Privacy Policy
Last updated:
This Privacy Policy explains how Lumate Tenant Insight System (“Lumate TIS”, “Lumate”, “we”, “us”, or “our”) collects, uses, discloses, stores, and protects information when you use our websites, tenant and landlord dashboards, Tenant Insight Reports, verified screening features, rental listings, applications, messaging tools, and related services (collectively, the “Services”).
1. Information We Collect
The information we collect depends on the Services you use.
1.1 Account and Profile Information
- Name and display name.
- Email address.
- Phone number when provided.
- Firebase user identifier and authentication information.
- Account role, such as tenant, landlord, or administrator.
- Account preferences and related profile information.
1.2 Tenant Insight Report Information
Applicants may provide information used to create a Tenant Insight Report, including:
- Declared monthly income and income source.
- Target rent.
- Employer and employment information.
- Employment duration.
- Months at a previous residence.
- On-time payment history and reported payment rate.
- Self-reported credit information.
- Housing-program information when applicable.
- Current housing status and reason for moving.
- Preferred move-in timeline and lease preference.
- Household information.
- Pet information.
- Co-applicant or financial-support information.
- Applicant-provided criminal or eviction background disclosures.
- Consent and authorization records.
1.3 Generated Lumate Information
Lumate may generate or calculate information from applicant-provided inputs, including:
- Overall Tenant Insight Score.
- Affordability Score.
- Stability Rating.
- Profile-completion information.
- Lease-readiness indicators and related informational summaries.
- Tenant Insight Report PDF files.
1.4 Verified Screening Information
If you request or authorize a verified screening, Lumate may receive screening or verification information from Checkr or another disclosed provider.
Depending on the screening products selected and information available, this may include:
- Verification status and completion information.
- Identity-verification results.
- Credit-file information and verified credit-related metrics.
- Income-verification information.
- Criminal-history screening results.
- Eviction-history screening results.
- Sex-offender-registry results.
- Global-watchlist results.
- Case numbers, filing dates, courts, jurisdictions, charges, statutes, offense dates, disposition dates, and dispositions where returned by the screening provider.
- Provider-reported names, aliases, descriptions, dates of birth, or generalized location information where included in an authorized screening result.
Applicant-provided information and independently verified information are treated as separate categories within Lumate.
A value submitted by an applicant should not be interpreted as independently verified unless the Services specifically identify it as verified.
1.5 Sensitive Identity Information Used for Verification
Some verification products require sensitive identifiers such as date of birth and Social Security number.
Lumate's verification workflow is designed to transmit these applicant-supplied identifiers to the applicable screening provider for the authorized verification request without storing the submitted Social Security number or applicant-entered date of birth in Lumate's standard Firestore screening record.
The screening provider may independently collect, process, maintain, or return identifying information under its own systems, legal obligations, and privacy practices. Provider-reported identifying information may also appear in an authorized verified report or authenticated screening view when it forms part of the screening result.
1.6 Rental Listings and Applications
When users interact with Lumate rental features, we may collect and process:
- Rental listing details and property addresses.
- Listing photographs and descriptions.
- Rent, availability, deposit, and move-in information.
- Rental applications.
- Applicant and landlord identifiers.
- The Tenant Insight Report attached to an application.
- Application status, such as submitted, reviewing, approved, or declined.
- Verification status associated with an application.
1.7 Messages, Notifications, and Feedback
We may collect messages exchanged through Lumate, notification records, read/unread states, support communications, feedback, survey responses, and related timestamps.
1.8 Payment Information
Payments are processed through Stripe. Lumate may receive and retain transaction-related information such as payment status, Stripe transaction or checkout identifiers, purchased product information, amount, and timestamps.
Lumate does not intentionally store full payment-card numbers. Payment-card information is processed by Stripe under Stripe's applicable terms and privacy practices.
1.9 Technical and Usage Information
We may collect technical and operational information necessary to operate, secure, troubleshoot, and improve the Services, including logs, timestamps, authentication activity, device or browser information, feature interactions, error information, notification activity, and similar usage data.
2. How We Use Information
We may use information to:
- Create and manage user accounts.
- Authenticate users and enforce account roles.
- Create Tenant Insight Reports and Lumate informational metrics.
- Generate, store, and provide access to report PDFs.
- Initiate and administer user-authorized verification requests.
- Transmit required information to Checkr or another disclosed verification provider.
- Receive, normalize, organize, and display screening results.
- Create verified Tenant Insight Reports.
- Allow applicants to submit rental applications.
- Allow authorized landlords to review applicant information connected to their listings and applications.
- Provide secure access to verified screening information where authorized.
- Process payments and maintain transaction records.
- Send transactional emails, in-app notifications, and push notifications.
- Provide messaging between authorized users.
- Respond to support, privacy, dispute, and security requests.
- Prevent fraud, unauthorized access, abuse, and misuse.
- Debug, maintain, analyze, and improve the Services.
- Comply with applicable legal requirements and enforce our Terms.
3. Applicant Consent and Verification Authorization
Lumate processes information submitted through the Services to provide the features requested by the user. Certain features require affirmative consent, authorization, payment, or other action before information is processed or sent to a third-party provider.
When an applicant intentionally initiates an independent verification through Lumate, Lumate may transmit the information required to create and administer that screening request with the disclosed provider.
Additional provider disclosures, authorizations, or applicant actions may be required depending on the screening product and applicable law.
4. How We Share Information
We disclose information only as reasonably necessary to operate the Services, fulfill user requests, protect the platform, or satisfy legal obligations.
4.1 Checkr and Screening Providers
Lumate uses Checkr for supported verification and screening functionality. Information necessary to initiate, complete, retrieve, and administer an authorized screening may be transmitted to or received from Checkr.
Checkr operates under its own privacy notices, data-retention practices, security controls, and legal obligations.
4.2 Google Firebase
Lumate uses Google Firebase services, which may include Firebase Authentication, Cloud Firestore, Firebase Storage, Firebase Cloud Messaging, and related infrastructure used for authentication, application data, files, notifications, and platform operation.
4.3 Stripe
Lumate uses Stripe to process applicable payments and receives transaction information needed to confirm purchases and maintain payment records.
4.4 Email, Push, and Infrastructure Providers
We may use service providers to deliver transactional email, notifications, hosting, monitoring, security, or other technical infrastructure. These providers receive only information reasonably necessary to provide their applicable service.
4.5 Landlords and Property Managers
When an applicant submits a rental application through Lumate, information attached to that application may be made available to the landlord or property manager responsible for the applicable listing.
This may include the applicant's Tenant Insight Report, applicant contact and rental information, Lumate informational metrics, application status, verification status, normalized verification results, and an authenticated verified report when available.
Access to verified screening information is subject to Lumate's authentication and application-authorization controls.
4.6 Legal and Safety Disclosures
We may preserve or disclose information when we reasonably believe doing so is necessary to comply with law, legal process, regulatory requirements, enforce our agreements, investigate fraud or security incidents, protect the rights or safety of users, or defend Lumate and its Services.
4.7 Business Transactions
Information may be transferred as part of a merger, acquisition, financing, corporate reorganization, sale of assets, bankruptcy, or similar business transaction, subject to applicable law.
4.8 Sale of Personal Information
Lumate does not sell personal information for monetary consideration. If our practices change in a manner that triggers additional rights or disclosures under applicable privacy law, we will update this Policy and provide any required choices.
5. Free Reports and Verified Reports
A free or unverified Tenant Insight Report primarily contains applicant-provided information and Lumate-generated informational metrics.
A verified Tenant Insight Report may additionally contain selected results received from an independent screening provider. The report identifies which fields or screening products were independently verified.
A provider result marked “Not included” means that the corresponding product was not included in that screening. It does not mean that the underlying category was reviewed and found clear.
6. Data Storage
Lumate stores application data primarily using Firebase and related cloud infrastructure. Depending on the feature, stored information may include account records, Tenant Insight Report data, rental applications, screening status, privacy-limited normalized verification results, payment metadata, messages, notifications, feedback, and files.
Verified report PDFs are stored in private storage locations and are intended to be accessed through authenticated Lumate endpoints rather than public file URLs.
7. Sensitive Information and Data Minimization
Lumate is designed to limit unnecessary storage and exposure of sensitive verification data.
- Applicant-entered Social Security numbers used to initiate a verification are not intended to be stored in Lumate's standard Firestore screening records.
- Applicant-entered dates of birth submitted for provider verification are not intended to be stored in Lumate's standard Firestore screening records.
- Lumate does not intentionally place full SSNs in portable verified report PDFs.
- Lumate does not intentionally reproduce identity-document files, bank account numbers, temporary provider download URLs, or the provider's complete raw private screening payload in portable verified reports.
- Selected provider-reported record details may be displayed when needed to explain a screening result, including case information, dates, court information, offenses, dispositions, reported names, aliases, descriptions, DOB, or generalized location information where available.
8. Data Retention
Lumate retains information for the period reasonably necessary to provide the Services, maintain account and transaction records, administer applications, support users, investigate security or fraud, handle disputes, comply with legal obligations, and maintain appropriate operational records.
A verified report may display a 30-day verification-validity period. That validity period describes how long the verification is intended to be treated as current; it does not necessarily determine how long Lumate retains the underlying report or screening record.
Lumate may retain report and screening records for up to 120 days for internal recordkeeping and operational purposes unless a longer period is required or permitted by law, needed to resolve a dispute or security matter, or otherwise disclosed at the time of collection.
Certain account, transaction, legal, security, or audit records may be retained longer where reasonably necessary or required by law. Third-party providers may apply their own retention schedules to information processed through their systems.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, loss, or misuse.
Depending on the feature, these safeguards may include authentication, role-based authorization, server-side ownership checks, private file storage, restricted backend service credentials, secure HTTPS communications, provider-side payment handling, and limiting the sensitive information stored in standard application records.
No electronic transmission, service, or storage system can be guaranteed to be completely secure.
10. Access Controls for Rental Applications and Screening
Lumate uses account and application relationships to control access to private applicant information.
For example, landlord access to a verified screening may require Lumate to confirm the authenticated user's role, ownership of the applicable listing or application, the applicant connected to the application, the report attached to that application, and the screening connected to that report before access is granted.
Users may not attempt to circumvent these controls.
11. Accuracy and Third-Party Screening Disputes
Applicants may contact Lumate regarding information they submitted directly to Lumate or information generated by Lumate.
If disputed information originated from Checkr or another independent screening provider, correction of the underlying provider record may require the applicant to use that provider's dispute procedures. Lumate may assist by identifying the source of the information where appropriate.
Federal law provides consumers with rights concerning certain consumer reports, including rights to obtain and dispute information from the consumer reporting company that supplied it.
12. FCRA and Tenant-Screening Information
Certain third-party information accessed through Lumate may be supplied by a consumer reporting agency and may be subject to the Fair Credit Reporting Act (“FCRA”) or related federal, state, or local requirements.
Lumate-generated informational scores and third-party screening information are distinct data categories. We do not represent that every piece of information available through the Services has the same legal classification.
Landlords and property managers are responsible for their own permissible-purpose, authorization, adverse-action, fair-housing, and other legal obligations when using screening information.
13. Your Privacy Choices and Rights
Depending on your location and applicable law, you may have rights concerning personal information, which may include rights to request access, correction, deletion, or other information regarding our processing practices.
Some requests may be limited where retention is required or permitted for legal compliance, fraud prevention, security, transaction records, disputes, or other legitimate purposes.
Before fulfilling certain privacy requests, we may need to verify your identity and authority to make the request.
Requests concerning Lumate-held information may be submitted to privacy@lumateinc.com.
Rights concerning information maintained independently by Checkr, Stripe, Google, or another third party may need to be exercised directly with that provider.
14. Account Deletion
If account-deletion functionality is available through the Services, users may use that feature as instructed. Users may also contact Lumate regarding deletion requests.
Deleting an account does not necessarily require immediate deletion of every associated record where Lumate has a lawful reason or obligation to retain information, including payment records, application records, security records, dispute records, or records necessary to establish or defend legal claims.
15. Children's Privacy
Lumate accounts and tenant-screening Services are intended for individuals who are at least 18 years old. We do not knowingly provide applicant screening accounts to children under 18.
Applicants may provide household information indicating that children will occupy a rental property. Such household information does not create an account for the child and should not include unnecessary sensitive information about the child.
16. United States Processing and International Users
Lumate is operated from the United States, and information may be processed or stored in the United States or other locations in which our service providers operate.
Users accessing the Services from outside the United States understand that privacy and data-protection laws may differ from those in their jurisdiction.
17. Changes to This Privacy Policy
We may update this Privacy Policy as Lumate develops new features, integrates additional providers, changes data practices, or responds to legal or regulatory developments.
We will post the updated Policy here and revise the “Last updated” date. Where applicable law requires additional notice or consent, we will provide it.
18. Contact
Privacy questions and requests may be sent to privacy@lumateinc.com.
General support questions may be sent to support@lumateinc.com.