LEGAL

Privacy Policy

Last updated: 13 June 2026 ยท Version 1.0

This Privacy Policy explains how Renteroo Ltd collects, uses, stores, and protects your personal data when you use our platform at www.renteroo.co.uk.

We are registered in Wales, United Kingdom, and act as a Data Controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Contact us about privacy:

Email: privacy@renteroo.co.uk
Website: www.renteroo.co.uk
Registered: Renteroo Ltd, Wales, United Kingdom

1. What Data We Collect

1.1 Account and Identity Data

  • Full name, email address, and phone number
  • Date of birth (where required for identity verification)
  • Profile photograph (optional)
  • Your role: Landlord, Tenant, Tradesperson, or Property Manager

1.2 Property Data

  • Property address, postcode, type, size, and photographs
  • Rental price, deposit, and tenancy terms
  • Compliance certificates (Gas Safety, EICR, EPC)
  • Occupation contract and tenancy agreement details
  • Rent Smart Wales registration and licence numbers

1.3 Financial Data

  • Rental income and payment records
  • Expense records for tax purposes
  • Unique Taxpayer Reference (UTR) โ€” stored securely for Making Tax Digital
  • National Insurance number (NINO) โ€” stored securely for Self Assessment
  • Bank account details for property manager withdrawals
  • Deposit protection scheme references

1.4 Identity Documents

  • Passport or driving licence
  • Proof of address, payslips, bank statements
  • References from previous landlords or employers

1.5 Communications and Technical Data

  • Messages, callouts, enquiries, and applications
  • IP address, browser type, device type, session tokens, usage logs

2. How We Use Your Data

2.1 Providing the Platform

Legal basis: Performance of a contract (UK GDPR Article 6(1)(b))

  • Creating and managing your account
  • Enabling property listings and tenant applications
  • Facilitating secure messaging between platform users
  • Processing maintenance callouts and tradesperson bookings
  • Managing tenancy documents and compliance checklists

2.2 Legal and Regulatory Compliance

Legal basis: Legal obligation (UK GDPR Article 6(1)(c))

  • Complying with UK GDPR and the Data Protection Act 2018
  • Supporting compliance with the Renting Homes (Wales) Act 2016
  • Supporting Making Tax Digital (MTD) obligations
  • Responding to Subject Access Requests within one calendar month

2.3 Legitimate Interests

Legal basis: Legitimate interests (UK GDPR Article 6(1)(f))

  • Improving and developing the platform
  • Preventing fraud and ensuring platform security
  • Sending service notifications (e.g. compliance deadline reminders)
  • Anonymised analytics to understand platform usage

3. Who We Share Your Data With

We do not sell your personal data. We share data only in the following circumstances:

Other Platform Users

  • Landlords see tenant application details for their properties
  • Tenants see basic landlord contact details for properties they enquire about
  • Property managers see tenant name and address only during an active handover โ€” not full details or message history
  • Tradespeople see callout details posted publicly or sent directly by a landlord

Service Providers

  • Supabase โ€” database and authentication, EU (Ireland), subject to GDPR
  • Vercel โ€” hosting and content delivery only
  • Payment processors โ€” where payment functionality is enabled

Legal Requirements

We may disclose your data to law enforcement, regulatory authorities (HMRC, ICO), or courts where required by law.

4. How Long We Keep Your Data

  • Account data: 6 years after account closure
  • Tenancy records: 6 years after end of tenancy (Limitation Act 1980)
  • Financial records: 6 years as required by HMRC
  • Identity documents: tenancy duration plus 12 months
  • Messages and communications: 3 years
  • Technical logs: 90 days

5. Your Rights Under UK GDPR

  • Right of access โ€” request a copy of all personal data we hold (Subject Access Request). We respond within one calendar month.
  • Right to rectification โ€” request correction of inaccurate data
  • Right to erasure โ€” request deletion where there is no legitimate reason for continued processing
  • Right to restriction โ€” request we limit how we use your data
  • Right to data portability โ€” receive your data in a machine-readable format
  • Right to object โ€” object to processing based on legitimate interests

To exercise any right, contact privacy@renteroo.co.uk. No charge applies.

Right to complain: Contact the Information Commissioner's Office at ico.org.uk or call 0303 123 1113.

6. How We Protect Your Data

  • All data transmitted over encrypted HTTPS
  • Authentication via industry-standard JWT and bcrypt password hashing
  • Row Level Security at database level โ€” users access only their own data
  • Sensitive fields stored with appropriate technical safeguards
  • Database access restricted to authorised personnel only

In the event of a data breach likely to cause risk to your rights, we will notify the ICO within 72 hours and affected individuals without undue delay.

7. Cookies

  • Authentication cookies โ€” strictly necessary to keep you signed in
  • Security cookies โ€” strictly necessary to protect against cross-site request forgery

We do not currently use analytics, advertising, or tracking cookies.

8. Children's Data

Renteroo is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@renteroo.co.uk and we will delete it promptly.

9. Changes to This Policy

We may update this policy from time to time. We will notify registered users of material changes by email and by displaying a notice on the platform. The "Last updated" date always reflects the most recent version.

10. ICO Registration

Renteroo Ltd is registered with the Information Commissioner's Office (ICO) as a data controller. Our registration reference will be published here once complete. Verify our registration at ico.org.uk/ESDWebPages/Search.

Questions about your privacy?

We aim to respond to all enquiries within 5 business days and all Subject Access Requests within one calendar month.

Email privacy@renteroo.co.uk

Renteroo Ltd ยท Privacy Policy v1.0 ยท 13 June 2026