Privacy Policy
Last updated 11 September 2026
This draft explains what CommercialLeaseReview.ai collects, why it is processed, where it is sent, and how long the current implementation keeps it. It is pending counsel review and provider approval and is not a final legal policy.
1. Data we collect and create
Uploaded records. We accept leases, CAM and tax reconciliation statements, and supporting PDF or Word files. We record the customer filename, document type, MIME type, byte size, upload time and a digest used to verify the uploaded bytes. The contents may identify a tenant, business, property, landlord, contacts, lease terms, account references and financial amounts.
Extracted and report data. We create page text, OCR confidence records, statement lines and figures, lease-clause excerpts and parameters, citations, classification proposals and approvals, reconciliation runs, findings, evidence, arithmetic and released-report snapshots.
Order and account data. This includes name, email, optional phone, business and tenant type, location count, property name and address, state, lease type, optional landlord, statement-received date, notes, order reference and status, account identifiers, and the Terms and Privacy versions and acceptance time recorded with the order.
Payment and subscription data. Stripe handles card details. We do not receive the full card number. We retain quoted and settled amounts and currency, Stripe customer, checkout, payment, invoice and subscription identifiers, subscription status, cancellation dates, payment-failure counts, and refund or dispute events needed to reconcile the order.
Technical and delivery data. We use IP addresses in short rolling rate-limit windows. We also create job, webhook and audit events; customer capability verification data; email outbox linkage; provider message identifiers; delivery states, errors and timestamps; and provider webhook event identifiers, types and processing states.
Launch-notification email addresses. The pre-launch pages offer a form that collects an email address so we can tell you when the service opens. That form stores the address, the time it was submitted and, only if you choose to answer the optional question, which one of a short fixed list of options describes how you heard about us. It stores nothing else: not a name, an IP address, a browser fingerprint or the page you submitted it from, and an address submitted there is not linked to any order.
2. How uploaded records become a report
A source PDF is read directly. A Word document is first rendered to PDF, and that rendered PDF is retained with the source while the review is active because it is the artifact whose pagination the report cites. Text is extracted natively when possible and by OCR where needed. The resulting pages, figures and clause excerpts are stored for deterministic checks and human review.
A released report is an immutable snapshot of its findings, supporting evidence, arithmetic and approved classifications. A later release or rollback can become the current report without rewriting an earlier run.
We do not sell uploaded records, use them for advertising, contact a landlord on a customer’s behalf, or use them to train our own machine-learning model.
3. Retention and deletion implemented today
Unconfirmed uploads. A staged upload that is not confirmed is treated as abandoned after 24 hours and its source and any rendered object are deleted.
One-time reviews. Source files, rendered copies and extracted page and statement-line content are scheduled for deletion 30 days after the report is first released and the order is marked delivered.
Subscription reviews. Those same source, rendered and extracted records are scheduled for deletion 30 days after the subscription’s recorded cancellation time. Cancellation of a subscription, rather than an undated order state, starts this clock.
After content deletion, a document audit row remains with non-content metadata: filename, kind, MIME type, byte size, upload and deletion times, state, and order linkage. Storage locators and source or rendered digests are cleared only after all known object deletions succeed.
Released reports. The current implementation assigns the current report release a deletion date six years after it becomes current. If a newer release or an explicit rollback changes the current report, that transition receives a new release time and six-year date; it does not restart the source-document clock. This six-year period is provisional and must be confirmed by the product owner and counsel before launch.
Launch-notification email addresses. An address submitted to the pre-launch notification form is deleted 730 days (24 months) after it was submitted. The scheduled sweep removes the row outright, including any answer to how you heard about us; there is no retained copy and no audit record of the address afterwards. This 24-month period is provisional and must be confirmed by the product owner and counsel before launch. To be removed sooner, write to the address in clause 9 and the row will be deleted.
Other records. Order, payment, consent, subscription and audit records, plus scrubbed email outbox linkage and provider delivery telemetry, do not yet have a scheduled deletion in the implementation. A final policy must set any required period; this draft does not describe those records as short-lived.
4. Configured service providers
The production design uses the providers below for the stated data and purpose. This list describes code paths; it does not claim that vendor review, contracts or data-processing addenda have been completed.
- Vercel hosts and serves the application, so application requests, response data and associated network or runtime metadata pass through its platform.
- Neon hosts the application database containing order, contact, consent, payment-linkage, extracted, review, report, audit and delivery records.
- Cloudflare R2 stores uploaded source documents and rendered PDF artifacts until their deletion date.
- Stripe provides checkout, billing, subscriptions and refunds. Stripe receives payment and billing data, customer email, order reference, tier and amount, and returns identifiers and status events used to reconcile the order.
- Resend delivers transactional email. It receives the recipient and rendered message body, which may contain a name, order reference, customer capability link, billing link or report-ready notice. We retain its provider message identifier and delivery-event state, type, errors and timestamps, not its webhook body.
PDF and Word text extraction currently runs on service-controlled OCR and rendering infrastructure. No managed OCR provider is represented as approved. If that changes, the provider and data classes must be added here before document content is sent.
5. Conditional Anthropic classification — not approved
An Anthropic classifier integration exists but is not approved for production processing as of this draft date. It is a conditional processor only if the product owner completes provider review and explicitly enables the Anthropic mode with a configured credential. Until then, no document data should be sent through that path.
If approved and enabled, each classification request contains the printed statement-line label, an optional parent heading, and up to eight relevant lease-clause candidates. A candidate contains a lease-parameter identifier, section label and verbatim extracted clause excerpt. The request also contains a fixed category list, instructions and output schema. It does not contain statement amounts, filenames, page numbers, customer or contact details, property or order identifiers, computed findings, or human approval notes.
The sole purpose is to propose an expense category for a printed line. The model does not calculate a finding, select report evidence, or approve its own proposal. A recorded human approval is required before a proposal can affect a released report. Any claim about Anthropic’s contractual retention or training terms must be verified before this integration is approved; this draft makes no such claim.
6. Email outbox and provider telemetry
New outbox rows use stable identifiers such as an order, subscription, Stripe invoice or reconciliation-run identifier rather than a raw recipient, name or rendered body. After completion, the payload is replaced with an empty object. Resend still receives the recipient and rendered body to deliver the message. Our database keeps provider name, provider message identifier, state, error and timestamps, plus provider event identifier, type and processing state. SMTP development delivery is recorded as untracked.
7. Customer capability links and access
The customer order link is a stable bearer capability. It is not tied to a signed-in browser session and is not short-lived: anyone holding the complete link can view the customer order page and available report and can submit or confirm documents for that order. Keep it confidential and do not forward it to anyone you do not authorize.
The capability uses a versioned HMAC check derived from the internal order and normalized reference under the service secret; the raw token and secret are not stored in the database. Short-lived signed storage URLs used to transfer a file are separate from this stable customer capability. Authorized staff use a separate administrative access path.
8. Requests and legal rights
You may ask what data we hold, request a correction, or request deletion by using the contact below. Whether a request can be completed, and the response deadline, depend on the applicable law and records still needed to provide the service, document transactions or preserve the provisional released-report record. This draft does not claim that a particular privacy statute or deadline applies without counsel review.
Deleting source material while a review is in progress prevents completion of that review. Do not send source documents or the customer capability link in an ordinary email request.
9. Contact
Privacy questions and requests go to privacy@commercialleasereview.ai. This contact and the complete draft require confirmation before launch.