Privacy policy

Last updated 19 July 2026

Draft, pending legal review. This describes how the software actually handles data, but it has not been reviewed by a lawyer and still contains placeholders for company details. Do not rely on it as a published policy yet.

This explains what MyRentManager collects, why we collect it, who else sees it and how long we keep it. It covers this website and the MyRentManager application.

Who is responsible for your data

MyRentManager is operated by [registered company name], [registered address], CIN [CIN].

This distinction matters for residents. Where a managing company uses MyRentManager to run a building, that company decides what resident data is collected and why — they are the data fiduciary, and we process it on their instructions. If you rent a home managed on this software and want your data corrected or erased, ask your managing company first; we act on their instruction, not independently.

For the public website — the pages you are reading now, our contact form and our own sales records — we are the data fiduciary.

What we collect

  • When you enquire about a property: your name, and the phone number or email you leave, plus your message. This goes to the managing company that published the listing.
  • When you contact us about buying MyRentManager: your name, email, phone, company and message, and which plan you were looking at.
  • When you use the application:your account details, and a record of significant actions you take — who changed a rent figure, who recorded a payment, who refunded a deposit. This audit trail is deliberate: money moves through this system and it must be possible to answer “who did that?”
  • Resident and property records entered by managing companies: tenancy details, billing history, meter readings, maintenance requests and any documents they upload.
  • Technical records attached to form submissions: your IP address and browser user-agent. We keep these only to investigate abuse of forms that are open to the whole internet.

Cookies and tracking

We do not use tracking cookies, advertising pixels or third-party analytics.When you sign in, your session is held in your browser's local storage so you stay signed in — that is a technical necessity, it is not sent to anyone, and clearing your browser data removes it.

There is no consent banner on this site because there is nothing to consent to. If that changes, this section changes first.

Who else sees your data

We do not sell data. It reaches other companies only where the service requires it:

  • Razorpay — when a resident pays online. They receive the payment details needed to process the transaction. We never see or store full card numbers.
  • Brevo — to deliver email and WhatsApp messages such as invoices, receipts and reminders. They receive the recipient address and message content.
  • Our hosting provider, [hosting provider and region], where the data is stored.
  • Law enforcement, where we are legally required to disclose something. We ask for the request in writing.

How long we keep it

  • Property enquiries: retained by the managing company that received them, under their own retention policy.
  • Sales enquiries to us: up to [retention period, e.g. 24 months] after our last contact.
  • Financial and billing records: kept as long as Indian tax and accounting law requires, which is currently eight years — we cannot delete these on request while that obligation stands.
  • Audit trail: retained for the life of the workspace, because its purpose is to reconstruct what happened.
  • Form abuse records (IP and user-agent): [retention period, e.g. 90 days].

Your rights

Under the Digital Personal Data Protection Act, 2023 you may ask what personal data we hold about you, ask us to correct it, ask us to erase it, and withdraw consent you previously gave. You can also nominate someone to exercise these rights if you are unable to.

Some requests we must refuse, and we will say so plainly rather than ignore them — for example we cannot erase a payment record the tax authorities require us to keep.

To make a request, write to our grievance officer: [grievance officer name], [email protected]. We aim to respond within [response window, e.g. 30 days]. If you are not satisfied, you may complain to the Data Protection Board of India.

Security

Each managing company's data is held in its own separate database, so one client's records are not reachable from another's. Passwords are stored hashed and never in a form we can read. Access inside a workspace is controlled by permissions, and significant actions are recorded in the audit trail.

No system is immune. If a breach affects your personal data, we will notify the Data Protection Board and the people affected, as the Act requires.

Changes

If we change this policy we will update the date at the top. Where a change materially affects how we use your data, we will tell account holders directly rather than rely on you re-reading this page.

Questions: contact us.