Privacy Policy
Last updated: September 2026
This Privacy Policy explains how we collect, use, store and share your personal data when you use Landlord Office. The sections below describe the information used by the current service.
▣What Data We Collect
We collect the following categories of data when you use the platform:
- Account information — your name and email address used to log in.
- Property data — addresses, valuations, mortgage details, EPC ratings, and property notes.
- Tenancy data — tenant names, contact details, rent amounts, deposit information, and tenancy dates.
- Financial data — income and expense transactions, tax year summaries, and uploaded receipts.
- Compliance data — certificate dates, expiry dates, document uploads, and provider details.
- Client data — names, contact details, and portfolio information for clients you manage.
- Uploaded documents — certificates, tenancy agreements, evidence files, and receipts.
- Security and support data — recorded actions, account identifiers, IP addresses, browser details, and information you send in support requests.
♢Why We Collect It
Your data is collected to provide and improve the property management service. Specifically, we use it to:
- Manage your property portfolio, tenancies, and compliance records.
- Generate bookkeeping summaries and tax review reports, including MTD-style summaries; no direct HMRC submission.
- Track recorded certificate expiry dates and show in-app indicators.
- Store uploaded evidence such as certificates and receipts.
- Provide client portfolio management features where enabled.
The app does not include advertising trackers or automated profiling for advertising. Security logs help investigate access and technical issues.
▤How It's Stored
Supabase provides the database, authentication and private document storage. The app uses server-side ownership checks for account records and document access.
Uploaded documents link to properties, tenancies, compliance records or expenses. Document access uses controlled download routes and time-limited signed access where applicable.
Ending a tenancy or ceasing to use the app does not automatically delete its history. Some records cannot be deleted while linked history remains. Document removal may leave storage cleanup pending if it cannot safely complete. Account-wide deletion is not currently self-service; contact support to request a review of your data.
⌘Who It's Shared With
The service uses Supabase for data, authentication and documents, Vercel for application hosting, and Resend for client invitation emails when configured. Authentication emails are handled through Supabase Auth and its configured email service. Google receives sign-in information if you choose Google sign-in.
Agents can share selected client portfolio information through a read-only portal link. Anyone holding a valid link can open that portal without a separate login until it expires or is revoked. Portal views include property details, tenant names, compliance summaries and finance records; they do not include private tenancy evidence attachments.
Keep portal links and downloaded reports private and share them only with intended recipients. The current app has no payment processing or AI document-scanning integration.
Your rights: Under UK GDPR you may have the right to access, correct, export, object to, or delete your personal data. To exercise these rights, contact support.