Skip to main content
Housing & community services

Legal & privacy

Privacy notice

This notice explains the information handled through the Indivisible By One housing portal, why it is needed, who may receive it, and the choices available to applicants, waitlist members, residents, and account holders.

Sensitive information we do not request

Do not enter a Social Security number, government ID number, bank or payment-card number, account password, or medical record into a portal form or upload. Tenant-screening identity information is provided directly to the screening company, not to this portal.

1. Scope

This notice applies to the Indivisible By One public housing directory, availability pages, inquiry and waiting-list forms, rental-application workspace, and authenticated resident and staff portals. In this notice, “Indivisible By One,” “we,” and “us” mean the participating property owner or manager operating the portal for the community involved.

A community website, tenant-screening company, payment provider, or other site reached through a link may have its own privacy notice. This notice does not replace that provider's notice.

2. Information we collect

Depending on how you use the portal, we may collect:

  • Housing inquiries and waitlists: name, email, telephone number, preferred contact method, selected homes or bedroom needs, budget, move timing, and optional message.
  • Rental applications: applicant and household names, dates of birth, contact details, household composition, vehicles, animals, whether the applicant currently has income, any reported income sources and supporting images, the expected housing-fee payer and payer name when someone else will pay, rental history, landlord contacts, housing-history explanations, certifications, and signature.
  • New Horizon program intake: preferred name and referral source when provided, desired move-in date, available savings, ordinary monthly expense estimates, tobacco or nicotine use, usual bedtime, food preferences, daily schedule, activities, shared-living considerations, work or volunteer plans, questions, and acknowledgments about shared living, a substance-free residence, and keeping medical and identity information out of the form.
  • Program documents and license agreements: the exact document version and content hash presented, view and acceptance times, typed signature name, acceptance statements, qualification and issuance status, delivery events, selected bed hold, agreement status, and limited request-integrity evidence. The portal stores the finalized agreement in private storage and does not publish it.
  • Application activity: the community, whether an application was started or submitted, and event timestamps. This separate activity log does not contain application answers, uploaded files, contact details, or a raw device or network address. Activity for an abandoned draft is removed when that draft is purged.
  • Application-fee activity: whether the fee is required, the fixed amount, currency and provider mode, disclosure version and acceptance time, coarse payment status and timestamps, and limited Stripe identifiers and event-integrity evidence. The portal does not receive card details. Test-mode payments are clearly labeled and do not move real money.
  • Resident services: account identity, household, occupancy and lease information, ledger activity, documents, maintenance requests, attachments, comments, and notification preferences. When online rent payments are enabled, this also includes payment status, Stripe references, and limited saved-method display details such as the bank institution, account type, and last four digits. Historical payment records may retain limited provider-reported card details from payments made before rent checkout became ACH-only. Complete bank-account, routing, and card numbers are entered and stored by Stripe, not the portal.
  • Staff and security records: authorized membership, role, account-security state, audit history, and records of sensitive operational actions.
  • Technical information: request time, page or source URL, browser and device information, security events, and keyed abuse fingerprints used for rate limits. The portal does not use a public application number or property identifier as authorization.

An adult applicant may provide limited information about children who will live in the home. The portal is not intended for a child to create or manage an account independently.

3. How we use information

We use portal information to:

  • show management-verified housing availability;
  • respond to inquiries and manage property waiting lists;
  • receive, verify, review, and decide rental applications;
  • administer New Horizon program intake, document acknowledgments, qualification, license-agreement delivery and acceptance, and a temporary bed hold;
  • create approved resident, household, occupancy, lease, and ledger records;
  • provide resident documents, maintenance, account, and notification services;
  • protect accounts, prevent abuse, investigate errors, and preserve audit evidence; and
  • meet legal, accounting, safety, housing, and recordkeeping obligations.

The portal is not configured to sell or rent personal information for money, and application or resident information is not currently used for cross-context behavioral advertising.

4. How information is shared

Information may be disclosed only as reasonably needed to:

  • authorized property owners, administrators, managers, and service personnel with duties related to the relevant community;
  • Supabase, which provides authentication, database, and private file storage services;
  • Vercel, which hosts the portal and may provide aggregate traffic and performance measurement on ordinary public pages;
  • Resend, when production email delivery is enabled, and Checkr Tenant when a separate tenant-screening invitation is requested;
  • Stripe when a resident chooses an enabled online rent-payment service or when a New Horizon applicant deliberately opens the separately disclosed application-fee Checkout;
  • accountants, insurers, attorneys, auditors, regulators, courts, law enforcement, or emergency services when permitted or required; and
  • a successor owner or manager responsible for an affected property, subject to applicable obligations and safeguards.

Resident and applicant information is not made public through the property directory. Public availability uses approved marketing profiles and aggregate rental-space counts rather than resident data.

5. Tenant screening

If an application reaches screening, each adult receives a separate invitation from Checkr Tenant for the Essential package. Checkr presents its own disclosures and collects the adult's authorization and identity information on its secure site. The portal is designed not to store Social Security numbers, raw credit reports, credit scores, or criminal and eviction report files.

To initiate a screening, authorized management personnel may provide Checkr Tenant with the adult's name, email address, date of birth, and property-related request information already supplied with the application. Communities other than New Horizon may use this separate screening process. New Horizon does not require a background check for its application; its separate $20.00 Stripe application fee covers application review and administrative processing.

The portal may retain the provider name, an external reference, workflow and provider-payment status, review timestamps, decision evidence, and any required adverse-action record. It does not retain card details or Checkr's screening report. Screening does not make an automatic housing decision; authorized staff perform human review. Learn more in our Fair Housing statementand the FTC's landlord screening guidance.

6. Cookies and analytics

The portal uses necessary cookies for secure sessions, application-draft access, request integrity, and role routing. An application draft is linked to an opaque browser cookie, so applicants should return using the same private device and browser until the draft is submitted or expires.

A person opening a New Horizon license agreement first confirms the deliberate action from a one-time link. The portal then uses an opaque, expiring, secure browser cookie so the agreement can be reviewed and accepted without leaving the access token in the page address. The cookie is not an advertising identifier.

Aggregate traffic and performance measurement may operate on ordinary public pages. Those tools are excluded from application, authentication, account, staff, and resident routes, and form contents are not intended to be sent as analytics events.

7. Retention and deletion

The portal's current operational defaults are:

  • Unsubmitted application drafts: ordinarily expire after about three hours without a save. Saving may extend the draft, but never beyond seven days from creation. Periodic cleanup removes expired draft data and associated uploads.
  • Application activity records: privacy-minimized start and submission events for submitted applications are scheduled for deletion after 24 months. When an unsubmitted draft expires, its start activity is removed with the draft after the secure upload-replay cleanup window. No separate expiration event is retained.
  • Application-fee records: limited disclosure, transaction-status, reconciliation, refund, dispute, and audit evidence may be retained as needed for payment integrity, accounting, support, fraud prevention, or legal obligations. Card data is retained by Stripe under its own notice, not by this portal.
  • Submitted income documents: scheduled for deletion after 180 days unless a documented extension or legal hold applies.
  • Submitted application records: scheduled for deletion after 24 months unless a documented legal or operational reason requires otherwise.
  • Program and agreement evidence: published program document versions, applicant view and acceptance evidence, qualification records, delivery history, agreement acceptance, and the limited onboarding lineage may be retained separately from the application when needed to document the program process, agreement, occupancy, dispute, or legal obligation. Expired, unaccepted offers and their temporary bed holds are cleared through scheduled cleanup.
  • Listing inquiries and active waiting lists: the portal does not currently apply one automatic expiration period. A waiting- list record remains while active. When staff records a withdrawal, direct contact details, message, move timing, budget, and home preferences are anonymized while limited consent, status, and audit evidence remain.
  • Approved applicants and resident operations: names and contact details needed for onboarding may be copied into resident records. The application number and limited onboarding lineage may remain after application cleanup. Resident, lease, financial, maintenance, and property records do not currently share one fixed deletion period; they are retained while needed for tenancy, account service, accounting, safety, disputes, and legal obligations.

Backup copies, security logs, and provider records may remain for a limited period under their normal protection and deletion cycles. A legal hold, active dispute, accounting rule, or other lawful obligation may delay deletion. These defaults may be revised after jurisdiction- specific review; this page will be updated if they change.

8. Your choices

You may ask to access or correct information, withdraw from a waiting list, request deletion where available, change notification preferences, or ask questions about how information is handled. We may need to verify identity and property relationship before disclosing or changing a private record.

A request may be limited when information must be kept for a lease, accounting record, safety matter, legal claim, fraud prevention, screening or adverse-action requirement, or another lawful obligation. Use the privacy and data request instructions.

9. Security

The portal uses private storage, role- and community-based access, multifactor authentication for sensitive staff work, encrypted network transport, expiring access tokens, request-integrity controls, rate limits, and audit records. Sensitive application and resident pages are excluded from public analytics.

No online service can guarantee absolute security. If you believe information or an account may have been exposed, do not include the sensitive information in a message; contact the relevant property promptly through the support center.

10. Contact us

Privacy and data requests should be directed to the community connected to the record. The support center provides the current public telephone number, business email when available, and property website for every participating community.

We may update this notice as services, providers, or legal requirements change. The effective date at the top identifies the current version.