Skip to content
RentDariRentDari

Sub-processors

In force since4 min read

RentDari relies on third-party providers to operate its service. Where those providers process personal data on our behalf, they are sub-processors within the meaning of Article 28 of the General Data Protection Regulation.

This page gives the complete, up-to-date list. It forms an integral part of our data processing agreement and should be read together with our Data security page.

1. How to read this list

Two separate lists, because the responsibilities differ:

  • The first lists the providers RentDari relies on to deliver the service. They are involved for every customer, without any action on their part. These are our sub-processors proper.
  • The second lists services a customer switches on themselves in their workspace. Until they are switched on, no data is sent to them. For several of them, the customer contracts directly with the provider and supplies their own credentials.

Each entry states the purpose, the data concerned and where it is processed.

2. RentDari's sub-processors

  • Akamai Technologies (Linode) — Hosting of the application infrastructure (Kubernetes). Data: all data processed by the platform, while being processed. Location: European Union.
  • DigitalOcean — Managed PostgreSQL database. Data: all application data at rest: accounts, properties, reservations, guests, owner accounting. Location: European Union.
  • Google Cloud Storage — File storage. Data: property photos, arrival-guide media, field-operation photos, and identity documents submitted by guests during online check-in. Location: European Union.
  • Stripe — Payment and management of RentDari subscriptions. Data: workspace name and billing email address. No card data passes through our servers: entry happens on a Stripe-hosted page. Location: Ireland · United States.
  • ZeptoMail (Zoho) — Transactional email delivery. Data: name and email address of recipients (users, guests, owners), message content, and owner statements sent as attachments. Location: European Union.
  • PostHog — Product usage analytics. Data: user identifier, email address and name, pages viewed and usage events. Session recording is disabled on guest-facing pages. Location: European Union.
  • Sentry — Application error monitoring. Data: technical stack trace, address of the page concerned, technical identifier and IP address of the user. Location: Germany.
  • OneSignal — Push notification delivery. Data: identifier of the recipient user, notification title and body — which may mention a guest name or a message excerpt. Location: United States.
  • Apple (APNs) · Google (FCM) — Delivery of push notifications to devices. Data: technical device token and notification content. These services are inseparable from push notifications on iOS and Android. Location: United States.
  • Expo (EAS) — Distribution of mobile application updates. Data: installation identifier, application version and IP address at update time. Location: United States.
  • Google Maps Platform — Geocoding and map display of addresses. Data: property address entered by the customer, geographic coordinates, and browser IP address when a map is displayed. Location: United States.
  • Channex.io — Connection to distribution platforms (channel manager). Data: property address and characteristics, rates and availability, then, for incoming reservations, the guest name, email address, phone number and language, together with messages and reviews exchanged. Location: to be confirmed.
  • GraphQL Hive (The Guild) — Technical monitoring of the programming interface. Data: name and shape of the queries sent to the API, response times and error rates. No personal data is transmitted. Location: to be confirmed.
  • OpenRouter · Z.AI — Automatic content translation, triggered by the customer. Data: only text written by the customer (contract templates, message templates, arrival guide). Template variables are masked before sending: neither guest names nor access codes are transmitted. Location: to be confirmed.

3. Services activated by the customer

The following services receive no data until the customer switches them on in their workspace.

  • PriceLabs — Dynamic pricing. Data: reservation dates, amounts and status, without any guest-identifying data, together with the email address of the customer's PriceLabs account. Location: to be confirmed.
  • Tuya IoT — Smart locks and per-stay door codes. Data: device identifier and validity window derived from the stay dates. No guest name or email address is transmitted. The customer contracts directly with Tuya and supplies their own credentials. Location: European Union.
  • iCal — Import and export of availability calendars. Data: the feed we publish contains only busy periods and the property name, never guest data. On import, we contact the address the customer entered. Location: determined by the customer.
  • MCP · IA — Assistance through an artificial-intelligence tool chosen by the customer. Data: the workspace data the tool reads, including guest messages, reservations and owner statements. RentDari holds no model credentials: the artificial-intelligence provider is the customer's own, and the customer contracts with it directly. Location: determined by the customer.
  • Google · Apple — Sign-in with a Google or Apple account. Data: email address and profile elements transmitted at sign-in, only if the user chooses this authentication method. Location: United States.

4. Distribution platforms

When a customer connects a property to a distribution platform — Airbnb, Booking.com and the other available channels — the property details, rates and availability are sent to that platform, and reservations originating from it reach us with the guest's contact details. These exchanges pass through our distribution connector.

Those platforms determine the purposes of their own processing: they are not our sub-processors but separate controllers, with which the customer holds their own contractual relationship.

5. Changes to this list

Any addition or replacement of a sub-processor is published on this page, and the date at the top is updated.

A customer may ask to be notified in advance of such changes by writing to [email protected]. They then have thirty days from the notification to raise a reasoned objection, under the conditions set out in Article 5 of our data processing agreement.

6. Contact

For any question about this list, about a particular provider, or to obtain the corresponding contractual documentation: [email protected].