Privacy notice
What Rentura holds, where it lives, who can see it and for how long. Last updated 2 September 2026.
1. Who is responsible
Rentura runs Rentura. For the details you give us about yourself (your name, email address, login and billing) we are the data controller. For everything you enter about your properties and your tenants, you are the controller and we are your processor, acting only on your instructions. Questions and requests go to hello@rentura.co.uk.
2. What we hold
- Your account: name, email address, a hash of your password (never the password), when you last signed in.
- Your portfolio: property addresses, certificates and their dates, tenancies, rent amounts and payments, repairs and the notes and files you attach.
- Statements you choose to import: incoming credit dates, amounts, descriptions, references, transaction IDs, your bank account label and the rent matches or other classifications you confirm. We do not ask for bank login details.
- Your tenants, as you enter them: names, contact details and tenancy terms. We do not collect anything about tenants ourselves.
- Billing: your tier, subscription status and the dates of your billing periods. Card details are held by Stripe, never by us.
- A history of what was done in your account and by whom, including any time Rentura support entered it, so you can see it.
- Technical logs: the address and browser a request came from, kept for security and fault-finding.
A statement CSV is processed to prepare your preview; the original file and outgoing transaction rows are not saved. Saved credits are available to authorised users of your landlord account and in its export. Tenant statements contain the confirmed rent entries, without the raw bank descriptions.
3. Why, and on what basis
To provide the service you signed up for (contract); to keep the service secure, to prevent abuse and to answer support requests (our legitimate interests); to send you the emails the service needs, such as password resets, billing receipts and notices about changes to the terms (contract); and to meet legal obligations such as tax records. We do not sell data, we do not use it for advertising, and we do not send marketing email unless you ask for it.
4. Where it lives
The application and its database run on Render, in Frankfurt, Germany (the EU), under the UK adequacy regulations. Germany is covered by the UK’s adequacy regulations, so no separate transfer safeguard is needed for the storage location. Our hosting provider is a US company that processes support and operational data in the United States under the UK Addendum to the standard contractual clauses.
5. Who else processes it
- Render Services, Inc. (United States; EU region): application hosting and database.
- Stripe Payments UK Ltd and Stripe, Inc.: subscription payments. Stripe is a controller for the card data it holds.
- Cloudflare, Inc.: edge caching of the public site and storage of files you upload.
- An email delivery service, for the transactional email the service sends.
Each is bound by a data processing agreement. If we add or replace one, we will update this page and, where it affects your tenants’ data, tell account owners by email at least 10 days before.
6. Who at Rentura can see it
Every account is isolated from every other in the database itself. Rentura support staff can enter an account only with a written reason, and every entry, exit and view is recorded in your account’s own history and shown to you with a banner while it is happening.
7. How long
For as long as your account is open. When you close it, or when a free account has been unused for twelve months and we have written to you, we delete the account and its data within 30 days, and it drops out of backups within 90 days. Billing records are kept for six years after the transaction as tax law requires. Technical logs are kept for 30 days.
8. Your rights
You can ask for a copy of what we hold about you, have it corrected or deleted, object to or restrict its use, and take it elsewhere in a usable format. Most of this you can do yourself from inside the account: the account export includes saved statement credits and matches, and a tenant's records and rent entries download from the tenants screen. Bank statement descriptions may also name other people, so requests for personal data within those descriptions need the landlord's review. For the rest, email us and we will answer within one month. If a tenant asks you about their data, you are the controller; a tenant with a portal login can also take their own copy from “Your data” without asking you. You can complain to the Information Commissioner’s Office at ico.org.uk.
9. Security
- Everything travels over HTTPS. The site refuses plain HTTP.
- Passwords are hashed with scrypt. Session tokens are stored only as hashes, so a copy of the database contains no usable login.
- Every database query for landlord data is filtered by account before it reaches the database, so a coding mistake cannot show one landlord another’s rows.
- Repeated failed logins lock the account for a period, and login attempts are rate-limited.
- Card numbers never touch our servers.
- If we ever discover a breach that affects you, we will tell you and, where required, the ICO within 72 hours.
10. Cookies
Rentura sets one cookie when you sign in, to keep you signed in, and nothing else. The public site sets none. There is no tracking and no analytics cookie.
11. Changes
We will post changes here and email account owners about any change that affects their tenants’ data or their rights.