Privacy policy
Last updated 9 September 2026.
Who we are
LetBuddy ("LetBuddy", "we", "us") provides a property management platform for UK residential lettings — used by landlords and by agents managing on their behalf — covering compliance tracking, rent, maintenance, documents, and tax. This policy explains what personal data we collect, why, and what rights you have over it.
The data controller for your personal data is LETBUDDY LTD, a company registered in Scotland under company number SC899802, with its registered office at 24 Manor Road, Gartcosh, Glasgow, Scotland, G69 8AN. LetBuddy ran as an unincorporated business before 20 August 2026; from that date the company is the controller for all personal data, including anything collected before incorporation, and this policy otherwise applies unchanged.
Registered with the Information Commissioner's Office, registration number ZC229182.
For any question about this policy, contact hello@letbuddy.co.uk.
What data we collect
- Account data: name, email address, and password (stored as a salted hash, never in plain text) when you sign up.
- Property and tenancy data: property addresses, rent amounts, tenancy dates, and tenant contact details you enter to use the app.
- Tenancy applications: if you advertise a property through LetBuddy, what prospective tenants tell you on the application form — contact details, address history, employment and income, household, and anything they choose to declare. You are the controller of that data; we hold it for you, and you can delete any application in one click. Nothing is shared with anyone unless you ask for it: if you start a referencing check with a connected provider, we send that provider the applicant's name, contact details and the advertised rent so they can run the check the applicant consented to — and nothing else, ever, without your action.
- Compliance documents: certificates (gas safety, EICR, EPC, etc.) you upload, including any personal data they contain.
- Financial data: rent payment records, expenses, and — if you choose to import one — transaction data from a bank statement you upload.
- Tax data: if you connect HMRC's Making Tax Digital service, the business and income data needed to prepare and submit that return.
- Billing data: we never see or store your card details directly — these are handled entirely by our payment processor, Stripe.
- Usage data: standard technical data such as IP address and browser type, collected automatically to keep the service secure and reliable.
- Page views: we count visits to our public pages using Vercel Web Analytics — which page, the site that referred you, a broad location, and the kind of device. It sets no cookies and assigns you no identifier, so these figures are aggregate counts rather than a record of an individual, and nothing in them follows you between visits or to another site. See our cookie policy for why we chose a tool that works this way.
Why we process this data
We process your data to provide the service you've signed up for: tracking compliance deadlines, recording rent and expenses, generating tax summaries, and sending you reminders. Where we rely on a specific legal basis under UK GDPR, it is either performance of a contract (providing the service you've subscribed to), legitimate interests (keeping the service secure and improving it), or your consent (for optional features like HMRC integration, which you actively choose to set up).
Who we share data with
We don't sell your data. We share it only with the third-party services that power specific features of LetBuddy, strictly to deliver those features:
- Supabase — hosts our database and handles authentication.
- Stripe — processes subscription payments.
- Resend — sends transactional emails (rent reminders, compliance alerts, maintenance updates).
- HMRC — receives the tax data needed to submit your return, if you choose to connect Making Tax Digital.
- GitHub — stores our nightly backups, so your records survive a failure at our database provider. The backup is encrypted before it leaves our systems, with a key GitHub does not hold, and each one is deleted automatically after 90 days.
- Anthropic — powers three optional AI features: reading uploaded compliance documents to extract certificate details (expiry dates, property references); drafting trade quote-request emails (using the job description, property address, and your trade contact's details); and triaging tenant-submitted maintenance reports to draft a suggested reply (using the tenant's report and property details). Each only runs when you actively use that feature.
- Google — powers the optional “search for local trades” button on a maintenance job, which looks up nearby businesses through the Google Places API. It receives only the trade you searched for and the property's postcode, sent as a single line of text such as “plumber near EH1 1AA, UK”. No tenant details, no job description, and no name or full address are sent, and it runs only when you click that button — never automatically.
Each of these providers only receives the data necessary for the feature they support, and is bound by its own data protection obligations.
Where your data is processed
Our database — where your property, tenancy, and financial records are stored — is hosted by Supabase in the European Economic Area (Stockholm, Sweden).
The application runs on Vercel, and the server-side code that reads and writes your records — every page and every action — executes in Stockholm, Sweden, alongside the database. Ahead of that sits Vercel's global routing layer, which terminates the connection at whichever location is nearest to you (London, for most of our landlords) and sees the technical details of the request rather than your records. Vercel Inc. is a US company, so we treat that as a transfer outside the UK and rely on the same safeguard either way: Vercel Inc. is an active participant in the UK Extension to the EU-U.S. Data Privacy Framework, which is the safeguard we rely on for that transfer.
Stripe, Resend, and Anthropic also process limited data outside the UK under their own transfer safeguards. HMRC submissions stay within the UK. You can read the technical detail on our security and compliance page.
How long we keep data
We keep your data for as long as your account is active. If you close your account, we delete your personal data within a reasonable period, except where we're required to retain certain records for longer (for example, financial records relevant to a submitted tax return).
Ending or losing a paid subscription is not account closure and does not delete anything. Properties beyond your free one are archived, and everything attached to them is retained in full and restored if you subscribe again. Only you can erase your records, from Settings, and you can export all of them at any time.
Your rights
Under UK GDPR, you have the right to access, correct, delete, export, or restrict the use of your personal data, and to object to certain processing. Two of them don't need us at all: Settings has a one-click export of everything on your account and a permanent account deletion, both self-service. For anything else, email hello@letbuddy.co.uk. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO).
Security
We use industry-standard measures to protect your data, including encryption in transit and at rest, and access controls that restrict data to your own account. The most sensitive items — your National Insurance number and any HMRC authorisation tokens — get a second layer of application-level encryption on top of that, with the key held outside the database. No system is perfectly secure, but we take reasonable steps to protect what you share with us, and we set out exactly what those steps are on our security and compliance page.
Changes to this policy
If we make material changes to this policy, we'll notify you by email or via a notice in the app before the changes take effect.
