Privacy Policy
Last updated: 27 July 2026
This policy explains what personal data LetClear collects, how we use it, and the rights you have under UK GDPR. If anything is unclear, email hello@letclear.co.uk.
1. Who we are and our role
The operator is the controller for account, billing, security, support, and product-operation data. For tenant or occupier information a landlord uploads solely for their own records, the landlord determines why that data is processed and LetClear processes it to provide the service.
Uploaded files may contain special-category or criminal-offence information chosen by the landlord. Do not upload this information unless it is necessary, lawful, and relevant. Remove unnecessary identity, medical, financial, or allegation details before uploading.
For any privacy enquiries, including subject-access and other rights requests, contact us at hello@letclear.co.uk.
2. Data we collect
We collect only what we need to run the service:
- Account data. Email address and a password hash, set during signup.
- Property data. Address, type, and country of properties you add.
- Tenancy data. Start date, deposit details, prescribed-information status, and tenancy type.
- Compliance data. Certificate issue and expiry dates you record for gas safety, EPC, EICR, and smoke alarm checks.
- Documents. Files you upload to attach to a property or compliance record.
- Trial-abuse prevention.A one-way keyed reference derived from Stripe's card fingerprint. We never receive or store the full card number.
- Service logs. Standard request logs (IP address, user agent, timestamp) used to run and secure the service.
- Bot-verification data. Cloudflare Turnstile processes limited browser, device, network, and challenge-result information on authentication forms to distinguish legitimate visitors from automated abuse.
- Product interaction data.With your permission, privacy-limited PostHog events such as whether a decision briefing, assessment change, upgrade prompt, or checkout action was viewed or opened. Signed-in events use your Supabase authentication UUID as a persistent pseudonymous identifier. PostHog may use the connection IP address to add approximate country, region, city, postal area, latitude, longitude, and time-zone information. We use this enrichment to understand regional adoption and product performance. It is not taken from a property address or a property's recorded jurisdiction. We do not include property addresses, recommendation wording, recorded legal facts, documents, or form text.
- Communication preferences. Your separate choices for service monitoring updates and optional plan reminders, plus a minimal history of preference changes and unsubscribe actions.
3. Lawful basis for processing
We rely on the lawful bases in Article 6 UK GDPR as follows:
- Article 6(1)(b) contract performance: account, property, tenancy, compliance, and document data. Without this data we cannot deliver the service you signed up for.
- Article 6(1)(f) legitimate interest: service logs, bot verification, communication-preference records, and plan reminders sent under the electronic-mail soft-opt-in where its conditions apply. These uses help us secure the service, prevent automated abuse, record your choices, and offer previous customers a direct way to resume the service. You may object or unsubscribe from plan reminders at any time.
- Article 6(1)(c) legal obligation: limited records we are required to keep, for example billing records under HMRC rules.
- Article 6(1)(a) consent: only where we expressly ask for it, including optional PostHog analytics, session replay, and plan reminders where the electronic-mail soft-opt-in does not apply. You may withdraw consent at any time.
4. Where data is stored and processed
We store the primary application data (account records, property and tenancy information, compliance items, and uploaded documents) in Supabase's London (UK) region.
Some of our other service providers (listed in section 5) are headquartered outside the UK or EEA and may process limited personal data such as your email address, IP address, or payment details outside the UK or EEA, in particular in the United States. Specifically:
- Vercel hosts the web application and serves static assets through a global content delivery network. Request and analytics data may be processed by Vercel infrastructure outside the UK or EEA.
- Resend sends transactional and reminder emails. Your email address transits through their infrastructure, which may include servers outside the UK or EEA.
- Stripe, when you subscribe, processes your payment details on its global payments infrastructure.
- Cloudflare Turnstile processes limited authentication-form traffic and challenge data to detect automated abuse.
Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards under UK GDPR and EU GDPR, including the UK International Data Transfer Addendum and the EU Standard Contractual Clauses. You can request more information about these safeguards by emailing hello@letclear.co.uk.
5. Sharing with third parties
We share data only with the service providers we use to operate the product:
- Supabase, for database, auth, and storage.
- Vercel, for application hosting.
- Cloudflare Turnstile, for bot and automated-abuse protection on authentication forms.
- PostHog Cloud EU, for optional product analytics, performance measurements, and separately consented session replay.
- Resend, for transactional emails, monitoring updates, and optional plan reminders.
- Stripe, when subscription billing is enabled, for payment processing only.
We do not sell your data. We do not share it with advertisers.
6. How long we keep data
Specific retention periods:
- Account, property, tenancy, compliance and document data: for as long as your account is active. When you delete your account we delete this data within 30 days. Normal processing is disabled when a verified deletion request is received, except for processing needed to complete deletion, prevent fraud, resolve disputes, or meet a legal obligation.
- Personal-data request packages: secure export packages are removed seven days after approval. Each generated download link expires after five minutes.
- Privacy-request handling records:minimal evidence of receipt, identity verification, review, approval, notification, supply-link issuance, deletion processing, and completion is retained for six years to demonstrate how requests were handled and resolve disputes. This record does not retain export contents, property records, uploaded files, or a deleted account's email address.
- Service logs (request logs, IP address, user agent, timestamp): up to 90 days for security and debugging, then deleted or aggregated.
- Billing and tax records: for at least 6 years from the end of the accounting period to which they relate, as required by HMRC.
- Trial-redemption and legal-acceptance records: retained while needed to prevent repeated trials, operate subscriptions, resolve disputes, or establish legal claims, then deleted or anonymised.
- Communication preferences and audit history: retained while needed to apply your choices, demonstrate how an email preference was obtained or withdrawn, resolve disputes, or establish legal claims, then deleted or anonymised. Unsubscribe links use random tokens; only their hashes are stored.
- Optional analytics: retained according to the PostHog account configuration. Signed-in events use a pseudonymous account UUID but exclude direct profile, property, tenant, document, and legal-fact content.
- Backups: rolling backups may retain previously deleted data for up to 30 days before being overwritten.
7. Your rights
Under UK GDPR you have the following rights:
- Right of access (Article 15). Obtain a copy of the personal data we hold about you and information about how we use it.
- Right to rectification (Article 16). Have inaccurate or incomplete personal data corrected.
- Right to erasure (Article 17). Have your personal data deleted in defined circumstances. You can delete your account from settings at any time.
- Right to restriction (Article 18). Restrict our processing of your personal data while a request is investigated.
- Right to data portability (Article 20). Receive a copy of your data in a structured, commonly used and machine-readable format.
- Right to object (Article 21). Object to processing based on legitimate interest, including any direct marketing.
- Rights related to automated decision-making (Article 22). We do not subject users to fully automated decision-making that produces legal or similarly significant effects (see section 11).
- Right to withdraw consent. Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right to complain to the regulator.You have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk) if you believe we have mishandled your personal data. We would prefer to address your concerns directly first, so please contact us before complaining where you can.
You can submit a formal personal-data access request or request account deletion from Settings > Privacy and data. Access requests require your current password, are reviewed before release, and are delivered as a machine-readable package through a short-lived secure link. You can also exercise any right by emailing hello@letclear.co.uk. We will respond within one calendar month, which may be extended by up to two further months for complex or numerous requests as permitted by Article 12(3) UK GDPR. We may need to verify your identity before responding.
8. Cookies and analytics
LetClear uses essential cookies for authentication, security, interface preferences, and remembering your privacy choices. We do not use advertising cookies.
With your permission, we use PostHog Cloud EU for product analytics and performance measurement. Signed-in analytics uses your Supabase authentication UUID as a persistent pseudonymous identifier. Event properties are limited to categorical states, booleans, coarse counts, sanitised route templates, and approximate location inferred from the connection IP. Location enrichment may include country, region, city, postal area, latitude, longitude, and time zone and helps us understand regional adoption and product performance. It is not derived from the rental-property address or recorded jurisdiction. We exclude names, email addresses, property addresses and their postcodes, tenant information, document contents, free text, recommendation wording, and recorded legal facts.
Reviewed public pages may use masked heatmaps and interaction signals after analytics consent. Session replay requires a separate choice and applies masking and blocked regions. You can change either choice in Settings. See our Cookie Notice for details.
9. Security
We take appropriate technical and organisational measures to protect your personal data, taking into account the nature of the data and the risks involved. These include encryption in transit and at rest, row-level security so users can only read and write their own records, principle-of-least-privilege access controls, regular review of infrastructure security advisories, and secure software-development practices.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office within 72 hours where required by Article 33 UK GDPR, and we will notify you without undue delay where required by Article 34.
10. Children's data
LetClear is not directed at children. The service is intended for adult landlords (18+) and we do not knowingly collect personal data from anyone under 18. If you become aware that a minor has provided personal data to us, please contact us and we will take steps to delete it.
11. Automated decision-making
LetClearsurfaces compliance status and readiness signals computed deterministically from the data you supply and the rules we encode. These outputs are decision-support information, not legally binding decisions about you, and they do not produce legal or similarly significant effects on you within the meaning of Article 22 UK GDPR. You remain in control of any action taken on the basis of the service's output.
12. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top of this page reflects the most recent change. Material changes will be announced via email to your account address and surfaced inside the application before they take effect.
13. Contact
Questions about this policy or your data: hello@letclear.co.uk.