Privacy Policy

Last updated: 17 August 2026

This Privacy Policy explains how Propertira collects, uses and protects personal information when you use our website and services.

Propertira is operated by Origin Collective Limited. Origin Collective Limited is the controller of the personal data described in this Privacy Policy.

Your property data is private

Other Propertira users cannot access the property information stored in your account. Authorised personnel and our service providers may process it only where reasonably necessary to operate, secure, support or comply with the law — see section 9.

We don't sell your data

We do not sell personal information and we do not use your property numbers to build advertising profiles.

No bank connection

Propertira never connects to your bank or card accounts. You type in the figures you want to track.

1. Who we are

Propertira is a rental-property profit dashboard for small landlords. It is operated by Origin Collective Limited, a company registered in England and Wales, which is the data controller for the personal data described here.

Origin Collective Limited

Company number: 16566341

Registered office: 124-128 City Road, London, England, EC1V 2NX

For any privacy question or request, please use our contact page. We reply by email.

2. Scope of this policy

This policy applies to information we process when you:

  • visit or use the Propertira website and app;
  • create an account and sign in;
  • add or manage properties and enter income, expense and mortgage figures;
  • use calculators, dashboards, reports and other product features;
  • buy or manage a paid subscription;
  • contact us through the contact form;
  • interact with cookies, browser storage and similar technologies we use.

3. Information we collect

A. Account information

Your email address, a Propertira user identifier, an optional display name, your default currency, and authentication data handled by our authentication provider (see service providers). Passwords are never stored by us in readable form. We do not ask for your postal address, phone number or date of birth.

B. Property and financial information you enter

You decide what to record. The fields Propertira stores today include: property name, optional city and country, property type, currency, monthly rent, parking, storage and other income, mortgage payment, property tax, insurance, service charges, utilities, internet, management fee, maintenance allowance and other recurring costs; one-off and recurring expenses with a name, amount, category, date and optional note; and monthly history values for past months.

Please keep tenant details out of Propertira

Propertira is designed for property and financial figures, not tenant records. Please avoid entering sensitive or unnecessary personal information about tenants or other individuals into notes or other free-text fields. Anything you type there is stored as ordinary text you provided.

C. Subscription and billing information

Propertira offers paid Plus and Portfolio plans today. Payments and subscriptions are handled by Stripe. In our own database we store the plan, subscription status, billing cycle, current period dates, cancellation flag, the Stripe customer and subscription identifiers, the price identifier, and records of the subscription events Stripe sends us. Card numbers are entered on Stripe's checkout and are not sent to or stored by Propertira. Our checkout is configured so that Stripe collects a billing address for tax and payment purposes; Stripe holds that information as part of your payment record.

D. Technical and security information

When you use the service, our hosting and database providers process technical information such as IP address, browser and device information, request timestamps, session and authentication events, and error details. We use server logs and error reports to keep the service working and secure. We do not build advertising or behavioural profiles from this.

E. Usage information

Propertira can record limited product-usage events such as which calculator or page was opened, or that a checkout was started. These events are only recorded after you turn analytics on in cookie settings; until then they are dropped. No third-party analytics SDK is bundled in the app — events are made available to a tag manager only if one is present on the page. Where we describe information as anonymous or aggregated, we only do so where it cannot reasonably be linked back to an individual; usage events sent from a signed-in session could in principle be linked to you, so we do not claim they are anonymous.

F. Communications and feedback

If you use the contact form or in-app feedback, we store the name and email address you give us, the content of your message, and any later correspondence about it.

4. Where your information comes from

We collect most information directly from you — when you create an account, add properties, enter figures, use the product, subscribe or contact us. We receive billing and subscription information from Stripe, and certain technical and security information is generated automatically by your device and by our hosting and database providers when you use the service.

5. How and why we use your information

  • creating, maintaining and securing your account, and signing you in;
  • storing your properties, expenses and monthly history;
  • running calculations and producing your dashboard, insights, comparisons, reports and the optional monthly summary email;
  • selling, renewing, changing and cancelling paid subscriptions, and applying plan limits;
  • replying to your messages and providing support;
  • detecting and preventing fraud, abuse and security incidents;
  • diagnosing errors and improving reliability;
  • optional usage analytics, if you have enabled it;
  • keeping tax, accounting and other business records required by law.

We do not sell your personal information, and we do not use your property figures for advertising.

6. Lawful bases for processing

Under UK GDPR and EU GDPR we must have a lawful basis for each purpose. In short:

What we doLawful basisNotes
Creating and running your Propertira account, signing you inPerformance of a contractWe cannot provide an account without processing your email and authentication data.
Storing your properties, income, expenses and monthly history, and producing calculations, dashboards and reportsPerformance of a contractThis is the service you signed up for.
Managing paid Plus and Portfolio subscriptions, applying plan limitsPerformance of a contractNeeded to sell, renew, change or cancel a subscription.
Keeping payment, invoice, tax and accounting recordsLegal obligationUK company, tax and accounting law.
Keeping accounts and the service secure, preventing fraud and misuse, diagnosing errorsLegitimate interestsOur interest in protecting Propertira, our users and the service from fraud, abuse and security threats, and in keeping the product working.
Replying to messages you send us through the contact formContract, or legitimate interests where you are not (yet) a customerOur interest in answering questions about our own product.
Optional usage analyticsConsentOff unless you switch it on in cookie settings. You can withdraw consent at any time.
Optional monthly Property Pulse summary emailConsentOff unless you enable it in Settings; you can turn it off again there.

Where we rely on consent, you can withdraw it at any time — through for analytics, or in Settings for the monthly summary email. Withdrawing consent does not affect processing that already took place.

7. Payments and Stripe

Paid plans are live. Payment processing and subscription management are provided by Stripe. You enter your card details directly into Stripe's checkout, and Stripe collects a billing address there. Propertira does not receive or store complete card details.

Stripe tells us what we need in order to run your subscription: the customer and subscription identifiers, the plan and price, the status, the billing period, and whether the subscription is set to cancel. Stripe processes payment data both on our behalf and for its own purposes as a regulated payment provider, under its own privacy notice and terms.

8. Service providers and other recipients

We use a small number of providers to run Propertira:

  • Supabase — database, storage of your account and property data, and authentication (sign-in, sessions, password resets).
  • Lovable — the application platform and hosting infrastructure the website and app run on, including application-level error reporting.
  • Stripe — payments and subscriptions.
  • Resend — delivery of transactional email such as contact-form forwarding and the optional monthly summary.

We may also disclose information where we are legally required to, to respond to lawful requests from authorities, to establish or defend legal claims, to protect the rights, safety or security of Propertira and its users, or to a buyer or successor in connection with a business reorganisation or acquisition. In practice this is rare.

9. Who can see your property data

Other Propertira users cannot access your properties, expenses, monthly history, profile or settings. Access is scoped per account and enforced at the database level with row-level security policies, so a signed-in session can only read and write rows belonging to that account.

Authorised personnel and our service providers may process your information where reasonably necessary to operate, secure and support Propertira — for example to investigate a fault or suspected misuse, to maintain the database and its backups, or to comply with a legal obligation.

10. International data transfers

Origin Collective Limited is based in the United Kingdom, and the providers listed above operate internationally. Depending on the provider and its infrastructure, your personal information may be processed outside the UK or outside the country you live in, including in countries whose data-protection laws differ from your own.

Where personal data is transferred out of the UK or the EEA, we rely on the transfer mechanisms made available by the relevant provider — such as an adequacy decision where one applies, or the provider's standard contractual clauses and UK international data transfer addendum. We are keeping our documentation of these arrangements under review as the product grows, and we will describe them more specifically here as that work completes. If you would like to know how a specific provider handles transfers, please ask us through the contact page.

11. Cookies, local storage and similar technologies

Propertira uses very little browser storage, and most of it is not a traditional cookie but your browser's localStorage or sessionStorage. The same rules apply to those technologies as to cookies.

Authentication and security

Our authentication provider stores your signed-in session in your browser (a key beginning sb-) so you stay logged in and your requests can be authenticated. Without it you cannot use an account. Our hosting and platform providers may also set storage necessary to serve and secure the site.

Preferences and functionality

These are not strictly necessary — the app works without them, just less conveniently:

  • rentprofit.demo-mode — remembers that you switched Demo Mode on.
  • rentprofit:calc-prefill — keeps the figures from a public calculator so your first property can be pre-filled after signup; it is cleared once used.
  • rentprofit.checkout_intent — session-only note of which plan you chose so checkout can continue after sign-in.

Your default currency is a setting saved with your account rather than in browser storage.

Analytics

Optional and off by default. When you switch it on, Propertira records limited product-usage events (see section 3E). No advertising or cross-site tracking technologies are used. You can turn it off again at any time.

Your cookie choice

We store your choice under landluno:consent (with a version and timestamp) so we do not ask again on every visit. You can review or change it here, or from the “Cookie settings” link in the footer and in Settings:

12. Emails and marketing

We send service emails you cannot opt out of while you hold an account — for example password resets, and messages about your subscription or important changes to the service.

The monthly Property Pulse summary is optional: it is off until you enable it in Settings and can be switched off there at any time. Propertira does not currently run a promotional marketing email programme. If we start one, we will ask for consent where required and every marketing email will include an unsubscribe link. Unsubscribing from marketing would not stop essential account and service emails.

13. How long we keep information

  • Account, property, expense and monthly history data — kept while your account exists. You can delete individual properties and expenses at any time, and deleting your account removes this data from the live application.
  • Subscription, payment and business records — transaction, invoice and accounting information may be kept after account deletion for as long as UK tax and accounting law requires, and while it may be needed for disputes or chargebacks. Stripe applies its own retention to the records it holds.
  • Security and error logs — kept for a limited period, determined by our hosting and database providers' logging settings, and longer only where needed to investigate a specific security or abuse incident.
  • Contact and feedback messages — kept for as long as reasonably needed to resolve the issue and to keep a record of what was asked and answered.
  • Backups — our database provider takes routine backups, so deleted data can persist in backup copies until those copies are cycled out in the normal course of the provider's backup rotation. We do not state a fixed number of days here because that period is set by the provider's backup configuration rather than by us.

14. Account deletion

You can delete your account yourself from Settings. Doing so deletes, from the live application, your properties, expenses, monthly history, profile and settings, your subscription record, your monthly-email log and any in-app feedback tied to your account, and then deletes your sign-in credentials with our authentication provider.

Deleting your account removes or anonymises application data according to the retention practices above, except information we must or may lawfully retain — for example for accounting and tax, fraud prevention, security, dispute resolution or other legal obligations. Copies may also remain in routine backups until those are cycled out, and payment records held by Stripe are subject to Stripe's own retention.

If you would prefer us to handle the deletion, or you can no longer sign in, contact us through the contact page.

15. Your privacy rights

Depending on where you live and the circumstances, you may have the right to ask us to:

  • give you access to the personal information we hold about you;
  • correct information that is inaccurate or incomplete;
  • delete your personal information;
  • restrict how we process it;
  • object to certain processing (see the next section);
  • provide certain information in a portable, machine-readable format;
  • withdraw consent where our processing relies on consent;
  • complain to a data-protection authority.

These rights have legal conditions and exceptions, so we may not be able to grant every request in full — if that happens we will explain why. Where we cannot reasonably be sure who is making a request, we may ask you to confirm your identity, for example by writing from the email address on the account, before we act on it.

To exercise any of these rights, use our contact page.

16. Your right to object

You can object to processing based on legitimate interests

Where we rely on legitimate interests — mainly security, fraud and abuse prevention, and error diagnosis — you can object to that processing. Tell us why, and we will stop unless we have compelling grounds to continue or need to keep processing for legal reasons. If we ever send direct marketing, you can object to it at any time and we will stop, without needing a reason.

Object through our contact page.

17. Complaints and supervisory authorities

Please come to us first — we would like the chance to put things right. You also have the right to complain to a data-protection authority.

In the UK, that is the Information Commissioner's Office (ICO), ico.org.uk. If you are in the EU or EEA, you may instead be able to complain to the supervisory authority in the country where you live or work, or where you think the issue arose.

18. Automated calculations and labels

Propertira uses automated calculations and rule-based labels — such as “Strong cash flow”, “Thin margin” or “Negative cash flow” — to present information about your properties. These features organise and explain the figures you entered. They do not make legal or similarly significant decisions about you: Propertira does not carry out credit scoring, lending decisions, tenant screening or profiling of that kind.

Results are estimates based on your inputs and are not financial, tax, legal or investment advice.

19. Required and optional information

  • An email address and a password (or a supported sign-in method) are required to create an account — without them we cannot give you one.
  • A display name is optional. Property city, country and expense notes are optional too.
  • Property and financial figures are yours to choose, but Propertira cannot produce meaningful profit, cash-flow or comparison results without the relevant inputs.
  • Payment and billing details are needed only if you buy a paid plan; without them you can continue on the Free plan.
  • Analytics and the monthly summary email are optional and off unless you turn them on.

20. Children

Propertira is intended for adults managing their own rental properties. Our Terms of Service require you to be at least 18 years old, and the service is not directed at children. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will remove it.

21. Security

We use technical and organisational measures appropriate to a service of this kind. Traffic to Propertira is encrypted in transit over HTTPS. Authentication is handled by our authentication provider and passwords are stored only in hashed form. Access to your rows in the database is enforced per account by row-level security policies, and administrative database access is restricted to server-side code. Sensitive credentials are held as server-side secrets and are never sent to your browser.

No internet service can promise absolute security. We make no claim to any certification or audit that has not actually been carried out.

22. Changes to this Privacy Policy

We may update this policy when Propertira's features change, when we change providers, when our privacy practices change, or when the law requires it. The “Last updated” date at the top will change when we do. If a change is material, we will give additional notice where appropriate — for example in the app.

23. Contact us

Origin Collective Limited

Company number: 16566341

Registered office: 124-128 City Road, London, England, EC1V 2NX

For privacy questions, data requests or anything else in this policy, use our contact page and we will reply by email. You can also review our Terms of Service.