Legal
Privacy Policy
Last updated: 5 May 2026 · Compliant with DPDP Act 2023, IT Rules 2011
Rent Right Technologies Private Limited ("Rent Right", "we", "us") is committed to protecting the privacy of all users. This Privacy Policy explains how we collect, use, share, and protect personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and other applicable Indian laws.
1. Who We Are
We are a Data Fiduciary as defined under the DPDP Act 2023. Our registered office is in Hyderabad, Telangana, India.
Contact: privacy@rentright.in
2. Data We Collect
We collect the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Identity Data | Full name, date of birth, gender | Registration form |
| Contact Data | Email address, mobile number, WhatsApp number | Registration / KYC |
| Property Data | Property address, rent amount, ownership documents | Landlord dashboard |
| Identity Documents | Aadhaar (masked), PAN, photograph | KYC flow |
| Financial Data | Bank account (last 4 digits), UPI VPA, payment history | Payment processing |
| Device Data | IP address, device ID, browser type, OS version | Automatic |
| Usage Data | Features accessed, session duration, click paths | Analytics |
| Communication Data | Support tickets, chat logs | Customer support |
| Location Data | City-level location (to display relevant vendors) | With your permission |
3. Sensitive Personal Data (SPDI)
The following data is classified as Sensitive Personal Data or Information under Rule 3 of the SPDI Rules, 2011, and receives enhanced protection:
- Aadhaar number (only the masked version is handled; full Aadhaar is processed by UIDAI's servers directly);
- Financial account information (bank account details for rent receipt);
- Biometric data used for facial verification (if enabled);
- Health information (only if disclosed voluntarily in maintenance requests).
We collect SPDI only with your explicit, informed, written consent as required under Rule 5 of the SPDI Rules. You may withdraw consent at any time (see Section 12).
4. Purpose & Legal Basis
We process personal data for the following purposes and on the following legal bases:
| Purpose | Legal Basis (DPDP Act) |
|---|---|
| Account creation & authentication | Consent / Contractual necessity |
| Aadhaar KYC verification | Legal obligation (PMLA, RBI KYC Directions) |
| Processing rent payments (UPI) | Contractual necessity |
| Sending WhatsApp rent reminders | Consent (WhatsApp opt-in) |
| Generating digital rent agreements | Contractual necessity |
| Deposit Shield administration | Contractual necessity |
| Vendor dispatch notifications | Legitimate interest |
| GST invoice generation | Legal obligation (GST Act 2017) |
| Fraud detection & AML compliance | Legal obligation (PMLA) |
| Product analytics & improvement | Legitimate interest |
| Marketing (opted-in users only) | Consent |
5. How We Use Your Data
We use your data to:
- Provide, operate, and improve the Platform;
- Verify identity and prevent fraud;
- Process and track rent payments;
- Generate and store tenancy agreements and GST receipts;
- Send transactional communications (payment confirmations, reminders, maintenance updates);
- Comply with applicable laws including GST, Income Tax, and PMLA;
- Respond to your support requests;
- Conduct internal analytics to improve product features.
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.
6. Data Sharing & Disclosure
We share data only as described below:
| Recipient | Purpose | Safeguards |
|---|---|---|
| Razorpay / Payment Aggregator | Payment processing | RBI-licensed, PCIDSS compliant |
| UIDAI (via licensed KUA) | Aadhaar OTP authentication | UIDAI regulations |
| AWS S3 / Cloud storage | Document & data storage | AES-256 encrypted, India region |
| Twilio / Meta | WhatsApp & SMS delivery | Data processing agreement (DPA) |
| Tax authorities | Statutory reporting (TDS, GST) | Legal obligation |
| Law enforcement | Court orders, national security | Only as legally required |
| Successor entities | Merger or acquisition | User notice given |
All third-party processors are bound by data processing agreements that prohibit secondary use of your data.
7. International Transfers
As an NRI-focused platform, your data may be accessed by our team members or processors located outside India (e.g., for customer support). Such transfers are made only to countries with adequate data protection standards or with appropriate contractual safeguards (Standard Contractual Clauses) in place.
Your SPDI and sensitive KYC data is never transferred outside India unless required by law or with your explicit consent.
8. Data Localisation
In compliance with emerging requirements under the DPDP Act 2023, all primary user data is stored on servers located within India (AWS Mumbai region). Payment data is governed by RBI's data localisation circular of 2018, and all payment data is stored exclusively in India.
9. Cookies & Tracking
We use the following cookies:
| Type | Purpose | Duration |
|---|---|---|
| Essential / Session | Authentication, security, CSRF protection | Session |
| Preference | Language and UI settings | 1 year |
| Analytics (anonymised) | Understand usage patterns (no PII) | 90 days |
We do not use advertising, retargeting, or third-party tracking cookies. You may manage cookie preferences via your browser settings. Disabling essential cookies may impair Platform functionality.
10. Data Retention
| Data Type | Retention Period | Basis |
|---|---|---|
| Account & profile data | Duration of account + 7 years | Tax & legal (IT Act 1961) |
| Payment records | 8 years from transaction date | PMLA, GST Rules |
| Rent agreements | 10 years from agreement date | Limitation Act 1963 |
| KYC documents | 5 years from account closure | PMLA / RBI KYC Directions |
| Support communications | 3 years | Consumer Protection Act 2019 |
| Device / access logs | 180 days | IT Rules 2021 |
After the applicable retention period, data is securely deleted or anonymised.
11. Security Practices
We implement security measures meeting or exceeding the standards specified in Rule 8 of the SPDI Rules, 2011, including:
- Encryption: TLS 1.3 for data in transit; AES-256 for data at rest;
- Access Control: Role-based access; principle of least privilege;
- Infrastructure: AWS VPC isolation; private subnets for databases;
- Vulnerability Management: Regular penetration testing and security audits;
- Incident Response: Data breach notification to the Data Protection Board within 72 hours as required by DPDP Act (upon commencement of relevant provisions).
12. Your Rights (DPDP Act 2023)
Under the Digital Personal Data Protection Act, 2023, you ("Data Principal") have the following rights:
| Right | What It Means |
|---|---|
| Access | Know what personal data we hold about you |
| Correction | Request correction of inaccurate data |
| Erasure | Request deletion of data not required for legal purposes |
| Withdraw Consent | Withdraw previously given consent (affects future processing only) |
| Grievance Redressal | File complaints with our Grievance Officer or the Data Protection Board |
| Nominate | Nominate a person to exercise your rights in case of death or incapacity |
To exercise any right, email privacy@rentright.in with subject line "Data Principal Request — [Your Right]". We will respond within 30 days. Identity verification may be required before processing requests.
Note: Erasure requests cannot override legal retention obligations under PMLA, GST, or Income Tax law.
13. Children's Privacy
The Platform is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that a minor has registered, we will promptly delete that account and associated data. Please notify us at privacy@rentright.in if you believe a minor has created an account.
14. WhatsApp Communications
By providing your WhatsApp number and opting in to WhatsApp communications, you consent to receiving:
- Rent payment reminders and confirmations;
- Maintenance update notifications;
- Agreement signing requests;
- Account and security alerts.
WhatsApp messages are delivered via Twilio/Meta Business API. Meta's data practices are governed by its own Privacy Policy. You may opt out of WhatsApp communications at any time from your account settings or by replying "STOP" to any message. Opting out of transactional messages may limit Platform functionality.
15. Aadhaar & KYC Data
Aadhaar-based verification on our Platform is conducted exclusively via UIDAI's official OTP-based authentication API, through a UIDAI-licensed KYC User Agency (KUA). We receive only a success/failure flag and the masked Aadhaar number. The full 12-digit Aadhaar number is never stored on Rent Right's systems, in compliance with the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and UIDAI circulars.
PAN verification is conducted via government-approved APIs. PAN data is used only for identity verification and GST compliance.
16. Third-Party Links
The Platform may contain links to third-party websites, apps, or payment portals. We are not responsible for the privacy practices of those third parties. Please review their privacy policies before providing any data.
17. Changes to this Policy
We may update this Policy to reflect changes in law, technology, or our practices. Material changes will be notified via email and in-app notice at least 15 days in advance. The latest version will always be available at rentright.in/privacy.
18. Data Protection Officer
For DPDP Act compliance queries:
Email: dpo@rentright.in
Response Time: Within 30 days for data requests
19. Grievance Officer
Email: grievance@rentright.in
Address: Rent Right Technologies Private Limited, Hyderabad, Telangana — 500081
Acknowledgement: Within 24 hours · Resolution: Within 15 days
If unsatisfied with our response, you may approach the Data Protection Board of India (once constituted under the DPDP Act 2023) or the National Consumer Helpline at 1800-11-4000.
20. Contact
General privacy queries: privacy@rentright.in