll verify it’s you and respond within 30 days, and we never treat you differently for exercising your rights. Most exports don’t even need an email — CSV export is built into the app on every plan.

We send almost no marketing email; anything promotional includes an unsubscribe link. Transactional messages (receipts, security notices, alerts you configured) continue while you have an account, and alert emails are configurable in Settings.

13Children

Plain English

This is a service for adults.

The Service is for adults 18 and over. We don’t knowingly collect personal information from children; if you believe a child has provided us data, contact us and we’ll delete it.

14Where data lives

Plain English

On servers in the United States.

We host and process data in the United States, and our service providers are primarily U.S.-based. If you use the Service from elsewhere, you understand your data is processed in the U.S. under this policy.

15Changes to this policy

Plain English

Material changes come with advance notice by email — never a silent edit.

We’ll update this policy as the Service evolves. Material changes get advance notice by email or in-app before they take effect, and the effective date at the top always reflects the current version. Earlier versions are available through our support form.

Questions about any of this?

Send us a private support request — a person reads every ticket. And read the companion document: Terms of Service.

Effective October 1, 2026. Earlier versions available on request.