Legal

Privacy Policy

Effective from On publication

1. Who We Are

This Policy explains how RentSnagr (“RentSnagr”, “we”, “us”) collects and uses your personal data when you use the RentSnagr service.

2. Data We Collect

When you use RentSnagr, we collect the following:

Information you give us

Your full name and email address (required to deliver your Report)

Your mobile number (optional)

The property address and any tenancy reference (such as Ejari) you choose to enter

Your move-in or move-out date and property type

The photographs you capture, plus any titles, notes, severity ratings, and overall condition ratings you add

Whether you opted in to marketing emails

Information collected automatically

Technical data such as your IP address, browser user-agent, and the time of each action — used for security and fraud prevention, and to record consent

EXIF metadata embedded in your photographs, including the time the photo was taken and (where present) GPS coordinates and camera model — used to make the Report tamper-evident

A SHA-256 hash of each photograph, computed server-side so that the Report can prove the file hasn't been altered after upload

Payment information

Payment card details are collected and processed by our payment partner Telr. We never see or store your full card number. We retain only a transaction reference for reconciliation.

3. Why We Use Your Data

We use your personal data for the following purposes:

To deliver the Service — generate your Report, email it to you, and store it so you can re-download it.

To take payment — process and reconcile your purchase through Telr.

To support you — respond to your questions and resolve disputes.

To protect the Service — detect fraud, abuse, and unauthorised access, and comply with applicable law.

To send you marketing — only if you have explicitly opted in. You can withdraw consent at any time by replying to any email from us or by writing to sbluey18@gmail.com.

4. Legal Basis

We process your data on the following bases:

Performance of a contract with you (delivering your Report).

Your consent (for marketing emails).

Our legitimate interests in running and protecting a secure service (fraud prevention, security logs).

Compliance with legal obligations where applicable, including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).

5. Who We Share It With

We share your personal data only with the service providers we rely on to run RentSnagr, each acting as a processor on our instructions:

Supabase — hosting of database records and your photograph files.

Telr — payment processing.

Resend — outbound email delivery (including your Report).

Vercel — application hosting and request logging.

We do not sell your personal data, and we do not share it with advertising networks. We may disclose data where required by law or to defend our legal rights.

6. International Transfers

Some of our service providers store data outside the United Arab Emirates (typically in the European Union or the United States). Where this happens, we rely on the safeguards offered by the provider — including standard contractual clauses where applicable — to ensure your data continues to be protected to the standard required by the PDPL.

7. How Long We Keep Your Data

Your Report and the photographs in it are retained indefinitely so you can re-access them as evidence in any future dispute. You can ask us to delete them at any time (see Your Rights below).

Payment transaction references are retained for at least 7 years to comply with UAE tax and accounting requirements.

Marketing consent records (including the IP address and time at which you opted in) are retained for as long as we send you marketing emails, and for 12 months after you unsubscribe.

Abandoned sessions that never result in a paid Report are deleted automatically after 7 days.

8. Your Rights

Under the PDPL — and, where applicable, the GDPR — you have the right to:

access the personal data we hold about you;

correct any inaccurate or incomplete data;

request deletion of your data (this will also remove your Report);

restrict or object to certain processing;

receive your data in a portable format;

withdraw your consent at any time (this does not affect any processing already done on the basis of your prior consent);

lodge a complaint with the UAE Data Office (or, where applicable, your local data protection authority).

To exercise any of these rights, email sbluey18@gmail.com. We will respond within 30 days.

9. Cookies and Similar Technologies

We use a small number of strictly necessary cookies to keep you signed in to your in-progress session and to remember your preferences. We do not use advertising or third-party analytics cookies. Because our cookies are strictly necessary, no consent banner is required under UAE or EU law.

10. Security

We protect your data with industry-standard measures, including encryption in transit (TLS) and at rest, access controls, and tamper-evident hashing of uploaded photographs. No service can guarantee absolute security; in the unlikely event of a personal data breach affecting your data, we will notify you and the relevant authority in line with PDPL requirements.

11. Children

The Service is not directed at, and not intended for, anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, please contact sbluey18@gmail.com and we will delete it.

12. Changes to This Policy

We may update this Policy from time to time. The “Effective from” date at the top of the page tells you when the current version came into force. Material changes will be notified to you, where appropriate, by email.

13. Contact

For general support questions, email sbluey18@gmail.com. For data protection questions, including to exercise any of your rights, email sbluey18@gmail.com.