How we protect your data
Last updated: April 2026
RentManager NZ is built by a New Zealand landlord, for New Zealand landlords and property managers. Your property data, tenant details, and financial information deserve the same protection as your bank account. Here is how we look after it.
The main application database and file storage use AWS Auckland. Outbound email and selected provider workflows may process limited information elsewhere. See Data and security for current scope.
Your password is scrambled before it is stored. Nobody at RentManager can read it - not even us.
Your data is completely separated from every other landlord's data. This is enforced by the database itself, not just our code.
Bank sync is read-only - we can see transactions come in, but we cannot move money, make payments, or change anything.
Your data is backed up hourly and stored in a separate location within New Zealand. We keep 7 days of backups.
If there is ever a data breach, we will email you within 72 hours and report it to the NZ Privacy Commissioner.
You can import bank transactions via CSV upload from your bank. If you use Xero and your bank feed already reaches it, you can connect Xero and we read the money-in side of the account you nominate: read-only, revocable from Xero or RentManager at any time. Direct NZ Open Banking (CDR) connections are not available yet.
When an authorised landlord requests a credit report after the prospective tenant gives consent, the tenant's data receives additional protections:
We follow the Privacy Act 2020 and align our practices with the NZ Information Security Manual. All 13 Information Privacy Principles are addressed - see our Privacy Policy for the full mapping.
For technically minded readers, here is more detail on how we implement the protections described above.
Every database query is scoped to your account using PostgreSQL Row-Level Security (RLS). This is a database-enforced boundary - even if an application bug occurs, it cannot expose another landlord's data. Each request sets the owner context before any query executes, and the database rejects any attempt to access rows belonging to a different account.
| Framework | Status |
|---|---|
| NZ Privacy Act 2020 | Compliant - all 13 IPPs addressed |
| NZISM | Aligned - encryption, access control, logging |
| NIST SP 800-63B | Aligned - password policy, MFA, sessions |
| NZ data sovereignty | Enforced - AWS Auckland only |
| Credit Reporting Privacy Code 2020 | Compliant - explicit consent, audited landlord-initiated checks, provider-controlled report retention |
| PCI DSS | Delegated to Stripe - we never handle card data |
If you discover a security issue, please let us know at . We will respond within 48 hours and will not take legal action against anyone who reports issues in good faith.
Contact us at - we are happy to explain anything on this page in plain English.