Privacy Policy
Last Updated: March 4, 2026
Overview
This Privacy Policy explains how Subletly ("we" or "us") collects, uses, and shares personal information when you use our website or services ("Platform"). It is designed to inform you about our data practices and to help you understand your privacy rights. By using the Platform, you agree to the collection and use of your information as described in this Policy. If you do not agree with these practices, please do not use Subletly.
Information We Collect
We only collect personal data that is necessary to provide and improve our services. This includes information you provide to us directly, information we obtain through your use of the Platform, and information from third parties (such as verification services). The types of personal information we may collect include:
- Personal Identifiers: Information that identifies you, such as your full name, email address, phone number, postal address, and date of birth. We also collect account credentials (username, password) when you register an account.
- Government IDs and Identity Verification Data: Copies of government issued identification documents (e.g. driver's license, passport, national ID card) and related details (such as the ID number, your legal name, photo, and selfie verification) to confirm your identity. For example, we may ask for an image of your official ID and a selfie as part of our verification process, and we will extract or obtain information from those documents as needed for identity verification.
- Property and Address Documentation: If you are a host or property owner, we may collect proof of property ownership or residence. This can include the property address and documents like lease agreements, property deeds or titles, utility bills, tax bills, or homeowner's insurance documents to verify you have rights to sublet or list the property. We may also ask for land registry records or other evidence of ownership as necessary.
- Business Information (for Company Hosts): If you represent a business or are a professional landlord, we may collect business-related information such as your business name, Employer Identification Number (EIN), proof of business license or real estate license, and other credentials. For instance, property managers or agents may be asked to provide their real estate license or documentation showing authorization to act on behalf of the property owner.
- Lease and Listing Data: When you create a listing, Subletly collects details about the rental period, including the intended length of stay. To promote compliance with local housing regulations, Subletly restricts listings to durations of 30 days or longer. This information is used solely to validate listing eligibility and is not shared with unrelated third parties.
- Financial and Payment Information: When you make or receive payments through Subletly, we collect information necessary to process the transaction. This may include your payment method and billing details. However, Subletly does not store full credit card numbers or bank account numbers on our servers. All credit/debit card payments are processed securely by our third-party payment processor, Stripe. We rely on Stripe to handle your card information, and we do not retain your card details after the transaction. (Any sensitive payment information you provide is transmitted directly to Stripe and is subject to Stripe's own privacy policy.)
- Communications and Messages: Content of communications through our Platform, such as messages, chats, or emails between users or with Subletly support. We collect and store these communications to facilitate interaction and for trust and safety monitoring. For example, if renters and landlords communicate via Subletly's messaging system, those messages are stored and may be reviewed for compliance with our policies. Communication metadata (timestamps, participants, etc.) may also be logged. Note: To protect user privacy, direct contact information (like email addresses or phone numbers) might be masked or proxied through our system, so users can communicate without revealing personal contact details.
- Usage Data and Device Information: Like most websites, we automatically collect certain technical information when you use our Platform. This includes your IP address, browser type, device type, operating system, referring URLs, and pages viewed. We also use cookies or similar technologies to gather data about your interactions with the site (e.g., pages visited, time spent, and navigation clicks). This information helps us secure the Platform, prevent fraud, and improve our services. We may also derive approximate location data from your IP or device (for example, to display relevant listings or for fraud detection).
- Subletly's messaging system may restrict the types of content that can be shared between users. For example, messaging between users may be limited to text communications only and may prohibit the transmission of photos, attachments, or external files, in accordance with our Terms of Service.
We may collect other information with your consent or as disclosed to you at the time of collection. Any information you choose to provide us (for example, additional profile details, descriptions, pictures, or feedback) will also be stored and treated as personal data under this Policy.
How We Use Your Information
Subletly uses the collected information to provide, maintain, and improve our services, as well as to protect our users and comply with legal obligations. Specifically, we use personal information for purposes including:
- Providing and Improving Services: We use your information to facilitate the rental and subletting process on our Platform. This includes using your personal data to create and manage your account, list properties, search for listings, and enable bookings or sublease agreements between renters and landlords. For example, your contact information and documents are used so you can communicate with other parties and complete transactions.
- Identity Verification and Trust & Safety: Information like your government ID, selfies, or property documents is used to verify identities and property ownership to increase trust and safety on the Platform. We may use third party verification services or databases to confirm the authenticity of IDs, addresses, or other details you provide. This helps prevent fraud and ensures that users are who they claim to be and have the right to list a property. Note that while we may conduct identity and background checks, we do not guarantee to catch all issues, and the absence of a warning does not mean a user has no past misconduct.
- Facilitating Communication: We use your information to enable communications between users. For instance, we use your email to send notifications or your messaging content to deliver chat messages to the intended recipient. We also may monitor or scan communications on the Platform for security, fraud prevention, and enforcement of our terms (for example, to prevent spam or harassment). Some communications, such as support calls or chats with customer service, may be recorded or retained for quality assurance and training.
- Payments and Transactions: We use financial and contact information to process payments, provide receipts, and keep transaction records. Charges for bookings or services are facilitated through Stripe, which uses your payment details to complete the transaction. We also keep records of transactions (amounts, dates, parties) for accounting, dispute resolution, and to provide transparency (for example, showing your payment history in your account).
- Sharing with Other Users: In the context of a rental or sublet transaction, we will share certain information with the involved parties. For example, if you are a tenant applicant, we may share your profile or application details with the landlord of the property you're interested in. Likewise, if you are a landlord/host, your listing details and profile info will be visible to prospective renters. We only share information that is necessary and as part of the intended use of the Platform. Personal contact information is typically mediated through the Platform (see "Communications" above) to protect privacy.
- Marketing and Service Communications: We may use your email or phone number to send you service-related announcements (e.g., booking confirmations, account alerts) or updates about new Subletly features. With your consent or as permitted by law, we might also send promotional materials or newsletters about our services or related offers. You can opt out of marketing emails at any time. (Transactional or account-critical messages will still be sent as needed.)
- Analytics and Personalization: Usage data and cookies help us understand how users navigate our Platform, which features are popular, and where improvements are needed. We analyze this data to personalize your experience (such as showing relevant property listings or recommendations) and to improve site functionality and design. We may use third party analytics tools (like Google Analytics) that employ cookies or similar technologies to assist with this, but such tools are only used in accordance with our Privacy Policy and applicable law.
- Legal Compliance and Protection: We may use your information to comply with applicable laws, regulations, legal processes, or enforceable governmental requests. For example, to satisfy know-your-customer (KYC) regulations, tax reporting obligations, or valid subpoenas. Additionally, we use and may disclose data as needed to enforce our Terms of Service, to investigate or prevent fraud and other unlawful activities, to resolve disputes, or to protect the rights, property, and safety of our users, ourselves, or others.
- Platform Safety Investigations: Subletly may review listings, user communications, booking records, identity verification data, and other relevant information when investigating reports of fraud, policy violations, disputes between users, or safety concerns.
- Haven Rescue Support: In the event a renter triggers the Haven Rescue feature due to inability to access a booked stay, Subletly may use booking data, communications, verification records, and other relevant information to investigate the situation, confirm eligibility, and facilitate either a refund or temporary lodging assistance. We may share limited information with lodging providers or partners to facilitate emergency accommodations.
- Fraud Prevention and Risk Monitoring: Subletly may analyze account activity, communications, transaction patterns, device information, and verification data to detect fraudulent activity, prevent abuse of the Platform, enforce our Terms of Service, and maintain a trusted marketplace environment.
- Automated Safety Systems: Subletly may use automated systems, algorithms, or artificial intelligence tools to identify suspicious activity, detect fraud, enforce platform policies, and support trust and safety operations. These systems may analyze patterns in listings, communications, and transactions to flag potential policy violations.
- Trust and Safety Operations: Subletly processes certain personal information to maintain a safe and reliable marketplace. This may include identity verification, monitoring of platform activity, enforcement of platform policies, and responding to reports of misconduct, fraud, or unsafe behavior.
We will not use your personal information for purposes incompatible with those above without your consent. We do not sell your personal data to third-party advertisers. If we intend to process your information for a new purpose, we will update this Privacy Policy and notify you when required.
Sharing and Disclosure of Information
Subletly understands the importance of keeping your personal information private. We share your data only in limited situations, such as to operate our services, with your consent, or when required by law. The scenarios in which we may share information include:
- With Other Users: As noted, during the normal course of using Subletly, certain information needs to be exchanged between users. If you are a renter, information you submit in a rental application or inquiry (your name, profile, message, etc.) will be shared with the landlord or sublessor you are communicating with or transacting with. If you are a landlord/host, details about your listing and your host profile (name or business name, property address, terms, etc.) will be visible to users browsing or inquiring about the listing. We do not expose your contact details directly; communications are relayed through our Platform email/messaging system to maintain privacy.
- Service Providers and Contractors: We employ trusted third party companies and individuals to help us provide the Platform's services (e.g. cloud hosting, data storage, customer support software, identity verification services). These third party service providers may have access to personal information only as needed to perform tasks on our behalf and are obligated to protect it and use it solely for the purposes we specify.
- Payment Processing (Stripe): All online payments on Subletly are handled by Stripe, a third party payment processor. When you enter credit card or payment details, that information is sent directly to Stripe; we do not store or see your full credit card numbers. Stripe processes your payment information in accordance with their own security standards and privacy policy. We share with Stripe the minimum information necessary to process payments (such as your order amount, name, and payment method). By making a payment on Subletly, you may also be agreeing to Stripe's terms and privacy policy for the processing of your payment. Similarly, if payouts to hosts are processed, bank details provided for payouts are handled through secure third party banking systems.
- Business Transfers: If Subletly is involved in a merger, acquisition, sale of assets, bankruptcy, or other business transaction, user information may be transferred to a successor or affiliate as part of that deal. We reserve the right to transfer your information to a new owner or successor entity so they can continue to provide the services. In such cases, we will ensure the receiving party is bound by confidentiality obligations and will honor the commitments of this Privacy Policy (unless you're notified otherwise and consent to any new policy).
- Legal Requirements and Protection: We may disclose your information when required by law or in response to valid legal process (e.g., subpoenas, court orders, or lawful requests by public authorities). We may also share information if we believe in good faith that such disclosure is necessary to investigate or enforce our terms and policies, to protect the rights, safety, or property of Subletly, our users, or the public, or to prevent fraud and security issues. This could include exchanging information with law enforcement or other companies for fraud prevention and credit risk reduction (to the extent permitted by law).
- Aggregated or De-Identified Data: We might share information that has been aggregated or anonymized, so it no longer identifies a specific individual. For example, we may publish trends or statistics about how many rentals occur in a certain city or average rental prices. Such information does not contain personal data and may be shared with partners, advertisers, or the public for marketing, analytics, or other purposes.
We do not sell personal information to third parties. We also do not share personal data with third party advertisers for their direct marketing purposes without your consent. If in the future we anticipate a need to share your information in ways not outlined above, we will update this Policy and, if required, seek your permission.
Data Security
Subletly is committed to protecting your personal information. We implement a variety of technical and organizational security measures to guard your data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, and secure protocols:
- Encryption & Secure Transmission: We use Secure Sockets Layer (SSL) or equivalent encryption technology to protect data transmitted between your browser/app and our servers. This means that when you provide sensitive information (such as uploading an ID or entering a password), the data is encrypted in transit to prevent eavesdropping. Our website is secured via HTTPS, indicated by the padlock in your browser address bar.
- Payment Security: For payment transactions, Subletly adheres to industry security standards. Since payments are processed by Stripe, your card data is handled in compliance with PCI-DSS (Payment Card Industry Data Security Standards). We do not store your credit card information on our systems after processing. Stripe and our systems employ security measures such as tokenization and encryption to safeguard financial data. Subletly itself maintains PCI compliance for the parts of payment processing under our control.
- Access Controls: Personal information stored in our systems is restricted to authorized personnel who need access in order to operate or improve the Platform. Our staff and contractors are bound by confidentiality obligations. We also employ measures like two-factor authentication and regular password audits internally to prevent unauthorized access to administrative tools.
- Data Storage and Protection: Your data is stored on secure servers, which may be cloud-based. We select reputable hosting providers with strong security track records. Regular backups, firewalls, and monitoring are utilized to protect data integrity and availability. Where applicable, sensitive data is additionally encrypted at rest.
- Monitoring and Testing: We regularly monitor our Platform for vulnerabilities and attacks. Security patches and updates are applied to our software and infrastructure promptly. Periodic security audits, vulnerability scans, or penetration tests may be conducted to evaluate and improve our security posture.
Despite our efforts, no security measure is 100% infallible. We thus cannot guarantee absolute security of data. However, we strive to protect your information and have incident response plans in place. In the unlikely event of a data breach that affects your personal information, we will notify you and the appropriate authorities as required by law.
Data Retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, and to comply with legal and contractual obligations. For example, we keep your account information while your account is active, and for a reasonable period thereafter in case you choose to reactivate or to resolve any post closure issues. Communications and transaction records may be retained to resolve disputes or for audit purposes. When we no longer have a legitimate need to keep your personal data, we will securely delete or anonymize it.
If you request deletion of your data (see "Your Rights" below), we will delete or anonymize your personal information, unless we are required to keep it for legal reasons or other legitimate business purposes (for example, some transaction records might need to be kept for tax/regulatory requirements even after account deletion).
Subletly will respond to verified data deletion requests within a reasonable timeframe, typically within thirty (30) days unless longer retention is required for legal, tax, or regulatory purposes.
Your Rights and Choices
You have certain rights and choices regarding your personal information. We are committed to providing you with access and control over your data in accordance with applicable laws:
- Access and Update: You can access and update some of your personal details by logging into your Subletly account and visiting your account settings or profile page. It is your responsibility to keep your information accurate and up to date. If any personal information changes (like your contact details), please update it promptly. You may also contact us to request a copy of the personal data we hold about you.
- Data Portability: In certain cases, you have the right to obtain a copy of personal data you provided to us in a machine readable format, and to request that we transfer it to another service provider where technically feasible.
- Deletion of Data: You may request that we delete the personal information we have collected about you. You can do this by contacting us (see Contact Us below) or, where available, using self service tools on the Platform. We will honor a deletion request to the extent we are not required to retain the data for reasons such as completing a transaction you initiated, for legitimate business or legal obligations, or other exceptions provided by law. When we delete data, it will be removed from our active databases, though residual copies may persist in backups for a short period.
- Withdrawal of Consent: If we are processing your personal information based on your consent, you have the right to withdraw that consent at any time. For example, you can opt out of marketing emails by clicking the unsubscribe link in the email, or adjust your notification preferences in your account. Withdrawal of consent will not affect the lawfulness of any processing we already performed prior to your withdrawal.
- Opt-Out of "Sale"/Sharing: Subletly does not sell personal information to third parties for profit. However, if you are a resident of California or a region with similar laws, you may have the right to direct us not to "sell" or share your personal information as defined by those laws. We will honor such requests. (For instance, California residents can use a "Do Not Sell My Information" option if we ever engage in practices that fall under that definition, in accordance with the California Consumer Privacy Act.)
- Opt-Out of Cookies: Most browsers allow you to remove or reject cookies. You can set your browser to refuse cookies or alert you when cookies are being used. However, note that if you disable cookies, some features of the Platform may not function properly. We provide information in our Cookies Policy (or this section of the Privacy Policy) about how to manage your cookie preferences.
- Complaint: If you have concerns about our data practices, you have the right to lodge a complaint with a supervisory authority (if applicable in your jurisdiction). We encourage you to contact us first, so we can address your concerns directly.
Special Note for Residents in Certain Regions: Depending on where you live, you may have additional privacy rights. For example, residents of the European Economic Area (EEA), UK, or other jurisdictions may have rights to object to processing or request restriction of processing of their data, or not be subject to decisions based solely on automated processing. California residents have specific rights under the CCPA/CPRA, such as the right to know what categories of information we collect and for what purposes, which this Policy addresses. We will respect the rights afforded to you by relevant privacy laws. If you have any questions about your privacy rights, please contact us.
Age Restrictions (Children's Privacy)
Subletly is intended for use by adults. You must be at least 18 years old to register an account or use our Platform. We do not knowingly solicit or collect personal information from anyone under the age of 18. The Platform and its content are not directed at children or minors. If you are under 18, please do not attempt to use Subletly or send us any personal data.
In the event we learn that we have collected personal information from an individual under 18 without verified parental consent (in a jurisdiction where such consent is required), we will take steps to delete that information as soon as possible. If you believe that we might have any information from or about a minor under 18, please contact us immediately (see Contact Us below). We also encourage parents and legal guardians to monitor their children's online activities and help enforce this policy by instructing minors never to provide personal data on the Platform.
Professional and Student Eligibility Information
Because Subletly serves individuals seeking mid-term housing for work, education, or temporary relocation, we may collect information necessary to verify a user's eligibility or intended use of the Platform.
Depending on the circumstances, this may include:
- Educational enrollment verification (such as university acceptance letters, student identification, or enrollment confirmations)
- Employment or assignment verification (such as employment letters, travel nurse contracts, hospital placement confirmations, or employer verification documents)
- Program participation documentation (for example, exchange programs, internship programs, or academic placement programs)
- Visa or residency status information where required to verify eligibility for housing or identity verification for international users
This information is collected solely for the purposes of identity verification, fraud prevention, compliance with applicable housing regulations, and maintaining trust and safety within the Subletly marketplace. Subletly does not use this information for employment decisions, immigration determinations, or unrelated background checks.
Where possible, Subletly limits collection to the minimum information necessary to confirm eligibility and may rely on trusted third-party verification services to assist with this process.
International Users and Data Transfers
Subletly is based in the United States and our services are primarily intended for users located in the United States. If you are using the Platform from outside of our primary operating country, please be aware that your personal information may be transferred to, stored, and processed in the United States or other jurisdictions where our service providers operate. These countries may have data protection laws that are different from those in your country of residence. We take steps to ensure appropriate safeguards are in place to protect your information in transit and when stored abroad, in accordance with applicable legal requirements. This may include using standard contractual data protection clauses approved by relevant regulatory authorities or other lawful transfer mechanisms. By using our services, you acknowledge the transfer of your personal data to the United States and other jurisdictions as described in this Policy.
Third Party Links and Services
Our Platform may contain links to third party websites or integrate with services not operated by Subletly (for example, identity verification services, map providers, or social media login options). This Privacy Policy does not apply to information collected by those third-party sites or services, which have their own privacy policies. We encourage you to review the privacy policies of any third party site or service you interact with. Subletly is not responsible for the privacy practices or content of such third parties.
Changes to This Privacy Policy
We may update or revise this Privacy Policy from time to time as our services evolve or as privacy laws require. If we make material changes, we will notify you by posting the updated Policy on our website and updating the "Last Updated" date at the top of the Policy, and/or by sending a notice to the contact information associated with your account. We encourage you to periodically review this Privacy Policy to stay informed about how we are protecting your information. Your continued use of Subletly after any changes to this Policy indicates your acceptance of the revised terms.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:
- Email: support@subletly.com
We will respond to your inquiries within a reasonable timeframe. Your privacy is important to us, and we welcome your feedback. Thank you for trusting Subletly with your information.