Legal

Privacy Policy

Last updated: July 19, 2026

What this policy covers

This policy explains what RentRecord collects when you use the app, how long we keep it, and what choices you have about it. RentRecord is built to produce a neutral, shared inspection record between a tenant and a landlord — that design goal shapes several of the retention rules below, and we've tried to be direct about it rather than bury it in boilerplate.

What we collect

  • Account information: name, email, phone (optional), and role (tenant or landlord).
  • Inspection content: photos, room and appliance notes, condition observations, and timestamps you or the other party add while documenting a property.
  • Property information: address and unit details entered when an inspection is created.
  • Billing information: credit purchases and inspection unlocks are processed by Stripe. RentRecord stores the transaction record (amount, date, credit/unlock granted) but not your full card number.
  • Usage and error data: basic application logs and error reports (via Sentry) used to keep the app working.

How retention works — before and after a counterparty joins

This is the part of our data handling that's specific to how RentRecord works, so we're stating it plainly:

  • Before a counterparty accepts an invite to an inspection — meaning only you have contributed to that inspection group and no tenant/landlord has joined it — that inspection, including its photos and notes, is permanently deleted (not just hidden) if you delete your account from Account settings.
  • Once a counterparty accepts an invite and joins an inspection group, the inspection becomes a shared, two-party record. From that point on, the photos and notes submitted to that inspection are retained permanently and cannot be deleted by either party alone, including by deleting your account — only your own login and profile information are removed in that case. This is intentional: a record that either party could delete or edit after the other party has relied on it would no longer be neutral, and neutrality is the reason the record exists. If you believe specific content should not have been retained (for example, it was uploaded in error or does not depict the property), contact support@rentrecord.app and we will review it.
  • Deleting your account is irreversible and forfeits any unused credit balance (no refund). Before you delete, we give you a one-time bulk download of the PDFs for any inspections you've unlocked — we cannot regenerate this download afterward, so we ask you to confirm you've downloaded it before the deletion proceeds.
  • If any of your inspections is subject to a litigation hold (for example, a subpoena or legal preservation notice related to a dispute), account deletion is blocked entirely until the hold is released, so that record can't be lost while it may be needed as evidence.
  • Account-level information not tied to a shared inspection record (login credentials, contact info, billing history) is deleted along with everything else described above, subject to what we're legally required to retain (for example, transaction records for tax and payment-processor compliance, which are kept but are not personally identifying once your account is deleted).

We know "permanent once shared" is a real limit on your control over your own data, and we think you should know about it before you invite a counterparty or accept an invite — not discover it afterward.

Who can see your data

Inspection content is visible to the other participant(s) in the same inspection group, and to anyone with the permanent vault link generated once an inspection is sealed (the vault link is intentionally public and requires no login — that's what makes it usable as shareable evidence). RentRecord staff can access data as needed to provide support, investigate abuse, or comply with law. We do not sell your data.

Where your data lives

Account and inspection data is stored in Supabase (Postgres). Photos are stored in Amazon S3, which by default is provisioned in a United States region. Payments are processed by Stripe. Transactional email is sent via Resend. Error monitoring is handled by Sentry. Each of these providers processes data only as needed to provide their part of the service. All of these providers are US-based companies, so your personal information may be stored, processed, or accessed in the United States regardless of where you are located, and while there it may be subject to disclosure under US law.

Canadian users

If you are located in Canada, your personal information is also subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial private-sector privacy legislation (for example, Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25). We collect, use, and retain your personal information only as described in this policy — the same collection, retention, and deletion rules described above apply to Canadian users; we do not apply a different retention standard by location.

As described in "Where your data lives" above, using RentRecord means your personal information is transferred to and processed by service providers based in the United States. This is a cross-border disclosure of your personal information outside Canada, and while it is held by these providers it may be accessible to US authorities under US law.

If we become aware of a breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify you and, where required by law, report the breach to the Office of the Privacy Commissioner of Canada.

Questions, access requests, or complaints about how we handle your personal information can be sent to support@rentrecord.app. If you are not satisfied with our response, you have the right to complain to the Office of the Privacy Commissioner of Canada, or, if you are a Quebec resident, to the Commission d'accès à l'information du Québec.

Your choices

You can change your email at any time from Account settings, and delete your account from that same page — see the retention rules above for what deletion does and doesn't remove. You can request a copy of your data or ask about what we hold by emailing support@rentrecord.app. Depending on where you live, you may have additional statutory rights (for example, under California's CCPA/CPRA, or under PIPEDA and provincial privacy law if you are in Canada — see "Canadian users" above) to access, delete, or opt out of certain processing of your personal information — the retention limits described above for shared inspection records apply to these requests in the same way they apply to a direct deletion request.

Changes to this policy

If we make a material change to how we handle your data — especially to the retention rules above — we'll update this page and the "last updated" date, and where required, notify you directly.

Contact

Questions about this policy or a specific data request: support@rentrecord.app.