Safe Healthy Homes Act: 59d 4h until November 1, 2026
Skip to content
Philly Rental Compliance

Privacy Policy

Version 8 · effective August 30, 2026

Information collected

Philly Rental Compliance collects only what it needs to provide the service. To run the Property Readiness Check, we need a property address. If you activate Compliance Watch, sign in, or request an emailed preview, we also store your email address and the properties involved. We do not ask for or store deeds, photo IDs, or uploaded document files.

Free scans and preview links

A free scan uses the address you enter to retrieve supported public records. If you ask us to email the preview link, we store the email and property needed to deliver it. The form discloses a short educational series of up to four follow-up messages over about two weeks. Every message includes a one-click unsubscribe, and opting out stops the remaining series.

Renter address checks and reports

A free renter lookup sends the address you enter to our server and supported Philadelphia public-record sources. The application may keep the resulting address lookup in a separate in-memory cache for no more than six hours, then it expires automatically. It is not joined to owner accounts, customer properties, leads, or marketing lists. We do not ask for an email or create an account for the free lookup.

If you buy the $9.99 one-time Philadelphia Renter Property Report, Stripe provides the email needed for the receipt and delivery. The payment session receives an encrypted, opaque fulfillment snapshot, not readable address, license, or violation fields. We retain the email, matched and typed addresses, purchased record snapshot, checked time, and Stripe fulfillment identifier for 90 days from purchase so the private report link can reopen; a daily retention job deletes the record after that deadline. Delivered email bookkeeping is normally removed after 35 days, and terminal delivery failures by 90 days. Save or print the report if you need it longer. Reopening checkout does not shorten or otherwise change the access, receipt, retention, or refund rights attached to an earlier purchase.

Renter addresses and raw queries are submitted in the request body, not placed in the page URL, and our application does not intentionally write them to application logs. Hosting and security providers may retain IP addresses, request paths, headers, and operational metadata under their account retention settings; those logs are not used to contact a landlord or for advertising.

Reminder emails

If you opt into the free license-expiry reminder, we store your email and the selected property after you confirm from your inbox. One reminder when the rental-license expiration date on City records is about 30 days away, or shortly after confirmation if fewer than 30 days remain. The reminder includes a one-click unsubscribe that turns off the free license-reminder email type for that inbox across its selected properties. It does not cancel paid annual monitoring, receipts, or security messages.

Annual subscription and monitoring

We use this information to build the supported-record activation baseline and owner workspace for Compliance Watch, run recurring supported-source checks, send alerts after material supported-record changes, send monthly status messages, and provide service communications. Up to three reminders around 60, 30, and 7 days before the rental-license expiration date on City records, depending on when annual monitoring begins. We do not sell your personal information.

Analytics and cookies

We use only essential cookies: a session cookie that keeps you signed in and a small signed-in flag so the header can reflect your session. We do not use advertising or cross-site tracking cookies. Vercel Web Analytics counts page views and anonymous funnel actions, such as a scan or checkout starting. Those events never include an address, unit, parcel number, license number, owner or LLC name, email, payment details, Checkout Session or receipt token, raw query text, or cross-site tracking identifier.

When Google Search Console is configured, it provides aggregate search-performance totals and the public site pages shown in Google results so we can identify indexing problems. We do not request or store the search-query text people typed into Google.

Browser storage

The portfolio builder temporarily saves its draft in this browser for up to two hours so an interrupted setup can be recovered. That device-local draft may include entered addresses, matched parcel identifiers, and City owner metadata. It is not an analytics event and does not sync to another device; clearing site data removes it, and a successfully saved portfolio clears the temporary builder draft. Signed-in owner confirmations, compliance tasks, and their activity history are durable service records stored server-side and are not erased by clearing browser data.

Portfolio inquiries

If you request portfolio pricing, we collect your name, email, number of Philadelphia rental properties, and any optional company name or workflow message you provide. We use it to review and respond to the request. The form does not create a subscription or enroll you in an unrelated marketing list.

Customer feedback

Verified buyers and subscribers may optionally rate a report and leave a comment. We store a one-way respondent hash rather than an email or checkout token with that feedback. Comments are private by default. We consider one for public use only after separate public-use permission; any optional display name, role, or company is retained only with that permission and reviewed before use.

Compliance Vault

Signed-in Compliance Watch customers and customers with retained legacy access may add private Compliance Vault metadata, including document type, owner-confirmed status, dates, and notes. These records are labeled owner provided and are not treated as City verification. The Vault stores record details, not uploaded files. Do not put Social Security numbers, payment-card data, photo IDs, or other unnecessary sensitive information in notes.

Service providers

Stripe processes payments; we never see or store full card numbers. Supabase stores application data, Vercel hosts the service and provides analytics, Resend delivers transactional email, and Google Search Console may provide the aggregate and public-page search-performance data described above. Each provider handles data under its own security and privacy commitments.

Retention and deletion

We keep account and subscription-monitoring data while you use the service and as needed for legal and accounting obligations. Renter-report access records follow the 90-day period above. You can request deletion by emailing us from the purchase email with the approximate purchase date and property address, and we will delete what we are not required to retain. Deleting a renter record ends access through its private link.

Contact

Questions or requests about your data: support@phillyrentalcompliance.com.