Data deletion

Your data.
Your call.

Request deletion of your Rento account and the personal information we hold about you. Effective date: 13 June 2026. Last updated: 13 June 2026.

Introduction

This page explains how to request deletion of your Rento account and the personal information we hold about you. It is provided in compliance with the Protection of Personal Information Act 4 of 2013 ("POPIA") and with the social-login platform requirements set by Facebook (Meta) and Google.

It must be read together with our Privacy Policy, which sets out what personal information we collect, who we share it with, and your full rights under POPIA.

If you signed up to Rento using Facebook Login or Google Sign-in, deleting your Rento account also revokes Rento's access to your social-provider profile. It does not delete your Facebook or Google account itself — that has to be done directly with the relevant provider.

How to request deletion

Email privacy@therento.com from the email address on your Rento account, with the subject line "Delete my Rento account". Include:

  • Your full name as it appears on the account.
  • The email address and (if applicable) mobile number associated with the account.
  • Your role on the Platform — Tenant, Landlord, Agency Admin, or Agent.
  • (Optional) The reason for your request. This helps us improve and is not required.

If you cannot send the request from the email address on file, we will ask for additional information to verify your identity before processing the request (e.g. a copy of your ID document, or confirmation through your registered mobile number). This is to protect you against unauthorised deletion of your data by a third party.

Postal address (if you prefer to write to us): Rento, 80 Strand Street, Cape Town, South Africa, marked for the attention of the Information Officer.

What we delete

On a verified deletion request, we delete or irreversibly anonymise the following from Rento's systems (primarily the Rento application database hosted on Azure SQL, and supporting Azure Blob Storage):

  • Account profile — full name, email address, mobile number, hashed password, role, profile photo, two-factor authentication secrets, recovery codes, and active magic-link tokens.
  • Social-login linkages — Facebook and Google UserSocialLogins records, including provider user IDs and access tokens.
  • Tenant or Landlord profile — application drafts, preferences, dependents, pet/smoker declarations, employer contact details, and any uploaded supporting documents that are not attached to a finalised lease (see "What we keep").
  • Bank-statement and supporting-document uploads stored in Azure Blob Storage (rentostorage account) that are not attached to a finalised lease or a closed transaction.
  • In-Platform messages that you have sent and that are not part of an active conversation with another User. Messages received by other Users will remain in their mailboxes — we cannot reach into another User's data.
  • Help Centre AI bot conversations (BotConversations, BotMessages), support tickets, and ticket attachments you have authored.
  • Search history, saved properties, notification preferences, and UI preferences (e.g. sidebar state).
  • Device, IP, and session metadata held in Rento's primary database, including any non-essential analytics events tied to your account ID.
  • Marketing-channel records — your subscription state with SendGrid (transactional email provider). Transactional delivery logs are aged out per "What we keep".
  • SMS opt-in/opt-out records held by Twilio under Rento's account, where applicable.

What we are required to keep, and why

Some information must legally or operationally be retained after account closure. Such records are access-restricted, used only for the purposes set out below, and never used for marketing.

  • Signed lease agreements, addenda, suretyships, and handover documents, together with their signature audit trail (timestamps, IPs, OTPs, signing certificates) — retained for the contract retention period (typically 5–7 years after the lease ends) for legal, regulatory, and audit reasons. Documents and audit data are held by Rento and, where applicable, by Zoho Sign and TrustFactory under their own retention policies.
  • Financial records — invoices, payment confirmations, refund records, and chargeback notices processed through Paystack — retained for 5 years as required by the South African Revenue Service under the Tax Administration Act, and longer where required by VAT rules. Rento does not store full card numbers; only Paystack-issued tokens and last-4 digits.
  • Identity-verification records — KBA outcomes, Mobile ID results, credit-bureau reports, and ID-document scans processed through TransUnion, TruID, and Loom — retained for the period agreed with those providers, and for any fraud-prevention period required by the National Credit Act and Financial Intelligence Centre Act.
  • Transactional email and SMS delivery logs held by SendGrid and Twilio — retained for the rolling period set by those providers (typically up to 30 days for SendGrid event data) for delivery diagnostics; thereafter they age out automatically.
  • Aggregated and de-identified data — once we have anonymised information so that it can no longer be associated with you, we may continue to use it for analytics, product improvement, and the training of internal models (e.g. the Rento CCM Score). Anonymised data is, by definition, no longer your personal information.
  • Records we are required to keep to comply with a court order, regulatory directive, or active investigation — for as long as the order or directive requires.

Where third parties (Zoho Sign, TrustFactory, TransUnion, TruID, Loom, Paystack, SendGrid, Twilio) act as independent responsible parties for personal information they hold, you may need to contact them directly to delete personal information stored under their own platforms. We will tell you which providers held what when we confirm deletion, so you know where to follow up.

How long it takes

We will acknowledge your request within 5 business days and complete deletion within 30 days, except where a longer period is required by law (see "What we keep") or to resolve an active dispute, investigation, or open transaction (e.g. a lease in the process of being signed). We will confirm completion by email.

If you have an open lease, an unresolved payment, or an in-progress verification, we will hold your account in a restricted state until those transactions are closed, and complete deletion thereafter.

Authoritative URL

The authoritative version of these instructions is published at www.therento.com/data-deletion. This URL is registered with Facebook (Meta) as the User Data Deletion Instructions URL for the Rento app, and is referenced from our Privacy Policy.

Contact

You also have the right to lodge a complaint with the Information Regulator (South Africa)inforegulator.org.za, complaints.IR@justice.gov.za — at any time.

Ready to delete your data?

Email our privacy team and we'll guide you through every step.