Privacy

Privacy Policy

for Tenants & Apartment Seekers

Application Folder (Direct Use)

These privacy provisions apply to the direct use of the rentcard platform, where you independently create and manage a digital application folder. rentcard is the data controller in this case.

If you use rentcard via a landlord or real estate partner, the provisions in Part B ("Verification for Landlords") also apply.

1. Name and Contact Details of the Data Controller

This privacy policy applies to the processing of personal data on the website www.rentcard.app. The controller is:

rentcard GmbH
Leopoldstraße 169 a, 80804 München

External Data Protection Officer pursuant to Art. 37 GDPR:
IITR Datenschutz GmbH – Dr. Sebastian Kraska
Reachable at: email@iitr.de

E-Mail: info[at]rentcard.id
Phone: +49 89 2154576

If you have questions about data protection law or your rights as a data subject, you can contact the Data Protection Officer at email@iitr.de or rentcard at privacy@rentcard.id .

2. Retention Periods for Personal Data

As a general rule, your personal data will be deleted as soon as it is no longer necessary for the purpose for which it was collected.

The data in your user account will be stored for as long as the account exists. Upon termination of the contractual relationship, we will lock your user account.

At the latest six (6) months after termination of the contract, or 24 months after the last activity or last login, we will permanently delete your user account including all personal data.

Shorter retention periods apply to certain categories of data:

  • Verification results (credit, income verification, rent payment verification) are deleted at the latest six (6) months after the three-month validity period of the application folder expires.
  • Identity data (verified name and address) are stored for the lifetime of the user account, as identity confirmation does not expire.
  • Bank data (released transactions and average values) are deleted at the latest six (6) months after the application folder validity expires. Unreleased transactions are never stored at rentcard.

This does not apply where we still need the data to enforce claims against you, or where we are legally or contractually obliged to retain the data. If data cannot be deleted, its processing will be restricted.

3. Processing of Personal Data and Purposes of Processing

a) Web Hosting

For the provision of this website, we use the web hosting service of Google Cloud EMEA Limited (70 Sir John Rogerson's Quay, Dublin 2, Ireland) in the data centre at 9909 TA Eemshaven.

Google is engaged pursuant to Art. 6(1)(f) GDPR on the basis of our legitimate economic interest. We have concluded a data processing agreement with Google.

b) When Visiting the Website

You can visit the website without disclosing your identity. The browser automatically sends information to the server (e.g. date and time of access, browser type, referrer URL). This includes the IP address of your device, which is temporarily stored in a log file and automatically deleted after 12 weeks.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and functionality of the website).

c) When Creating an Application Folder

To create the folder, we require the following information from you:

  • First name, last name, phone number
  • a valid email address

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

d) Use of the Account Information Service

To create your application folder, we use an account information service (BaFin-licensed under PSD2). Your banking credentials are transmitted exclusively to finAPI GmbH, Munich. rentcard never receives your banking credentials, account balance, IBAN or other account metadata.

With your consent, finAPI retrieves account transactions for the last six months. From these, potential salary and rent transactions are suggested for your selection. You decide which transactions are released. Only those are stored at rentcard.

e) When Creating the Application Folder (Account Transactions)

Based on a defined keyword list, potential salary receipts and rent payments in your account transactions are pre-selected. You can see the pre-selection transparently and adjust it freely. rentcard does not assess your ability to pay. Interpretation of the values is the responsibility of the recipient of your application folder.

Retention period: The application folder is generally valid for 90 days. We delete the personal data no later than six (6) months after the validity period expires.

Legal basis: Art. 6(1)(b) GDPR.

f) Use of the Self-Disclosure

To use the self-disclosure in full, we additionally require personal information (master data) from you, such as:

  • Address
  • Number of rooms
  • Age
  • Gender
  • Nationality
  • Net household income
  • Smoking behaviour
  • Phone number

Self-disclosure data is stored for up to 24 months after the last active use. Credit check data is handled separately and deleted at the latest six (6) months after the three-month validity period expires.

g) Document Verification

You can upload documents (e.g. pay slips, employment contracts, tenancy agreements). Uploaded documents are processed in two ways:

  • Data Extraction (OCR): Predefined fields are extracted via Google Vertex AI Document AI. No content assessment or full-text analysis takes place.
  • Authenticity Check: For PDF documents, metadata is used to verify whether the document is original or has been subsequently altered. For documents with a QR code, the code is verified against the issuer's online original.

The extracted data is displayed to you for review. Original documents are not permanently stored after processing unless you explicitly save them. Vertex AI does not store documents or results.

Legal basis: Art. 6(1)(b) GDPR.

h) Sharing of Application Folder Data

You can instruct rentcard to transmit selected content to landlords or property portals. Disclosure takes place exclusively on the basis of your explicit consent (Art. 6(1)(a) GDPR). You may revoke consent at any time with effect for the future.

Alternatively, you can download your application folder as a PDF and share it yourself. In this case, the data does not leave the rentcard platform via our servers.

i) Use of the Credit Check

Personal data such as name, address and date of birth is processed to obtain credit information from a connected credit reference agency. Legal basis: Art. 6(1)(b) GDPR.

rentcard receives only a reduced credit result in the form of a traffic-light colour (Green = no payment issues known, Yellow = minor irregularities, Red = payment issues present, Grey = insufficient data). Detailed credit data is not stored by rentcard.

The credit check is conducted by CRIF GmbH as an independent controller. The credit result is shared with third parties only with your explicit consent.

j) Roles and Responsibilities in the Credit Check

When using the application folder directly, rentcard is the controller for the processing of your data. CRIF GmbH is independently responsible for conducting the credit check. The relationship between rentcard and CRIF is a data transfer between controllers, not data processing on behalf.

rentcard does not make decisions about rental applications. The decision to rent is made solely by the landlord.

k) Use of Digital Identity Verification

Personal data such as name, date of birth, ID document data and photo or video sequences (e.g. liveness check) are processed. Biometric data within the meaning of Art. 9(1) GDPR is processed (matching the selfie with the ID photo). This biometric processing is carried out exclusively by Veriff OÜ. rentcard does not store any images, ID data or biometric data.

Legal basis: Art. 6(1)(b) GDPR. For the processing of biometric data, separate explicit consent is obtained pursuant to Art. 9(2)(a) GDPR. Identity verification via Veriff is optional. As an alternative, identity confirmation via bank account (finAPI) is available.

rentcard receives only the verification result (e.g. "verified" or "not verified").

l) Roles and Responsibilities in Identity Verification

Veriff OÜ acts as a processor within the meaning of Art. 28 GDPR. Images are transmitted directly from the user's device to Veriff. They do not pass through rentcard servers.

rentcard receives only: first name, last name, address and verification status (verified / not verified).

m) Use of Sanctions List Screening

To ensure the integrity of the platform, rentcard may match personal data against publicly available international sanctions, embargo and PEP lists. Name, date of birth and nationality are generally processed for this purpose.

Legal basis: Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. rentcard processes only the screening result and does not make automated individual decisions.

n) Use of the Rental Deposit Guarantee

For the eligibility check, personal data (e.g. name, address, date of birth, tenancy contract data, guarantee amount) is processed. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures).

After submission, the insurance partner (R+V Versicherung AG) decides independently on acceptance or rejection and is the independent controller in this regard. rentcard does not store any credit or risk assessment data from the insurer.

o) Service and Marketing Communications

Transactional messages are sent for the performance of a contract. Legal basis: Art. 6(1)(b) GDPR.

Marketing emails are sent only with your consent (double opt-in). Consent can be withdrawn at any time (unsubscribe link in every email). Legal basis: Art. 6(1)(a) GDPR and § 25(1) TTDSG.

Retention period: Sending and interaction data is stored until revocation, for a maximum of 24 months after the last interaction, or until the user account is deleted.

p) When Using the Contact Form

We collect: name, email address, subject, your message. Legal basis: Art. 6(1)(f) GDPR. The data is deleted once your enquiry has been conclusively answered.

q) When Using the User Account

To use our services, you can register at www.rentcard.app Your profile information is stored for the period set out in section 2.

r) Note: No Automated Assessment of You

rentcard does not assess you and does not make decisions about your rental application. Specifically, this means:

  • We extract salary data from your documents but do not assess whether your income is sufficient.
  • We suggest transactions and calculate an average, without weighting or assessment.
  • The credit check is carried out by CRIF GmbH, not rentcard. We merely forward the result.
  • The results of the various modules are displayed individually and independently of each other. We do not combine them into an overall profile.
  • No automated individual decision within the meaning of Art. 22 GDPR takes place.

4. Data Disclosure

Your data will not be transferred for purposes other than those listed below.

I) Purpose of Service Provision and Billing

The data you transmit to us via www.rentcard.app are processed by us for the provision and billing of the respective services.

II) For Other Purposes

We only disclose your data to third parties if:

  • you have given your explicit consent (Art. 6(1)(a) GDPR);
  • there is a legal obligation (Art. 6(1)(c) GDPR).

III) Use of External Service Providers and Partners

To provide certain services, rentcard works with selected service providers. These process personal data either on behalf of rentcard or as independent controllers.

a) Mailjet

Email Communication

Mailjet SAS, Paris · Processor · Art. 6(1)(f) GDPR

Privacy Policy →

b) Brevo

Email Marketing

Sendinblue GmbH, Berlin · Processor · No third-country transfer

Privacy Policy →

c) Customer.io

Marketing & Upselling

Peaberry Software, Inc. · Data processing in the EU · DPA in place

Privacy Policy →

d) HERE Global B.V.

Map Services / Address Validation

Art. 6(1)(f) GDPR

Privacy Policy →

e) Stripe

Payment Processing

Stripe Payments Europe Ltd., Dublin · Independent controller · Art. 6(1)(b) GDPR

Privacy Policy →

f) OpenSanctions.org

Sanctions List Screening

OpenSanctions Project gGmbH, Berlin · Data matching with official sources (EU, UN, OFAC)

Privacy Policy →

g) R+V Versicherung AG

Deposit Guarantee

Independent controller

Privacy Policy →

h) Veriff OÜ

Identity Verification

Processor (Art. 28 GDPR) · Images are transmitted directly from the device to Veriff, not via rentcard servers

Privacy Policy →

i) FinAPI GmbH

Account Information Service

BaFin-regulated provider (PSD2) · Independent controller · Banking credentials, account balance and IBAN are never stored at rentcard

Privacy Policy →

j) CRIF GmbH

Credit Check

Independent controller · rentcard stores only a traffic-light colour (Green/Yellow/Red/Grey) · Detailed credit data is not stored

Privacy Policy →

k) Lexoffice / Envoix GmbH

Accounting

Haufe Lexware GmbH & Co. KG, Freiburg · Envoix GmbH, Frankfurt · Processor

l) Freshdesk

Support Communication

Freshworks Inc. · Processor · Art. 6(1)(b) and (f) GDPR

Privacy Policy →

5. Cookies and Pixel Tags

We use cookies on our website. These are small files that your browser automatically creates and stores on your device when you visit our site. Cookies do not cause any damage to your device and do not contain viruses, trojans or other malware.

We use pixel tags as part of our online offering. The pixels send your IP address, the referrer URL, the time the pixel was viewed, the browser used and previously set cookie information to a web server.

The use of cookies serves, on the one hand, to make the use of our offering more convenient for you (session cookies). In addition, we use cookies to statistically record usage and to evaluate it for the purpose of optimising our offering for you (see section 6).

The data processed by cookies is necessary pursuant to Art. 6(1)(f) GDPR. Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored or a notice always appears before a new cookie is created.

6. Web Analytics

The tracking and targeting measures listed below are carried out on the basis of Art. 6(1)(f) GDPR to ensure needs-based design and ongoing optimisation of our website.

a) Google Analytics

We use Google Analytics (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Pseudonymised usage profiles are created. Data transfer to the USA is based on the EU-US Data Privacy Framework (DPF). We have concluded a data processing agreement with Google. IP addresses are anonymised (IP masking).

b) Google Ads Conversion Tracking

Google Ads places a cookie on your computer if you reached our website via a Google ad. These cookies expire after 30 days. Data transfer to the USA is based on the EU-US Data Privacy Framework (DPF).

Privacy policy: policies.google.com/privacy

c) Google DoubleClick

On our website, cookies are used to collect and evaluate information for the optimisation of advertisements (Google LLC, DoubleClick). The cookie is automatically deleted after 30 days. You can manage interest-based advertising settings via Google's ad settings manager.

d) Google Tag Manager

The Google Tag Manager tool manages the tools described in this privacy policy. The tool itself is a cookieless domain and does not access any collected data. If deactivation has been set at the domain or cookie level, it remains in effect for all implemented tracking tags.

e) Google Dynamic Remarketing

This feature allows interest-based, personalised advertising messages to be displayed on other devices. If you have given Google the corresponding consent, Google links your web and app browsing history to your Google account for this purpose.

Opt-out: google.com/settings/ads/onweb

f) Mouseflow

We use "Mouseflow" (Mouseflow ApS, Denmark) to record randomly selected visits with anonymised IP addresses. The collected data is not personal and is not passed on to third parties. Storage takes place within the EU.

Opt-out: mouseflow.com/opt-out

7. Data Subject Rights

You have the right:

  • pursuant to Art. 7 para. 3 GDPR to withdraw any consent you have given at any time. This means that we may no longer continue the data processing that was based on this consent in the future.
  • pursuant to Art. 15 GDPR to request information about your personal data processed by us.
  • pursuant to Art. 16 GDPR to request without delay the rectification of inaccurate or completion of incomplete personal data stored by us.
  • pursuant to Art. 17 GDPR to request the deletion of your personal data stored by us, unless processing is necessary for the fulfilment of a legal obligation or the assertion of legal claims.
  • pursuant to Art. 18 GDPR to request restriction of the processing of your personal data.
  • pursuant to Art. 20 GDPR to receive your personal data in a structured, commonly used and machine-readable format or to request transmission to another controller.
  • pursuant to Art. 77 GDPR to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or our place of business for this purpose.

8. Information about Your Right to Object under Art. 21 GDPR

You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions.

If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

If your objection relates to the processing of your data for direct marketing purposes, we will immediately cease the processing.

If you wish to exercise your right to object, simply send an email to email@iitr.de or privacy@rentcard.id.

9. Data Security

All data you personally transmit is encrypted using the generally accepted and secure TLS (Transport Layer Security) standard. TLS is a secure and proven standard that is also used in online banking, for example.

We also use appropriate technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction and unauthorised access by third parties. Our security measures are continuously improved in line with technological developments.

10. Currency and Amendment of this Privacy Policy

This privacy policy is currently valid and dated April 2026.

Due to the further development of our website or due to changed legal or regulatory requirements, it may be necessary to amend this privacy policy. The current privacy policy can always be accessed and printed from the website at www.rentcard.app/privacy at any time.