Skip to main content

Legal

Privacy Policy

Effective date: September 2026

Overview

Fidem operates a document verification workflow platform for landlords and property managers. This Privacy Policy describes how Fidem collects, uses, stores, shares, and deletes information when you use the service — as a landlord, property manager, or as a rental applicant submitting documents.

If you have questions not answered here, contact privacy@usefidem.com.

Who this policy applies to

Operators (landlords and property managers)

If you create a Fidem account to manage rental application verification workflows, this policy applies to your account data, your organization's uploaded documents, and your use of the platform.

Applicants (rental applicants)

If a landlord or property manager sent you a secure upload link to submit documents, this policy applies to the documents you upload and the personal information you provide as part of that submission. You do not need to create an account. Your documents are held by the landlord's organization on the Fidem platform. All tenancy decisions are made solely by the property manager.

Information we collect

Account information

When a landlord or property manager creates an account, we collect their email address and display name, the name of their organization, and a contact phone number if they choose to provide one. Payment processing is handled by Stripe — Fidem does not store payment card data.

We also record when an operator accepts these Terms of Service and this Privacy Policy — the policy version and a timestamp — so we can show which version applied at any point in time.

Submitted documents

Documents uploaded through the platform — pay stubs, bank statements, employment letters, and government-issued IDs — are stored in private, access-controlled cloud storage (Supabase Storage, hosted on AWS). These documents are processed for field extraction as described below.

Extracted field data

Fidem uses optical character recognition (OCR) to extract structured fields from uploaded documents (such as income amounts, employer names, and account numbers). Extracted data is stored alongside the document record in the platform database. Extraction is performed by Microsoft Azure Content Understanding when the production extraction provider is active, or by an internal mock provider in test and development environments.

Consent records

When an applicant uploads documents via a secure link, they are shown the processing terms and must explicitly acknowledge them before any uploads are accepted. The timestamp, policy version, and requesting IP address are recorded as part of the consent record.

Verification records

We store verification evaluations, verification reports, review actions, and activity audit logs. These records are associated with the landlord's organization and are retained to provide an accurate historical record of completed verifications.

Usage information

We collect server-side access logs for error tracking and performance monitoring. We use Sentry for error and exception tracking, with personal information scrubbed before transmission.

We use privacy-conscious analytics and performance tools (Vercel Analytics and Vercel Speed Insights) to understand page performance and usage patterns. These tools receive page paths, page events, and performance telemetry. We configure them to scrub applicant upload link tokens before transmission, and they do not receive submitted document contents, extracted document data, or applicant financial details.

When configured, structured application logs are sent to Axiom for operational monitoring. These logs carry event names, correlation identifiers, and error classes, and are designed to exclude document contents and applicant identifiers.

How we use information

We use collected information to:

  • Provide the document verification workflow service
  • Extract fields from submitted documents using OCR and generate verification reports
  • Maintain an activity and audit record for each verification
  • Authenticate users and manage sessions
  • Process billing transactions through Stripe
  • Send transactional emails (e.g., document upload requests to applicants) through Resend
  • Track application errors and monitor service health via Sentry
  • Respond to support and privacy inquiries

We do not use submitted documents or extracted data to build scoring models, train AI systems, or produce assessments of any kind beyond the immediate document verification workflow.

Document processing and subprocessors

Fidem uses the following third-party services that may process personal data on our behalf. Our agreements with these vendors include contractual data-protection terms consistent with applicable privacy law; we are working toward formal data processing agreements with each as our compliance program matures.

SubprocessorPurposeData processed
SupabaseAuthentication, database, and object storageAccount data, uploaded documents, all platform records
Microsoft AzureAutomated document processing (Azure Content Understanding) - classification, text recognition, and field extraction from documentsUploaded document content (when production extraction is active)
StripePayment processing and billingBilling and payment data for operators
ResendTransactional email deliveryApplicant email address and document request details
SentryError tracking and monitoringApplication error context (PII scrubbed before transmission)
VercelApplication hosting, content delivery, and page analytics (Vercel Analytics and Speed Insights)Request traffic and metadata handled in transit; de-identified page paths, page events, and performance telemetry (applicant upload link tokens scrubbed before transmission)
AxiomStructured application log ingestion for operational monitoring (when configured)Operational log events (event names, correlation identifiers, error classes), designed to exclude document contents and applicant identifiers
Google PlacesProperty address autocomplete and address detailsAddress search text entered by operators, proxied through Fidem servers (no document contents or applicant financial data)

We do not sell or share your information with third parties for marketing purposes. We do not share submitted documents with tenant screening bureaus, credit agencies, or background check providers.

This subprocessor list is also available as a standalone page for procurement and vendor-review purposes.

Cookies and tracking technologies

Fidem uses only essential cookies. When you sign in, our authentication provider (Supabase) sets first-party session cookies, including short-lived cookies used during the secure sign-in flow, so that you stay signed in and your session can be refreshed as you use the app. These cookies are necessary for the Service to function.

We do not use advertising, marketing, or cross-site tracking cookies. Our analytics and performance tools (Vercel Analytics and Vercel Speed Insights) are cookie-free: they do not set or read cookies, and they collect only aggregate page and performance information. Before any analytics event is sent, we scrub applicant upload link tokens and similar credentials from page addresses.

A small amount of browser storage (session storage) is used for functional purposes only, such as remembering an email address during sign-up or a recent search in the admin area. It is not used to track you across sites or sessions.

Because we currently rely on essential cookies and cookie-free analytics, Fidem does not display a cookie consent banner. If you block or clear cookies, you may not be able to stay signed in. This section describes the technologies we use today; see the "Policy changes" section below for how we communicate updates.

Document storage and access

Submitted documents are stored in private, access-controlled cloud storage (Supabase Storage on AWS). There are no public document links. Access to stored documents requires authentication and authorization to the associated verification workflow.

For applicants: your documents are accessible only to the landlord or property manager who sent you the upload link, and to Fidem personnel for support and maintenance purposes. Fidem does not share documents between organizations or with third parties outside the processors listed above.

Data retention

The following default retention periods apply. For full details on the deletion process and how to request deletion, see our Data Practices page.

Data typeDefault retentionTrigger
Uploaded documents & extracted dataDuration of active application + 7 years after archiveApplication archived
Verification reports7 years after archiveApplication archived
Audit and activity logs7 years minimumNot automatically deleted
Applicant upload linksLink becomes inactive immediately; link and contact-detail records are retained and later anonymized (see "Uploaded documents" row above)Link submitted, expired, or revoked (inactive); PII anonymized when the associated application is purged
Abandoned uploads1 hour after upload URL expiryAutomatic cleanup job
Operator account dataDuration of active accountAccount deletion request

An automated weekly job hard-deletes uploaded document blobs and anonymizes remaining personal data once the 7-year archive period above has elapsed, unless the record is under legal hold.

Applicant upload links are not deleted on a separate fixed schedule. A link becomes inactive as soon as it is submitted, expires, or is revoked — it can no longer be used to upload documents — but the underlying record follows the same 7-year archive-and-purge schedule as the rest of the application (see "Uploaded documents" above); direct identifiers (name, email, phone) are anonymized at that point.

Deletion requests

Operators (account holders)

To request deletion of your account and associated organization data, contact privacy@usefidem.com. We will acknowledge your request within 5 business days and aim to complete it within 30 days.

Note: audit and activity logs are retained for a minimum of 7 years for legal compliance purposes and may not be deleted on request.

Applicants

If you submitted documents via a Fidem upload link and wish to request deletion of your documents, contact privacy@usefidem.com with your name and the name of the property management company that sent you the link. We will coordinate deletion with the relevant organization.

Verification scope

Fidem is a document verification workflow tool. It is not a credit bureau, background check service, eviction record provider, or consumer reporting agency under the Fair Credit Reporting Act (FCRA) or similar legislation.

Verification results describe signals extracted from submitted documents only. They do not constitute tenant assessments, tenancy recommendations, approval or denial decisions of any kind. All tenancy decisions are made by the landlord or property manager.

Your rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us at privacy@usefidem.com. We will acknowledge your request within 5 business days and aim to complete it within 30 days.

If you are located in the European Economic Area (EEA), the United Kingdom, California, or another jurisdiction with privacy rights legislation, you may have additional rights. These may include the right to data portability, the right to restrict processing, and the right to lodge a complaint with a supervisory authority. Contact us to discuss these rights.

Fidem does not use your personal data to make solely automated decisions that produce legal effects or similarly significantly affect you. Verification results are informational signals only — the landlord or property manager reviews them and makes every tenancy decision.

Children's privacy

The Service is intended for use by adults — landlords, property managers, and rental applicants of legal age to enter into a tenancy. It is not directed to children, and we do not knowingly collect personal information from children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us with personal information, contact privacy@usefidem.com and we will take steps to delete it.

International users and data transfers

Fidem's infrastructure is hosted in the United States (Microsoft Azure, East US region, for document processing; Supabase and Vercel hosting are also US-based). If you access the Service from outside the United States, your information — including uploaded documents and account data — is transferred to and processed in the United States, which may not have the same data protection laws as your home jurisdiction.

We are not currently certified under an EU-US or UK-US data transfer framework and do not currently rely on Standard Contractual Clauses. By using the Service from outside the United States, you acknowledge this transfer. If you have questions about international data transfers, contact privacy@usefidem.com.

Security

We implement industry-standard security practices including encryption in transit (TLS), private object storage with no public access, access-controlled APIs, and audit logging for sensitive operations. See our Security page for details.

Policy changes

We may update this Privacy Policy as the service evolves. If we make material changes, we will update the effective date above. Continued use of the service after a policy update constitutes acceptance of the revised policy. For material changes, we will make reasonable efforts to notify active users.

Contact

For privacy-related questions or data requests: privacy@usefidem.com

See also: Data Practices · Terms of Service · Security