Where we stand, gaps included
The product reads a government ID and matches a face. That is the most sensitive data a rental ever asks for, and it carries real duties. Here is our position, and what is still open.
Last updated · August 30, 2026
- 01
What this page claims
It states a position. It does not claim a certification. We hold no SOC 2 report, no ISO certificate and no third-party audit, and we will not imply one. When we obtain one, it will be named here with its date and its scope.
Where an obligation applies and we have not finished meeting it, this page says so. A gap you can read is a gap somebody can close.
- 02
Your rights over your data
You can ask what we hold, ask for a copy, ask us to correct it, ask us to delete it, and ask us to limit how we use sensitive data. An identity document and a face image are the most sensitive data we touch. We answer these requests for every reader, not only where a law forces us to.
We do not sell personal information and we do not share it for cross-context behavioural advertising. No advertising technology exists on this site or in the product, so there is no mechanism through which either could happen.
We answer a verified request within 45 days, and we tell you if we need longer. An authorised agent may act for you with written permission. Exercising a right costs you nothing and changes nothing about the service you receive.
Where a property manager uses the product, the data is theirs and we process it for them. We act on their instruction, we do not use their tenant data for our own purposes, and we pass a request we receive directly to them.
- 03
The selfie match
This is the sharp point, so we will not blur it. Before a door code is issued, the product compares the selfie to the photograph on the government ID. A comparison of two faces can produce a measurement of face geometry, and a measurement like that is data a person can never change. It is held to a higher standard than an email address, and it should be.
What we hold ourselves to:
- a written policy, public, with a retention schedule and a rule for destruction
- notice and a real, informed consent from the person, before the check begins
- no sale, no lease and no other profit from a face image
- storage and transmission under the standard of care the work deserves
- destruction once the purpose is met, rather than storage without end
Where we stand on each, item by item:
- We do not sell, lease or otherwise profit from a face image or an identity document. That one is unconditional.
- Consent is taken in the product, before the check begins, and it must be a real choice rather than a checkbox nobody reads. The exact wording sits in the verification flow, not on this page.
- The retention and destruction schedule is not published here yet. Retention is currently set per customer agreement. This is the open item, and we are naming it rather than hiding it.
- Whether the match produces a face template, and whether any template is stored rather than compared and discarded, is a detail held by our identity vendor, Persona. We are not settling it on this page from the outside.
The images do not reach MyRemotely at all. The match runs inside the identity provider and we receive a decision, so the record that would be worth stealing is not ours to lose.
- 04
Security posture
This website is static files. Cloudflare serves them at the edge over HTTPS, and there is no application code on the request path, so the marketing site has no database to breach and no session to steal.
In the product:
- A door code is written for one unit and one tour window, then removed when the window closes.
- A code is bound to a visitor who passed the identity check. It is not a shared key.
- Every code issued and every code entered is timestamped in an access log scoped to one organisation.
- Offline locks carry daily fallback codes so a tour still runs, and the lock is reconciled when it is reachable again.
- Identity verification runs through Persona rather than through storage we built ourselves.
Encryption at rest, key management and penetration testing are not described on this page, because we will not state a control we cannot show you evidence for. Ask, and we will answer in writing about your deployment.
- 05
Subprocessors
The companies that process data for us today:
- Cloudflare — website hosting and delivery
- HubSpot — CRM, and the scheduler embedded on /meeting
- SignNow — the NDA signing flow on /nda
- Persona — identity document and selfie verification
- Twilio — SMS to and from a prospect
Lock vendors TTLock and Sifely receive the codes the product writes to their hardware. Property management systems Rentvine and Showdigs exchange unit and lead data when a customer connects them. Those connections are the customer's choice.
This list changes as the product does. Write to us if you want to be told before it changes.
- 06
If something goes wrong
If personal data of yours is exposed, we will notify you and the authorities the law names. The exact timeline is set by the law that applies where you are and by your customer agreement; it is not fixed on this page.
Report a vulnerability to the email address below. Tell us what you found and how you found it. We will confirm we received it and we will not pursue a researcher who reported in good faith and did not touch other people's data.
- 07
How to file a request or a complaint
Email us with "Privacy request" or "Complaint" in the subject line, and say what you want: a copy, a correction, a deletion, or an answer. Give us the email address, the phone number or the unit that lets us find your record. We ask for nothing beyond what identifies you.
If our answer does not satisfy you, you can take it to the data protection authority where you live, and nothing on this page takes away a right the law gives you. We would prefer to fix it first, and we will try.
- info@myremotely.ai
- (312) 572-9948
- (888) 885-6729 (second line)
- 3205 N Wilke Rd #3205-121, Arlington Heights, IL 60004
This is a plain-language summary of how we work, written to be understood rather than to be impressive. It is not legal advice, and it is pending review by counsel.