Avail
avail.coAvail (operated by Rentalutions, Inc., a Delaware corporation) is a property-management platform for DIY landlords that handles tenant screening, credit/background checks, lease signing, and ACH rent payments — activities that place it squarely in the fintech-adjacent space with heavy handling of sensitive personal and financial data. The consumer terms and privacy policy are reasonably detailed about what data is collected and how it flows to third-party providers (TransUnion, Plaid, HelloSign/Dropbox Sign, Yelp), and the service model inherently requires sharing tenant data with landlords. However, the documents are silent on nearly every modern compliance framework (no SOC 2, GDPR, CCPA/CPRA, PCI DSS, or GLBA claims despite processing SSNs and bank data), rely on a self-managed 256-bit encryption statement with no third-party attestation, disclose no breach history, impose binding individual arbitration with a class-action waiver, and pair a March 2025 Terms with an April 2024 privacy policy plus an unfinished placeholder community privacy policy. A material cross-document contradiction on selling/marketing use of non-personal data further undercuts confidence. Suitable for individual landlords with awareness, but professional or portfolio operators handling significant tenant PII should seek contractual protections.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The terms address ownership of the Website and its contents (owned by Avail) but do not clearly grant or reserve ownership of the user-submitted data such as application information, unit listings, or uploaded leases. Users retain their own information in practice, but no explicit ownership clause protects user input, and the vendor reserves broad rights over the platform.
Output Data Ownership
The service generates outputs such as Rent Roll reports, Cash Flow reports, and populated lease agreements, but the documents do not state who owns these generated materials. Reports are provided 'solely for general information purposes' with all warranties disclaimed, and no ownership right in generated output is expressly conveyed to the user.
Training Data Usage
The privacy policy does not mention AI/ML model training. It does state that aggregated, non-identifying information is pooled to improve the service, which is a form of improvement use but not model training. Silence on any model-training use is itself a finding for a platform holding sensitive financial data.
Data Retention & Deletion
Users can request access, correction, and deletion by emailing support, and the policy commits not to store Background Check Results after an application is evaluated. However, there are no defined retention schedules or deletion SLAs, deletion is limited (data on another user's account is retained), and the community privacy policy contains an unfilled placeholder for its log-retention period.
Third-Party Data Sharing
Sharing tenant data with landlords and with named third-party providers (TransUnion, Plaid, HelloSign, Yelp) is integral to the service the user signs up for and is generally well disclosed and limited to service purposes. However, the main privacy policy says non-personal data may be shared 'without restriction,' the community policy says non-identifiable info 'may be provided to other parties for marketing, advertising, or other uses,' and Personal Information may be transferred in a business sale — broadening the sharing beyond the strict service purpose.
Opt-Out Rights
The documents provide concrete opt-out mechanisms for marketing email (unsubscribe) and SMS ('STOP' to 22445), and cookie controls via the browser. However, there is no opt-out from the core data collection or from the aggregate/non-identifying data sharing, and the email opt-out explicitly does not extend to transactional communications.
Compliance & Certifications
Despite processing SSNs, taxpayer IDs, bank account/routing numbers, and credit/background data, the documents name no privacy or security certification or framework — no SOC 2, ISO 27001, GDPR, CCPA/CPRA, PCI DSS, or GLBA. The only compliance references are operational rules (NACHA, OFAC, FinCEN, DMCA, the California Shine-the-Light statute, and a general Fair Housing Policy) rather than data-protection attestations. For a fintech-adjacent platform this absence is a significant risk.
Model Explainability & Auditability
The documents contain no mention of AI/ML models, algorithmic decision-making, explainability, or enterprise auditing capabilities. The only audit-related language concerns NACHA compliance audits of the user, not any transparency into the platform. Given the platform influences screening decisions, the total silence is a notable gap.
Security Practices & Breach History
The privacy policy describes several concrete security measures — 256-bit encryption of sensitive fields, separated application and database servers, RSA-key-restricted server access, and a secured hosting facility with frequent patching. However, there is no third-party attestation (no SOC 2, pen-test, or bug bounty referenced), no dedicated trust center, no formal incident-response commitment, and no breach-history disclosure.
Enterprise vs. Consumer Risk Delta
The terms describe free and paid ('Unlimited Plus') tiers but the legal documents draw no distinction in data handling between them — the same privacy policy governs all users. No enterprise/DPA terms were located, so business users receive no documented data-handling upgrade over consumers.
Human Review of User Inputs
The documents do not state that staff routinely read user prompts or content, but Avail reserves broad rights to validate identity, investigate transactions for fraud, and disable accounts at its discretion, which implies access to user data. The service also inherently exposes tenant application data to landlords by design.
Regulatory & Litigation Exposure
The privacy policy discloses that Avail will comply with court orders, legal process, and government/regulatory requests, and will share taxpayer and account data with regulators and financial institutions for compliance. The terms impose mandatory individual arbitration with a class-action waiver governed by Illinois law, which limits user legal recourse. No specific current litigation is disclosed.
PII & SPI Data Inventory
Avail collects extensive PII (name, email, phone, address, birthdate, IP, device/browser data) and substantial SPI, including Social Security/taxpayer numbers, bank account and routing numbers, income and employment history, and highly sensitive screening data such as felony convictions, bankruptcy, and eviction history. While disclosure of collection is reasonably clear, the sheer volume of financial and sensitive personal data, combined with the absence of formal privacy-law certifications, warrants a high-risk rating.
Policy–Product Currency
The Terms of Use are dated 'Last Modified: March 4, 2025' and the main Privacy Policy 'Last Modified: April 2, 2024,' both within roughly 12–24 months of the analysis date. The product surface describes conventional property-management features (screening, e-signature, rent collection) with no clearly AI-driven capability, and the policies cover the corresponding data flows and named third parties reasonably well; the rating is capped by the aging privacy policy and by an unfinished placeholder community privacy policy that references undefined dates and fields.
Cross-Document Consistency
Multiple documents were supplied (two Terms copies, the main Privacy Policy, and a separate community Privacy Policy). A material contradiction exists on marketing/advertising use of non-identifiable data: the main policy limits disclosure to enhancing services, while the community policy states non-personal visitor information may be provided to other parties for marketing and advertising. The community policy is also an unfinished template containing an admin placeholder note and blank fields, undermining consistency and reliability.
You've read all 15 risk ratings for Avail. Create a free account to see the exact policy wording behind each rating.