Talk to an expertProduct tour

228 Park Ave South, PMB 71905 New York, NY 10003

Product

  • Leasing
  • Maintenance
  • Vendor Management
  • Resident
  • AI Harness
  • Integrations
  • Data Platform
  • Field Operations
  • Call Center
  • Centralization
  • Revenue Management
  • Reports
  • Applicant Screening
  • AI Marketing
  • Move-in & Move-out

Solutions

  • Consulting
  • Asset Management
  • Senior Living
  • Student Housing
  • Affordable Housing
  • Hospitality

Resources

  • Articles
  • Glossary

Company

  • About
  • Contact Us

Socials

  • LinkedIn

Industry members

  • NAA
  • NMHC

© Accolade. All rights reserved.

  • Privacy Policy
  • Cookie Policy

Built in New York and Bangalore

Biometric Information Policy

1. Who we are and what this policy covers

MLE Software LLC, doing business as Accolade ("Accolade," "we," "us"), provides an operations platform that property owners and managers ("Customers") use to lease and run residential communities.
This is our public written policy on biometric identifiers and biometric information. It states what we collect, why, who handles it, how long we keep it, when and how we destroy it, and how we protect it. We publish it because laws in Illinois, Colorado, and other states require a written retention and destruction policy from any business that holds biometric information, and because we think you should be able to read it before you are asked for it.
This policy applies to:
  • •
    applicants who complete identity verification inside an Accolade application flow; and
  • •
    anyone else whose biometric information we receive through our products or services.
It applies whether we hold the information for a Customer or for ourselves. When we hold it for a Customer, the Customer decides why identity verification is required, and the Customer's own privacy notice and application terms also apply. If this policy and the Customer's notice differ on what we do with biometric information, this policy is the accurate description of our practices.
This policy does not cover other personal information. Our Privacy Policy covers information we handle for our own business, and the Customer's privacy notice covers the rest of your application.

2. What biometric information means

In this policy, "Biometric Identifier" means a retina or iris scan, a fingerprint, a voiceprint, or a scan of hand or face geometry. "Biometric Information" means information, in any form, that is based on a Biometric Identifier and is used to identify a person. We use the lower-case phrase "biometric information" for both.
A photograph, a video, a voice recording, or a written description of a person is not by itself a Biometric Identifier. A numeric representation of face geometry computed from a photograph is. Where a state defines these terms more broadly, we apply the broader definition for people in that state.

3. Where we collect it

Surface
What happens
Biometric information involved
Applicant identity verification in the Accolade application flow
The applicant photographs a government-issued ID and takes a live selfie with the device camera. [TBD: identity verification vendor] checks the ID for authenticity, compares the face in the selfie with the face on the ID, and checks that the selfie shows a live person rather than a photograph or a generated image.
A scan of face geometry computed from the selfie and from the ID photo for the comparison. [TBD: whether Accolade receives the face-geometry template, or only the match result, the images, and the data extracted from the ID]
Call recording and transcription in the call center and AI agents
Calls with residents, prospects, and vendors are recorded and transcribed for the Customer.
None. We do not create voiceprints and we do not use speaker recognition to identify callers. [CONFIRM: no vendor in the voice stack extracts a speaker model or voiceprint; checklist item B-3]
Resident, technician, and leasing-agent apps
Users attach photographs to maintenance requests, inspections, listings, and messages.
None. We do not scan these photographs for face geometry.
We do not use biometric information for marketing, for profiling, to decide whether an applicant qualifies for housing, or to train a general-purpose machine-learning model.

4. Why we use it and what we never do

We obtain and use biometric information only to:
  • •
    confirm that the person completing an application is the person shown on the government ID;
  • •
    detect and prevent identity fraud in applications; and
  • •
    comply with law, respond to lawful requests, and resolve a dispute about a verification.
We never:
  • •
    sell, lease, trade, or otherwise profit from biometric information;
  • •
    use it for any purpose other than those listed above; or
  • •
    disclose it to anyone except (a) with your consent or at your direction, (b) to the Customer and the service providers named in Section 5 to complete the verification you requested, (c) when federal, state, or local law requires the disclosure, or (d) under a valid warrant or subpoena.
The verification result, which is a pass, fail, or review flag and is not biometric information, is shown to the Customer's leasing staff. Housing decisions are made by the Customer's trained personnel, not by the verification tool and not by Accolade.

5. Who processes it

Party
Role
What it holds
[TBD: identity verification vendor]
Performs the ID check, the face comparison, and the liveness check under a written contract that limits its use of the information to that service, requires security at least as protective as our own, prohibits sale or further disclosure, and requires destruction on the timetable in Section 7.
The selfie, the ID images, the face-geometry templates created for the comparison, and the result. [TBD: link to the vendor's published biometric policy]
[TBD: hosting provider]
Stores encrypted copies of records that Accolade holds, on our instructions.
Whatever Accolade holds.
Accolade
Operates the application flow and shows the result to the Customer.
[TBD: the selfie, the ID images, and the data extracted from the ID; or only the result and an audit log].
The Customer
Receives the result and the application record to make its own leasing decision.
The result and [TBD: the images]. No face-geometry template.
We will update this table before we add any other party that handles biometric information.

6. Notice and consent before capture

We do not capture biometric information without your knowledge. Before the camera opens, the application flow shows a notice that:
  • •
    says a scan of face geometry will be created from your selfie and your ID photo;
  • •
    states the purpose in Section 4, the parties in Section 5, and the retention period in Section 7;
  • •
    links to this policy and to the Customer's privacy notice; and
  • •
    asks for your written release by electronic signature, which you give by typing your name and confirming. Capture does not start until you do.
If you do not want to provide a selfie, you can decline. The Customer will tell you what other way to verify your identity it offers. [TBD: alternative verification method offered by the Customer or by Accolade.] Declining does not by itself affect your application.

7. How long we keep it and when we destroy it

We keep biometric information only as long as the purpose in Section 4 requires, and we destroy it on the earliest of the following dates:
  • •
    when the verification is complete and the result has been recorded;
  • •
    24 months after your last interaction with Accolade or with the Customer about the application;
  • •
    45 days after our annual review of stored records finds that the record is no longer needed, which we may extend once by up to 45 days if the volume of records requires it; or
  • •
    any earlier date a state law requires.
In no case do we keep biometric information longer than three years after your last interaction with us or the Customer.
Record
Held by
Destroyed
Face-geometry templates created for the comparison
[TBD: identity verification vendor]
When the result is returned to Accolade, and in any case within [TBD: number] days of capture
Selfie and ID images
[TBD: Accolade or the vendor]
[TBD: number] days after the Customer records its application decision, subject to the outer limits above
Verification result and audit log, which contain no biometric information
Accolade
According to the Customer's record-retention policy and our contract with the Customer
Destruction is permanent. We delete the record from production systems and backups within [TBD: number] days of the destruction date and obtain written confirmation from each vendor that holds a copy. We review this timetable at least once a year and whenever we change a product, vendor, or purpose.
If a warrant, subpoena, court order, or litigation hold requires us to keep a record past its destruction date, we keep only that record, only for as long as required, and then destroy it.

8. Security and incident response

We protect biometric information using a reasonable standard of care for our industry and at least as protectively as we protect our other confidential information. Our safeguards include encryption in transit and at rest, access limited to personnel and vendors who need it to perform the verification, access logging, and written vendor commitments on security and destruction.
We maintain a written incident-response protocol for biometric information. If a security incident affects your biometric information, we will contain and assess it, tell the Customer, and give you and the relevant authorities the notice that applicable law requires. No security system is perfect, and we cannot promise that unauthorized access will never occur.

9. Your rights

You may ask us to:
  • •
    confirm whether we hold biometric information about you and tell you what it is;
  • •
    delete it ahead of the timetable in Section 7, unless a law or a legal hold requires us to keep it; or
  • •
    withdraw the consent you gave in Section 6 for future use.
Send your request to the Customer whose property you applied to, or to us at the contact in Section 10. We will verify that the request comes from you, and we will respond within 45 days. We will not discriminate against you for making a request. If we hold the information for a Customer, we will carry out the Customer's instructions on your request, and we will tell you if the Customer asks you to work with it directly.

10. Changes and contact

We will post any change to this policy on this page and update the effective date. If a change affects how long we keep biometric information or who may receive it, we will give notice in the application flow before the change applies to new verifications.
MLE Software LLC, doing business as Accolade
[228 Park Ave South, PMB 71905, New York, NY 10003]
Email: legal@accoladehq.com
Phone: [(212) 287-7916]
2026