1. Who we are
DevOrbit Studio operates RentalManagerHub from Philippines. This Privacy Policy applies to our website, Android application, landlord workspaces, tenant portals, public listings, support, and related services.
For privacy questions or requests, email dev@devorbitstudio.com.
2. Information we process
- Account and identity information: name, username, email, telephone number, address, company details, account role, verification status, profile image, signature, and optional tax or business information.
- Rental and property information: listings, property addresses, lease dates, rent, deposits, occupants, assignments, notes, inquiries, applications, viewings, inspections, permits, and landlord-tenant communications.
- Payment and utility records: amounts, balances, due dates, meter readings, billing source, payment channel, transaction references, status, payer details, and uploaded payment proof.
- Documents and verification: contracts, receipts, identification images, selfies, income or business evidence, maintenance attachments, and other files submitted by a user or an authorized landlord representative.
- Support and communications: messages, inquiries, reviews, maintenance requests, complaints, account-deletion requests, and responses.
- Technical and security data: IP address, device and browser information, session and access-token data, timestamps, audit events, error logs, and actions needed to secure the service.
- Public information: listing details, landlord profile information, public contact channels, and published reviews selected or approved for public display.
Passwords are stored as cryptographic hashes. Payment providers handle wallet or card authorization; RentalManagerHub does not request or store a user's wallet PIN or password.
3. Why we use information
- Create, verify, authenticate, and protect landlord and tenant accounts.
- Operate listings, inquiries, leases, billing, utilities, receipts, documents, maintenance, reporting, and support.
- Connect a tenant account to the correct landlord, company, property, and rental records.
- Process or reconcile payments and subscriptions through approved providers.
- Prevent fraud, abuse, duplicate accounts, unauthorized access, and security incidents.
- Comply with legal obligations, enforce platform rules, resolve disputes, and preserve evidence.
- Maintain, troubleshoot, measure, and improve service reliability and usability.
Depending on the context, processing may be based on consent, performance of a contract, compliance with law, protection of vital interests, or legitimate interests such as operating and securing the platform. We apply the principles of transparency, legitimate purpose, and proportionality.
4. Who receives information
- Linked landlords and authorized staff: tenant and rental information needed to manage the rental relationship, according to assigned roles and permissions.
- Linked tenants: property, landlord, billing, maintenance, document, and payment information associated with their rental account.
- Service providers: hosting, database, storage, email, security, error monitoring, and other vendors that process information for us under appropriate restrictions.
- Payment providers: PayMongo and the payment channel selected by the payer, such as GCash or Maya, to create and reconcile a transaction.
- Authorities or affected parties: when reasonably necessary to comply with law, protect rights or safety, investigate fraud, or respond to a lawful request.
- Business transitions: a successor involved in a merger, financing, reorganization, or sale, subject to confidentiality and applicable law.
A landlord or property company may independently control tenant records it enters or is legally required to retain. Its own privacy obligations may apply in addition to this policy.
We do not sell personal information for money and do not use sensitive rental documents for third-party behavioral advertising.
5. Security
We use administrative, technical, and organizational safeguards appropriate to the nature of the information, including HTTPS encryption in transit, password hashing, authenticated sessions, role-based permissions, protected file access, validation, rate limits, audit controls, backups, and security monitoring. Access is limited to people and systems that need it for an authorized purpose.
No method of storage or transmission is completely secure. Users must protect their passwords, devices, email accounts, and one-time codes, and report suspected unauthorized access promptly.
6. Retention and deletion
We keep information while an account is active and as reasonably needed to provide the service, complete transactions, resolve disputes, enforce agreements, prevent fraud, and meet legal or accounting requirements.
- Verified landlord member and company deletion requests are deactivated and normally scheduled for permanent deletion after a 30-day recovery and review period.
- A standalone tenant portal account may be deleted directly. If it is linked to an active or historical rental, portal credentials can be removed while necessary lease, billing, receipt, or landlord records are retained or de-identified.
- Backups and security logs may remain for a limited backup cycle before secure overwrite.
- Information subject to a legal hold, dispute, fraud investigation, or statutory recordkeeping period is retained only for the applicable purpose and period.
7. Your choices and rights
Subject to applicable law, you may ask to be informed, access personal information, correct inaccurate information, object to or restrict certain processing, withdraw consent where consent is the basis, request portability, request erasure or blocking, and complain to the National Privacy Commission.
Use the controls in your profile, visit the Account Deletion page, or email our privacy contact. We may verify identity before acting on a request and may explain when a lawful exception applies.
8. Cookies, sessions, and mobile storage
The website uses essential cookies and session storage for authentication, security, saved preferences, and form protection. The Android application stores the signed-in session token in secure device storage. Disabling essential storage may prevent login or other core functions.
9. Children
RentalManagerHub is intended for adults who can enter rental or service agreements. We do not knowingly invite children to create independent accounts. A parent or legal guardian should contact us if a child's information was submitted without proper authority.
10. Changes and contact
We may update this policy when the service, providers, or legal requirements change. Material changes will be communicated through the service or account contact details, and the effective date and version above will be updated.
Privacy contact: dev@devorbitstudio.com.