This policy explains what personal data LettingOS collects, why we collect it, where it's stored, and your rights under UK GDPR. Plain English, no marketing fluff. If anything is unclear, email support@lettingos.com.
Who we are
LettingOS is a UK-based rent-tracking tool for landlords with small portfolios. The data controller is the operator of LettingOS, contact via support@lettingos.com.
What we collect
Two categories:
- Your account data — name, email, and any payment method details captured during checkout. Authentication is handled by Clerk; payment by Stripe.
- Tenant records you create — names, contact details, payment histories, notes, documents and calendar events you choose to enter. You are the controller of this data; we are the processor.
Why we use it
- To provide the service you signed up for.
- To send transactional emails (payment reminders to your tenants, calendar event reminders to you).
- To process subscription payments and invoices.
- To respond to support requests.
We do not sell your data. We do not run third-party advertising on LettingOS, and we do not share your tenants' details with anyone except the sub-processors listed below.
Where it lives
- Database — Convex, EU region. All data encrypted at rest and in transit (TLS 1.2+).
- Uploaded documents — Convex managed storage, EU region.
- Hosting — Vercel, EU edge regions for the application layer.
Sub-processors
We rely on these vetted vendors to operate the service:
- Clerk — authentication and identity (email, password hash, session tokens).
- Stripe — payment processing and subscription management. Stripe holds card details directly; we never see them.
- Resend — transactional email delivery (reminders and confirmations).
- Convex — primary database and file storage.
- Vercel — application hosting and analytics (anonymised pageviews only).
Each sub-processor is bound by a data-processing agreement and is GDPR compliant.
Retention
Account data is retained while the account is active. Once you delete your account from Settings → Danger zone, every tenant record, payment, note, document, reminder log and event is permanently erased from our database within seconds. Stripe and your chosen email provider retain their own records for tax and audit purposes per their own retention schedules (typically 6 years for UK VAT records).
Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data — most fields are editable in Settings.
- Erase your data — self-serve via Settings → Danger zone, or by emailing us.
- Port your data — email us for an export.
- Object to or restrict processing — email us to discuss.
- Lodge a complaint with the Information Commissioner's Office (ICO) if you believe we've mishandled your data.
To exercise any right, email support@lettingos.com. We respond within 30 days.
Cookies
LettingOS uses essential cookies only — session cookies for Clerk authentication, and a CSRF token. We do not use marketing cookies. We use Vercel Analytics for anonymised pageview counting; no personal data is sent to it.
Changes to this policy
If we materially change how we handle your data, we'll notify active users by email at least 30 days before the change takes effect. The current version, with effective date, always lives at this URL.
Contact
Questions, requests, complaints — support@lettingos.com.