Privacy Policy
Effective date: 2026-04-17. Last updated: 2026-04-17.
1. What we collect
We collect the information you provide when you use the Service, including:
- Identity and contact: name, email address, phone number, mailing address, date of birth.
- Apartment information: address, borough, unit, move-in date, current rent, lease dates, landlord contact information.
- Documents you upload: DHCR rent histories, leases, receipts, correspondence, and related records.
- Payment information: processed by Stripe; we do not store full card numbers.
- Usage data: IP address, device information, and pages visited, collected through our hosting provider (Vercel) and our error-tracking tool (Sentry).
2. Sensitive information
The information you provide includes sensitive personal information as defined under New York law, including date of birth and residential address. We treat this information as protected private information under the New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act and maintain reasonable administrative, technical, and physical safeguards.
3. How we use it
We use the information we collect to:
- Provide the Service: analyze your rent history, prepare your RA-89 complaint, and communicate with you.
- Request your rent registration history from DHCR as your administrative agent.
- Facilitate attorney review if you select contingency representation.
- Process payments and issue receipts.
- Improve our analysis engine. Data used for improvement is aggregated and stripped of identifiers.
- Comply with law and enforce our Terms.
4. Who we share it with
We share your information only as necessary to deliver the Service, and only with these categories of recipients:
- DHCR: rent-history requests sent on your behalf include your apartment address and unit.
- Your attorney (if you choose contingency): the partnered attorney and their staff, subject to attorney-client privilege and confidentiality obligations.
- Service providers: Supabase (database and storage), Vercel (hosting), Stripe (payments), Resend (email), Anthropic (document parsing), Sentry (error tracking, with PII scrubbed from events). Each provider is bound by its own data protection commitments.
- As required by law: in response to a lawful subpoena, court order, or legal process, or to protect the rights, property, or safety of RentGuard, our users, or others.
We do not sell your personal information.
5. Artificial intelligence use
We use a large-language-model provider (Anthropic) to extract structured data from rent-history documents you upload. We do not include tenant personal identifiers in LLM prompts beyond what the specific task requires. The provider does not use this data to train general-purpose models.
6. Retention
We retain case data for the duration of your engagement and for up to seven years thereafter to allow for DHCR appeals and downstream questions. You may request earlier deletion of your account and associated data; we honor such requests within thirty days except where retention is required by law or by the scope of an active engagement.
7. Security
Data is stored in encrypted databases and object storage (Supabase, AES-256 at rest; TLS in transit). Access is restricted to RentGuard personnel whose work requires it and to your partnered attorney if applicable. We log access to sensitive fields.
8. Your rights
Under New York law, you have the right to:
- Know what personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your information (subject to the retention schedule above).
To exercise these rights, contact us at privacy@rentoverchargenyc.com.
9. Children
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated by email to the address on file.
11. Contact
Privacy questions can be sent to privacy@rentoverchargenyc.com.
See also our Terms of Service.