Privacy Policy
This Privacy Policy explains how SAHAB LLC, an Indiana limited liability company that operates the Sahab Key platform ("Sahab Key", "we", "us", or "our"), collects, uses, shares, and protects information when property managers and tenants use our property management platform, including the manager portal, the tenant portal, and this website (together, the "Service"). Sahab Key is operated from the United States and is intended for use with US residential rentals.
The Service is a business-to-business platform. Property management companies and landlords ("Managers") use Sahab Key to manage their rentals, and their residents ("Tenants") use it to pay rent and interact with their Manager. When a Manager uses the Service to process information about its Tenants and properties, the Manager is the controller of that information and Sahab Key acts as a service provider or processor on the Manager's behalf. This policy describes our own practices. Your Manager's own privacy notice may also apply to you.
1. Information we collect
Information Managers provide
- Account and organization details: name, business or organization name, email address, phone number, and a password stored only as a secure hash.
- Property and lease records: buildings, units, lease terms, rent amounts, charges, deposits, and the Tenants attached to each lease.
- Housing assistance status: for Tenants enrolled in Section 8 or another housing-assistance program, participation status and housing-authority details (such as the housing authority's name and the subsidized portion of rent), entered by the Manager to reconcile housing-authority payments against the right charges. Sahab Key treats this as potentially sensitive information, and the Manager, not Sahab Key, controls it.
- Financial records: charges, payments, expenses, receipts, and payout configuration for each building.
- Team members: additional manager accounts you create and the roles and permissions you assign them.
- Tenant notes: free-text notes a Manager writes on a Tenant's record.
- Eviction records: eviction cases a Manager opens and tracks. When a case is closed, the Service keeps an archived copy that includes the Tenant's name, email address, phone number, and housing-assistance status, the unit and lease details, and the charge, payment, and balance history as of the eviction. That archive is designed to remain after the Tenant's own record is gone, and the personal details in it are kept only until the eviction-archive retention window in Section 8 clears them, after which the unit, lease, and financial history are what remain.
- Messages: the subject line and full body of each email a Manager sends through the Service, together with its recipients, kept as a communication record.
- Assistant conversations: when a Manager uses the in-product assistant, we store the transcript of that conversation, meaning the questions asked and the answers returned, so the Manager can come back to it. A transcript is private to the user who started it and is not shared with the rest of the team.
Information Tenants provide
- Account details: name, email address, phone number, and a password stored only as a secure hash.
- Application details: when you apply for a unit, the profile information you give, meaning your date of birth, your current address and any prior addresses, your employer, job title, and the monthly income you state, an emergency contact's name, phone number, and relationship to you, the unit you want, and your desired move-in date. You also pay the application fee. A Manager reviews what is submitted and decides whether to approve the application.
- Application documents: through the public application link, you upload a photo ID, proof of income such as a pay stub, and a bank statement. When a Manager's staff enters an application on your behalf instead, the Service provides five document slots, and two of those are an image of your Social Security card and a criminal background check record. Those two are uploaded by the Manager's staff, not through the public application link. Every application document is stored in our private file storage and served only through short-lived signed URLs, the same as any other document on the platform. How long it is kept depends on what happens to the application, and Section 8 sets out both schedules and the file deletion that goes with them. Sahab Key does not run biometric identity verification, does not link or verify your bank account, and does not obtain or generate credit, criminal, eviction, or other consumer reports about you. Section 7 explains that distinction in full.
- Payment setup: the bank account or card you connect to pay rent, and any autopay schedule you configure. Full bank and card numbers are handled by our payment processor and are described in Section 2.
- Requests and uploads: maintenance requests and the photos attached to them, and documents such as your signed lease.
Information collected automatically
- Authentication and security data: sign-in events, multi-factor authentication status, failed login attempts, and account lockout events, used to keep accounts secure. Each login attempt and security event is recorded with the IP address and the browser user-agent string it came from, and a lease signature is recorded with the signer's IP address and user-agent string.
- Device and log data: IP address, user and organization identifiers, and timestamps, recorded in server logs. When a request fails with an error, the log entry and our error-monitoring provider also record the method and path of that request.
- Support access records: when Sahab Key staff sign in to an organization's account to provide support, we record which staff member did it, which user and organization were accessed, the reason given, when the access started and ended, and the IP address and browser user-agent of that staff session.
- Session and cookie data: a session cookie that keeps you signed in, plus cookies that are necessary for the Service to function and to protect it. Our public website also uses analytics cookies, which are described in Section 6.
2. Payment information
Rent and other payments are processed by Stripe. When a Tenant pays by bank transfer (ACH) or by credit or debit card, the sensitive account and card details are collected and stored by Stripe under its own security and compliance program. Sahab Key does not store full bank account numbers or full card numbers on its servers. We retain payment records such as the amount, date, status, the type of method used, and a reference token that lets us recognize a saved method without seeing the underlying number.
Each building is connected to its own Stripe payout account so that payouts route to the correct party, and a building cannot collect Tenant payments until that account is connected. Managers who connect a payout account are subject to Stripe's Connected Account Agreement in addition to this policy.
3. How we use information
- To provide the Service: create and maintain accounts, manage leases and units, compute balances, bill rent, apply late fees, and process payments and payouts.
- To operate the Tenant experience: show balances and payment history, run autopay and its automatic retries, accept maintenance requests, and handle lease signing.
- To operate the application flow: let applicants submit a profile, documents, and an application fee, and let Managers review and decide on applications.
- To communicate: send account, billing, payment, and maintenance notifications, and deliver broadcast messages a Manager sends to its Tenants.
- To secure the Service: authenticate users, enforce multi-factor authentication and account lockout, validate uploaded files, and detect and investigate abuse.
- To meet legal and accounting obligations and to enforce our Terms of Service.
4. Automated features and AI
Some features of the manager and investor experience are assisted by automated processing, including a portfolio risk radar, an in-product assistant, maintenance-request triage, owner and investor report summaries, and financial forecasting. These features analyze organization and tenant-derived data already in the Service (such as leases, balances, payments, and maintenance records) to produce summaries, suggestions, and projected figures.
Which parts of the output the AI model produces, and which parts our own code produces, differ by feature, so we describe each one plainly.
- Tenant risk radar: our code computes behavioral and financial aggregates for a Tenant from that organization's own ledger (months of history, on-time payment rate, average days late, partial payments, autopay failures, waived charges, current balance and its trend, service-request counts, eviction flags, and how soon the lease ends). The model then produces the risk score itself, a number from 0 to 100, along with the factors it cites and the plain-language summary. Only the low, medium, or high label is derived in code from the model's score. The score is stored on the Tenant's record with each run and is visible to the Manager's authorized team. It is built only from that Manager's own history with that Tenant. It is not a credit report, a background check, or a consumer report, it is never used to screen applicants, and nothing about it triggers an automated action.
- Maintenance triage: the model produces its own classification of a maintenance request, meaning a suggested category, a suggested priority, an urgency flag, and whether the request looks like a duplicate of another open request for the same unit. Nothing is applied to the request until a Manager accepts the suggestion, and the model never assigns, closes, or messages anyone.
- In-product assistant, owner and investor report summaries, and financial forecasting: the figures are computed by our own code and the model writes explanatory prose around them.
To generate these outputs, we send the relevant data to Anthropic, our AI provider, which processes it on our behalf under its commercial terms and does not use it to train its models. What we send depends on the feature. The risk radar sends only the computed aggregates for one Tenant, never that Tenant's name and never demographic information. The assistant sends Tenant full names together with the balances they owe and, when a Manager asks about risk, together with their unit number, risk score, risk level, and score summary. Maintenance triage sends the text of the request and up to three of the photographs the Tenant attached to it, as image data. These features are advisory only. They are not legal, tax, accounting, financial, or investment advice, and a Manager remains responsible for its own decisions. We do not use these features to screen rental applicants or to make automated approval or denial decisions about any Tenant.
5. How information is shared
- Within your organization: a Manager and its authorized team members can see the Tenant, lease, payment, and property records inside their own organization, according to the roles and permissions the Manager sets. Tenants see their own account, balance, payments, lease, and requests.
- With owners and investors your Manager authorizes: when a Manager enables the investor feature, the building owners or investors it authorizes can see read-only financial information for their own buildings or units, such as statements, payouts, occupancy, and related figures. This sharing is directed by the Manager.
- With service providers: we share information with the vendors listed in Section 7 so they can perform services for us, and only for that purpose.
- For legal reasons: we may disclose information if required by law, to respond to lawful requests, or to protect the rights, property, or safety of users, the public, or Sahab Key.
- In a business transfer: if Sahab Key is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
We do not sell personal information for money, and we do not share personal information with advertisers or advertising networks. We use Google Analytics on our public website, as described in Section 6. Under some state privacy laws, that analytics activity can be treated as a "sale" or "sharing" of personal information, and you can opt out as described in Section 6.
6. Cookies and analytics
The manager portal and the tenant portal use only cookies that are strictly necessary: a session cookie that keeps you signed in and security cookies that protect the Service. Those portals do not carry advertising or analytics trackers.
Our public marketing website (sahabkey.com) uses Google Analytics to understand aggregate website traffic, such as which pages are visited and the general location, device, and browser type of visitors. Google Analytics sets cookies and collects usage data through the Google tag, and Google processes that data under its own terms. We use Google Analytics for website analytics only, not for advertising, and we do not run separate advertising or retargeting pixels on the website.
You can block or delete cookies in your browser and use Google's opt-out tools; blocking strictly necessary cookies will prevent the portals from working. You can also opt out directly: use the "Do not share my information for analytics" control on this page, which stops Google Analytics from loading on this website for this browser. If your browser sends a Global Privacy Control (GPC) signal, or has Do Not Track turned on, we honor that automatically and no analytics script runs at all.
7. Service providers
We use the following providers to operate the Service. Each receives only the information it needs for its function.
| Provider | Purpose | Information shared |
|---|---|---|
| Stripe | Payment processing, ACH and card payments, and connected payout accounts | Payment amounts, bank and card details entered by the payer, payout configuration |
| SendGrid | Transactional and broadcast email delivery | Recipient email address and message content |
| Supabase | Image, document, and file storage and delivery | Uploaded photos and documents, including maintenance photos, receipts, and leases |
| DocuSeal | Lease electronic signature | Lease documents and signer name, email, and signature |
| Google Maps Platform | Address lookup and mapping | Property addresses entered by Managers |
| Anthropic | AI-assisted features (risk radar, assistant, maintenance triage, report summaries, forecasting) | Computed portfolio and tenant figures; Tenant full names paired with the balances they owe and with their unit number, risk score, and score summary when a Manager uses the assistant; the text and attached photographs of a maintenance request when it is triaged |
| Cloudflare (Cloudflare, Inc.) | Bot protection (Turnstile) on the public rental-application link, when we have it configured | The applicant's IP address and the challenge response token from their browser |
| Google Fonts (Google LLC) | Web font delivery in the manager and tenant portals | IP address and browser user-agent of anyone who loads a portal page, including the sign-in and sign-up pages |
| MongoDB Atlas | Primary database hosting | The account, lease, and financial records described above |
| Render | Application and website hosting | Requests served, including IP address and log data |
| Sentry (Functional Software, Inc.) | Error monitoring | Error and exception data tagged with a user identifier and organization identifier; cookies and auth headers are scrubbed before sending |
| Google Analytics (Google LLC) | Aggregate analytics on the public marketing website | Website usage data, approximate location, device and browser type, and cookie identifiers |
Sahab Key does not provide tenant screening. We do not obtain, order, procure, or generate credit reports, criminal background reports, eviction reports, or any other consumer report about an applicant or a Tenant, we do not connect the Service to a screening provider, and we do not act as a consumer reporting agency. If a Manager chooses to screen applicants, it does so outside the Service using its own providers, and the Manager is responsible for the notices and consents that its screening requires.
Storing a document is a separate thing from running a check, and both statements are true at once. A Manager may require an applicant to provide documents, and the Service gives the Manager's staff slots to upload them, including an image of a Social Security card and a criminal background check record obtained by the Manager. When that happens, Sahab Key stores and serves those documents on the Manager's behalf as its processor, at the Manager's direction. We do not go out and get them, we do not read or evaluate them for you, and we do not use them for any purpose of our own. The Manager decides what to require and what to do with it, within the retention schedules described in Section 8, which delete these documents and their files automatically.
8. Data retention
We keep account and financial records for as long as an organization uses the Service, and afterward as needed to meet legal, tax, and accounting obligations and to resolve disputes. Because rent ledgers are financial records, a Manager may be required to retain them for a period of years even after a Tenant moves out. On top of that, two deletion rules run on a schedule. A job runs once a day and applies both of them.
Rental applications that did not become a tenancy. An application that was declined, withdrawn, or expired without a decision is deleted 24 months after that outcome. The deletion is not limited to database records. It removes the application itself, every document uploaded with it, the underlying files in our private storage, and the notifications about that application. For an application submitted through the public link, that includes the photo ID, the proof of income, and the bank statement. For an application entered by a Manager's staff, it also includes the Social Security card image and the criminal background check record. Two things are held back on purpose: an application whose application-fee payment is still settling is skipped and picked up on a later run, and a document that has since been attached to a live Tenant record, a lease, or a unit is left in place, because it now belongs to something else. Approved applications are not covered by this rule. An approved application became a tenancy, and it follows the rule below.
Former Tenants. Seven years after a Tenant's last lease has ended, and only if that Tenant holds no active or pending lease, we delete that Tenant's identity documents and the files behind them, meaning the photo ID, the Social Security card image, the criminal background check record, any externally run screening report the Manager recorded, the proof of income, and the bank statements. We also delete the application that became the tenancy, together with its documents and files. Then we anonymize the Tenant's user record: the name, email address, and phone number are replaced with placeholder values, the Manager's free-text notes on that record are erased, and the account is deactivated. Documents that record the agreement or the money, such as the lease, notices, and invoices, are kept, and so is anything a Manager filed as "other", because we do not know what is in it.
Both windows are per-organization settings, so a Manager's organization can be set to a shorter or a longer one: from 1 month to 120 months for applications, and from 1 year to 30 years for former Tenants. The 24 months and 7 years described above are what applies unless a different window has been set for that organization. A Tenant who wants to know which window applies to their own records should ask their Manager.
The eviction archive. Ten years after an eviction, we clear the personal details from the archive's tenant snapshot: the name, email address, phone number, and housing-assistance status are removed, and the unit, lease, balance, charge and payment history, and debt-collection record are kept as they are. The archive itself is never deleted. This window is a per-organization setting too, from 1 year to 30 years.
These rules delete what they name and keep everything else. The following are not deleted by either rule, and can remain after a Tenant has moved out and after their user record has been anonymized:
- Charges, payments, and the rent ledger: the accounting record of what was owed and what was paid.
- Leases, including the signed lease document: the contract itself.
- Eviction cases and the eviction archive: as described in Section 1, the archive is designed to remain after the Tenant's own record is gone. It keeps the unit and lease details and the charge, payment, and balance history as of the eviction, and it keeps the name, contact details, and housing-assistance status until the ten-year window above clears them.
- Maintenance requests and the photos attached to them.
- Communication records, autopay records, and management activity logs: an autopay authorization is revoked rather than deleted when autopay is turned off or the method is removed, because the authorization is itself a record we are expected to keep.
- Saved payment methods: what we store is a reference token at our payment processor rather than the account or card number (Section 2). Removing our copy on its own would not detach the method at the processor, so a Tenant who wants a saved method removed should delete it in the Tenant portal, which detaches it at the processor as well.
When an organization's own account is deleted at its owner's request (Section 10), every record belonging to that organization is removed from our database, along with the files it had in our private storage. Two things are deliberately kept afterward: a permanent record of the deletion, which holds the organization's name, who requested it, who carried it out, when it ran, and how many records were removed, and a copy of the organization's final data export, stored in our private file storage.
Tenants who want a copy of their records, or who want a record corrected or removed, should contact their Manager, who controls the workspace data. See Section 10 for how account deletion works. Where Sahab Key controls the data directly, contact us using Section 14.
9. Security
We build the Service to protect financial data. Money is handled in whole cents to avoid rounding errors, payment recording is atomic and uses idempotency keys designed to prevent a payment from being applied twice, and Stripe webhooks are signature-verified and processed idempotently to help prevent a retried event from charging twice. Manager accounts support multi-factor authentication, repeated failed logins lock the individual account, uploads are limited to an allowlist of file types and are rejected outright when their contents look like markup or script, PDFs and images are checked further so that their actual contents match the type they claim (other allowed types, such as Word documents, are not content-verified this way), documents are served through short-lived signed URLs, and the manager and tenant portals are protected by a Content Security Policy that blocks inline scripts unless they carry a per-request nonce, while still permitting inline styles and images loaded from any HTTPS host. This website uses a fixed Content Security Policy. Each organization's data is scoped to its own organization, and we use per-organization access controls designed to keep it separate from every other organization. Traffic is encrypted in transit using HTTPS. No system is perfectly secure, and if we discover a breach that affects your information, we will notify affected users and regulators as required by applicable law.
10. Your choices and rights
- Access and correction: view and update your profile and, for Managers, your records directly in the Service. Tenants can update account details and payment methods in the Tenant portal.
- Notifications: manage the notifications you receive in your account settings, subject to essential billing and account messages we still need to send.
- Deletion: an organization owner can request deletion of the organization's account from billing settings. We review every request before anything is deleted, so deletion is not immediate, and the request can be canceled at any time while it is under review. Before deletion completes, a JSON export of the organization's workspace data is available from billing settings. Tenants do not request deletion directly from Sahab Key; a Tenant should contact their property manager, who controls the workspace data. When the deletion runs, every record belonging to the organization is removed from our database along with its stored files, and we keep a permanent record of the deletion itself and an archived copy of that final export, as described in Section 8.
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act or other state privacy laws, including the right to know what personal information we hold, to request deletion, and to be free from discrimination for exercising these rights. Because Managers control much of the Tenant information on the platform, a Tenant who wants to exercise these rights should contact their Manager, who controls the workspace data. If a Tenant contacts Sahab Key directly, we will forward the request to the relevant Manager and confirm to the Tenant that we have done so. For information that Sahab Key controls directly, you can make a request to Sahab Key using the contact details in Section 14.
11. Children
The Service is intended for adults who are parties to, or who manage, a residential lease. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information to us, contact us and we will address it.
12. International users
Sahab Key is operated in the United States, and the information we process is stored and handled in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify account holders. Continued use of the Service after a change takes effect means you accept the updated policy.
14. Contact us
Questions about this policy or your information can be sent to privacy@sahabkey.com. If you are a Tenant, you can also contact your property manager, who controls much of your information on the platform.
You can also reach us by mail:
SAHAB LLC
11807 Allisonville Rd. #669
Fishers, IN 46038