Legal

Privacy Policy

Last updated: 2 September 2026. Effective on publication.

This Privacy Policy explains what information RentalLeak (“RentalLeak”, “we”, “us”) collects when you use the RentalLeak mobile app and web app (together, the “Service”), why we collect it, and the choices you have. RentalLeak is business software sold to contracting companies; the account owner is our customer and controls the company’s data.

1. Information we collect

Account information

When you or your company create an account we collect your name, email address, company name, your role on the team (owner, manager or field), and a hashed password. Authentication is handled by our backend provider, Supabase; we do not store your password in readable form.

Rental and business data you enter

The core of the Service is the rental records you create: vendor and project names, equipment descriptions, rental rates and billing periods, purchase-order and unit numbers, start and return dates, status history, notes, and the reminders and verification requests attached to each rental. This information is provided by you and stored on your company’s behalf.

Uploaded documents, photos and PDFs

When you photograph or upload a rental agreement or a vendor invoice, we store that image or PDF file, along with the fields extracted from it and a record of which extracted values you confirmed. Photos are resized and compressed on your device before upload; we do not keep the full-resolution original. Files are held in private storage and are only reachable through short-lived signed links issued to signed-in members of your company.

Payment information

Subscription billing is processed by Stripe. RentalLeak never receives or stores your full card number, expiry date or security code. We store only non-sensitive references that Stripe returns to us: a customer identifier, a subscription identifier, the plan/price identifier, the current billing-period end date, and — for display only — your card brand and its last four digits.

Device and technical information

To operate the Service we process standard technical data such as your IP address and app or browser version when your device communicates with our servers, and, on mobile, an operating-system push/notification token used to deliver rollover reminders. We do not use advertising identifiers.

Error and diagnostic reports

Crash and error reporting is off by default. If we enable it for a release, diagnostic reports are sent to Sentry and are automatically scrubbed before they leave your device to remove access tokens, card-like numbers, email addresses and the contents of uploaded documents. We do not use product analytics, session recording or behavioural tracking.

2. How we use information

  • Provide the Service: store your rentals, calculate rollover dates and the next charge, and send reminders.
  • Read your uploaded agreements and invoices using an AI document-extraction provider (see “AI and OCR processing” below) so fields can be pre-filled for your review.
  • Authenticate users, enforce team roles and keep each company’s data separate from every other company’s.
  • Process subscription payments and manage trials, upgrades and downgrades through Stripe.
  • Send transactional messages such as email confirmation, password reset, team invitations and, on mobile, rollover reminders.
  • Provide support, diagnose problems, prevent abuse and meet legal obligations.

We do not sell your data, and we do not use your rental records or uploaded documents to train third-party AI models.

3. AI and OCR processing

When you scan or upload an agreement or invoice, the file is sent from our server to a third-party AI provider (currently Anthropic) to extract structured fields. The AI provider processes the document to return that result and does not use it to train its models. The extracted result is cached on our side for a short period (about 24 hours) so that re-opening the same document does not trigger a second call. The document’s contents are never written to our application logs. The extracted values are only ever suggestions: your confirmed entries, not the AI output, are the rental’s data.

4. How information is shared

We share information only with service providers that help us run the Service, each under a contract that limits them to that purpose:

  • Supabase — database, authentication and file storage.
  • Stripe — subscription billing and payment processing.
  • Anthropic — AI extraction of fields from uploaded agreements and invoices.
  • A transactional email provider — sending invitations, confirmations and password-reset messages.
  • Sentry — crash and error diagnostics, only if enabled for a release.
  • Our hosting and CDN providers — serving the website and app.

We may also disclose information if required by law, to enforce our agreements, or in connection with a merger or acquisition, in which case we will provide notice as required.

Within your company, rental data, documents and history are visible to other signed-in members according to their role. The account owner and managers can add or deactivate members.

5. Data location and international transfer

Our providers may process and store data in the United States and other countries. Where required, transfers rely on appropriate safeguards such as standard contractual clauses. [Legal review: confirm processing regions and transfer mechanism before public launch.]

6. Retention and deletion

We keep your company’s account and rental data for as long as the account is active. Uploaded files and their extracted fields are retained with the rental they belong to. Short-term caches used for AI extraction expire automatically (about 24 hours).

Account deletion is request-based. An owner can request deletion from within the app; the request starts a 30-day grace period during which it can be cancelled, after which the company’s data is purged from our production systems. Backups are rotated on their own schedule and then expire. Some records may be retained where we are legally required to keep them (for example, billing records).

7. Your rights and choices

  • Access and correction — you can view and edit most of your data directly in the app. Contact us for anything you cannot change yourself.
  • Deletion — request account deletion in the app, or email us.
  • Notifications — you can turn rollover reminders off in your device settings or in the app.
  • Marketing — we only send transactional email for the Service; there is no marketing email programme at this time.

Depending on where you live, you may have additional rights under laws such as the GDPR or the CCPA/CPRA, including the right to a copy of your data or to lodge a complaint with a regulator. Because RentalLeak is sold to companies, we will generally route individual requests through your company’s account owner. [Legal review: confirm the controller/processor split and the specific state/region disclosures required before public launch.]

8. Security

Access to company data is restricted at the database level so that a signed-in user only reaches their own company’s rows. Payment card data never touches our servers. Uploaded files are private and served only through expiring signed links. No method of transmission or storage is perfectly secure, but we work to protect your information and to limit what we collect in the first place.

9. Children

The Service is for business use by adults and is not directed to anyone under 18. We do not knowingly collect information from children.

10. Changes to this policy

We may update this policy as the Service evolves. If we make a material change we will update the date above and, where appropriate, notify account owners.

11. Contact

Questions or privacy requests: [email protected].

This document describes RentalLeak’s current data practices in plain terms. It has not yet been reviewed by an attorney and is not legal advice. A legal review is recommended before a paid public launch.