Skip to content
RentDariRentDari

Privacy Policy

In force since3 min read

1. Preamble and Data Controller

The purpose of this privacy policy is to set out, for users of the site RentDari :

  • How their personal data is collected and processed.
  • What rights users have over that data.
  • Who is responsible for the processing of the personal data collected and processed.

The data controller is El Mehdi Bouhou (Sole Trader), trading under the business name RentDari, who can be contacted at the email address: [email protected].

2. Data Collected

In the course of your use of the Service, we may collect the following data:

A. Data collected directly from you

  • Identification data: Last name, first name, email address.
  • Security data: Password (encrypted).
  • Financial data (where applicable): Payment history (through our secure provider).

B. Data you enter in the application

To provide you with the rental management service, you may need to enter data concerning third parties (your tenants):

  • Tenants' names and contact details.
  • Information about the rented properties.
  • Rent and charge amounts.

You act as the Data Controller for this data, and RentDari acts as the Data Processor. We undertake to use this data solely to deliver the service and never to sell it.

C. Technical data

  • IP address.
  • Browser type and version.
  • Operating system.
  • Connection and error logs.

3. Purpose of Processing

Personal data is collected for the following purposes:

  • Managing your user account and access to the service.
  • Providing the rental management features (document generation, calculations).
  • Improving the quality of our services and fixing bugs.
  • Communicating with you (customer support, important notifications).
  • Complying with our legal and regulatory obligations (accounting, fraud).

4. Recipients of the data

The data collected is intended for the exclusive use of RentDari. It may however be passed on to our third-party technical subprocessors who help us deliver the service:

  • Hosting and database: secure servers (PostgreSQL) located in the European Union.
  • File storage: Google Cloud Storage.
  • Transactional email: ZeptoMail.
  • Payment: Stripe.

All our subprocessors are bound by a strict obligation of confidentiality and by GDPR compliance.

RentDari does not sell, rent out or trade your personal data to third parties.

5. Retention period

Your personal data is kept for as long as your account is active. If the account is closed or remains inactive for a long period (more than 3 years), we will delete or anonymize it, unless a legal obligation requires otherwise (e.g. keeping invoices for 10 years).

6. Your Rights

In accordance with the applicable regulations (GDPR and Law 09-08), you have the following rights:

  • The right to access, rectify and erase your data.
  • The right to restrict processing.
  • The right to data portability.
  • The right to object to processing.

You can exercise these rights by contacting us at [email protected].

7. Guest risk reporting network

RentDari offers hosts a reporting network that warns them when a guest has been reported by other hosts (repeated cancellations, no-shows, damage, fraudulent payment, abusive behaviour). Participation is optional and off by default: a host must explicitly enable it in their settings.

What the network shares between hosts is deliberately minimal:

  • Transformed identifiers: phone numbers, emails and ID document numbers are NEVER shared in the clear. They are converted into irreversible cryptographic fingerprints (HMAC-SHA256) that can only link two reports when the identifier is exactly the same.
  • Reason category only: only the standardised reason travels, as a counter.
  • Never shared: the guest's name, the host's internal notes, their contact details, the exact date of a report, or the identity of the reporting host.
  • Anonymity threshold: no signal is shown until at least two distinct other hosts have reported the same person, so a signal can never point at one specific host.

Legal basis: the legitimate interest of hosts in preventing fraud and unpaid stays (GDPR art. 6.1.f), balanced against the rights of data subjects by the safeguards above.

Retention: a report stops counting on the network after 12 months, or immediately if the host who filed it retracts it.

Your rights: anyone may ask whether they appear in the network, request rectification or erasure, and object to the processing, by writing to [email protected]. On erasure, the corresponding fingerprints are deleted: no lookup can reach that person again.

8. Cookies

Our site uses cookies to improve the user experience (audience measurement and preferences). You can refuse or delete them at any time through your browser settings.