Legal
Privacy policy
Last updated: 17 May 2026 · Applies to tenantright.uk
1. Who we are
RenterRight UK ("we", "us", "our") operates tenantright.uk — a platform providing free compliance tools for UK tenants and a paid compliance dashboard for landlords. We are the data controller for all personal data collected through this website.
Contact: hello@tenantright.uk
ICO registration: Application pending. Reference number will be published here once confirmed.
2. Data we collect
- Account data: name and email address when you create an account.
- Repair log data: issue descriptions, property addresses, dates, and severity you enter into the repair log. This data is stored on our servers and attributed to your account.
- Property & compliance data: addresses, compliance item statuses, and due dates entered by landlords.
- Payment data: handled entirely by Stripe — we never see or store your card number, CVV, or full card details. We receive only a Stripe customer ID and subscription status.
- Session data: a signed session cookie (
tenant_rights_session) to keep you signed in. It contains only your session ID, not personal data. - Password reset tokens: time-limited, single-use tokens stored in our database and deleted after use or expiry.
- Usage data: if Google Analytics is added in future, this policy will be updated and a consent banner will appear before any tracking begins.
3. Lawful basis for processing
4. Processors and sub-processors
We share data with the following third-party processors only to the extent necessary to deliver the service. All are bound by data processing agreements and are GDPR-compliant.
We do not sell your data. We do not share it with any third party for marketing or advertising purposes.
5. Data retention
- Account and repair log data: retained for as long as your account is active.
- Password reset tokens: deleted immediately after use, or after 1 hour if unused.
- Session cookies: expire after 30 days of inactivity or on sign-out.
- Compliance data (landlords): retained for the life of the account. You can delete individual items from the dashboard.
- On account deletion: your personal data is permanently deleted within 30 days of your request. Email hello@tenantright.uk to request deletion.
- Anonymised aggregated statistics (e.g. total repair logs logged) may be retained indefinitely as no individual is identifiable.
6. Your rights under UK GDPR
As a UK data subject you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data (subject to legal obligations).
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests, including direct marketing (we do none).
- Withdraw consent — where processing is based on consent (e.g. analytics cookies), withdraw it at any time without affecting prior processing.
To exercise any right, email hello@tenantright.uk. We will respond within one calendar month as required by UK GDPR. If you are dissatisfied with our response, you can complain to the ICO at ico.org.uk/make-a-complaint.
7. Cookies
You can manage cookies in your browser settings. Blocking the session cookie will prevent sign-in but will not affect anonymous tool use (rent checker, rights guide). Analytics cookies are only placed after explicit consent via our cookie banner.
8. Security
Passwords are hashed using scrypt with a random salt — we never store plaintext passwords. Session tokens are signed with HMAC-SHA256. All data is served over HTTPS. Our database is hosted on DigitalOcean's London region and is not publicly accessible. Payment processing is handled entirely by Stripe — we never see card numbers or CVV codes.
9. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email to registered users and by updating the "Last updated" date at the top of this page. Continued use of the service after the effective date constitutes acceptance of the revised policy.
10. Contact
For any privacy-related queries, data subject requests, or to report a concern:
hello@tenantright.uk