Privacy Policy
Last updated: April 2026 | Effective immediately
1. Who We Are
Numen (“VeriRent”, “we”, “us”) operates verirent.io, a tenant screening and verification platform. We are committed to strict data handling standards and comply with GDPR, Swedish data protection law, and applicable US fair housing regulations.
2. Definitions
The terms below carry the same meaning everywhere in this policy:
- →Applicant: the individual whose information is being collected and screened in connection with a rental application — i.e. the person filling out the screening form before any leasing decision.
- →Tenant: the same person after they have signed a lease and become the rent-paying party. Used interchangeably with Applicant only where the distinction does not matter.
- →Landlord: the property owner or authorized agent who initiates the screening request through VeriRent.
- →User: any natural person interacting with the VeriRent service, including Applicants, Tenants, Landlords, and references.
3. Data We Collect
We collect the following information from applicants (tenants):
- →Identity: Name, email, phone, government-issued ID
- →Biometric: Facial geometry derived from ID photo + video (used only for identity verification, deleted within 30 days)
- →Financial: Income documents (pay stubs, bank statements)
- →Network: IP address (for fraud detection only)
- →References: Contact information and responses from provided references
4. How We Use Your Data
- →Identity verification (biometric face matching)
- →Document authenticity analysis (Frankenstack™ forensics)
- →Income verification and rent-to-income ratio calculation
- →Fraud signal detection (VPN, IP collusion, metadata anomalies)
- ✕We never sell your data to third parties
- ✕We do not use your data for advertising or marketing
5. Data Sharing
We share your screening report only with the landlord who initiated your screening. We do not share data with:
- ✕Credit bureaus or other CRAs
- ✕Marketing or advertising companies
- ✕Other landlords or property management companies
We may share data with law enforcement when required by valid legal process.
6. Biometric Data
We collect facial geometry (biometric identifiers) for identity verification: matching your live selfie to the photo on your government-issued ID (1:1 comparison).
Processing & storage:
- →Biometric data is processed by our identity verification provider, a specialist third-party data processor
- →All biometric data — facial geometry, similarity scores, liveness detection results, raw selfie images, and ID document photographs — is permanently deleted within 30 days of screening completion, both from VeriRent's systems and from the identity verification provider's systems
- ✕Never sold, licensed, traded, or used for AI model training
For full details including retention schedules, destruction procedures, and your rights, see our Biometric Data Policy.
7. Data Retention
- →Screening reports: Up to 7 years (legal retention)
- →Biometric data (facial geometry, similarity scores, liveness detection results, selfie and ID document images): 30 days from screening completion
- →Uploaded documents: 7 years (legal retention)
- →Login tokens: Deleted immediately after use
8. Your Rights
- →Access: Request a copy of your verification report at any time
- →Correct: Request correction of inaccurate information
- →Delete: Request deletion of your data (subject to legal retention requirements)
Exercise any right by contacting: support@verirent.io
9. Security
We use industry-standard encryption, access controls, and security monitoring. Sensitive files (ID documents, videos) are served only to authenticated landlords. We do not store raw SSNs or credit card numbers.
10. EU & Swedish Law (GDPR)
VeriRent is operated by a Swedish entity and complies with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the Swedish Data Protection Act (2018:218). The supervisory authority is IMY (Integritetsskyddsmyndigheten).
- →Legal basis for biometric processing: Explicit consent (GDPR Art. 9(2)(a)), withdrawn at any time.
- →Data location: All personal data stored within the EU (Frankfurt datacenter). No transfers outside the EU/EEA.
- →Biometric retention: All biometric data — facial geometry, similarity scores, liveness detection results, selfie images, and ID document photographs — is deleted within 30 days of screening completion, both from VeriRent's systems and from the identity verification provider's systems.
- →No credit bureau data: VeriRent does not obtain data from UC, Creditsafe, or any third-party credit bureau. All documents are submitted directly by the applicant. We operate under GDPR, not the Swedish Kreditupplysningslagen (KuL).
- →Data Processing Agreement: Landlords using VeriRent act as data controllers. VeriRent acts as data processor per GDPR Art. 28. A DPA is accepted at account creation.
- →Analytics: With your consent, PostHog Cloud EU receives public-page views, a random browser identifier, and a small set of fixed conversion events. We do not send form values, screening data, names, emails, payment identifiers, or URLs containing query strings.
Your GDPR Rights
- →Access (Art. 15): Request a copy of your personal data
- →Erasure (Art. 17): Request deletion of your data. Submit deletion request →
- →Withdraw consent (Art. 7): Email privacy@verirent.io to withdraw biometric consent at any time
- →Lodge complaint: Contact IMY at imy.se if you believe your rights have been violated
11. Contact
Privacy inquiries: privacy@verirent.io
Support: support@verirent.io