← Back to LeasePace

Privacy Policy

Last updated: August 21, 2026
This policy is provided as a good-faith description of our data practices and is not legal advice. Have it reviewed by counsel before relying on it for a specific jurisdiction.

This Privacy Policy explains how LeasePace ("LeasePace", "we", "us") handles personal information in connection with the LeasePace leasing CRM platform (the "Service"). It applies to the Service on the web and in our iOS and Android apps.

1. Information we collect

2. How we use it

To provide, secure, and improve the Service; to send messages, run showings, process applications and screening, generate documents and e-signatures on your behalf via your connected providers; to process billing; and to comply with legal obligations.

We do not sell personal information. We do not use Customer Data — including any data received from Google APIs — to develop, improve, or train generalized or non-personalized AI or machine-learning models, and our AI providers are contractually barred from training their models on it.

3. Roles, and your responsibilities

For Customer Data about your leads, applicants, and tenants, you (the Workspace) are the data controller and LeasePace is a processor acting on your instructions. You are responsible for having a lawful basis and any required consents — including consent for SMS/voice communications under the TCPA and applicable law, and Fair Housing / FCRA compliance for screening.

Call recording. Recording is enabled by default for calls placed and received through the Service, and captures both sides of the call. Some U.S. states require the consent of every party to a call before it may be recorded, and the requirements differ from state to state. You are responsible for giving any notice and obtaining any consent required where you and the people you call are located, including any spoken recorded-line announcement. The Service does not currently play such an announcement automatically. If you cannot meet those requirements, do not use the calling features — contact us at privacy@leasepace.io to discuss disabling them for your Workspace.

4. Subprocessors

We share data with vetted service providers strictly to deliver the Service. A provider only receives data relevant to the feature you use:

ProviderPurpose
SupabaseDatabase, authentication, and encrypted file storage
VercelApplication hosting and delivery
TwilioSMS/MMS messaging and voice calls
WeimarkTenant screening (background, credit, and eviction data) — only when your Workspace enables screening
Anthropic (Claude)AI features: lead responder, message drafting, screening and call summaries, and the one-time column-mapping suggestion when you link or re-map a spreadsheet. Not used to train models. See Section 6.
DeepgramTranscription of recorded phone calls
ResendTransactional email delivery, including the summary of each spreadsheet sync sent to your Workspace's owners and admins
GoogleAddress lookup (Maps); Calendar sync for showings; and Linked Spreadsheets — reading the Google Sheets you link — where you connect them. See Section 5.
StripeSubscription and usage billing

A current subprocessor list is available on request. Messaging and voice run on Twilio accounts that LeasePace owns and operates on your behalf; a dedicated Twilio subaccount is provisioned for your Workspace so your messaging identity and policy standing are your own. You do not contract with or pay Twilio directly.

5. Google user data (Linked Spreadsheets and Calendar)

LeasePace's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.

How access is granted. Linked Spreadsheets works one of two ways, and you choose which:

What we access. From a linked file we read its title and ID, the names of its tabs, the column headers, and the cell values in the tabs you link. If you separately connect Google Calendar, we access only the calendar events for showings scheduled in LeasePace.

Access is read-only. LeasePace never creates, edits, deletes, moves, or shares your spreadsheet, and nothing you change in LeasePace is written back to it. The Google scopes we request are read-only, so Google enforces this as well as we do.

How we use it. Google user data is used for one purpose: keeping your LeasePace unit records in step with your sheet — matching each sheet row to a unit and creating, updating, or archiving unit records accordingly. When you first link a sheet, and again if a mapped column is renamed or removed, we send that sheet's column headers and up to five sample rows to our AI provider so it can suggest which column corresponds to which LeasePace field; a person in your Workspace confirms the result before it is applied. Routine scheduled syncs make no AI calls at all. See Section 6.

How we store it. Values from the tabs you link are copied into your Workspace — into your unit records and into a sync ledger we keep so we can detect changes and let you undo a sync — and are stored in our database under the tenant isolation and encryption described in Section 10. Google OAuth refresh and access tokens are encrypted at rest with AES-256-GCM, are readable only by our servers, and are never exposed to the browser.

How we share it. We share Google user data only with the providers listed in Section 4, and only to operate this feature: Google (the source), Supabase (storage), Vercel (hosting), Anthropic (the one-time column-mapping suggestion described above), and Resend (the sync summary email sent to your Workspace's owners and admins, which names the units that changed).

What we will not do. We do not sell Google user data, we do not transfer it to third parties for advertising or marketing purposes, and we do not use or transfer it to develop, improve, or train generalized or non-personalized AI or machine-learning models. No LeasePace employee reads your Google user data except with your explicit permission (for example, when you contact us for support), where necessary for security purposes such as investigating abuse, or to comply with applicable law.

How to revoke and delete it. You can disconnect at any time in Settings → Linked spreadsheets. Disconnecting revokes our token with Google, deletes it from our systems, and stops all further reads. You can also revoke our access directly at myaccount.google.com/permissions. If you shared a sheet with our service-account address instead, remove that address from the sheet's sharing list. Disconnecting does not by itself delete the unit records and sync history already created from that sheet — those are your Workspace's data and are retained as described in Section 8. To have them deleted, email privacy@leasepace.io.

6. AI processing

Some features use a third-party AI provider (Anthropic) to process content on your behalf: replying to leads, drafting messages, summarising screening reports and call transcripts, and — for Linked Spreadsheets — proposing which spreadsheet column corresponds to which unit field.

For Linked Spreadsheets, the mapping call happens once, when a sheet is first linked or its column layout changes. The column headers and up to five sample rows from that sheet are sent to the AI provider's API so a model can propose a mapping, which a person in your Workspace then reviews and confirms. Those rows are real rows and may contain personal information from your sheet. Routine scheduled syncs make no AI calls.

Data sent to the AI provider's API is not used to train its models. AI output can be inaccurate; a person in your Workspace is responsible for reviewing anything sent on your behalf. Our leasing assistant identifies itself as an AI and does not impersonate a person.

7. Screening & sensitive data

When you run tenant screening, applicant information is transmitted to our screening provider (Weimark) to produce a report. LeasePace does not store applicant Social Security numbers in plaintext — every SSN in a screening report is reduced to its last four digits before it is saved, and the full number stays with the screening provider. An applicant's date of birth from a completed report is stored with the report so the report can be displayed. Identifiers are redacted from our internal audit logs and are stripped before any part of a report is sent to our AI summarizer. Screening results are retained only as needed to display and act on the report. Screening data is subject to the Fair Credit Reporting Act (FCRA) and Fair Housing laws, and you are responsible for using it lawfully.

8. Retention & deletion

We retain Customer Data for as long as your Workspace is active, and then as described below.

DataRetention
Leads, applicants, tenants, messages, units, documentsLife of the Workspace; deleted on Workspace deletion
Call recordings (audio)90 days live, then moved to a restricted archive and permanently erased at 120 days
Call transcripts and AI summariesLife of the Workspace — retained after the audio is erased, because our leasing assistant uses them to understand a lead's history
Screening reportsLife of the Workspace; identifiers redacted from logs (see Section 7)
Data read from a linked spreadsheetLife of the Workspace; unlinking the sheet stops further reads but does not delete records already created
Account and billing recordsRetained as required for tax and accounting purposes after the Workspace closes

Deleting your Workspace. Workspace deletion is performed by us rather than self-serve: email privacy@leasepace.io from the Owner's address and we will permanently delete the Workspace and all of its data. On deletion we remove the Workspace's records from our database and its files from storage; residual copies in encrypted infrastructure backups are overwritten as those backups expire. If you need a shorter retention window for any category above, contact us.

9. Your rights

Depending on your location (e.g., GDPR/CCPA), you may have rights to access, correct, delete, or export personal information. Workspace members should direct requests to their Workspace Owner; others may contact us at privacy@leasepace.io. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we will not discriminate against you for exercising a privacy right. A Data Processing Addendum is available on request.

The Service is operated from the United States and Customer Data is stored there. If you access it from outside the United States, you are transferring information to the United States.

10. Security

We use industry-standard measures including encryption in transit (TLS), encryption of integration secrets at rest (AES-256-GCM), role-based access controls, and per-Workspace tenant isolation (row-level security). No method of transmission or storage is 100% secure. If we become aware of a breach affecting your personal information, we will notify you without undue delay and as required by applicable law.

11. Children

The Service is a business tool intended for property-leasing professionals and is not directed to children under 13. We do not knowingly collect personal information from children.

12. Changes & contact

We may update this policy; material changes will be notified in-app or by email. Contact: privacy@leasepace.io.