My Own RentalsProperty, beautifully managed
Documents & OrganizationPayments & AutoPayMaintenance & VendorsBuilt-in E-SignaturesQuickBooks Export
PricingAboutSupport
Sign InGet Started

Data Processing Agreement

Data protection terms grounded in how Verde operates today.

Effective Date: September 9, 2026

This Data Processing Agreement (DPA) governs Verde Homes' processing of personal data on behalf of a landlord, property manager, or other business customer. It supplements Verde's Terms and any order, subscription, or other services agreement between the customer and Verde. Verde remains a controller for its own account, billing, security, and service-usage data as described in the Privacy Notice; that independent processing is outside this DPA.

Request DPA Acceptance

Common Paper Standard Terms

This page uses the Common Paper Data Processing Agreement Standard Terms Version 1.1 as its base and incorporates those Standard Terms by reference. Common Paper makes the form available under CC BY 4.0. The Verde-specific details and modifications on this page control if they conflict with the incorporated Standard Terms.

How This DPA Is Accepted

This DPA becomes binding only when the customer and Verde sign or electronically accept a cover page or other written agreement that incorporates this page and the Common Paper Standard Terms. Publication alone does not establish that an existing customer has accepted it. Existing customers should contact support@verde-homes.com to document acceptance until a product acceptance workflow is available.

Roles and Scope

For customer-provided tenant, applicant, lease, property, payment, maintenance, vendor, utility, expense, deposit-ledger, document, and communication data, the customer is the Controller and Verde is the Processor. If the customer processes that data for another Controller, Verde acts as the customer's Subprocessor. Each party retains any separate controller responsibilities imposed by applicable law.

Documented Processing Instructions

The customer instructs Verde to process Customer Personal Data only to provide, secure, support, and maintain the rental-operations service; carry out the customer's configuration and use of the service; comply with the services agreement and this DPA; and follow additional lawful written instructions that Verde accepts. Verde will notify the customer if it cannot follow an instruction or reasonably believes it violates applicable data-protection law.

U.S. State-Law Processor Restrictions

Verde will not sell Customer Personal Data, share it for cross-context or targeted advertising, retain, use, or disclose it outside the direct business relationship or for a purpose other than the services and instructions described here, or combine it with personal data received from another customer or from Verde's own interaction with an individual except as permitted by applicable law. Verde will notify the customer if it can no longer meet these obligations. The customer may take reasonable and appropriate steps to stop and remediate unauthorized use.

Nature and Purpose

Processing includes collecting, receiving, organizing, storing, displaying, retrieving, transmitting, reconciling, securing, supporting, exporting, anonymizing, and deleting data as needed to provide account access, property and lease administration, eligible payments, maintenance workflows, documents and electronic signatures, operational reporting, transactional email, support, and security. Verde does not collect security deposits through its payment rails.

People and Data Types

Data subjects may include tenants, rental applicants, occupants, guarantors, landlords, property managers, organization users, vendors, maintenance contacts, and authorized representatives. Data may include names and contact details; account and role identifiers; property, application, household, lease, maintenance, vendor, utility, expense, and deposit-ledger records; documents and e-signature records; communications; payment status, allocations, fees, and provider references; and device, request, consent, security, and audit metadata.

Sensitive Data Boundaries

Verde does not request or store online-banking credentials, full bank account numbers, or full routing numbers; Stripe hosts collection of those details. The current rental-application flow does not ask for Social Security numbers, driver's-license or passport numbers, citizenship or immigration status, biometric identifiers, health information, or precise geolocation. Customers must not submit sensitive data unless it is necessary, lawful, disclosed, and supported by any required consent. Free-form files and notes can nevertheless contain sensitive data.

Duration and Retention

Processing continues for the term of the services agreement and afterward only for deletion, return, security, backup expiration, dispute resolution, or retention required or permitted by law. Operational customer data is deleted upon an eligible organization closure. Anonymized financial records are retained for seven years and anonymized security, audit, consent, and minimized lifecycle records for two years. Managed backups currently expire through eight daily snapshots.

Return or Deletion

At termination or on a lawful customer instruction, Verde will make available the export functionality supported by the service and then delete or anonymize Customer Personal Data, unless law requires or permits retention. Provider-managed backups expire on their lifecycle. If immediate deletion is technically impracticable, Verde will isolate the remaining data from ordinary use, continue protecting it, and delete it when practicable. Legal holds, active payments, disputes, tax or accounting duties, and fraud or security investigations may delay deletion.

Confidentiality and Security

Verde limits Customer Personal Data access to authenticated users and personnel who need it for authorized service or support functions and are subject to confidentiality duties. Verde uses organization- and role-scoped authorization, authenticated server operations, encryption in transit, provider-managed encryption at rest, private storage controls, audit records, and documented incident and account-deletion procedures. Verde does not currently claim SOC 2, ISO 27001, or an independent security audit certification.

Security Incidents and Assistance

Verde will notify the customer without undue delay and, where feasible, no later than 72 hours after confirming a Security Incident involving Customer Personal Data. Verde will provide reasonably available information, take reasonable containment and investigation steps, and assist with legally required notices and assessments, taking into account the nature of processing and information available to Verde.

Audit Rights and Current Evidence

On written request no more than once annually, Verde will provide information reasonably necessary to demonstrate compliance and answer a reasonable security questionnaire. Verde does not currently have an independent audit report to provide. If documentation is insufficient, applicable law requires more, or a material Security Incident has occurred, the parties will arrange a reasonable remote audit and, only where necessary, a scoped inspection. Audits must protect other customers, security, confidentiality, and privilege, avoid unreasonable disruption, and ordinarily be at the customer's expense.

Subprocessor Authorization and Flow-Down

The customer authorizes the subprocessors listed below. Verde will use written provider terms that restrict each subprocessor to the services it performs and impose data-protection obligations appropriate to that processing. Verde remains responsible for its DPA obligations when work is delegated. Verde will provide at least 10 business days' written notice before adding or replacing a subprocessor that processes Customer Personal Data and will work in good faith on a timely reasonable objection.

Subprocessor: Supabase

Supabase, Inc. — database, authentication, and private file-storage infrastructure. Expected processing includes customer account identifiers, rental records, documents, role and authorization data, and operational or audit records. Primary contracting location: United States; processing locations are governed by Supabase's applicable service and data-processing terms.

Subprocessor: Vercel

Vercel Inc. — application hosting, delivery, request logs, and cookieless Web Analytics. Expected processing includes application requests and transient content needed to serve them, request metadata, and anonymous page-view data. Primary contracting location: United States; processing locations are governed by Vercel's applicable service and data-processing terms.

Subprocessor: Stripe

Stripe, Inc. and its applicable affiliates — subscription billing, bank connection, eligible tenant payment processing, connected-account transfers, fraud prevention, and reconciliation. Expected processing includes payer and payee identifiers, contact and transaction data, bank details collected in Stripe-hosted flows, and payment-provider references. Processing locations are governed by Stripe's applicable service and data-processing terms.

Subprocessor: Resend

Resend, Inc. — transactional email delivery. Expected processing includes recipient names and email addresses, delivery metadata, and the content of invitations, notices, and other service messages. Primary contracting location: United States; processing locations are governed by Resend's applicable service and data-processing terms.

Known Contract and Retention Gaps

Verde has not completed a centralized inventory confirming the executed version and settings of every provider DPA or the exact provider-side retention period for all data classes. Verde relies today on the providers' published standard terms and product configurations. Verde's final contracting entity name and public mailing address also remain to be designated. Completing that contract-and-retention inventory and documenting acceptance of this DPA with each existing business customer remain operational compliance actions; this page does not represent them as already complete.

Verde-Specific Modifications

The Common Paper Standard Terms apply except that Section 5.2 is replaced by the audit-rights language on this page because Verde does not currently undergo a recurring independent security audit. References to a Security Policy mean Verde's then-current written information security program and documented technical and organizational controls. No independent certification or audit report is promised unless Verde later obtains one.

Contact and Execution

Questions, security requests, subprocessor objections, and requests to execute this DPA should be sent to support@verde-homes.com. Verde has not yet designated a public postal mailing address; that remains a documented launch-readiness gap. Email is the current operational and security contact.