Privacy Policy

How we collect, use, and protect your information.

Effective date: 19 April 2026  ยท  Last updated: 19 April 2026

RentalHelm ("RentalHelm", "we", "us", or "our") provides a web application and companion iOS app that help vacation rental hosts automate door codes, pool and spa control, thermostats, and guest notifications. This Privacy Policy explains what information we collect, why we collect it, how we use it, and the choices you have.

By using RentalHelm you agree to this policy. If you do not agree, please do not use the service.

1. Who we are

RentalHelm is operated by Danks.AI. For any privacy questions or requests, please use our contact form and we will get back to you.

2. Information we collect

Information you give us

  • Account details โ€” name, email address, password (hashed), and optional phone number.
  • Property details โ€” address, nickname, and configuration settings (lock entity IDs, pool pump details, thermostat mapping, etc.) that you add yourself.
  • Guest records โ€” names, email addresses, phone numbers, check-in/check-out dates, and door PIN codes โ€” either entered manually or imported from a connected Property Management System (PMS) such as OwnerRez.
  • Integration credentials โ€” API tokens and usernames for services you connect (PMS, Home Assistant, etc.). These are stored encrypted at rest.
  • Support correspondence โ€” messages you send us via the contact form or in-app support.

Information collected automatically

  • Usage and device data โ€” IP address, browser or app version, operating system, and timestamps of actions taken in the app, kept in standard server logs.
  • Mobile push tokens โ€” when you enable push notifications on the iOS app, your device's APNs token is stored so we can deliver alerts (e.g. "Pool heat turned on", "Front door code added for Jane Smith").
  • Cookies and session data โ€” strictly necessary cookies used to keep you signed in and protect against CSRF. We do not use advertising cookies.
  • Audit logs โ€” records of system actions (lock code added/removed, pool temperature changes, who triggered a manual command) used for your security and for in-app reporting.

Information we do not collect

  • We do not collect camera, microphone, photo library, contacts, location, or health data from the iOS app.
  • We do not use third-party advertising networks and we do not sell personal information.

3. How we use your information

  • To create and maintain your account.
  • To operate the service โ€” programming lock codes, scheduling pool/spa events, running automations, and sending push alerts you have opted into.
  • To sync bookings and door codes from PMS providers you have connected.
  • To send you transactional emails (password reset, invitation acceptance, billing receipts if applicable).
  • To diagnose problems, prevent abuse, and improve the service.
  • To comply with legal obligations.

We do not use your data to train AI models, and we do not profile you for advertising.

4. Legal basis (UK/EU users)

Where GDPR applies, we rely on (a) performance of a contract to provide the service you signed up for, (b) legitimate interests to keep the service secure and to debug issues, and (c) consent for push notifications and optional marketing.

5. How we share information

We share data only with service providers who help us run RentalHelm, and only to the extent needed:

  • Hosting and infrastructure โ€” our cloud hosting provider, where the application and database run.
  • Email delivery โ€” transactional email providers used to send password resets and account emails.
  • Push delivery โ€” Apple Push Notification service (APNs) via Firebase Cloud Messaging for iOS notifications.
  • PMS and smart-home integrations โ€” only the data required to operate the integration you configured (e.g. sending a door code to Home Assistant on your property).

We do not sell personal data and we do not share it with advertisers or data brokers. We may disclose information if required by law or to protect the rights, property, or safety of RentalHelm, our users, or others.

6. Data retention

  • Account data โ€” kept while your account is active. If you delete your account, we remove your personal data within 30 days, except where we must keep it for legal reasons (for example, billing records).
  • Guest records โ€” kept while needed to run automations for upcoming and past stays, then automatically cleaned up after check-out per our retention defaults.
  • Audit and action logs โ€” retained for up to 12 months.
  • Backups โ€” encrypted backups may persist for up to 35 days after deletion before being overwritten.

7. Your rights

Depending on where you live, you may have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated data.
  • Object to or restrict certain processing.
  • Withdraw consent for push notifications at any time (Profile โ†’ Notifications, or at the device level in iOS Settings).
  • Lodge a complaint with a data protection authority.

To exercise any of these rights, get in touch via our contact form. We will respond within 30 days.

8. Security

We protect your data with industry-standard measures: TLS in transit, encryption at rest for integration credentials and access tokens, hashed passwords, isolated production infrastructure, and access controls limiting who can view data. No system is perfectly secure โ€” if you believe your account has been compromised, contact us immediately.

9. Children

RentalHelm is a business tool for vacation rental hosts and is not directed to children under 16. We do not knowingly collect personal data from children.

10. International transfers

RentalHelm is operated from the United Kingdom. If you access the service from outside the UK, your information will be transferred to and processed in the UK and other countries where our service providers operate. We use standard contractual clauses or equivalent safeguards where required.

11. iOS app specifics

  • The iOS app is a wrapper around the secure RentalHelm web application. It does not independently collect personal data.
  • Push notifications are optional. You can disable them per-property inside the app (Profile โ†’ Notifications) or globally in iOS Settings.
  • The app does not use IDFA, does not integrate advertising SDKs, and does not use third-party analytics SDKs.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes we will notify you by email or via an in-app notice before they take effect. The "Last updated" date at the top of this page always reflects the most recent version.

13. Contact us

Questions, requests, or concerns about privacy? Please reach out through our contact form.