For everyone who uses Inlet
Privacy policy
Last updated 20 September 2026
[COMPANY NAME] LIMITED (company number [COMPANY NUMBER]), registered at [REGISTERED OFFICE ADDRESS], runs Inlet. We are registered with the Information Commissioner's Office under number [ICO REGISTRATION NUMBER].
This policy explains what we do with personal information. It covers landlords who hold an account, and the tenants, applicants and contractors who are given a login.
Inlet is not free of personal data about other people: a landlord's account holds details of their tenants. Who answers for that data is the first thing to be clear about, so it is the first section.
Who is responsible for what
Data protection law splits responsibility between the organisation that decides why data is held (the controller) and the one that holds it on their behalf (the processor). Inlet is sometimes one and sometimes the other.
| Information | Controller | Our role |
|---|---|---|
| A landlord's own account and billing details | Inlet | We decide what to collect and why |
| Details of a landlord's tenants, applicants and tenancies | That landlord | We hold it for them and act on their instructions |
| Repairs, messages and photos on a landlord's jobs | That landlord | As above |
| Contractors a landlord adds themselves | That landlord | As above |
| Suppliers listed in Inlet's own directory | Inlet | We decide who is listed and what approval means |
| Tenant and contractor logins | Inlet | The login itself is ours; the tenancy behind it is the landlord's |
So if you are a tenant and want your details corrected or removed, your landlord decides. Ask them first; we will help them do it, and we will pass your request on if you contact us instead.
If you are a landlord
We hold:
| What | Why | Our lawful basis |
|---|---|---|
| Your name and email address | To run your account and send reminders | Performing our contract with you |
| Your password | To let you sign in. It is handled by Supabase Auth and stored only as a one-way hash, never in a form we can read | Performing our contract |
| Your mobile number, if you switch on text alerts | To text you about emergency repairs | Your consent, which you can withdraw in Settings |
| Devices you switch phone notifications on for | To send notifications to that device | Your consent, withdrawn by switching them off |
| Your plan, subscription status and Stripe customer reference | To know what your account allows, and to take payment | Performing our contract |
| Records of payments and invoices | Because company and tax law requires us to keep them | A legal obligation |
| A log of who looked at or changed sensitive records | So a tenant's question about who saw their data can be answered | Our legitimate interest in accounting for access, and yours in meeting your duties |
| Technical logs, including IP addresses | To keep the service running and to investigate abuse | Our legitimate interest in security |
We do not use your information to advertise to you, we do not sell it, and we do not use anything in your account to train artificial intelligence models. If we ever want to email you about something other than your own account, we will ask first.
If you are a tenant or an applicant
Your landlord chose to use Inlet and decides what is held about you. We hold it for them. In short, that is your name and contact details, your tenancy, repairs you report and the messages about them, the outcome of a Right to Rent check, and any paperwork you send in.
Two things we do on purpose, to keep your information safe:
- For Right to Rent we ask for a Home Office share code rather than a copy of your passport, and we never ask for the date of birth the check also needs, so Inlet never holds both halves. Only British and Irish citizens, who cannot get a share code, are asked for a document photo.
- Your referencing paperwork is deleted automatically: six months after you are accepted, or six months after a decision if you are declined or withdraw. Right to Rent evidence is deleted a year after the tenancy ends.
Your landlord, and the contractor working on a repair, see what they need to. A contractor never sees your side of a message thread or your documents. Your landlord's other tenants never see anything of yours.
Please do not include medical details in a repair message unless they matter to the repair. If a damp problem is making someone ill it is right to say so, and that information is then held as part of the repair record.
There is a fuller notice written for you at /legal/portal.
If you are a contractor
Where a landlord added you themselves, they decide what is held about you and we hold it for them: your name, business, contact details, the jobs you were asked about, your quotes and costs, and the landlord's own rating of your work.
Where you are listed in Inlet's own supplier directory, we are responsible. We hold your business details, the trades and services you offer, the areas you cover, any registrations you tell us about, your logo, and whether we have approved the listing. Landlords see that listing. You keep it up to date yourself once you have a login.
You can ask us to remove your listing at any time, and we will.
What Inlet itself can see
We run Inlet, so we can see enough to support you and to know how the business is doing. Being specific about the limits:
- We see counts across all accounts — how many landlords, properties, repairs and documents there are. Numbers only.
- We can open a landlord's own account for support: their properties, how many tenancies and documents they have, and what compliance is overdue.
- Every time we open a landlord's account that way, it is written to that landlord's own access log, naming who looked and when. They can ask us for it at any time.
- We do NOT have a screen that shows a tenant's name, contact details, documents, Right to Rent evidence or repair messages across accounts. Those belong to the landlord, and we hold them on their behalf.
- Inlet staff today means one person. If that changes, this section changes with it.
Supabase, as the company hosting the database, can technically reach stored data — that is true of any hosting provider, and is why they are named as a processor above.
Where your information is held
The database and every uploaded document sit on servers in London. UK personal data stays in the UK at rest.
Some of the companies above are based in the United States, so certain data — an email address we send a reminder to, a card payment, technical logs — is handled outside the UK. Where that happens we rely on the UK's International Data Transfer Addendum or an adequacy decision, which obliges the company to protect the data to UK standards.
How long we keep things
Where the law sets a period, we follow it. Otherwise we keep records for as long as a question about them could reasonably arise.
| Record | Kept for |
|---|---|
| Your account, while it is open | Until you close it, then 30 days |
| Gas safety records | At least 2 years |
| Other compliance certificates | Until replaced, then 6 years |
| Tenancy records and deposit evidence | 6 years after the tenancy ends |
| Right to Rent checks and evidence | 1 year after the tenancy ends — then deleted automatically |
| Referencing paperwork of an accepted tenant | 6 months after acceptance — then deleted automatically |
| A declined or withdrawn applicant's record | 6 months after the decision — then deleted automatically |
| Repairs, messages and photos | 6 years after the job is closed |
| Financial records, rent and costs | 6 years |
| Invitations | 12 months after they are accepted, cancelled or expire |
| The log of who accessed sensitive records | 12 months |
| Payment records we must keep for tax | 6 years |
Tenant paperwork is deleted by an automatic daily job. The other periods are policy we apply, and some deletions are still done by hand. We are honest about that rather than claiming an automation we have not built yet.
How it is protected
- One landlord's records are separated from another's by the database itself, not merely by the app. The rule is enforced on every read and write, and tested automatically from outside the application.
- Uploaded documents sit in private storage, never on the open web. Opening one produces a link that expires in 60 seconds and is only issued after checking the file belongs to the person asking.
- Passwords are handled entirely by Supabase Auth. Inlet contains no code that stores or compares a password.
- Everything travels encrypted, and the database refuses unencrypted connections. Stored data and backups are encrypted by the platform.
- Phone notifications are encrypted so that only your device can read them, and never contain anything anybody typed.
- Who opened a sensitive record is logged.
No system is perfect. If there is a breach that puts people at risk we will tell the Information Commissioner within 72 hours, and tell the people affected where the risk to them is high.
Your rights
You can ask us to:
- Tell you what we hold about you, and give you a copy.
- Correct anything wrong.
- Delete information we no longer have a reason to keep.
- Stop or limit a particular use, including withdrawing consent for text alerts or notifications.
- Give you your data in a portable form, or send it to someone else.
- Object to a use we have based on our legitimate interests.
Inlet makes no decision about anyone by automated means alone, and does no profiling.
Email support@inlet-homes.com. We answer within one month, free of charge. If your request is about data your landlord controls, we will pass it to them and help them answer it.
If you are unhappy with our answer you can complain to the Information Commissioner's Office: ico.org.uk, or 0303 123 1113. We would rather you came to us first.
Changes to this policy
The version here is always the current one, and the date at the top says when it changed. If a change matters to you — a new company handling data, a new purpose — we will email account holders before it takes effect.