Legal
Privacy Policy
Effective date: September 2026
Overview
Fidem operates a document verification workflow platform for landlords and property managers. This Privacy Policy describes how Fidem collects, uses, stores, shares, and deletes information when you use the service — as a landlord, property manager, or as a rental applicant submitting documents.
If you have questions not answered here, contact privacy@usefidem.com.
Who this policy applies to
Operators (landlords and property managers)
If you create a Fidem account to manage rental application verification workflows, this policy applies to your account data, your organization's uploaded documents, and your use of the platform.
Applicants (rental applicants)
If a landlord or property manager sent you a secure upload link to submit documents, this policy applies to the documents you upload and the personal information you provide as part of that submission. You do not need to create an account. Your documents are held by the landlord's organization on the Fidem platform. All tenancy decisions are made solely by the property manager.
Information we collect
Account information
When a landlord or property manager creates an account, we collect their email address and display name, the name of their organization, and a contact phone number if they choose to provide one. Payment processing is handled by Stripe — Fidem does not store payment card data.
We also record when an operator accepts these Terms of Service and this Privacy Policy — the policy version and a timestamp — so we can show which version applied at any point in time.
Submitted documents
Documents uploaded through the platform — pay stubs, bank statements, employment letters, and government-issued IDs — are stored in private, access-controlled cloud storage (Supabase Storage, hosted on AWS). These documents are processed for field extraction as described below.
Extracted field data
Fidem uses optical character recognition (OCR) to extract structured fields from uploaded documents (such as income amounts, employer names, and account numbers). Extracted data is stored alongside the document record in the platform database. Extraction is performed by Microsoft Azure Content Understanding when the production extraction provider is active, or by an internal mock provider in test and development environments.
Consent records
When an applicant uploads documents via a secure link, they are shown the processing terms and must explicitly acknowledge them before any uploads are accepted. The timestamp, policy version, and requesting IP address are recorded as part of the consent record.
Verification records
We store verification evaluations, verification reports, review actions, and activity audit logs. These records are associated with the landlord's organization and are retained to provide an accurate historical record of completed verifications.
Usage information
We collect server-side access logs for error tracking and performance monitoring. We use Sentry for error and exception tracking, with personal information scrubbed before transmission.
We use privacy-conscious analytics and performance tools (Vercel Analytics and Vercel Speed Insights) to understand page performance and usage patterns. These tools receive page paths, page events, and performance telemetry. We configure them to scrub applicant upload link tokens before transmission, and they do not receive submitted document contents, extracted document data, or applicant financial details.
When configured, structured application logs are sent to Axiom for operational monitoring. These logs carry event names, correlation identifiers, and error classes, and are designed to exclude document contents and applicant identifiers.
How we use information
We use collected information to:
- Provide the document verification workflow service
- Extract fields from submitted documents using OCR and generate verification reports
- Maintain an activity and audit record for each verification
- Authenticate users and manage sessions
- Process billing transactions through Stripe
- Send transactional emails (e.g., document upload requests to applicants) through Resend
- Track application errors and monitor service health via Sentry
- Respond to support and privacy inquiries
We do not use submitted documents or extracted data to build scoring models, train AI systems, or produce assessments of any kind beyond the immediate document verification workflow.
Document processing and subprocessors
Fidem uses the following third-party services that may process personal data on our behalf. Our agreements with these vendors include contractual data-protection terms consistent with applicable privacy law; we are working toward formal data processing agreements with each as our compliance program matures.
| Subprocessor | Purpose | Data processed |
|---|---|---|
| Supabase | Authentication, database, and object storage | Account data, uploaded documents, all platform records |
| Microsoft Azure | Automated document processing (Azure Content Understanding) - classification, text recognition, and field extraction from documents | Uploaded document content (when production extraction is active) |
| Stripe | Payment processing and billing | Billing and payment data for operators |
| Resend | Transactional email delivery | Applicant email address and document request details |
| Sentry | Error tracking and monitoring | Application error context (PII scrubbed before transmission) |
| Vercel | Application hosting, content delivery, and page analytics (Vercel Analytics and Speed Insights) | Request traffic and metadata handled in transit; de-identified page paths, page events, and performance telemetry (applicant upload link tokens scrubbed before transmission) |
| Axiom | Structured application log ingestion for operational monitoring (when configured) | Operational log events (event names, correlation identifiers, error classes), designed to exclude document contents and applicant identifiers |
| Google Places | Property address autocomplete and address details | Address search text entered by operators, proxied through Fidem servers (no document contents or applicant financial data) |
We do not sell or share your information with third parties for marketing purposes. We do not share submitted documents with tenant screening bureaus, credit agencies, or background check providers.
This subprocessor list is also available as a standalone page for procurement and vendor-review purposes.
Cookies and tracking technologies
Fidem uses only essential cookies. When you sign in, our authentication provider (Supabase) sets first-party session cookies, including short-lived cookies used during the secure sign-in flow, so that you stay signed in and your session can be refreshed as you use the app. These cookies are necessary for the Service to function.
We do not use advertising, marketing, or cross-site tracking cookies. Our analytics and performance tools (Vercel Analytics and Vercel Speed Insights) are cookie-free: they do not set or read cookies, and they collect only aggregate page and performance information. Before any analytics event is sent, we scrub applicant upload link tokens and similar credentials from page addresses.
A small amount of browser storage (session storage) is used for functional purposes only, such as remembering an email address during sign-up or a recent search in the admin area. It is not used to track you across sites or sessions.
Because we currently rely on essential cookies and cookie-free analytics, Fidem does not display a cookie consent banner. If you block or clear cookies, you may not be able to stay signed in. This section describes the technologies we use today; see the "Policy changes" section below for how we communicate updates.
Document storage and access
Submitted documents are stored in private, access-controlled cloud storage (Supabase Storage on AWS). There are no public document links. Access to stored documents requires authentication and authorization to the associated verification workflow.
For applicants: your documents are accessible only to the landlord or property manager who sent you the upload link, and to Fidem personnel for support and maintenance purposes. Fidem does not share documents between organizations or with third parties outside the processors listed above.
Data retention
The following default retention periods apply. For full details on the deletion process and how to request deletion, see our Data Practices page.
| Data type | Default retention | Trigger |
|---|---|---|
| Uploaded documents & extracted data | Duration of active application + 7 years after archive | Application archived |
| Verification reports | 7 years after archive | Application archived |
| Audit and activity logs | 7 years minimum | Not automatically deleted |
| Applicant upload links | Link becomes inactive immediately; link and contact-detail records are retained and later anonymized (see "Uploaded documents" row above) | Link submitted, expired, or revoked (inactive); PII anonymized when the associated application is purged |
| Abandoned uploads | 1 hour after upload URL expiry | Automatic cleanup job |
| Operator account data | Duration of active account | Account deletion request |
An automated weekly job hard-deletes uploaded document blobs and anonymizes remaining personal data once the 7-year archive period above has elapsed, unless the record is under legal hold.
Applicant upload links are not deleted on a separate fixed schedule. A link becomes inactive as soon as it is submitted, expires, or is revoked — it can no longer be used to upload documents — but the underlying record follows the same 7-year archive-and-purge schedule as the rest of the application (see "Uploaded documents" above); direct identifiers (name, email, phone) are anonymized at that point.
Deletion requests
Operators (account holders)
To request deletion of your account and associated organization data, contact privacy@usefidem.com. We will acknowledge your request within 5 business days and aim to complete it within 30 days.
Note: audit and activity logs are retained for a minimum of 7 years for legal compliance purposes and may not be deleted on request.
Applicants
If you submitted documents via a Fidem upload link and wish to request deletion of your documents, contact privacy@usefidem.com with your name and the name of the property management company that sent you the link. We will coordinate deletion with the relevant organization.
Verification scope
Fidem is a document verification workflow tool. It is not a credit bureau, background check service, eviction record provider, or consumer reporting agency under the Fair Credit Reporting Act (FCRA) or similar legislation.
Verification results describe signals extracted from submitted documents only. They do not constitute tenant assessments, tenancy recommendations, approval or denial decisions of any kind. All tenancy decisions are made by the landlord or property manager.
Your rights
You may request access to, correction of, or deletion of your personal data at any time by contacting us at privacy@usefidem.com. We will acknowledge your request within 5 business days and aim to complete it within 30 days.
If you are located in the European Economic Area (EEA), the United Kingdom, California, or another jurisdiction with privacy rights legislation, you may have additional rights. These may include the right to data portability, the right to restrict processing, and the right to lodge a complaint with a supervisory authority. Contact us to discuss these rights.
Fidem does not use your personal data to make solely automated decisions that produce legal effects or similarly significantly affect you. Verification results are informational signals only — the landlord or property manager reviews them and makes every tenancy decision.
Children's privacy
The Service is intended for use by adults — landlords, property managers, and rental applicants of legal age to enter into a tenancy. It is not directed to children, and we do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us with personal information, contact privacy@usefidem.com and we will take steps to delete it.
International users and data transfers
Fidem's infrastructure is hosted in the United States (Microsoft Azure, East US region, for document processing; Supabase and Vercel hosting are also US-based). If you access the Service from outside the United States, your information — including uploaded documents and account data — is transferred to and processed in the United States, which may not have the same data protection laws as your home jurisdiction.
We are not currently certified under an EU-US or UK-US data transfer framework and do not currently rely on Standard Contractual Clauses. By using the Service from outside the United States, you acknowledge this transfer. If you have questions about international data transfers, contact privacy@usefidem.com.
Security
We implement industry-standard security practices including encryption in transit (TLS), private object storage with no public access, access-controlled APIs, and audit logging for sensitive operations. See our Security page for details.
Policy changes
We may update this Privacy Policy as the service evolves. If we make material changes, we will update the effective date above. Continued use of the service after a policy update constitutes acceptance of the revised policy. For material changes, we will make reasonable efforts to notify active users.
Contact
For privacy-related questions or data requests: privacy@usefidem.com
See also: Data Practices · Terms of Service · Security