Skip to main content

Privacy

Your information should only go where it needs to go.

This policy explains how Resi handles personal information across resirentals.ca, the secure Resi application experience and our internal leasing operations. It is a robust launch draft and remains noindexed until final contact details and legal review are complete.

Scope

Resi is responsible for personal information under its control.

This policy applies to Resi’s public website, secure applicant experience, property-partner inquiry flow and related leasing operations. Resi uses service providers to operate parts of the service, but remains responsible for how personal information under its control is handled.

What we collect

We limit collection to information needed for a clear business purpose.

When you browse the public website, ordinary technical information needed to deliver and protect the site may be processed. If you start a rental application from a listing, the public step asks only for your name, email address and the rental you selected. If you submit a property-partner inquiry, we may collect your organization, name, business contact details, role, market, approximate portfolio size and the message you choose to provide.

Sensitive renter information—such as identity information, employment and income details, rental history, credit-related workflow information and supporting documents—is collected only inside Resi’s secure applicant experience when required for the application process. The public website is not a document repository or applicant database.

How we use information

We use personal information to provide, secure and operate the Resi service.

Purposes can include showing and administering rental opportunities, creating and supporting rental applications, verifying applicant access, communicating about an application, preparing an application package for an authorized property, responding to property-partner inquiries, maintaining business relationships, preventing abuse and fraud, troubleshooting the service, meeting legal obligations and keeping appropriate audit records.

Resi does not use a renter’s application information to guarantee approval. Participating properties remain responsible for their final tenancy and lease decisions.

Who receives information

Information is shared only where the workflow requires it.

Resi may disclose information to authorized participating property organizations when needed for the rental application and decision process, and to service providers that help us host, secure, communicate through or operate the platform. Our current architecture can include Floot for application hosting, database and email services; Cloudflare R2 for private applicant-document storage; and Twilio for business calling. Service providers receive only the access needed for their role and may process information in jurisdictions outside Ontario or Canada, where it may be subject to local law.

Resi may also disclose information where required or permitted by law, to protect users or the service, or as part of a legitimate business transaction subject to appropriate safeguards.

Applications & documents

Sensitive applicant documents stay behind the private application boundary.

Applicant uploads move through private transient storage into Resi’s private Cloudflare R2 document repository. Public-site code has no direct database, document-repository or private CRM authority.

For unsuccessful applicants, Resi’s current retention workflow deletes sensitive source documents after the relevant listing becomes leased when the application outcome is declined, withdrawn or closed as not selected. Minimal non-sensitive workflow and audit information may be retained for operational, legal and accountability purposes. Successful-renter information is retained only as needed for the continuing transaction, legal obligations and legitimate operational purposes.

Safeguards

Security is matched to the sensitivity of the information.

Resi uses role-based access, organization and building scopes, private document storage, authenticated applicant sessions, short-lived verification codes, hashed or opaque security tokens, audit logging and rate limiting. No security system can eliminate every risk, so Resi also limits what the public website can access in the first place.

Analytics & marketing

The current public site does not require a third-party tracking profile.

Resi currently uses a provider-neutral, privacy-minimized event layer and does not load a third-party analytics cookie, advertising pixel or behavioural-tracking provider by default. If Resi later adds non-essential tracking, the privacy and consent requirements will be reviewed before it is enabled.

Transactional messages about an application or account are used to deliver the service. Separate promotional email or text marketing, if introduced, will be handled under applicable Canadian electronic-messaging requirements, including consent and unsubscribe obligations where required.

Your choices & access

You can ask about, access or correct personal information Resi holds about you.

Subject to applicable legal and contractual limits, you may ask Resi about the existence, use and disclosure of your personal information, request access or correction, or withdraw consent for uses that rely on consent. Withdrawal may affect Resi’s ability to continue a requested application or service where the information is necessary to provide it.

Privacy questions, access requests or complaints should be sent through Resi’s official Contact page. A dedicated privacy-contact address will be added before this policy is indexed as final production legal text.

Updates

We will update this policy when our practices materially change.

When a material change affects how personal information is collected, used or disclosed, Resi will update this policy and provide additional notice or seek new consent when required. Launch-draft date: August 16, 2026.