Last updated: April 2026
RentManager NZ is built by a New Zealand landlord, for New Zealand landlords and property managers. Your property data, tenant details, and financial information deserve the same protection as your bank account. Here is how we look after it.
Everything is stored on servers in Auckland. Your tenant information and financial records never leave the country.
Your password is scrambled before it is stored. Nobody at RentManager can read it - not even us.
Your data is completely separated from every other landlord's data. This is enforced by the database itself, not just our code.
Bank sync is read-only - we can see transactions come in, but we cannot move money, make payments, or change anything.
Your data is backed up every day and stored in a separate location within New Zealand. We keep 7 days of backups.
If there is ever a data breach, we will email you within 72 hours and report it to the NZ Privacy Commissioner.
You can import bank transactions via CSV upload from your bank. Live bank sync via NZ Open Banking (Consumer Data Right) is coming soon.
If a prospective tenant uses our Apply portal to obtain a credit report, their data receives additional protections:
We follow the Privacy Act 2020 and align our practices with the NZ Information Security Manual. All 13 Information Privacy Principles are addressed — see our Privacy Policy for the full mapping.
For technically minded readers, here is more detail on how we implement the protections described above.
Every database query is scoped to your account using PostgreSQL Row-Level Security (RLS). This is a database-enforced boundary - even if an application bug occurs, it cannot expose another landlord's data. Each request sets the owner context before any query executes, and the database rejects any attempt to access rows belonging to a different account.
| Framework | Status |
|---|---|
| NZ Privacy Act 2020 | Compliant - all 13 IPPs addressed |
| NZISM | Aligned - encryption, access control, logging |
| NIST SP 800-63B | Aligned - password policy, MFA, sessions |
| NZ data sovereignty | Enforced - AWS Auckland only |
| Credit Reporting Privacy Code 2020 | Compliant - tenant-initiated checks, explicit consent, encrypted storage |
| PCI DSS | Delegated to Stripe - we never handle card data |
If you discover a security issue, please let us know at . We will respond within 48 hours and will not take legal action against anyone who reports issues in good faith.
Contact us at - we are happy to explain anything on this page in plain English.