
Privacy & Cookies Policy
Your privacy matters to us. This policy explains how we collect, use, and protect your personal information, and how we use cookies and similar tracking technologies.
Last updated: August 26, 2026
Our Cookie Policy is part of this page. Jump straight to Cookies and Tracking Technologies.
1. Introduction and Scope
RentAxis ("we," "our," or "us") provides a software-as-a-service platform for property management, rental and lease administration, tenant and resident management, payments, maintenance, communications, and related real estate operations (the "Service").
This Privacy & Cookies Policy explains what information the Service collects, how that information is used, who it is shared with, how long it is kept, and the choices available to you. It applies to our public website, the RentAxis web application, and every optional integration described below.
This document also serves as our Cookie Policy — see section 7, Cookies and Tracking Technologies. If you connect a Google or Gmail account to the Service, please read section 5, Google User Data and Gmail Integration, which describes that integration in full.
2. Our Role: Platform Provider and Customer Organizations
The Service is organized around organizations (also called workspaces). A landlord, property management company, or real estate business creates an organization, invites its staff, and uses the Service to manage its own properties, leases, residents, vendors, and communications.
This creates two distinct relationships, and your rights differ depending on which applies to you:
Where RentAxis decides how data is used. For our own account records, billing, platform security, support, and our public website, we determine the purposes of processing and are responsible to you directly.
Where a customer organization decides how data is used. Property, lease, resident, maintenance, accounting, document, and mailbox data entered into or connected to an organization's workspace is controlled by that organization. We process it on their behalf, under their instructions, to operate the Service. If you are a tenant, resident, applicant, vendor, or contractor, the organization that manages your property is the primary point of contact for questions about that data, and we will direct certain requests to them.
Each organization's data is logically separated from every other organization's data, and access is scoped to the organization a user belongs to.
3. Information We Collect
Account information
Name, email address, phone number, and profile photo
Password, stored only as a salted cryptographic hash — we never store or have access to your password in readable form
Two-factor authentication settings and recovery codes, where you enable two-factor authentication
Email verification status, password reset requests, and login session records
Your role and permissions within an organization
Organization and workspace information
Company name, business contact details, address, and branch or office locations
Branding assets such as logos, and display, localization, and timezone preferences
Subscription plan, billing configuration, feature settings, and integration configuration
Team member lists, invitations, roles, and permission assignments
Property and unit information
Property and unit addresses, descriptions, amenities, and specifications
Photos, floor plans, and other media uploaded to properties and public listings
Listing content, availability, and pricing published to the public listings pages
Approximate geographic coordinates used to display properties on a map
Tenant, resident, and applicant information
Names, contact details, and emergency contacts
Rental applications and the information submitted in them
Occupancy records, tenancy history within the organization, and portal activity
Any identification or supporting documents an organization or applicant chooses to upload
Lease information
Lease terms, dates, rent amounts, deposits, fees, and renewal records
Lease documents, signing requests, and signature records
Late fee policies and their application to a tenancy
Maintenance information
Maintenance and work order requests, descriptions, status, and history
Photos and files attached to a request
Vendor and contractor assignments, quotes, invoices, and completion records
Payment and financial information
Invoices, charges, rent ledgers, payment records, refunds, and payout records
Expenses, accounting entries, chart of accounts, budgets, and financial reports
Bank account and transaction data, where an organization connects a bank account through our banking integration
Accounting records synchronized where an organization connects an accounting integration
We do not collect or store full payment card numbers. Card payments are handled by our payment processor on its own hosted payment pages and infrastructure. We receive and store only transaction references, status, amounts, and limited descriptive details such as the card brand and last four digits returned by the processor.
Communications
Email sent through the Service, including messages to tenants, vendors, leads, and prospects
In-app chat, notifications, announcements, and message threads
Messages exchanged with the public "Talk to us" support widget on our website, including any name and email address you provide in that conversation
Newsletter subscriptions and marketing preferences
Support requests and correspondence with us
Mailbox content, where an organization connects a mailbox — described separately in section 5
Documents and files uploaded by users
Leases, agreements, notices, invoices, receipts, inspection reports, and other documents
Images and media attached to properties, units, listings, maintenance requests, and messages
Files attached to an AI conversation, where a user chooses to attach them
Usage and technical information
IP address, browser type and version, device type, and operating system
Pages viewed, actions taken in the application, and timestamps
Approximate location derived from IP address, using a geolocation database consulted locally on our servers
Activity and audit logs recording significant actions taken within an organization
Application, delivery, and error logs used to operate and troubleshoot the Service
4. How We Use Information
We use the information described above to:
Provide, operate, maintain, secure, and improve the Service
Create and administer accounts, authenticate users, and enforce roles and permissions
Deliver the specific features an organization has enabled, including listings, leasing, payments, maintenance, accounting, messaging, and reporting
Process transactions and send related confirmations, invoices, receipts, and reminders
Enable communication between property managers, tenants, applicants, vendors, and contractors
Send service and administrative notifications, such as maintenance updates, payment reminders, security alerts, and changes to the Service
Generate reports, statements, and analytics for the organization about its own portfolio and operations
Provide customer support and respond to enquiries
Detect, investigate, and prevent fraud, abuse, security incidents, and technical faults
Comply with legal obligations and enforce our Terms of Service
We send marketing communications about RentAxis only to people who have signed up for them or who have an account with us, and every marketing message includes a way to opt out. Opting out of marketing does not stop transactional and service messages, which are necessary to operate your account.
5. Google User Data and Gmail Integration
RentAxis offers an optional Gmail and Google Workspace mailbox integration. An organization administrator may connect a Google account so that the organization can send and receive mail from that mailbox inside the RentAxis Mail module. This section describes that integration completely and specifically. If no Google account is connected, none of the processing in this section takes place.
5.1 Google sign-in is not used to log in to RentAxis
Google OAuth is used only to connect a mailbox. RentAxis accounts are created and authenticated with an email address and password managed by us, with optional two-factor authentication. We do not offer "Sign in with Google," and connecting a Google mailbox does not change how you log in.
5.2 Scopes we request and why each is required
When an administrator connects a Google account, we ask for your permission to the following scopes:
https://mail.google.com/ — required to send mail from the connected mailbox and to read, organize, and manage messages in it on your behalf. This scope is required because RentAxis connects to Gmail using the IMAP and SMTP protocols with OAuth 2.0 (XOAUTH2) authentication, and Gmail accepts only this scope for those protocols. It is what allows the Mail module to display your inbox and sent mail, send and reply to messages, save and update drafts, apply labels, and move messages to and from Trash.
openid, email, and profile — required solely to identify which Google account has been connected, so the mailbox can be labelled correctly in the application, matched to the right organization, and reconnected if the authorization expires. We use the email address and display name returned by these scopes and nothing else.
We request offline access so the connection continues to work in the background for inbox synchronization and scheduled sending without requiring an administrator to sign in again each time.
5.3 What Google user data we access
For a connected mailbox, we access:
Messages in the Inbox and Sent folders — sender name and address, recipients including To and Cc, subject, message body in both HTML and plain text, a short preview snippet, and the date and time sent
Message identifiers and state — the message ID, mailbox UID, Gmail conversation (thread) ID, Gmail labels, read and starred flags, and whether the message has attachments
Attachment metadata — file name, type, and size
Attachment contents — retrieved from Gmail on demand, only at the moment a user opens or downloads a specific attachment, or when a message with attachments is forwarded
The email address and display name of the connected Google account
We also write to the connected mailbox when a user performs those actions in RentAxis: sending and replying to mail, creating and updating drafts, applying and removing labels, and moving messages to Trash, restoring them, or deleting them permanently.
5.4 How Google user data is used
Google user data is used exclusively to provide and improve the mailbox features you asked for — displaying your mail inside RentAxis, letting your team read, search, reply, forward, draft, label, assign, and organize it alongside the properties, leases, and contacts it relates to, and sending mail from your own address. It is not used for any other purpose.
5.5 Whether Google user data is stored, and for how long
Yes. To make mail usable inside the application, the message data listed in section 5.3 — including message bodies — is stored in our database, scoped to the organization that owns the connected mailbox. Attachment contents are not stored on our servers; only attachment metadata is stored, and file contents are fetched from Gmail on demand each time they are opened.
The OAuth access token and refresh token for the connection are stored encrypted at rest and are used only to authenticate to Google on that organization's behalf.
Google user data is retained for as long as the mailbox remains connected to the organization. When an administrator disconnects or deletes the mailbox connection, we permanently delete the stored messages, synchronization records, and stored OAuth tokens for that connection. This deletion is performed automatically shortly after the disconnection is confirmed. Deleting a RentAxis organization removes the same data.
5.6 Whether Google user data is shared with third parties
No. We do not sell, rent, or transfer Google user data, and we do not share it with any third party for that third party's own purposes. Google user data is not disclosed to advertisers, data brokers, analytics vendors, or AI providers. It is accessible to the authorized users of the organization that connected the mailbox, and is held on the hosting infrastructure that runs the Service. We may disclose data only where we are legally compelled to do so, as described in section 9.
5.7 Advertising, marketing, and analytics
Google user data is not used for advertising. It is not used for marketing, and it is not used to build marketing lists, profiles, or audiences. It is not used for analytics: it is not sent to any analytics service, it is not included in our website or product analytics, and it is not used to produce aggregate statistics or benchmarks about users or about the Service.
5.8 AI and machine learning
Google user data is not used to develop, train, retrain, fine-tune, or improve any artificial intelligence or machine learning model, whether our own or anyone else's.
Specifically and without exception:
Google user data is not sent to OpenAI.
Google user data is not sent to Anthropic.
Google user data is not sent to Google Gemini or to any other Google AI service.
Google user data is not sent to any other third-party AI or machine learning provider, model host, aggregator, or gateway.
The RentAxis Mail module contains no AI functionality. The AI features described in section 6 operate on separate parts of the application and have no access to mailbox data. This separation is enforced in the application itself: the AI features cannot read mail messages, mailbox contents, drafts, or attachments, and no code path passes mailbox data to an AI provider.
The single exception is deliberately limited and contains no mail content: the in-app assistant can report whether an email provider has been configured for the organization, as part of a settings health check. That check reads configuration status only — never messages, addresses, credentials, or tokens.
5.9 Limited Use commitment
RentAxis's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
5.10 Revoking access
You can end the Gmail integration at any time, in either of two ways, and we recommend doing both:
In RentAxis — an organization administrator can delete the mailbox connection from the email settings page. This stops all access and permanently deletes the stored messages and tokens for that connection.
In your Google Account — visit myaccount.google.com/permissions, select RentAxis, and choose to remove access. This withdraws the authorization at Google. Removing access at Google stops future access but does not by itself delete data already stored in RentAxis; delete the mailbox connection in the application to remove that data.
6. AI Features and AI Providers
RentAxis includes optional AI-assisted features. They are inactive unless enabled and configured, and they are separate from the Gmail integration in every respect.
6.1 What the AI features do
Ask AI assistant — answers questions about the organization's own operational data, such as rent collected, outstanding balances, expenses, occupancy, and configuration health, by querying the organization's records
Document explanation — summarizes or answers questions about a lease or other PDF that a user explicitly submits for explanation
Content drafting — helps draft announcements, reports, investment summaries, and vendor-related content
Website support assistant — the public "Talk to us" widget, which answers visitor questions using our published help documentation, public pricing plans, and public listings
Knowledge base search — generates text embeddings of our own published help documentation so support search works; this processes our documentation, not customer records
6.2 Which providers are used
Depending on the configuration chosen by the organization, or by us for the public website assistant, these features may send data to one of the following third-party AI providers: Anthropic, OpenAI, or Google Gemini. Only one provider is active for a given feature at a time. An organization may supply its own API key for its chosen provider, in which case its AI requests are made under its own account with that provider and are governed by that provider's terms in addition to this policy.
6.3 What data reaches an AI provider
Only the content required to answer the specific request is sent: the user's prompt, the conversation in progress, any file the user has explicitly attached, and the results of the internal queries the assistant runs to answer the question. We do not send an organization's entire database to an AI provider, and we do not send data from features the user is not using.
No data received from Google Workspace or Gmail APIs is ever included. See section 5.8.
6.4 AI records we keep
AI conversations and their attachments are stored in the organization's workspace so users can return to them, and can be deleted by the user. Separately, we record usage metadata for each AI request — the feature used, the provider and model, token counts, estimated cost, response time, and success or failure. This usage record contains no prompt or response content.
We do not use customer content to train our own models, and we do not build models from customer data.
7. Cookies and Tracking Technologies
Cookies are small text files stored by your browser. We also use your browser's local storage for one interface preference. Below is a complete and accurate account of what RentAxis uses. We do not use any other tracking technology, and we do not operate tracking pixels, device fingerprinting, or cross-site advertising trackers of our own.
Strictly necessary cookies
These are required for the Service to function and cannot be switched off. Without them you cannot log in or submit forms securely.
Session cookie — maintains your signed-in session and links your browser to your account for the duration of your visit
XSRF-TOKEN — a security token that protects forms and requests against cross-site request forgery
Remember-me cookie — set only if you choose "remember me" at login, so you stay signed in between visits
Functional cookies
These remember interface preferences. They contain no personal information and no tracking identifiers.
appearance — remembers whether you have chosen the light, dark, or system colour theme. The same preference is also kept in your browser's local storage so the correct theme is applied before the page renders.
sidebar_state — remembers whether the application sidebar is expanded or collapsed
Analytics cookies
Our public website can be configured to use Google Analytics and Google Tag Manager to understand how visitors find and use the site. When enabled, these set their own cookies, which typically identify a browser across visits so returning visits are not double-counted. This measures activity on our public website and product pages.
These tools load only when an analytics or tag manager identifier has been configured by the site operator. Where no identifier is configured, no analytics scripts are loaded and no analytics cookies are set.
Analytics never covers Google user data from a connected mailbox. Mailbox content is never sent to Google Analytics, Google Tag Manager, or any other analytics service.
Marketing and advertising cookies
RentAxis does not set marketing or advertising cookies, does not operate an advertising network, and does not share your information with advertisers or ad networks for targeted advertising.
Third-party content
Some pages embed third-party components that may set their own cookies or receive your IP address as a normal part of loading, including Google Maps where a map or address autocomplete is displayed, and our payment processor's hosted payment pages when you make a payment. These are governed by those providers' own privacy policies.
Managing cookies
You can block or delete cookies through your browser settings, and browsers generally allow you to refuse third-party cookies specifically. Blocking strictly necessary cookies will prevent you from logging in and using the Service. You can also opt out of Google Analytics across all websites using Google's browser opt-out add-on.
8. Third-Party Services
We rely on the following categories of third-party provider to deliver the Service. Each receives only the data needed for its function.
Payment processing — Stripe, for card payments, hosted payment pages, and payouts to connected accounts
Banking data — Plaid, where an organization connects a bank account to import balances and transactions
Accounting — QuickBooks, where an organization connects an accounting integration to synchronize records
Email delivery — our transactional email providers, which may include Postmark, Resend, or Amazon SES, and any SMTP or Gmail mailbox an organization connects itself
Google — Google OAuth and the Gmail APIs for the mailbox integration described in section 5, Google Maps for maps and address autocomplete, and Google Analytics and Google Tag Manager where enabled as described in section 7
AI providers — Anthropic, OpenAI, or Google Gemini, for the features described in section 6
Cloud hosting and storage — our hosting provider and object storage for the application, database, and uploaded files
Operational alerting — Slack and Telegram, where configured, to notify our team of events such as a support request escalating to a person
These providers act as our service providers, or as integrations the organization has chosen to connect. They are not permitted to use the data for their own independent purposes.
9. How We Share Information
We do not sell your personal information. We share information only in these circumstances:
Within your organization — with other users of the organization's workspace, according to the roles and permissions the organization has configured.
Between parties to a tenancy — with property managers, tenants, vendors, and contractors as necessary to operate a tenancy, process a request, or complete work.
With service providers — as described in section 8, limited to what each provider needs to perform its function for us.
For legal reasons — where required by law, regulation, legal process, or enforceable governmental request, or where necessary to investigate fraud or a security incident, or to establish, exercise, or defend legal claims.
In a business transfer — in connection with a merger, acquisition, financing, or sale of assets, subject to the acquirer continuing to honour this policy for the information transferred.
10. Data Retention
We retain information for as long as it is needed for the purpose it was collected, then delete or anonymize it. In practice:
Account and workspace data is retained while the account or organization is active.
Google user data from a connected mailbox is retained only while the mailbox connection exists, and is permanently deleted shortly after the connection is deleted. See section 5.5.
Financial and transaction records may be retained for longer where accounting, tax, or audit obligations require it.
Activity and audit logs are retained for a limited, configurable window and are then archived or deleted on a scheduled basis.
Mailbox synchronization logs are pruned automatically after a short retention window.
Backups may retain copies for a limited period after deletion from the live system, after which they expire.
11. Data Security
We apply security measures appropriate to the data we handle, including:
Encryption in transit using TLS for connections to the Service and to third-party APIs
Encryption at rest for sensitive credentials, including OAuth tokens and integration keys, which are stored in encrypted form and are never displayed back once saved
Passwords stored only as salted cryptographic hashes
Optional two-factor authentication for user accounts
Role-based access control and per-organization data scoping, so users only reach data belonging to their own organization
Server-side authorization on protected operations, rather than relying on the interface to hide them
Activity and audit logging of significant actions
Validation and type restrictions on uploaded files
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not claim any formal security certification for the Service, and this policy should not be read as asserting one. If you believe you have found a security issue, please contact us at privacy@rentaxis.io.
12. International Data Transfers
The Service is operated using cloud infrastructure, and the third-party providers listed in section 8 operate internationally. Your information may therefore be processed in a country other than the one you live in, including countries whose data protection laws differ from those of your own. Where information is transferred across borders, we rely on the safeguards offered by the relevant provider and take reasonable steps to keep the information protected consistently with this policy.
13. Your Rights and Choices
Depending on where you live, you may have some or all of the following rights over your personal information:
Access — ask what personal information we hold about you and obtain a copy
Correction — ask us to correct information that is inaccurate or incomplete
Deletion — ask us to delete your personal information, subject to legal, accounting, and contractual obligations that may require us to keep certain records
Portability — ask for a copy of certain information in a portable format
Restriction and objection — ask us to limit or stop certain processing
Withdraw consent — where processing is based on consent, withdraw it at any time, without affecting processing already carried out
Opt out of marketing — unsubscribe from marketing emails at any time using the link in any such message
To exercise any of these rights, contact us at privacy@rentaxis.io. We may need to verify your identity before we act. Where the information is held in a customer organization's workspace and that organization determines how it is used, we will refer your request to that organization and support them in responding.
These rights derive from the privacy laws that apply to you, and the rights actually available differ by jurisdiction. We describe them here so you know how to reach us; this is not a claim of certification under any particular privacy framework.
14. Data Deletion and Account Closure
Deactivating your account — you can deactivate your own user account from your profile settings. Deactivation signs you out and prevents further sign-in.
Deleting a user — an organization administrator can delete a user from the organization.
Deleting an organization and its data — contact us at privacy@rentaxis.io to request closure of an organization and deletion of its data. Deleting an organization removes the records associated with it, including any connected mailbox data.
Deleting Google user data specifically — delete the mailbox connection in email settings, which permanently deletes the stored messages and tokens for that mailbox, and revoke the authorization at myaccount.google.com/permissions. See section 5.10.
Some records may be retained after deletion where law or a legitimate business obligation requires, as described in section 10.
15. Children's Privacy
The Service is intended for use by adults in a business or tenancy context and is not directed to children. We do not knowingly collect personal information directly from anyone under 18. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it. Organizations may record household members, including minors, as part of tenancy records; that information is entered and controlled by the organization.
16. Changes to This Policy
We may update this policy as the Service changes or as legal requirements evolve. When we make a material change, we will update the "Last updated" date at the top of this page and, where the change significantly affects how we handle your information, provide additional notice through the Service or by email. Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy.
17. Contact Us
For questions about this policy, our data practices, the Gmail integration, or to exercise your privacy rights, contact us at privacy@rentaxis.io or visit our Help & Contact page.
If you are a tenant, resident, applicant, vendor, or contractor, please also contact the property management organization you deal with, as they control the records held about you in their workspace.
