Privacy Policy
Last updated: September 23, 2026
⚠️ Legal disclaimer: This is a plain-English privacy policy written by the operator of RentReel (RentReel LLC (a Wyoming limited liability company, wholly-owned subsidiary of Joy Family Holdings LLC)). It describes our actual current practices honestly. It is not a substitute for legal review by an attorney. If you operate RentReel commercially in a regulated jurisdiction, have your attorney review and customize before reliance.
1. What we collect
RentReel collects only the data you give us, in service of the product:
- Account info: your email address and a password hash (we never store your password in plaintext)
- Your financial data: the transactions, property setup, and settings you enter or import via CSV
- Browser metadata: standard request data (IP, user agent, timestamp) for security logging via our hosting provider (Cloudflare) and database provider (Supabase)
- Estimate emails (optional, homepage): if you type your email into the tax-savings estimator and click “Email me my estimate”, we receive that email address, the figures on screen (purchase price, tax bracket, estimated deduction and tax offset), the page it was sent from, and how you reached us (UTM campaign tags or the referring website’s name). Nothing is sent unless you click the button.
We do not collect: your bank credentials, or your CSVs as files (only the parsed transaction rows).
Marketing analytics on rentreel.co: Our public marketing pages (rentreel.co and its sub-pages, including this privacy policy) load the Meta Pixel only after you click Accept on the consent banner. If you decline, no Meta code loads and no data is shared with Meta. We do not currently use Google Analytics. The app itself (app.rentreel.co) does not load any advertising or behavioral-analytics tools once you sign in; only Cloudflare's privacy-preserving Web Analytics runs there. See §4 for the full sub-processor list.
First-party page measurement: Separate from the consent-gated Meta Pixel, our marketing pages send a small first-party measurement event (page viewed, referrer, timestamp) to our own database so we can count visits and see which pages people read. This is our own infrastructure. No advertising network or third party receives it, it is not joined to your app account or financial data, and it contains no cookies or cross-site identifiers. We treat it as essential site telemetry, similar to a server log. This measurement runs on our own self-hosted analytics (Umami) on our own infrastructure: cookieless, no cross-site tracking, never shared.
First-party session replay: On our public marketing pages we also record a first-party session replay: a re-render of how the page was used (mouse movement, clicks, and scrolling) so we can see where visitors get stuck and improve the page. Form fields are masked in your browser before anything is sent, and so are the figures the deduction estimator calculates, so we never capture what you type or the numbers derived from it. The recording is stored only in our own database (Supabase), contains no cookies or cross-site identifiers, is never shared with any third party and is not joined to your app account or financial data. It honors your browser’s Do Not Track setting, stops if you choose “Essential only” on the consent banner, and runs only on our marketing pages, never inside the app at app.rentreel.co.
2. Where your data lives
Your transaction and account data is stored in Supabase (Postgres) hosted on AWS US-West (Oregon). Your account is protected by Row-Level Security (RLS) at the database level. Other RentReel users cannot read or modify your data, regardless of any client-side bug.
Your CSVs are parsed in your browser. Only the resulting transaction records leave your device. The original CSV file never does.
3. How we use your data
- To make the product work (display your books, sync across your devices)
- To send transactional email (password resets, account confirmations)
- To send the estimate you asked for from the homepage estimator, and to follow up with you about it
- To investigate security incidents and respond to subpoenas if legally required
We do not use your data for: advertising, training AI models, sharing with affiliates, or selling to third parties, ever.
4. Third parties (sub-processors)
We use the following service providers, each of which receives only the data necessary to fulfill its role:
- Supabase Inc. (database + auth) stores your encrypted account and data. AWS US-West (Oregon). SOC 2 Type 2 audited.
- Cloudflare, Inc. (hosting, CDN, Workers, edge compute) serves the app and logs request metadata (IP, user-agent, timing). SOC 2 Type 2 audited.
- Stripe Inc. (billing for all paid tiers) processes payment and stores card data on PCI-compliant infrastructure. We never see full card numbers.
- Steadily (insurance quotes, only when you request one). If you click “Get a quote” on a property and tick the consent box in that form, RentReel sends that property’s street address, city, state and ZIP, plus any property details you have filled in (year built, square footage, replacement value, bedrooms, bathrooms) and your role, through a RentReel Cloudflare Worker to Steadily so it can return a premium estimate. Nothing is sent unless you tick that box and submit the form, and no transaction, booking or financial data is included. RentReel is not a licensed insurance agent, broker, or producer (see §7).
- Anthropic PBC (on-demand, only when you invoke an AI feature, and only after you have enabled AI features via the in-app consent prompt or the Settings → AI Features toggle). RentReel sends data to Anthropic's Claude API in seven places, each one triggered by an action you take:
- Property document auto-extract: the mortgage / insurance / property-tax document you upload, sent to read fields such as interest, servicer and address.
- Receipt photo scan: the receipt image you choose to scan, sent to read the vendor, date and amount on it.
- AI auto-categorization: for the uncategorized transactions you choose to run, the payee, description, amount and date of those transactions, plus your property names and LLC names as context. Transactions you do not run through this feature are not sent.
- AI PDF statement import: the contents of the bank or credit-card statement PDF you upload, so the transactions can be read out of it.
- AI PDF mileage import: the contents of the mileage report PDF you upload.
- AI property insight: when you request an AI read on a property, that property's performance metrics (revenue, expense and occupancy figures and portfolio comparison medians) are sent to generate the analysis. Individual transactions are not sent.
- Support reply drafting (our side): when we use an AI assistant to draft a reply to a support message you sent us, the text of that support conversation is processed. This is a tool we use to answer you faster; drafts are reviewed by a human before sending.
Per Anthropic's commercial terms, submitted data is not used to train models and is retained only long enough to process the request. Nothing is sent to Anthropic for any purpose other than the specific request that triggered it, your full dataset is never sent, and you can turn AI features off at any time in Settings → AI Features (they stay off until you turn them back on).
- Meta Platforms, Inc. (public marketing pages only) loads the Meta Pixel on rentreel.co and its sub-pages so we can measure ad performance. Meta receives standard web-analytics events (page URL, referrer, timestamp, hashed IP/user-agent), never your transaction data. The Pixel does NOT load inside the app at app.rentreel.co.
- Google LLC (fonts): our pages load the Outfit and JetBrains Mono typefaces from Google Fonts, which means your browser sends its IP address to Google's font servers when a page loads. No analytics data is shared with Google; we do not use Google Analytics.
- Script & library CDNs: the app loads open-source libraries (Chart.js via cdnjs/Cloudflare, SheetJS via sheetjs.com, supabase-js via jsDelivr). These CDNs see your IP address as part of serving the file, like any web host. No account or financial data is sent to them.
- YouTube (privacy-enhanced mode): where a demo video is embedded we use youtube-nocookie.com, YouTube's reduced-tracking embed.
Outside the AI features listed above, we do not transmit your transaction data (bank exports, PMS reservations, cleaning logs, mileage) to any third party for any purpose other than storage / serving. Where an AI feature is involved, only the specific document you uploaded, or the specific transactions you chose to categorize, are sent, never your full dataset, and never on a schedule or in the background.
5. Your rights
- Access: view all your data inside the app at any time
- Portability: Settings → Export JSON Backup gives you your entire data in a portable file
- Deletion: Settings → Account → Wipe My Data deletes all your data. Account → Delete Account is a full GDPR/CCPA hard-delete: it removes your workspace, personal workspace, and authentication record from our database in a single atomic transaction, with no manual intervention required
- Correction: edit any transaction, category, or setting directly in the app
- Objection / restriction: contact us to restrict processing in specific ways
- CCPA, "Do Not Sell or Share My Personal Information": RentReel does not sell your personal information and does not share it for cross-context behavioral advertising. If you are a California resident and want to formally submit a Do-Not-Sell/Share request under the CCPA, email legal@rentreel.co with the subject "CCPA Do Not Sell/Share," and we'll process within 15 business days.
- GDPR (EU/UK residents): our lawful basis for processing is (a) contract performance: we need your data to deliver the bookkeeping service you signed up for; and (b) legitimate interest: for security logging, fraud prevention, and product analytics on public marketing pages. Where consent is required (e.g., non-essential cookies on our marketing site, see §4), we obtain it through the consent banner. You can withdraw consent, request a copy of your data, request erasure, or lodge a complaint with your local data-protection authority at any time.
Data retention windows
- Workspace data (transactions, properties, uploads): retained while your account is active. Deleted from active systems within 30 days of account deletion; purged from encrypted backups within 90 days.
- Authentication records (email, hashed password): purged on account deletion via the atomic hard-delete RPC. No lingering auth rows.
- Data sent to Anthropic for AI features (property documents, bank/card statement PDFs, mileage PDFs, and the transaction fields used for auto-categorization): the submitted contents are processed under Anthropic's commercial API terms: they are not used to train models, and Anthropic keeps them only for the limited period those terms allow before deleting them. The extracted fields and assigned categories remain in your workspace under your control.
- Billing records (Stripe): retained 7 years per US tax and financial-records requirements, even after account deletion, in Stripe's PCI-compliant environment.
- Security logs (Cloudflare request logs): retained 30 days for abuse investigation, then purged.
- Support correspondence: retained 2 years, then purged unless legally required.
6. Children
RentReel is a business product for adults. We do not knowingly collect data from anyone under 18.
7. Affiliate & referral disclosures
Some links on our marketing site (rentreel.co) and inside the app go to third-party services: currently insurance (Steadily) and any property-management software you choose to connect. Where a company has a marketing-referral relationship with us, we mark that link as a partner link and disclose the relationship on the same page (e.g., our /integrations page). You never pay more because you clicked our link, and the marketing-referral relationship does not change our review or recommendation of the product. RentReel is not a licensed insurance agent, broker, or producer. We do not sell insurance and do not receive commissions on any insurance policy. If you'd prefer to reach a partner directly, you can always type their URL yourself. None of RentReel's core bookkeeping features are gated behind partner signups.
Insurance-partner referrals in particular are limited to real-estate investors and property owners; RentReel does not refer tenants or owner-occupied primary residences to Steadily or any insurance partner.
8. Changes to this policy
If we materially change how we handle your data, we'll email account holders at least 30 days before the change takes effect. The current version of this policy lives at /privacy.html.
9. Contact
Questions, requests, or complaints: email support@rentreel.co. We aim to respond within 5 business days.
Mailing address: RentReel LLC (a Wyoming limited liability company) · Uhrichsville, OH (full address available on request)