Avail logo

Avail

avail.co
High Risk
Updated September 3, 2026

Avail (operated by Rentalutions, Inc., a Delaware corporation) is a property-management platform for DIY landlords that handles tenant screening, credit/background checks, lease signing, and ACH rent payments — activities that place it squarely in the fintech-adjacent space with heavy handling of sensitive personal and financial data. The consumer terms and privacy policy are reasonably detailed about what data is collected and how it flows to third-party providers (TransUnion, Plaid, HelloSign/Dropbox Sign, Yelp), and the service model inherently requires sharing tenant data with landlords. However, the documents are silent on nearly every modern compliance framework (no SOC 2, GDPR, CCPA/CPRA, PCI DSS, or GLBA claims despite processing SSNs and bank data), rely on a self-managed 256-bit encryption statement with no third-party attestation, disclose no breach history, impose binding individual arbitration with a class-action waiver, and pair a March 2025 Terms with an April 2024 privacy policy plus an unfinished placeholder community privacy policy. A material cross-document contradiction on selling/marketing use of non-personal data further undercuts confidence. Suitable for individual landlords with awareness, but professional or portfolio operators handling significant tenant PII should seek contractual protections.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The terms address ownership of the Website and its contents (owned by Avail) but do not clearly grant or reserve ownership of the user-submitted data such as application information, unit listings, or uploaded leases. Users retain their own information in practice, but no explicit ownership clause protects user input, and the vendor reserves broad rights over the platform.

Confidence
45%

Output Data Ownership

Moderate Risk

The service generates outputs such as Rent Roll reports, Cash Flow reports, and populated lease agreements, but the documents do not state who owns these generated materials. Reports are provided 'solely for general information purposes' with all warranties disclaimed, and no ownership right in generated output is expressly conveyed to the user.

Confidence
40%

Training Data Usage

Moderate Risk

The privacy policy does not mention AI/ML model training. It does state that aggregated, non-identifying information is pooled to improve the service, which is a form of improvement use but not model training. Silence on any model-training use is itself a finding for a platform holding sensitive financial data.

Confidence
40%

Data Retention & Deletion

Moderate Risk

Users can request access, correction, and deletion by emailing support, and the policy commits not to store Background Check Results after an application is evaluated. However, there are no defined retention schedules or deletion SLAs, deletion is limited (data on another user's account is retained), and the community privacy policy contains an unfilled placeholder for its log-retention period.

Confidence
60%

Third-Party Data Sharing

Moderate Risk

Sharing tenant data with landlords and with named third-party providers (TransUnion, Plaid, HelloSign, Yelp) is integral to the service the user signs up for and is generally well disclosed and limited to service purposes. However, the main privacy policy says non-personal data may be shared 'without restriction,' the community policy says non-identifiable info 'may be provided to other parties for marketing, advertising, or other uses,' and Personal Information may be transferred in a business sale — broadening the sharing beyond the strict service purpose.

Confidence
65%

Opt-Out Rights

Moderate Risk

The documents provide concrete opt-out mechanisms for marketing email (unsubscribe) and SMS ('STOP' to 22445), and cookie controls via the browser. However, there is no opt-out from the core data collection or from the aggregate/non-identifying data sharing, and the email opt-out explicitly does not extend to transactional communications.

Confidence
60%

Compliance & Certifications

High Risk

Despite processing SSNs, taxpayer IDs, bank account/routing numbers, and credit/background data, the documents name no privacy or security certification or framework — no SOC 2, ISO 27001, GDPR, CCPA/CPRA, PCI DSS, or GLBA. The only compliance references are operational rules (NACHA, OFAC, FinCEN, DMCA, the California Shine-the-Light statute, and a general Fair Housing Policy) rather than data-protection attestations. For a fintech-adjacent platform this absence is a significant risk.

Confidence
70%

Model Explainability & Auditability

High Risk

The documents contain no mention of AI/ML models, algorithmic decision-making, explainability, or enterprise auditing capabilities. The only audit-related language concerns NACHA compliance audits of the user, not any transparency into the platform. Given the platform influences screening decisions, the total silence is a notable gap.

Confidence
55%

Security Practices & Breach History

Moderate Risk

The privacy policy describes several concrete security measures — 256-bit encryption of sensitive fields, separated application and database servers, RSA-key-restricted server access, and a secured hosting facility with frequent patching. However, there is no third-party attestation (no SOC 2, pen-test, or bug bounty referenced), no dedicated trust center, no formal incident-response commitment, and no breach-history disclosure.

Confidence
60%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The terms describe free and paid ('Unlimited Plus') tiers but the legal documents draw no distinction in data handling between them — the same privacy policy governs all users. No enterprise/DPA terms were located, so business users receive no documented data-handling upgrade over consumers.

Confidence
45%

Human Review of User Inputs

Moderate Risk

The documents do not state that staff routinely read user prompts or content, but Avail reserves broad rights to validate identity, investigate transactions for fraud, and disable accounts at its discretion, which implies access to user data. The service also inherently exposes tenant application data to landlords by design.

Confidence
45%

Regulatory & Litigation Exposure

Moderate Risk

The privacy policy discloses that Avail will comply with court orders, legal process, and government/regulatory requests, and will share taxpayer and account data with regulators and financial institutions for compliance. The terms impose mandatory individual arbitration with a class-action waiver governed by Illinois law, which limits user legal recourse. No specific current litigation is disclosed.

Confidence
65%

PII & SPI Data Inventory

High Risk

Avail collects extensive PII (name, email, phone, address, birthdate, IP, device/browser data) and substantial SPI, including Social Security/taxpayer numbers, bank account and routing numbers, income and employment history, and highly sensitive screening data such as felony convictions, bankruptcy, and eviction history. While disclosure of collection is reasonably clear, the sheer volume of financial and sensitive personal data, combined with the absence of formal privacy-law certifications, warrants a high-risk rating.

Confidence
75%

Policy–Product Currency

Moderate Risk

The Terms of Use are dated 'Last Modified: March 4, 2025' and the main Privacy Policy 'Last Modified: April 2, 2024,' both within roughly 12–24 months of the analysis date. The product surface describes conventional property-management features (screening, e-signature, rent collection) with no clearly AI-driven capability, and the policies cover the corresponding data flows and named third parties reasonably well; the rating is capped by the aging privacy policy and by an unfinished placeholder community privacy policy that references undefined dates and fields.

Confidence
55%

Cross-Document Consistency

High Risk

Multiple documents were supplied (two Terms copies, the main Privacy Policy, and a separate community Privacy Policy). A material contradiction exists on marketing/advertising use of non-identifiable data: the main policy limits disclosure to enhancing services, while the community policy states non-personal visitor information may be provided to other parties for marketing and advertising. The community policy is also an unfinished template containing an admin placeholder note and blank fields, undermining consistency and reliability.

Confidence
60%

You've read all 15 risk ratings for Avail. Create a free account to see the exact policy wording behind each rating.