Rent Manager Uganda ("Rent Manager", "we", "us") is a rent-collection and tenant-management
platform used by landlords, their tenants, and platform administrators. This page explains what
personal data we collect through the platform, why, who we share it with, and how you can ask
about or control your own data - whether you're a tenant added by a landlord, a landlord running
your own portfolio, or someone we're in touch with about either.
If your landlord manages your tenancy through Rent Manager, or you manage tenants through it
yourself, this policy covers you. Tenants are typically added to the system by their landlord,
not by signing up directly - you're notified by email with your login details the moment an
account is created for you, and this policy is what that notice is pointing to.
2. What we collect
Exactly what we hold depends on your role on the platform:
Tenants
Full name, phone number, email address, move-in date, which house/unit you're assigned to,
your login password/PIN (stored as an irreversible hash, never in plain text), rent payment
and receipt history, any arrears/opening balance recorded against you, any maintenance
requests you submit, rent notices sent to you, messages you send in your estate's group
chat or directly to your landlord, any messages you report and anyone you block in direct
messages (see section 3), whether you've accepted our messaging conduct policy and when,
and a record of when you last logged
in. If you upload a profile photo, see the storage-mode note below - whether we hold it at
all depends on your landlord's admin's current setting.
Landlords
Full name, phone number, email address, your login password (hashed), the estates/houses/
tenants/staff you manage, a record of your last login and recent chat activity, any
messages you report and anyone you block in direct messages (see section 3), whether you've
accepted our messaging conduct policy and when, and any branding images you choose to upload - logo, company stamp, and
signature - which get stored and automatically applied to the receipts and reports the
system generates on your behalf. (Branding upload is a landlord-only feature - administrator
accounts don't have it.)
Full name, phone number, email address (optional), your login password/PIN (hashed), which
estate you're assigned to, your role label, a record of your last login/recent activity,
and whichever specific permissions your landlord has switched on for your account - viewing
tenants, managing maintenance requests, and/or viewing payment status. You only see what's
explicitly granted; nothing is on by default when a landlord creates your account.
Administrators
Full name, email address, a hashed password, and a record of your last login - platform-
operator accounts used to support landlords and keep the system running.
Payment records
Transaction ID, amount, payment method, the month it covers, and - because every payment
is cross-checked against the real mobile-money/bank transaction before it's recorded - the
actual confirmation message text (e.g. an MTN MoMo or Airtel Money SMS),
which can include the sender's name and phone number when someone other than the tenant
made the payment on their behalf.
Profile photos - server-stored or device-only, by admin setting. Our administrators
control, platform-wide, whether uploaded profile photos (tenant, landlord, or staff avatars) are
stored on our servers or not. In server mode, an uploaded photo is saved to our
database, validated and re-processed first, and becomes visible to whoever would normally see that
profile (e.g. a landlord viewing their own tenant). In device-only mode, a photo
you select never leaves your device at all - it's used locally in your browser/app and is never
uploaded to or stored on our servers; our server actively rejects the file if a request to store one
reaches it anyway. Check with your landlord or our admin team if you're unsure which mode is
currently active.
If you upload a screenshot or PDF of a payment confirmation instead of pasting
the text directly, that image may be sent to Amazon Web Services' Textract service for automatic
text extraction (OCR). This only happens for that specific upload - not for payments entered as
plain text, which covers most everyday use.
3. Chat and direct messages: conduct policy, reporting, and blocking
Before sending your first message - in your estate's group chat or a direct message with your
landlord - you're shown a short conduct policy and asked to agree to it: no threats, harassment,
hate speech, sexual or violent content, illegal content, or spam. This is a one-time acknowledgment;
once you've agreed, you won't be asked again on later messages. We store the date and time you
accepted it, not the checkbox click itself.
Reporting. If you receive a message you believe breaks that policy, you can report
it directly, with an optional written reason. The report - which message, who sent it, your name,
and your reason if you gave one - notifies both your landlord and our admin team; our admin team
reviews reports and marks them handled. This is separate from, and in addition to, a landlord or
admin's own existing ability to remove a message outright.
Blocking is direct-message-only and one-directional. In a direct-message thread, you
or the other party (landlord or tenant) can block each other independently - blocking someone stops
their messages from reaching you; it doesn't stop you from messaging them, and it doesn't affect the
estate group chat, which uses reporting and existing landlord/admin moderation instead. If you try to
message someone who has blocked you, you're told clearly that the message wasn't delivered, with a
note to contact support if you think it's a mistake - we don't silently discard it without telling
you. Either side can unblock at any time, which immediately restores messaging both ways. This is
distinct from a landlord or admin restricting an account on their side of a conversation, which
remains a separate, existing control.
4. Why we collect it
To let you log in securely and see only what belongs to you or your tenants
To record rent payments accurately and verify them against the real transaction before they
touch anyone's balance
To generate and deliver receipts, rent notices, and account/payment notifications
To detect and reject duplicate or fraudulent payment claims
To provide account recovery (temporary login codes) when you can't sign in
We don't use your data for advertising, and we don't sell it to anyone.
5. Who we share it with
We use a small number of outside services to actually run the platform. Each only sees what it
needs to do its specific job:
Email delivery
An SMTP-based email provider - your email address and message content, for account,
payment, and notification emails.
Optional OCR
Amazon Web Services (Textract), only for screenshot/PDF uploads of payment confirmations -
see the note above.
Hosting & database
Vercel (application hosting) and a managed PostgreSQL database provider - both store and
process data on our behalf to keep the platform running, under their own security
commitments.
We don't currently integrate with any payment processor. Rent is paid directly
between tenant and landlord through mobile money (Airtel Money, MTN MoMo) or bank transfer, entirely
outside this platform - we never handle, touch, or have access to the money itself. What we store
is a record of that transaction (see "Payment records" above), submitted by whoever's confirming
it, and checked against the real confirmation message for accuracy.
Where your data is physically stored depends on our hosting and database
providers' server regions, which may be outside Uganda. We're in the process of confirming this
is configured consistently with the Data Protection and Privacy Act, 2019 - if you have questions
about this, contact us using the details below.
6. How long we keep it
We keep your data for as long as your tenancy or landlord account is active, and afterward for
reasonable record-keeping (rent/payment history has real accounting and legal value even after a
tenancy ends). Removing a single tenant from a house moves their record to a recycle bin rather
than deleting it immediately, so a mistaken removal can be undone - contact us if you'd like a
record permanently deleted instead.
If a landlord's subscription access is revoked or expires, that only locks login
access - it does not delete anything. Every estate, house, tenant, payment, and receipt under that
account stays fully intact in our records. Tenants under a paused landlord can send a message
directly to our admin team from within the app if something seems wrong; we act on it as a support
request, not a stored complaint record. If access is later restored, everything picks back up
exactly as it was, with nothing lost.
Inactive-account check-in email. If a landlord or tenant account shows no activity
for 60 days - no login, and for a tenant, no payment, message, or maintenance request recorded on
their tenancy either - we send a one-time email to the address on file letting them know their
account currently looks inactive. Logging back in at any point clears this; it's a check-in, not an
action taken against the account.
If an administrator permanently deletes a landlord account (a separate, explicit
action from revoking access), that is a genuine, immediate, and permanent deletion - the landlord
account and everything under it (estates, houses, tenants, staff, payments, receipts, messages) is
removed at once and cannot be recovered. This is different from, and more final than, the tenant
recycle-bin described above.
7. How we protect it
Passwords and PINs are hashed - we can't see or recover your actual password, and neither can
anyone who gains access to the database
All traffic to the platform is encrypted (HTTPS), enforced site-wide
Repeated failed login attempts temporarily lock an account rather than allowing unlimited
guesses
Changing your password/PIN signs you out of every other device automatically
Uploaded images are validated and re-processed before storage, not saved as-received
Access is role-based and scoped: a landlord only ever sees their own estates/tenants/staff, a
tenant only ever sees their own account, and estate staff (caretakers etc.) only see the
specific permissions their landlord has explicitly switched on for them - nothing is visible by
default
We record when each account last logged in, which helps us detect and investigate unusual
access - admins can see this for every account, and landlords can see it for their own
tenants
8. Your rights
You can ask us what personal data we hold about you, ask us to correct anything inaccurate, or ask
us to delete your account and data - see the dedicated section below for exactly how deletion
works and what it covers. For anything else (a data request, a correction, a general question),
contact us using the details in section 12 - we'll aim to respond within a reasonable time.
9. How to delete your account and data
To request that your Rent Manager account and its associated personal data be deleted, email
rentmanagerug@gmail.com
from the address on your account (or, if you're emailing from elsewhere, include your full name and
the phone number your account is registered under) with "Delete my account" in the
subject line. We'll verify it's really you, then act on it - typically within a few business days.
What happens next depends on your role:
Tenants: your personal profile data - name, phone number, email address, and
login credentials - is removed from our systems. Because rent/payment records have ongoing
accounting value to your landlord even after your tenancy ends, payment and receipt history tied
to your tenancy is retained under your landlord's account (with no fixed expiry - it's kept
indefinitely for record-keeping) unless you specifically ask us to remove that too.
Landlords: deleting your account is a single, explicit, admin-performed action
that removes it and everything under it - estates, houses, tenants, staff, payments, receipts,
and messages - immediately and permanently. This cannot be undone, so we'll confirm directly
with you by email before carrying it out.
This is different from a landlord simply removing one tenant from a house, which moves that
tenant's record to a recycle bin rather than deleting it (see section 6) - that's meant to undo
accidental removals, not to fulfil a deletion request. If you want your data gone rather than
recycle-binned, say so explicitly in your email and we'll handle it as a real deletion instead.
10. Cookies
We use one functional cookie to keep you logged in between requests. We don't use advertising or
cross-site tracking cookies.
11. Changes to this policy
If this policy changes in a material way, we'll update the date at the top of this page and, where
appropriate, let you know through the same notification channels we already use for your account.