Legal

Privacy Policy

Last updated: 5 May 2026  ·  Compliant with DPDP Act 2023, IT Rules 2011

Rent Right Technologies Private Limited ("Rent Right", "we", "us") is committed to protecting the privacy of all users. This Privacy Policy explains how we collect, use, share, and protect personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and other applicable Indian laws.

1. Who We Are

We are a Data Fiduciary as defined under the DPDP Act 2023. Our registered office is in Hyderabad, Telangana, India.

Contact: privacy@rentright.in

2. Data We Collect

We collect the following categories of personal data:

CategoryExamplesSource
Identity DataFull name, date of birth, genderRegistration form
Contact DataEmail address, mobile number, WhatsApp numberRegistration / KYC
Property DataProperty address, rent amount, ownership documentsLandlord dashboard
Identity DocumentsAadhaar (masked), PAN, photographKYC flow
Financial DataBank account (last 4 digits), UPI VPA, payment historyPayment processing
Device DataIP address, device ID, browser type, OS versionAutomatic
Usage DataFeatures accessed, session duration, click pathsAnalytics
Communication DataSupport tickets, chat logsCustomer support
Location DataCity-level location (to display relevant vendors)With your permission

3. Sensitive Personal Data (SPDI)

The following data is classified as Sensitive Personal Data or Information under Rule 3 of the SPDI Rules, 2011, and receives enhanced protection:

  • Aadhaar number (only the masked version is handled; full Aadhaar is processed by UIDAI's servers directly);
  • Financial account information (bank account details for rent receipt);
  • Biometric data used for facial verification (if enabled);
  • Health information (only if disclosed voluntarily in maintenance requests).

We collect SPDI only with your explicit, informed, written consent as required under Rule 5 of the SPDI Rules. You may withdraw consent at any time (see Section 12).

4. Purpose & Legal Basis

We process personal data for the following purposes and on the following legal bases:

PurposeLegal Basis (DPDP Act)
Account creation & authenticationConsent / Contractual necessity
Aadhaar KYC verificationLegal obligation (PMLA, RBI KYC Directions)
Processing rent payments (UPI)Contractual necessity
Sending WhatsApp rent remindersConsent (WhatsApp opt-in)
Generating digital rent agreementsContractual necessity
Deposit Shield administrationContractual necessity
Vendor dispatch notificationsLegitimate interest
GST invoice generationLegal obligation (GST Act 2017)
Fraud detection & AML complianceLegal obligation (PMLA)
Product analytics & improvementLegitimate interest
Marketing (opted-in users only)Consent

5. How We Use Your Data

We use your data to:

  • Provide, operate, and improve the Platform;
  • Verify identity and prevent fraud;
  • Process and track rent payments;
  • Generate and store tenancy agreements and GST receipts;
  • Send transactional communications (payment confirmations, reminders, maintenance updates);
  • Comply with applicable laws including GST, Income Tax, and PMLA;
  • Respond to your support requests;
  • Conduct internal analytics to improve product features.

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

6. Data Sharing & Disclosure

We share data only as described below:

RecipientPurposeSafeguards
Razorpay / Payment AggregatorPayment processingRBI-licensed, PCIDSS compliant
UIDAI (via licensed KUA)Aadhaar OTP authenticationUIDAI regulations
AWS S3 / Cloud storageDocument & data storageAES-256 encrypted, India region
Twilio / MetaWhatsApp & SMS deliveryData processing agreement (DPA)
Tax authoritiesStatutory reporting (TDS, GST)Legal obligation
Law enforcementCourt orders, national securityOnly as legally required
Successor entitiesMerger or acquisitionUser notice given

All third-party processors are bound by data processing agreements that prohibit secondary use of your data.

7. International Transfers

As an NRI-focused platform, your data may be accessed by our team members or processors located outside India (e.g., for customer support). Such transfers are made only to countries with adequate data protection standards or with appropriate contractual safeguards (Standard Contractual Clauses) in place.

Your SPDI and sensitive KYC data is never transferred outside India unless required by law or with your explicit consent.

8. Data Localisation

In compliance with emerging requirements under the DPDP Act 2023, all primary user data is stored on servers located within India (AWS Mumbai region). Payment data is governed by RBI's data localisation circular of 2018, and all payment data is stored exclusively in India.

9. Cookies & Tracking

We use the following cookies:

TypePurposeDuration
Essential / SessionAuthentication, security, CSRF protectionSession
PreferenceLanguage and UI settings1 year
Analytics (anonymised)Understand usage patterns (no PII)90 days

We do not use advertising, retargeting, or third-party tracking cookies. You may manage cookie preferences via your browser settings. Disabling essential cookies may impair Platform functionality.

10. Data Retention

Data TypeRetention PeriodBasis
Account & profile dataDuration of account + 7 yearsTax & legal (IT Act 1961)
Payment records8 years from transaction datePMLA, GST Rules
Rent agreements10 years from agreement dateLimitation Act 1963
KYC documents5 years from account closurePMLA / RBI KYC Directions
Support communications3 yearsConsumer Protection Act 2019
Device / access logs180 daysIT Rules 2021

After the applicable retention period, data is securely deleted or anonymised.

11. Security Practices

We implement security measures meeting or exceeding the standards specified in Rule 8 of the SPDI Rules, 2011, including:

  • Encryption: TLS 1.3 for data in transit; AES-256 for data at rest;
  • Access Control: Role-based access; principle of least privilege;
  • Infrastructure: AWS VPC isolation; private subnets for databases;
  • Vulnerability Management: Regular penetration testing and security audits;
  • Incident Response: Data breach notification to the Data Protection Board within 72 hours as required by DPDP Act (upon commencement of relevant provisions).

12. Your Rights (DPDP Act 2023)

Under the Digital Personal Data Protection Act, 2023, you ("Data Principal") have the following rights:

RightWhat It Means
AccessKnow what personal data we hold about you
CorrectionRequest correction of inaccurate data
ErasureRequest deletion of data not required for legal purposes
Withdraw ConsentWithdraw previously given consent (affects future processing only)
Grievance RedressalFile complaints with our Grievance Officer or the Data Protection Board
NominateNominate a person to exercise your rights in case of death or incapacity

To exercise any right, email privacy@rentright.in with subject line "Data Principal Request — [Your Right]". We will respond within 30 days. Identity verification may be required before processing requests.

Note: Erasure requests cannot override legal retention obligations under PMLA, GST, or Income Tax law.

13. Children's Privacy

The Platform is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that a minor has registered, we will promptly delete that account and associated data. Please notify us at privacy@rentright.in if you believe a minor has created an account.

14. WhatsApp Communications

By providing your WhatsApp number and opting in to WhatsApp communications, you consent to receiving:

  • Rent payment reminders and confirmations;
  • Maintenance update notifications;
  • Agreement signing requests;
  • Account and security alerts.

WhatsApp messages are delivered via Twilio/Meta Business API. Meta's data practices are governed by its own Privacy Policy. You may opt out of WhatsApp communications at any time from your account settings or by replying "STOP" to any message. Opting out of transactional messages may limit Platform functionality.

15. Aadhaar & KYC Data

Aadhaar-based verification on our Platform is conducted exclusively via UIDAI's official OTP-based authentication API, through a UIDAI-licensed KYC User Agency (KUA). We receive only a success/failure flag and the masked Aadhaar number. The full 12-digit Aadhaar number is never stored on Rent Right's systems, in compliance with the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and UIDAI circulars.

PAN verification is conducted via government-approved APIs. PAN data is used only for identity verification and GST compliance.

16. Third-Party Links

The Platform may contain links to third-party websites, apps, or payment portals. We are not responsible for the privacy practices of those third parties. Please review their privacy policies before providing any data.

17. Changes to this Policy

We may update this Policy to reflect changes in law, technology, or our practices. Material changes will be notified via email and in-app notice at least 15 days in advance. The latest version will always be available at rentright.in/privacy.

18. Data Protection Officer

For DPDP Act compliance queries:

Email: dpo@rentright.in

Response Time: Within 30 days for data requests

19. Grievance Officer

Email: grievance@rentright.in

Address: Rent Right Technologies Private Limited, Hyderabad, Telangana — 500081

Acknowledgement: Within 24 hours · Resolution: Within 15 days

If unsatisfied with our response, you may approach the Data Protection Board of India (once constituted under the DPDP Act 2023) or the National Consumer Helpline at 1800-11-4000.

20. Contact

General privacy queries: privacy@rentright.in