Privacy Policy

Effective / last updated 2026-08-25 · Version 2026-08-25

This document is a drafted template and has not been reviewed by an attorney. It should be reviewed by qualified legal counsel before being relied on commercially.

This Privacy Policy explains how Meridian collects, uses, and protects personal data, and describes the rights available to you under applicable law, including the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

1. What we collect

Account data: name, email, company, hashed password.

Customer Data you enter: property details, tenant/applicant contact information, lease terms, rent amounts, and screening coordination records (status, provider reference, notes) that you as the landlord control.

Usage data: IP address and timestamps captured for security purposes (e.g. rate limiting, consent records) — we do not run advertising or analytics trackers.

2. Legal basis for processing (GDPR)

We process account and billing data to perform our contract with you (Art. 6(1)(b) GDPR).

We process security/consent-audit data (such as IP address at signup) under our legitimate interest in account security and legal accountability (Art. 6(1)(f) GDPR).

Where you enter tenant/applicant data, you act as the data controller for that information and Meridian acts as your data processor — see our Data Processing Agreement.

3. How we use data

To operate the service, process payments (via Stripe), send transactional email (via Resend) such as verification and password-reset messages, and maintain security.

We do not sell personal information and do not share Customer Data with third parties except the subprocessors listed below, or as required by law.

4. Subprocessors

Stripe, Inc. — payment processing.

Resend — transactional email delivery.

Our infrastructure/database hosting provider — see current hosting region details in your account or on request.

We will update this list as subprocessors change and will notify business customers of material changes where required by our Data Processing Agreement.

5. Your rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing.

You can self-serve an export of your data or delete your account at any time from Settings. For any other request, or if you are a tenant/applicant whose data was entered by a landlord using Meridian, contact us at [email protected] and we will route the request appropriately (landlords are the data controller for tenant data they enter).

6. California residents (CCPA/CPRA)

We do not sell or share personal information for cross-context behavioral advertising. California residents have the right to know, delete, and correct their personal information, and to non-discrimination for exercising these rights.

7. Data retention

Account and Customer Data are retained while your account is active. Deleting your account removes your data (and cascades to associated property/tenant/lease/screening records you created) within a short operational window, except where retention is required for legal, tax, or security-audit purposes (e.g. consent and adverse-action-notice records, retained for the period recommended under applicable screening law).

8. Security

Passwords are hashed, sessions use signed, HTTP-only cookies, and data in transit is encrypted via HTTPS. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

9. International transfers

If you access Meridian from the EEA/UK and our infrastructure is located elsewhere, we rely on appropriate safeguards (such as Standard Contractual Clauses) for any such transfer. Contact us for details of the safeguards in place.

10. Contact

Privacy questions or rights requests: [email protected].