Who we are
RentManager NZ is operated by RentManager NZ Limited (NZBN 9429053511362, IRD 148-225-788), a New Zealand registered company. We provide property management software to residential landlords and property managers in New Zealand.
Contact:
What information we collect
- Account information: Your name, email address, and password (stored as a one-way bcrypt hash - we never see your plain-text password).
- Property and tenancy data: Property addresses, tenant details (name, contact information, date of birth, emergency contacts), lease terms, and rent schedules you enter.
- Financial data: Bank transaction data imported via CSV upload or Open Banking (if connected) and manual payment records.
- Documents: Files you upload, stored in AWS S3 in Auckland (ap-southeast-6).
- Communications log: Notes and activity records you create within the platform.
- Tenant screening data: If a prospective tenant uses our RentManager Apply portal (apply.rentmanager.nz), we collect their name, email, phone, date of birth, current address, employment details, rental history, and references. With their explicit consent, we may also retrieve income data via bank connection and obtain a credit report.
- Referral data: If a tenant registers via a referral link, we record the referral code to attribute referral credit. Referral codes do not contain personal information.
- Address data: We use NZ Post address lookup and LINZ address databases to validate and enrich property addresses. This is publicly available reference data.
- Language preference: If you select a preferred language (English, te reo Maori, or Chinese), this preference is stored with your account.
- Usage analytics: We record page views and in-app activity events to monitor service health, detect abuse, and improve the platform.
- Notifications: We generate in-app notifications stored within your account.
How we use your information
- To provide and operate the RentManager NZ service, including the Apply tenant screening portal.
- To send service-related notifications (in-app and email).
- To monitor service health, analyse usage patterns, and improve the platform.
- To detect and prevent fraud or abuse.
- To display the interface in your preferred language.
- To match rent transactions and help you categorise expenses.
- To comply with legal obligations.
We do not sell your data to third parties and do not use it for advertising.
Artificial intelligence (AI) features
Some features use AI to read documents you upload (for example, extracting details from a tenancy agreement). AI features are clearly labelled, and any data extracted by AI may be subject to human review for quality purposes. We do not use your personal information to train third-party AI models.
Data storage and security
Core application database and file storage use AWS Auckland (ap-southeast-6). Some services process limited information elsewhere. See Data and security for current scope.
Outbound email (notifications, password resets, notices) is delivered through Amazon SES in Sydney because AWS has no email service in the New Zealand region. The relay transmits the message for delivery and does not retain its content; core application records remain stored in AWS Auckland. Other provider processing is described below and on the Data and security page.
Security measures include:
- All connections encrypted with TLS 1.2+.
- Passwords stored as bcrypt hashes (never reversible).
- Database row-level security isolating each account's data.
- Optional two-factor authentication (TOTP) for your account.
- Bank OAuth tokens encrypted at rest using AES-256-GCM.
For full details, see our Security Practices page.
Third-party services
- NZ Open Banking - optional bank transaction feed via Consumer Data Right (see dedicated section below).
- Stripe - payment processing. Stripe stores your billing details; we do not store card numbers.
- Centrix - credit-report provider. When an authorised landlord requests a check after consent, we send the applicant or tenant's name, date of birth, current or previous address, and optionally driver-licence details. Centrix holds the report under its provider terms; RentManager retains a time-limited enquiry reference and access audit records. It does not retain or display a derived score.
- Google - optional sign-in. Google shares your name and email address with us.
- AWS S3 - document storage in Auckland, bound by NZ data processing agreements.
- AWS SES (email) - outbound email is delivered through Amazon SES in Sydney, because AWS has no NZ email region. Message content (notices, reminders, password resets) passes through for delivery and is not retained there.
- Anthropic - reads tenancy agreements you choose to upload at /upload-agreement to extract the address, tenant names, rent, dates, and bond. The document is sent to Anthropic's PBC API for processing only; Anthropic does not use API-submitted data to train their models. We delete the staged copy within 30 days if you do not create an account. AI recognition can occasionally misread fields - any extracted data is a draft you must verify before relying on it. The endpoint accepts PDF or photo (JPG/PNG/WEBP) up to 8 MB, one upload per day per IP.
- NZ Post - address validation and postcode lookup. Only the address query is sent; no personal information is shared.
Cookies
We use a small number of first-party cookies. Some make the site work; one recognises a return visit so we can offer you a relevant product demo. They store no personal information, only a first-seen date and the general topics you read about, and we share nothing with third parties. No tracking pixels, no advertising cookies.
Bank transaction data
You can import bank transactions via CSV upload from your bank, or by connecting your Xero organisation so we can read the money-in side of the bank account you nominate there. Direct NZ Open Banking (CDR) connections are not available yet. This section explains what data we collect, how we use it, and your rights.
Data collected
- Bank account name and number (for identification only).
- Transaction history: date, amount, description, and merchant name.
How bank data is used
- To automatically match incoming payments to tenancies and track rent.
- To generate payment reports and detect arrears.
How bank data is stored
- Bank access tokens, and the Xero access tokens used to read a connected organisation, are encrypted at rest using AES-256-GCM encryption.
- Transaction data is stored in our New Zealand-hosted database (AWS Auckland, ap-southeast-6).
- Access is restricted to your account via database row-level security.
How bank data is not used
- We have read-only access - we cannot initiate payments or transfers.
- We do not sell, rent, or share your bank data with any third party.
- We do not use your bank data for advertising or profiling.
Data retention
- You can disconnect your bank account at any time from Settings > Bank Connections, and a connected Xero organisation from Accounting > Xero (or from Xero's own Connected Apps screen).
- Disconnecting immediately revokes access - we can no longer retrieve new data.
- Previously imported transactions remain in your account for reporting purposes unless you delete your account.
- On account deletion, all bank data is permanently deleted within 30 days, and all bank tokens are revoked.
Credit reporting (tenancy credit checks)
Our platform allows landlords to request a Tenancy Credit Check on a prospective tenant through Centrix, a licensed NZ credit bureau. This section explains how that data is handled, in accordance with the Credit Reporting Privacy Code 2020.
How credit checks work
- Credit checks are landlord-initiated. The landlord identifies a prospective tenant, requests a check, and pays the applicable fee.
- The prospective tenant must provide explicit consent before any check is submitted. Consent text version, timestamp, IP address, and request details are recorded.
- We act as the landlord's agent in submitting the enquiry. The landlord is the credit bureau's End User and the report is supplied to the requesting landlord and authorised delegated users.
How credit data is stored
- RentManager does not store the raw Centrix JSON or PDF report. We use a time-limited Centrix enquiry reference to retrieve the provider-held PDF and retain an access audit record. We do not retain a derived score.
- Report contents are not sent by email. An authorised user downloads the provider PDF through an authenticated RentManager session.
- A temporary download link is provided. RentManager and Centrix retention limits can end access.
How credit data is not used
- We do not sell, aggregate, or analyse credit data, and we do not make tenancy decisions based on it. We display the provider result; the tenancy decision remains the landlord's.
- Use is limited to the named tenancy screening purpose and authorised access for that request.
Applicant rights regarding credit data
- You can ask us what RentManager records we hold about a check, and ask the credit bureau for your own credit information under the Credit Reporting Privacy Code 2020.
- Disputes about the accuracy of credit information should be directed to Centrix, the credit bureau that issued the report.
- Deletion and retention requests are handled subject to Centrix's provider obligations and any records RentManager must retain for payment, consent, security, or legal compliance.
Tenant data and your obligations
You (as the landlord or property manager) are the data controller for tenant personal information. Under the Privacy Act 2020 you must tell tenants what information is collected and why, only collect information necessary for managing the tenancy, and keep it secure. RentManager NZ processes tenant data on your behalf as a data processor.
Your rights under the Privacy Act 2020
You have the right to:
- Access your personal information (IPP 6) - request a copy of all data we hold about you.
- Correct inaccurate information (IPP 7) - request correction of any errors.
- Delete your data - request account deletion, which permanently removes all data within 30 days.
- Export your data - request a machine-readable export of your property, tenancy, and transaction records.
- Complain to the Office of the Privacy Commissioner if you believe we have breached the Act.
To exercise any of these rights, contact . We will respond within 20 working days as required by the Privacy Act 2020.
Data retention
- Active accounts: Data is retained for as long as your account is active.
- Account closure: Your personal information (name, contact details, login credentials, tenant details, communications, and documents) is permanently deleted within 30 days, except where we are required to keep specific records by law (see Legal holds below).
- De-identified property data: After your account is closed, we may keep de-identified information about the property itself, such as rent amounts paid, expenses, and physical attributes like bedrooms and property type, which we may aggregate to produce market insights (for example, typical rents in an area). This information relates to the property, not to you: it is not linked to your account or to any named owner or tenant, and is not used to identify any individual. We treat it as information about a physical asset, not personal information under the Privacy Act 2020.
- Fraud prevention: For a limited period after closure we keep a one-way hashed form of your email address solely to detect sign-up abuse. It is not used for any other purpose and is removed when your account is fully deleted.
- Bank data: Previously synced transactions remain in your account for reporting unless you disconnect your bank or delete your account.
- Bank tokens: Revoked immediately on bank disconnection or account deletion.
- Usage analytics: Anonymous page-view data is retained for up to 90 days, and pseudonymous in-app activity events (tied to an internal account ID, not used to build a profile) for up to 180 days, then automatically purged.
- Server logs: Raw web server access logs are retained for up to 90 days, then automatically purged.
- Legal holds: Where retention is required by NZ law (e.g. tax records under the Tax Administration Act 1994), we retain only the minimum data necessary for the minimum required period (typically 7 years for financial records).
Breach notification
Under the Privacy Act 2020, we are required to notify both affected individuals and the Privacy Commissioner of any privacy breach that poses a risk of serious harm. In such an event we will:
- Notify affected users by email within 72 hours of becoming aware of the breach.
- Notify the Office of the Privacy Commissioner as required by the Act.
- Provide clear details of what data was affected, what we are doing to contain and remediate, and what steps you should take to protect yourself.
- Publish a notice on our website for transparency.
Information Privacy Principles
The Privacy Act 2020 sets out 13 Information Privacy Principles (IPPs) governing how personal information is collected, used, stored, and disclosed. Here is how we address each:
| IPP | Principle | How we comply |
|---|
| 1 | Purpose of collection | We collect information only for providing and operating the property management service. |
| 2 | Source of information | Information is collected directly from you, via bank connection with your explicit consent, from credit reporting agencies with the tenant's explicit consent, or from public reference databases (LINZ, NZ Post) for address validation. |
| 3 | Collection from subject | We collect information directly from the individual concerned. Tenant data is entered by the landlord as data controller. |
| 4 | Manner of collection | Collection is lawful, fair, and not unreasonably intrusive. We collect via web forms and authorised bank feeds only. |
| 5 | Storage and security | Core application data is stored in AWS Auckland; selected workflows send specified information to other providers. See Data and security for current scope. Encrypted at rest and in transit. Access controlled by RLS and authentication. |
| 6 | Access to personal information | You can access your data at any time within the application, or request a full export by contacting us. |
| 7 | Correction | You can edit your data directly in the application, or request corrections by contacting us. |
| 8 | Accuracy | We take reasonable steps to ensure data is accurate and up to date. |
| 9 | Retention | Personal information is retained only while your account is active and permanently removed within 30 days of deletion. De-identified property data that is not personal information may be kept for market insights (see Data retention). |
| 10 | Use limitation | Data is used only for the purpose it was collected. We do not sell data or use it for advertising. |
| 11 | Disclosure limitation | Data is not disclosed to third parties except as described in this policy. |
| 12 | Unique identifiers | We use internal UUIDs only - we do not assign or require government-issued identifiers. |
| 13 | Overseas disclosure | Core application data is stored in AWS Auckland. Outbound email uses Amazon SES in Sydney, and selected workflows may send specified information to other providers. See Third-party services and Data and security for current scope. |
Changes to this policy
Material changes will be notified by email or a banner in the application. Continued use of the service after changes constitutes acceptance.
Contact
RentManager NZ Limited
NZBN 9429053511362
IRD 148-225-788