Privacy Policy
Introduction
Finn Management LLC (“Finn Management,” “we,” “us,” or “our”) operates a property management platform that helps property managers and landlords manage leases, tenants, maintenance, billing, and tenant screening. This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use our services.
This policy applies to all users of our platform, including property managers, landlords, tenants, rental applicants, and visitors to property websites powered by our platform.
Information We Collect
Information You Provide
- Account information: Name, email address, phone number, organization name
- Rental application information: Name, email, phone, employment history, income, rental history
- Sensitive personal information: Social Security Number (SSN) and date of birth, collected only when you submit a rental application and consent to screening. This data is encrypted at the application layer and stored in a dedicated, access-restricted table.
- Payment information: Payment card and bank account details provided via our payment processor (Payabli) for rent payment setup. We do not directly collect or store your full payment credentials — payment methods are tokenized by Payabli.
- Documents: Files you upload, such as identification documents, lease agreements, or maintenance photos
- Communications: Messages and requests submitted through the platform, including conversations with our AI communication system
Information Collected Automatically
- Usage data: Pages viewed, features used, timestamps
- Device and browser data: IP address, browser type, operating system
- Log data: API request metadata (method, path, status code, request ID, duration)
Information from Third Parties
- Consumer reports: For tenant screening, we facilitate access to consumer reports provided by authorized consumer reporting agencies. These reports are delivered directly to the authorized property manager and are not modified, stored, or repackaged by our platform.
- Payment processors: We use Payabli for payment processing. Payment transaction data is shared with Payabli as necessary to process your payments.
How We Use Your Information
We use the information we collect to:
- Provide and operate the property management platform
- Process rental applications and facilitate tenant screening
- Process rent payments and manage billing
- Manage leases, maintenance requests, and communications
- Respond to inquiries via AI-assisted communication channels (SMS, email, web chat)
- Verify identity and prevent fraud
- Comply with legal obligations, including the Fair Credit Reporting Act (FCRA)
- Improve our services and develop new features
- Send service-related notifications (e.g., payment confirmations, lease reminders)
We do not use your personal information for advertising or marketing to unrelated third parties, selling your personal information, or building consumer profiles beyond what is necessary for the services described above.
How We Share Your Information
We share personal information only in the following circumstances:
- With your property manager/landlord: Rental application details, screening results, payment history, and lease information
- With service providers: We share data with third-party service providers as necessary to provide our services
- With your consent: When you explicitly authorize us to do so
- For legal compliance: When required by law, regulation, court order, or governmental request
- For safety and fraud prevention: To prevent fraud, protect our rights, or ensure the safety of our users
We do not sell, rent, or trade your personal information.
Third-Party Service Providers
| Provider | Purpose | Data Shared |
|---|---|---|
| Payabli | Payment processing | Payment card/bank details (tokenized), transaction amounts, payer identity |
| MicroBilt | Tenant screening | Applicant name, SSN, date of birth, address (with consent) |
| BlueMoon | Lease documents & e-signatures | Tenant names, lease terms, property details |
| Postmark | Email delivery | Email addresses, email content |
| Twilio | SMS delivery | Phone numbers, message content |
| SuperTokens | Authentication | Email addresses, phone numbers, session tokens |
| Cloudflare | Hosting & storage | All platform data (encrypted at rest and in transit) |
| Anthropic | AI language model | Message content (PII minimized) |
AI and Automated Communications
Our platform uses AI-powered assistants to help respond to inquiries from tenants and prospective renters via SMS, email, and web chat. When you interact with these systems:
- You are communicating with an AI, not a human. Our AI assistants identify themselves as AI-powered in their initial responses.
- Conversations are logged. Messages you send and AI responses are stored to provide conversation continuity and enable staff review.
- AI does not make leasing decisions. All leasing decisions are made by property management staff.
- You can request a human at any time and the AI will escalate your request.
- Data minimization. We minimize personal information sent to AI model providers.
- Fair Housing compliance. Our AI systems are programmed with Fair Housing guardrails.
SMS and Text Message Communications
- You may receive texts related to rent reminders, payment confirmations, maintenance updates, lease information, and responses to your inquiries.
- You can opt out at any time by replying STOP. Reply START to resume.
- Standard message and data rates from your wireless carrier may apply.
- Consent is not a condition of service. We do not share your phone number or opt-in consent with third parties for marketing.
Passwordless Authentication
Tenant and applicant accounts use passwordless authentication via secure one-time codes sent to your phone. No passwords are stored. Sessions remain active for up to 7 days. Staff accounts use phone-based authentication with additional security measures.
Cookies and Tracking
Our platform uses essential cookies (session cookies, CSRF tokens) and analytics cookies via Google Tag Manager and Google Analytics 4. Analytics cookies help us understand how visitors use our site so we can improve the experience. We do not use advertising or social media tracking cookies. You may disable analytics cookies in your browser settings without affecting site functionality.
Consumer Reports
Consumer reports obtained through our platform are requested only with your explicit consent, delivered to the authorized property manager, not modified or stored by our platform, and governed by the FCRA. If adverse action is taken, you will receive notice including the consumer reporting agency name and your right to dispute.
Data Security
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Application-layer encryption for SSN and date of birth
- Role-based access control (RBAC) with MFA for staff
- Multi-tenant data isolation by organization
- Audit logging of all data access and modifications
- Rate limiting and webhook signature verification
Data Retention
- Applicant sensitive data (SSN, DOB): encrypted at rest, retained for 5 years per screening provider contractual requirements, then permanently purged
- Rental application records: tenancy + 3 years
- Contact and lease records: relationship + 7 years
- Financial records: 7 years
- AI conversation logs: tenancy + 1 year
- Payment method tokens: while active; deleted on removal
- Consumer reports: not stored
Nevada Privacy Rights (NRS 603A.340)
Pursuant to NRS 603A.340, we disclose that we collect the categories of personal information described in the “Information We Collect” section above for the purposes described in “How We Use Your Information.” We do not sell your personal information. In the event of a security breach, we will notify you within 30 days as required by NRS 603A.220. You may submit a verified request directing us not to sell your personal information by contacting us at privacy@finnmgmt.com.
Your Rights
You may have the right to access, correct, delete, or port your personal information.
To exercise any of these rights, contact us at privacy@finnmgmt.com. We will respond within 30 days.
Children’s Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy and updating the “Last Updated” date.
Contact Us
Finn Management LLC
1980 Festival Plaza Drive, Suite 300
Las Vegas, NV 89135
Email: privacy@finnmgmt.com
Phone: (725) 334-2046