MySmartRental
Log inSign up

Legal

Privacy Policy

Last updated: 18 April 2026

1. Who we are

MySmartRental (“MySmartRental”, “we”, “us”, “our”) is a property management platform operated by Coded Vision Design. We act as the data controller for the personal data described in this policy. Questions or requests can be sent to info@mysmartrental.com.

2. Scope

This policy applies to our website, web application, and mobile apps. It covers everyone who interacts with us: landlords, property managers, tenants, prospective tenants, contractors, and site visitors.

3. Information we collect

Account data
Name, email, phone, role (landlord, tenant, contractor), and password hash.
Property and tenancy data
Property addresses, unit details, lease terms, rent amounts, and documents you upload.
Payment data
M-Pesa phone numbers and transaction references needed to process rent and invoices. We do not store full card numbers; card payments are tokenised by our payment processor.
Bank account & payee details (Payment profiles)
When you choose to attach bank account details to invoices you issue, we store the account holder name, sort code/account number (UK), bank code/account number (Kenya), IBAN, KRA PIN, UTR, and M-Pesa Paybill/Till numbers. Sensitive fields (sort code, account numbers, IBAN, KRA PIN, UTR) are encrypted at rest with AES-256-GCM; the master key never leaves our server. We decrypt only when generating an invoice you have authored or when exporting your data on your request. You can edit or delete your payment profiles at any time from Settings.
Messages and maintenance tickets
Content you send through the platform to your landlord, tenant, or contractor.
Technical data
IP address, device and browser, language, and pages visited.
Cookies
See our Cookie Policy for the full list and to change your choices.

4. How we use your information

  • Operate the platform: create your account, match you to your properties and tenancies, and show you the right data.
  • Process payments and send receipts via M-Pesa or card.
  • Send service communications such as maintenance updates, rent reminders, and lease documents.
  • Keep the service secure: prevent fraud, abuse, and unauthorised access.
  • Improve the platform through aggregate, anonymised analytics (only if you allow analytics cookies).
  • Meet our legal and regulatory obligations.

5. Legal bases

We rely on the following legal bases under the UK GDPR and Kenya’s Data Protection Act, 2019:

Contract
To deliver the service you or your landlord signed up for.
Legitimate interests
To keep the platform secure, prevent fraud, and improve our product.
Consent
For analytics and marketing cookies and any optional communications.
Legal obligation
Where we are required to retain records (for example, tax or anti-money laundering rules).

6. Sharing

We share data only when necessary:

Other users of your account
Landlords see their tenants, tenants see their landlord, contractors see jobs assigned to them.
Service providers
Hosting (Hostinger VPS), email (Nodemailer via our SMTP provider), payments (Safaricom M-Pesa), error monitoring (Sentry), and analytics (Google Analytics, only with your consent).
Authorities
Where required by law, court order, or to protect rights and safety.

We do not sell your personal data.

7. International transfers

MySmartRental is operated from Kenya and the United Kingdom. Some processors may store or process data in the EEA, the UK, or the United States. Where we transfer data outside Kenya or the UK, we use Standard Contractual Clauses or equivalent safeguards.

8. Retention

We keep personal data for as long as you have an account with us and for the period required by law afterwards (typically up to seven years for financial records). Uploaded lease and invoice documents are retained for the legally required period and then permanently deleted.

9. Security

Data is transmitted over TLS, passwords are hashed, and sensitive files are stored with access controls. We limit internal access to the staff who need it. No system is perfectly secure, but we monitor, log, and patch continuously.

10. Your rights

You can ask us to access, correct, delete, restrict, port, or object to the processing of your personal data. You can withdraw consent at any time for things that rely on it (for example, analytics cookies. Use our Cookie settings). You also have the right to lodge a complaint with your data protection authority: the Office of the Data Protection Commissioner in Kenya, or the Information Commissioner’s Office (ICO) in the UK.

11. Children

MySmartRental is not intended for children under 18. We do not knowingly collect data from minors.

12. Changes

We may update this policy from time to time. Material changes will be announced in the app and via email. The “Last updated” date at the top reflects the current version.

13. Contact

For any privacy questions or to exercise your rights, email info@mysmartrental.com.