Data-subject rights

Access, deletion, portability — verified and fulfilled.

Plain-English walk-through of the rights request workflow. Intake happens through the routed contact form on /contact (Privacy category).

  1. Open the contact form (Privacy category) at /contact?category=privacy — or email privacy@rentaraai.com

    Send the request from the email tied to your account. Use the routed contact form on /contact?category=privacy (Privacy category) so we record your tracker row immediately, or email privacy@rentaraai.com directly — both reach the same privacy desk. Include the type of request (access, deletion, portability, correction) and any property or reservation references that help us locate your data.

  2. Verification within two business days

    We acknowledge receipt and verify the requester’s identity using the information on file. If the verification fails we will not action the request, but the request is recorded for audit.

  3. Action within 30 days

    We complete the request within 30 days of verified receipt. Access requests get a structured data export; deletion requests trigger the purge pipeline described on /privacy (account rows, message threads, property metadata, compliance filings, consent ledger); portability requests take the access-export shape.

  4. Edge cases & escalation

    If a request conflicts with a legal hold, ongoing security investigation, or another data subject’s rights, we explain the reason in writing within 30 days and revisit when the underlying issue is resolved.

OR email privacy@rentaraai.com — same mailbox, no form needed.

Business identity

Who you’re contracting with

The contracting entity for RentaraAI is Steadwright LLC, an Indiana limited liability company, with its registered office at 2120 W Washington St, Suite 200, Indianapolis, IN 46222, United States. The entity governs itself under the laws of the State of Indiana, United States.

Data controller

Steadwright LLC (the entity above) decides why and how your personal data is processed when you use RentaraAI.

Third-party subprocessors: OpenAI — API, Polsia, Inc. — R2 object storage, Polsia, Inc. — Email proxy, Stripe, Inc., Render (hosting) + Cloudflare (edge).

Internal components (not shared with any third party): better-auth (local Postgres account store). Full table — categories, locations, retention, links — on /subprocessors.

Effective: 2026-09-11 · v2026-08-06