Privacy Policy

Last updated: 9 September 2026

1. Who We Are

RentFig is operated by RentFig Ltd, a company registered in England and Wales under company number 17437632, whose registered office is at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. In this policy "RentFig", "we", "us" and "our" mean RentFig Ltd. We are a property management platform designed for landlords in England, and we are the data controller for the personal data we collect through our service at rentfig.co.uk. We are registered with the Information Commissioner's Office under registration number ZC240896.

Before 4 September 2026 the RentFig service was run by its founder as a sole trader. RentFig Ltd took over the service, and responsibility as data controller for all personal data already held, on that date. Nothing about how your data is used has changed as a result.

2. What Data We Collect

We collect and process the following categories of personal data:

Account Data

  • Full name, email address, and phone number
  • Organisation name and billing address
  • Password (stored as a secure hash — we never store plaintext passwords)

Property & Tenancy Data

  • Property addresses, EPC ratings, and compliance certificates
  • Tenant names, contact details, and tenancy agreement information
  • Rent amounts, payment records, and deposit details
  • Documents you upload (tenancy agreements, certificates, invoices)

Financial Data

  • Bank transaction data imported via bank feed sync or CSV upload
  • Invoice and payment records
  • Subscription and billing information (processed by Stripe)
  • One-off tenant referencing check payments (processed by Stripe)

Usage Data

  • Log data (IP address, browser type, pages visited)
  • Activity logs within the application

Free Tenant Application & Referencing Tool

We offer a public tool that lets a landlord or agent (who may not hold a RentFig account) request a free tenant application link, and optionally purchase a credit check or full tenant reference.

If you are a landlord using the tool

  • We collect your email address to deliver your application link and any results. This is necessary to provide the service you requested (it is not conditional on marketing consent).
  • We only send you marketing if you give separate, optional consent, which you can withdraw at any time.

If you are an applicant completing the form

  • Your details are processed to provide your application to the landlord and, where a check is requested and you consent, to carry out referencing.
  • Credit checks and referencing are performed by our referencing partner, Vorensys, who contacts you directly to securely collect and obtain your consent for the information needed.

Depending on the step, RentFig acts as a data controller (for the email and account data we hold) and as a processor or joint controller for applicant data routed through the tool. Card payments for checks are processed by Stripe. The landlord who requested the check is the controller responsible for using its results lawfully and fairly.

Refer-a-landlord scheme

RentFig members can share a referral link. If you order a full tenant reference through someone's link, we record your email address, the order it relates to and the outcome of that reference against their referral, so we can apply your discount, issue their reward once your reference completes, and detect misuse of the scheme (for example, a person referring themselves). To do that we also keep an anonymised card fingerprint supplied by Stripe — never your card number. The referrer is only ever shown a count of successful referrals, never your name or email. This processing is necessary to perform the contract with you and for our legitimate interest in running the scheme fairly. Referral records are kept for as long as the reward they relate to could be used or disputed, and no longer than the related order record.

If you create a RentFig account through someone's referral link, we record that link on your organisation's account and, if you go on to pay for a RentFig subscription, keep a record of which of your invoices earned the referrer credit (never the invoice amount beyond what's already on your own billing history, and never your card details — only the same anonymised Stripe card fingerprint described above, used solely to detect a referrer misusing their own link). The referrer sees only how many of the people they referred are currently paying subscribers and the total credit earned, never your name, email or payment details. This processing is necessary for our legitimate interest in running the scheme fairly and is kept for as long as your subscription, and any related credit, could be queried or disputed.

3. How We Use Your Data

We use your personal data to:

  • Provide and maintain the RentFig service
  • Process rent payments and generate financial statements
  • Track compliance certificates and send expiry reminders
  • Send service notifications (e.g. payment confirmations, renewal alerts)
  • Improve our platform and develop new features
  • Comply with legal and regulatory obligations

4. Legal Basis for Processing

We process your data under the following legal bases (UK GDPR):

  • Contract: Processing necessary to provide the service you have subscribed to
  • Legal obligation: Retention of financial records as required by HMRC and UK tax law
  • Legitimate interest: Improving our service, preventing fraud, and ensuring platform security
  • Consent: Where you opt in to marketing communications

5. Data Retention

We retain your data for as long as your account is active, plus a mandatory retention period of 6 years after account closure or tenancy end. This retention period is required to comply with UK tax and financial record-keeping obligations.

After the 6-year retention period, your data is automatically archived and then permanently deleted. You may request early deletion of non-financial data at any time, but we are legally required to retain financial records for the full 6-year period.

6. Tenant Data

RentFig operates a one-directional communication model for tenants. Tenants receive messages, invoices, and PDF statements from landlords but do not have accounts on RentFig and cannot log in or interact with the platform directly.

Landlords are responsible for informing their tenants that their data is stored in RentFig and providing them with a copy of this privacy policy upon request.

7. Data Sharing

We share your data with the service providers below, each of which processes it only on our instructions and only for the purpose shown. We do not sell your personal data and we do not share it with advertisers.

  • Supabase: Database hosting and authentication (EU/UK data centres)
  • Vercel: Application hosting and serverless functions (EU/UK edge network)
  • Resend: Transactional and broadcast email delivery (EU)
  • Twilio: SMS, voice calls and voicemail recording, and WhatsApp message delivery (UK/EU data centres). Inbound voicemails are recorded by Twilio and then transcribed and summarised as described in Section 7a below.
  • Stripe: Subscription billing (card / Bacs Direct Debit) and one-off card payment processing for pay-per-check tenant referencing (EU)
  • Vorensys: Our tenant referencing provider (UK). Where a reference or credit check is requested, Vorensys carries out the credit check, affordability assessment, anti-money-laundering and sanctions screening, identity verification and Right to Rent check, and produces the reference report. Vorensys contacts the applicant directly to obtain their consent and collect the information required, and may contact their employer, current landlord or accountant.
  • Meta Platforms (WhatsApp Business API): Delivery and receipt of WhatsApp messages between you, your tenants and the RentFig assistant (EU/US). Message content is necessarily visible to WhatsApp in order to deliver it.
  • Anthropic (Claude AI): The AI assistant, WhatsApp assistant, document and receipt scanning, email classification and written summaries (USA, under Standard Contractual Clauses). See Section 7a below.
  • Groq: Speech-to-text transcription of voicemails and of voice notes sent to the WhatsApp assistant (USA, under Standard Contractual Clauses).
  • Sentry: Application error monitoring (EU). Error reports can include the page you were on and your account and organisation identifiers.
  • PostHog: Product analytics — how the Service is used, so we can improve it (EU).
  • Backblaze: Encrypted off-site storage of our scheduled database backups (EU).
  • Upstash: Rate limiting and abuse prevention (EU). Stores request counts keyed to an identifier such as your IP address or account.
  • HM Revenue & Customs (HMRC): If you connect your HMRC account and submit a Making Tax Digital quarterly update, the figures and the fraud-prevention data described in Section 8 are sent directly to HMRC's Making Tax Digital APIs. HMRC is a separate data controller for what it receives.
  • Hetzner Online GmbH (Germany/Finland): Hosts the server that relays your Making Tax Digital submission request to RentFig. It handles the request in transit and keeps a 30-day technical log (your connection address and port, browser user-agent and request metadata) — never your figures, sign-in token or HMRC credentials. See Section 8.

7a. AI Processing

RentFig uses third-party AI services for several features. In each case the data is sent to the provider only when the feature runs, and is not used to train their models.

The AI assistant and WhatsApp assistant. When you ask RentFig a question in AI Mode or over WhatsApp, your question and the portfolio records needed to answer it are sent to Anthropic (Claude AI) — based in the USA. Depending on what you ask, that can include property and tenancy details, tenant and contact names and contact details, payments and arrears, documents and compliance records. The assistant proposes actions but does not carry them out until you confirm them.

Documents, receipts and inbound email. Where you scan a receipt or certificate, forward a document by email, or let RentFig classify an inbound message, the contents of that document or message are sent to Anthropic to extract the details and suggest where to file it. You review what was extracted before it is saved.

Voicemails and voice notes. When a tenant leaves a voicemail on your RentFig number, or sends a voice note to the WhatsApp assistant, the audio is sent to Groq — based in the USA — for speech-to-text transcription. (If that is unavailable, Twilio's own transcription is used as a fallback for voicemails.) The resulting transcript is then sent to Anthropic, which generates a one-sentence summary, an urgency rating (emergency, high, medium, or low), and a category (maintenance, payment, complaint, or general) to help you triage messages quickly.

This is automated processing of personal data. It is advisory only: every AI output is a draft or a suggestion shown to you for review, and no decision producing legal or similarly significant effects for a tenant is taken by the AI alone. You retain full visibility of the underlying record — the original recording, transcript, document or message — alongside anything the AI generated from it.

Data transferred to Anthropic and to Groq in the USA is transferred under Standard Contractual Clauses. Neither provider uses the data to train its models. Anthropic deletes inputs and outputs within 30 days, except where content is flagged by its automated safety systems or retention is required by law. The full list of sub-processors used by RentFig is set out in our Data Processing Agreement.

7b. Public Property Adverts and Viewing Requests

If you choose to advertise a property publicly via our To Let portal (rentfig.co.uk/tolet), you control what is published: photographs, an asking rent, description and other listing details you enter. To protect the safety and privacy of prospective tenants and of your property, we do not publish the exact house or flat number on a public advert page — only the street, town/city and postcode are shown. Your full address remains private within your account.

When someone submits a viewing request through a public advert, we collect their name, email address, phone number (if given), and any message or preferred viewing times they enter. This is used only to notify you of the request — by email and in your dashboard — so that you can respond to it; it is not used for marketing. When you reply to a request through the Service, your email address is set as the "reply to" address so the enquirer can respond to you directly.

We do not publish your name, phone number or email address on public advert pages. All contact from prospective tenants happens through the viewing-request form.

Map and nearby places: where a public advert shows a map or a list of nearby amenities, we send the property's postcode — not its full address — to postcodes.io (a free UK postcode lookup service) to obtain approximate coordinates, and query OpenStreetMap for points of interest near those coordinates. Neither service ever receives an exact address.

7c. AI-Generated Advert Descriptions

Business-plan customers can request an AI-generated draft description for a public advert. Where you use this feature, that listing's details (bedrooms, rent, property type and similar) and any photos you have uploaded for it are sent to Anthropic (Claude AI) — based in the USA — to generate a suggested description. As with the voicemail processing described in Section 7a, this transfer is made under Standard Contractual Clauses. Anthropic is contractually prohibited from training its models on this data, and deletes inputs and outputs within 30 days, except where content is flagged by its automated safety systems or retention is required by law.

The generated text is a draft only: it is shown to you for review and is never published until you choose to save it. You remain responsible for checking that the final description is accurate and does not misrepresent the property.

8. Connecting to HMRC (Making Tax Digital)

RentFig can submit Making Tax Digital for Income Tax (MTD ITSA) quarterly updates for your UK property business directly to HMRC. This is optional and only happens if you connect your HMRC account and then choose to submit a period. Nothing is sent to HMRC automatically.

Connecting. You sign in on HMRC's own website and authorise RentFig. We never see your Government Gateway password. HMRC gives us access tokens for your account, which we store encrypted together with the National Insurance number you provide. You can disconnect at any time from the MTD page, which deletes those tokens.

What we send to HMRC when you submit. Your National Insurance number and HMRC business identifier, and the year-to-date income and expense totals for the property business calculated from your reconciled bank transactions and bills. We also read back what HMRC holds so we can confirm the submission and keep a record of it in your account.

Fraud-prevention data (required by law). HMRC requires all software that connects to its Making Tax Digital APIs to send "fraud prevention headers" with every request. When you submit, RentFig therefore also sends HMRC: a random identifier stored in your browser to recognise the device, your public internet (IP) address and the connection port, when that address was recorded, your time zone, screen and browser window size, your browser's user-agent string, the email address you sign in to RentFig with and your RentFig account identifier, the time and type of the two-factor check you completed together with a scrambled (hashed) reference to your authenticator — never the code or secret — the addresses of the RentFig servers that handled the request, and the versions of the RentFig software involved and of the relay server software (Caddy). HMRC explains how it uses this data at developer.service.hmrc.gov.uk/guides/fraud-prevention.

Two-factor authentication. A direct submission requires a fresh authenticator-app code every time, so a submission can only ever be made by you.

Servers involved. Your submission request travels from your browser to a RentFig relay server hosted by Hetzner (Germany/Finland), which records the connection details HMRC requires and passes the request to the RentFig application hosted by Vercel (London region). The relay keeps a 30-day technical log of the connection (your address and port, browser user-agent and request metadata); it never stores your figures, sign-in token or HMRC credentials. Your figures, tokens and submission records are held in RentFig's database (Supabase) as described in Section 7.

Retention. Your HMRC access tokens are kept until you disconnect. The record of each submission (what was sent, when, and HMRC's response) forms part of your accounting records and is retained with them. Questions: support@rentfig.co.uk.

9. Your Rights

Under UK GDPR, you have the right to:

  • Access: Request a copy of your personal data (available via Settings > Data Export)
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your data (subject to the 6-year financial retention requirement)
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interest
  • Withdrawal of consent: Withdraw consent for marketing at any time

To exercise any of these rights, use the Data Export feature in your account settings or contact us at legal@rentfig.co.uk.

10. Cookies

We use essential cookies required for authentication and session management. We do not use advertising or tracking cookies. Analytics cookies (if enabled) are anonymised and do not track individual users.

11. Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), encryption at rest, row-level security policies, and regular security reviews.

12. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes via email or an in-app notification. The "last updated" date at the top of this page indicates when this policy was last revised.

13. Contact

If you have questions about this privacy policy or our data practices, contact us at:

Email: legal@rentfig.co.uk

Post: RentFig Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ