Privacy policy
Draft — pending legal review. This document is a plain-language draft and has not yet been reviewed by a lawyer.
Who we are
Evictions API is operated by Future Cities LLC. This policy explains what personal data the website and the service handle, why, and what you can ask us to do. Last updated: [to be completed in legal review].
What we collect
Account data
When you sign up for the sandbox we store your email address, your name, the name of your organization and your password. The password is stored only as a hash, so we cannot read it back. We also store the sign-in sessions of your account. For partner attorneys we also hold the states where they are licensed and their bar numbers. API keys are stored only as hashes, so we cannot read them back. Everything an account does today is test mode, on a fictional state.
Case data
The information customers supply to run a case: the property address and owner of record, the names of the parties, including tenants, lease terms, rent ledgers and amounts owed, details of any lease violation, attestations, and uploaded documents such as deeds, management agreements and notices. Tenants do not give this data to us directly; the customer who submits the case supplies it. While everything is a sandbox, customers are asked to use made-up names and details, not a real person’s.
Forms on this website
When you ask for your state to be opened, apply as an attorney or contact us, we store your name, email address and what you write in the form, which can include your company, role, states and bar number. These forms do not ask for tenant information.
Analytics
When analytics are enabled, we use an analytics service without cookies. It counts page views and a few events, such as a click on a call-to-action button or a submitted form.
Cookies
When you sign up or log in, the website sets one cookie that keeps you signed in. It is strictly necessary for that: it holds a session token, it is not readable by scripts on the page (httpOnly), it is sent only to this website, and it expires after 30 days or when you log out. It is not used for tracking or advertising. The website sets no other cookies, and there are no tracking or advertising cookies.
How we protect data
- Case data, including tenant information, and uploaded documents are encrypted at rest.
- Data submitted through the website forms is encrypted at rest.
- Tenant personal data is not written to application logs.
- Every change to a case is recorded in an audit log that cannot be edited, and each organization can see only its own cases.
- Webhook messages sent to customers carry identifiers and status only, never names or addresses.
How we use and share data
We use case data to run the case: to check it against the state’s rules, generate documents, and send it to the partner attorney assigned to the case. Serving notices and filing in court are not available yet; any process servers, mail services or court e-filing providers we use for them will be listed here before they are used. We use form data to reply to you and to assess state requests and attorney applications. The service providers that host and process data for us are [to be completed in legal review].
We do not sell personal data, and we do not use it for advertising.
How long we keep data
[to be completed in legal review]
Your requests
You can ask us what personal data we hold about you, and ask us to correct or delete it, subject to what we must keep for a case or by law. This includes tenants whose information a customer supplied. Write to hello@evictionsapi.com. Your specific rights depend on where you live and are [to be completed in legal review].
Changes to this policy
We will post changes on this page. How we notify you of material changes is [to be completed in legal review].
Questions about your data?
Write to hello@evictionsapi.com.