Privacy Policy

Last updated 3 September 2026

This is a draft, not reviewed by a lawyer.

It describes accurately what the software does with data. Whether that satisfies the law where you and your tenants live — UK GDPR, state privacy laws in the US — is a question for a solicitor or attorney before you take on paying customers.

The short version

RentSimple holds the records a landlord needs to run a few rental properties: the properties, the people renting them, what was paid and when, repairs, costs, and any documents uploaded. Each landlord sees only their own records. Nothing is sold, and nothing is shared with advertisers.

Most of what is stored here is about your tenants, not about you. They did not sign up, and they cannot log in. That makes you responsible for what goes in, and it is the reason several of the sections below exist.

What is stored

About you — the account holder:

  • Username and email address.
  • Your password, stored only as a hash. It cannot be read back, by us or by anyone who obtains the database.
  • Optionally a phone number and company name, if you fill them in.

About your properties and tenants — everything you enter:

  • Property addresses, types, units and rent amounts.
  • Tenant names, email addresses and phone numbers.
  • Lease start and end dates, rent and deposit amounts.
  • Payments: amount, date, status, and whether a receipt or reminder was emailed.
  • Maintenance tickets, including any photo attached.
  • Expenses, including any receipt attached.
  • Documents you upload, such as signed lease agreements.

There is no analytics script, no advertising pixel, and no third-party tracker on any page. The app talks to its own API and nothing else.

Who can see it

Every record belongs to one landlord account, and every request is filtered by the account making it. Another RentSimple user cannot read your properties, tenants, payments or documents — not by guessing an address, and not by sending an identifier that belongs to you.

Uploaded files are not public. They are served through a view that checks who is asking, and are stored under randomly generated names rather than the names they were uploaded with, so a filename cannot be guessed. Requesting one without being signed in returns an error, not the file.

Emails sent to your tenants

Rent receipts and payment reminders are sent from RentSimple to the tenant email address you entered, and replies go to your address, not ours. You choose when each one is sent; the app never emails a tenant on its own.

Deletion, and the honest limit on it

Deleting a record removes it from the database. Deleting an attachment — a receipt, a ticket photo — removes the file from storage as well, not just the link to it.

Backups are the exception, and it is worth being clear about it. The database and uploaded files are copied to dated archives so that a mistake or a failure does not lose your records. Something you delete today remains inside archives already taken, until those rotate out of retention. If you need a deletion to reach the backups too, ask, and say so explicitly.

Your tenants' rights

Tenants have no account here. They cannot sign in, see what is held about them, correct it, or ask for it to be removed — because RentSimple has no relationship with them. You do.

In practice this means that under the UK GDPR you are the data controller for your tenants' information and RentSimple is a processor acting on your instructions. A tenant asking what you hold about them, or asking you to correct or erase it, is asking you. The app lets you edit or delete any record so that you can act on such a request.

How it is protected

  • Passwords are hashed, never stored in a readable form.
  • The token your browser uses to stay signed in is held in memory only, so a script on the page cannot steal it; the longer-lived one sits in a cookie JavaScript cannot read at all.
  • Sign-in attempts are rate limited, which makes working through a list of passwords impractical.
  • In production all traffic is over HTTPS.
  • Uploaded files are stored privately and served only after a permission check.

No system is beyond compromise. If something happens that affects your data, you will be told what happened and what it means, rather than finding out later.

Where it is stored

Records are held in a hosted database, and uploaded files in private object storage. The countries these sit in depend on the providers chosen at deployment. If you have tenants in the UK or the EU, that location matters legally, and it is worth confirming before you put real tenant data in.

Changes and contact

If this policy changes in a way that affects what is collected or who can see it, you will be told — not by a silently updated date at the top of a page.

Questions about any of this, or a request about your own data, go to the address on your account. See also the Terms of Service.