Last updated: March 2026

Privacy Policy

This policy explains how RentHack collects, uses, and protects your personal information. We are committed to keeping your data private and secure.

1. Information We Collect

We collect the following categories of information:

CategoryExamplesHow collected
Account informationEmail address, display name, organizationYou provide at signup or in your profile
Authentication dataEncrypted password hash, OAuth tokensCreated during account creation or OAuth login
Deal dataProperty addresses, financial assumptions, notes, photos, analysis resultsYou enter this data into the app
Usage dataPages visited, features used, tab navigation, errors encounteredAutomatically collected via PostHog analytics and Sentry error tracking
Payment dataSubscription status, Stripe customer IDGenerated when you subscribe; we do not store card numbers
Technical dataIP address, browser type, device type, timestampAutomatically collected with each request

2. How We Use Your Information

We do not use your data for advertising, sell your data to third parties, or share it with any party not listed in this policy.

3. Third-Party Services

We use the following third-party services to operate RentHack. Each has its own privacy policy governing their use of data.

ServicePurposeData shared
SupabaseDatabase, authentication, file storageAccount data, deal data, auth tokens — stored on Supabase's infrastructure
StripePayment processingEmail address for checkout; Stripe manages all payment card data
GoogleOAuth sign-in (optional)Email and name if you choose to sign in with Google
PostHogProduct analyticsAnonymous usage events (page views, feature interactions, no personal identifiers by default)
SentryError monitoringError stack traces and technical context; no deal data is sent to Sentry
ResendTransactional email deliveryYour email address and email content for account-related emails

4. Data Storage and Security

Your deal data is stored in Supabase, which uses row-level security (RLS) to ensure only your authenticated account can access your data. Passwords are hashed using bcrypt and are never stored or transmitted in plain text. We use HTTPS for all data transmission. Access to production databases is restricted to authorized personnel only.

No method of electronic storage or transmission is 100% secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security.

5. Data Retention

We retain your account and deal data for as long as your account is active. If you delete your account, we will delete your data from our active databases within 30 days. Residual copies in backups will be overwritten during our normal backup rotation (typically within 90 days). Payment records may be retained for up to 7 years to comply with financial recordkeeping requirements.

6. Your Rights

You have the following rights regarding your data:

To exercise these rights or if you have questions, contact us at [email protected].

7. Cookies and Tracking

We use the following cookies and local storage:

8. Children's Privacy

The Service is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date and, where appropriate, sending an email to your registered address. Your continued use of the Service after changes constitutes your acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us at: [email protected]