Privacy policy
This is written from what the software actually does, not from a template. Where something might surprise you, such as your lease documents being read by an AI provider or an IP address being kept against a signature, it is called out rather than buried.
1. What we hold
Your account. The email address you sign in with, and a hashed password. We never see or store your password itself. Hashing is handled by our authentication provider.
Everything you put in. Your corporations, properties, leases, tenants, expenses, payments, invoices, service contracts and insurance policies. This is the point of the product; it lives in a database row that is tied to your account and no one else’s.
Documents you upload. Leases, addendums, certificates of insurance, service contracts, vendor bills, rent rolls, annual reports, bank statements, and the signed copies of anything executed here. They are stored in a private bucket, in a folder keyed to your account, and are not publicly reachable by URL.
Paying vendors, if you set it up. To pay vendor bills from inside Amlak, each of your LLCs is set up once with Melio, the payment company (see section 3). That setup asks for the business’s legal name, EIN, address and the owner’s name, email and date of birth, because Melio verifies the business the way a bank does when you open an account. The EIN and the date of birth are passed to Melio and are not kept by Amlak — not in the database, not in a log. What we keep is Melio’s own identifier for the business, the bank’s name and the last four digits of the account you link (never the account number, which you enter on Melio’s own page), the label of how each vendor is paid (never a vendor’s account number), and a record of each payment you authorize: the amount, the dates, who confirmed it, when, from which address and browser, and what the screen showed you when you did. That last record exists so that a payment can be proven to have been yours if a bank ever questions it.
Email you receive here. If you use the communications features, replies from your tenants and your vendors are stored against your account so the app can show you the conversation rather than half of it. When a message arrives that we cannot match to anyone — a stranger, or a reply to an address that no longer belongs to a lease — we keep only the sender’s address and the reason we could not place it, for 30 days, so you can see that something was turned away rather than silently lost. That record deletes itself; nobody has to remember to clear it.
A small amount of technical data. Standard web-server logs from our host, and error logs from the server functions. We also keep an audit record of security-relevant events — a request refused because it asked for data belonging to another account, a rate limit being hit, an unauthorised call to one of the scheduled jobs — and that record includes the IP address the request came from. It exists so that if something is probing the service we can see it. Those rows are tied to your account and are deleted with it, the same as everything else in section 6. We run no advertising or tracking scripts, and nothing here follows you to another website.
There is one counter, and it is our host’s. Cloudflare, who already serves this site, reports which pages get read and which link brought you here. It sets no cookie, and in Cloudflare’s own words it does not “fingerprint” anyone by IP address, browser or anything else. It is switched on across our whole domain today, including inside the application, and we are narrowing it to this marketing site where it belongs — a page count is a marketing tool and has no business sitting inside your ledger.
2. Your tenants’ information
This is the part most privacy policies skip. When you enter a tenant’s name and email address, or upload a lease with their details in it, you are putting personal data about someone who is not our user into our system.
You decide what goes in. We hold it so the software can do its job, which is to work out what they owe, send them an invoice and take their signature, and for nothing else. We do not contact your tenants on our own initiative, ever. Every email to a tenant is one you triggered, and it goes out with your business name on it and replies addressed to your inbox.
We record when a tenant opens your email, and when they click a link in it. Our mail provider does this with a tracking pixel and by rewriting links, and it is on for every message Amlak sends on your behalf. It is what lets the app tell you a letter has gone unanswered for twelve days rather than just unanswered. We are naming it because your tenant is not our user and never agreed to it — you should know it is happening before you decide to send. We do not track them anywhere else, and never across other websites.
Making sure you are entitled to hold and share that information is your responsibility, not something we can judge for you.
3. Who else sees it
Amlak™ is built on other companies’ infrastructure. These are all of them, and what each one actually receives:
That is the complete list — seven companies, the seventh only if you pay vendors through Amlak. There is no advertising network, no data broker and no customer-tracking tool behind this page, and the only page counting is our own host’s, described in section 1. The typefaces on this site and in the app are served from our own servers rather than from a font provider, which would otherwise have received the address of every visitor to every page — an eighth company on a list that says it is complete.
And one thing that is not a company on a list. If we are compelled by law — a subpoena, a warrant, a court order — we may have to hand records to a court or an authority. If that ever happens to your account we will tell you which records and why, unless we are forbidden from telling you.
4. Electronic signature records
When a document is signed through Amlak we deliberately record more than usual: the signer’s name and email, the time they opened it, the time they consented, the time they signed, their IP address and their browser’s user-agent string. This is kept on purpose: it is what a certificate of completion is made of, and what makes an electronic signature stand up if it is ever questioned. It is retained with the signed document — for exactly as long as that document is in Amlak, and no longer. If you close your account it is deleted along with everything else, and section 6 says how. We do not keep a signature record after you have gone, and we do not promise to preserve one for you: the copies that outlive Amlak are the one in your backup folder and the one your tenant was emailed at the time.
One other page records an IP address, for a much smaller reason. When you send a tenant a link to the backup behind a CAM or tax bill, we log each time that link is opened, with the IP address and browser it was opened from. That is there so you can answer “did they ever look at it?” when a tenant disputes a charge. It is a weaker reason than a signature and we are naming it separately rather than letting the sentence above cover both.
5. What we never do
- We do not sell your data, or your tenants’ data, to anyone.
- We do not use it to advertise to you, or let anyone else advertise to you.
- We do not use your leases, figures or documents to train AI models.
- We set no cookie of our own — not an advertising one, not a tracking one, not even a session one. Your sign-in is kept in your own browser’s storage, on your device, and is never sent to us as a cookie. Nothing on this marketing site sets a cookie at all. One is set on the application and it is not ours: g_state, written by Google’s sign-in button to remember how you last used it — section 3 says what Google sees. The one thing we do track is whether a tenant opened an email you sent — said plainly in section 2, rather than left for you to find here.
- We do not email your tenants unless you tell us to.
6. How long we keep it
For as long as your account exists, because a lease from four years ago is still the lease that governs what a tenant owes today, and deleting history would break the arithmetic. If you close your account we delete your data and your uploaded documents. Backups roll off on their own cycle, so a short tail may persist there briefly after deletion.
There is a delete button, in Settings › Account, and it does the whole job. Pressing it schedules your account for permanent deletion in 30 days and signs you out immediately. Any bank connection is ended at your bank that same day — we do not keep access to your accounts while you are on the way out. Nothing else is touched until the 30 days are up: write to support@amlakre.com before then and we will put it all back exactly as it was.
On that date the deletion runs by itself and covers everything: every row in the database, every file in storage — leases, addendums, signed copies, signature images, certificates — and the encrypted copy of any bank token. We check the storage is empty before we call it done, and if any part fails, nothing is deleted and a person looks at it. Afterwards it cannot be recovered, by us or by anyone.
Take your records with you first. A signed lease can matter for a decade after you stop using our software, and once we have deleted our copy we cannot get it back for you. Settings › Onboarding & backup writes every document into a folder on your own computer; the same page is linked from the delete screen. Your tenants also keep the signed copies we emailed them at the time — those are theirs and we never had the right to delete them.
We may keep records where the law requires us to — for example if we are formally asked to preserve them for a legal dispute. If that ever applies to your account we will tell you which records and why.
7. Your choices
- Get it out. The income-and-expenses and rent-roll exports produce spreadsheets of your data whenever you want them, without asking us.
- Correct it. Every figure in Amlak is editable by you, directly.
- Delete it. Settings › Account › Delete my account. Thirty days’ grace, then everything goes — see section 6. Writing to us still works if you would rather a person did it.
- Ask what we hold. Write to us and we will tell you.
Depending on where you live you may have additional rights over your personal data. Ask and we will honor them; we would rather do that than argue about which statute applies. Either way you will have an answer within 30 days, and realistically the same week — there are not many of you yet.
8. Contact
Write to support@amlakre.com. A person reads it.
9. The standard clauses, in plain words
If the business changes hands. If Amlak is ever sold or merged, or its assets transferred, your data goes with it — there is no version of that where the software carries on and your leases do not. Whoever takes it on is held to this policy as it stands until you are told otherwise, and you would be told.
If something goes wrong. If your data is exposed in a security breach we will tell you — what happened, what was involved and what we did about it. Illinois law requires it and we would do it anyway: a landlord whose tenant records were exposed needs to hear it from us before they hear it from a tenant.
Children. Amlak is business software sold to landlords. It is not for anyone under 18, we do not market to children, and we have no reason to hold a child’s information.
Where your data is. In the United States, on the infrastructure named in section 3. If you use Amlak from outside the US, your data is being sent to and kept in the US, which may protect it differently than your own country would.
10. Changes
If this policy changes in a way that matters, we will say so on this page and change the date at the top. Amlak is in private beta with a small number of accounts, so if something significant changes you will most likely hear it from us directly.