Legal

Privacy Policy

Last updated: September 1, 2026

This Privacy Policy explains how Rentibly ("we", "us", "our") collects, uses, and discloses information when you use the Rentibly Hub platform, the Rentibly mobile inbox PWA, our marketing site, and any related services (collectively, the "Service").

1. Information we collect

We collect information that you provide to us directly, information we receive automatically when you use the Service, and information we receive from third parties such as channel partners and payment processors.

  • Account information. Name, email address, phone number, company name, role, and password (hashed).
  • Operational data. Properties, bookings, contacts (guests, owners, vendors), conversations, tasks, financial records, and configurations you upload to or generate within the Service.
  • Communications data. Email, WhatsApp, SMS, and OTA message content processed through connected channels.
  • Payment data. Last four digits of payment cards, transaction amounts, and metadata. Full card data is held by Stripe.
  • Technical data. IP address, browser, device, timestamps, and usage logs.

2. How we use your information

We use the information to provide and improve the Service, including:

  • Operating the Service, including booking management, communications, payments, and reporting.
  • Authenticating users and securing accounts.
  • Sending operational notifications and supporting your team.
  • Improving the Service through analytics on aggregated, de-identified usage.
  • Complying with legal obligations.

We do not sell your data. We do not sell your guests' data. We do not use the content of your guest conversations to train large language models without your explicit configuration.

3. Data sharing

We share data only with:

  • Service providers who help us operate the platform — including our hosting, database, content delivery, payment processor, messaging provider, and AI providers. Each is contractually bound to handle your data only as instructed.
  • Channel partners (Airbnb, Booking.com, Bayut, Property Finder, etc.) when you connect those channels to your account.
  • Authorities when required by law, and only to the extent strictly necessary.

4. Google user data (Calendar Connect)

If you connect your Google account via Settings → Calendar Connect, Rentibly requests access to your Google Calendar events (the calendar.events scope) and your basic profile (email address and name). Rentibly uses this access solely to:

  • create, update, and cancel calendar events for meetings you schedule in Rentibly, so invitations are sent from your own email address;
  • display your Google Calendar events alongside your Rentibly meetings in the Rentibly Connect calendar, including an event's details (title, time, location, description, and guest responses) when you open it;
  • check your availability when you schedule a meeting, to warn you about conflicts;
  • let you manage your own Google events from within Rentibly — create, edit, move, resize, and delete — with Google notifying your guests exactly as if you had made the change in Google Calendar.

Rentibly does not store your Google Calendar event content on its servers — events are fetched from Google when you view your calendar and discarded after display. The only Google-derived data Rentibly stores is: your OAuth tokens, encrypted at rest (AES-256-GCM); the email address of the connected account; the RSVP responses of guests on events Rentibly itself created, to show meeting attendance inside Rentibly; and opaque Google event identifiers when you apply a personal color tag to an event. Rentibly does not share Google user data with third parties and does not use it for advertising. Google user data is never transmitted to any AI or machine-learning service (first- or third-party) and is never used to create, train, or improve any AI or machine-learning model. You can revoke access at any time from your Rentibly settings (Disconnect) or at myaccount.google.com/permissions; on disconnect, stored tokens are deleted.

Rentibly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Google user data (Business Profile)

If you connect your Google account via Settings → Integrations → Google Business Profile, Rentibly requests access to the business listings you manage (the business.manage scope). Rentibly uses this access solely to:

  • list the business locations on your profile, so you can choose which ones to connect;
  • read the reviews left on those locations — the star rating, the review text, the reviewer's public display name, and the dates;
  • show those reviews to you inside Rentibly, and — only on the pages where you explicitly add a reviews section — on your Rentibly-hosted website;
  • publish your replies to those reviews when you write them in Rentibly.

Unlike calendar data, review content is stored on Rentibly's servers — a website cannot display reviews it has not kept. Rentibly stores the review text and star rating, the reviewer's public display name exactly as Google publishes it, the review and reply dates, your own published replies, and Google's opaque review and location identifiers. It also stores your OAuth tokens, encrypted at rest (AES-256-GCM), and the email address of the connected account. Rentibly never displays more of a reviewer's name than Google already shows publicly, and you may choose to show less — a first name only, initials, or no name at all. Rentibly does not combine a reviewer's Google display name with any other personal data it holds.

Rentibly does not share Google user data with third parties and does not use it for advertising. Google user data is never transmitted to any AI or machine-learning service (first- or third-party) and is never used to create, train, or improve any AI or machine-learning model — the automatic sentiment analysis Rentibly applies to reviews from other sources is not applied to reviews obtained from Google. You can revoke access at any time from your Rentibly settings (Disconnect) or at myaccount.google.com/permissions; on disconnect, stored tokens are deleted and the reviews Rentibly obtained from Google are removed from your website and from Rentibly.

Rentibly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Data residency

By default, data is hosted in the European Union region of our infrastructure providers. Enterprise customers may select alternative regions (US, UAE) as part of their contract.

7. Retention

We retain your account data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations. On request, we provide a complete data export and delete your data within 30 days, subject to legal retention requirements (e.g. tax records).

8. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, and delete your personal data. To exercise these rights, contact us at hello@rentibly.com.

9. Security

We use industry-standard security measures including encryption in transit (TLS), encryption at rest, JWT-based authentication with MFA support, role-based access control, and audit logging. No system is perfectly secure; we work continuously to improve.

10. Contact

Questions about this policy: hello@rentibly.com

Be among the first

Rentibly is rolling out to new operators in waves. Join the waitlist for early access, founder pricing, and a personal onboarding call.

No spam. We'll only email you about onboarding.

You're on the list — we'll be in touch within 48 hours.