Skip to main content

Security

Your property records stay behind authorised access.

RentalKey separates owner workspaces, keeps documents private and limits tenant and tradie access to the records shared with them.

Read privacy summary

Section 1

Protected owner access

Owner records sit behind authenticated website sessions. Public visitors cannot browse owner workspaces.

  • Owner routes require a valid session
  • Billing gates do not replace data authorization
  • Internal staff access is separated onto ops.therentalkey.com

Section 2

Separated workspaces

Database access rules are designed to restrict each owner to their own organisation records.

  • Supabase Row Level Security foundation
  • Server-side owner checks
  • Cross-owner access tests

Section 3

Private documents

Rental documents are stored privately with access granted only through authorised workflows.

  • Private storage buckets
  • Signed download/preview access
  • Owner-controlled tenant sharing

Section 4

Invitation-only portals

Tenant and tradie access works only after an owner enables portal access for the matching email address.

  • Accepted and last-seen tracking
  • Access revocation controls
  • Separate tenant and tradie portals

Section 5

Minimal-data principle

RentalKey should collect enough information to run rental workflows, not excessive applicant or tenant data.

  • No automated tenant rejection
  • Consent-first future screening
  • Privacy/legal review before commercial launch

Section 6

Responsible account security

Use a unique password and protect the email account connected to RentalKey. Known leaked passwords are rejected during signup or password change.

  • Invitation-bound portal access
  • Secure password changes
  • Leaked-password protection enabled

Common questions

Can one owner see another owner's property records?

Owner workspaces are designed around Supabase Row Level Security and server-side ownership checks so each owner only accesses records linked to their organisation.

Are rental documents public?

No. Rental documents are stored privately and should only be shared through authorised owner, tenant or tradie workflows.

Is the internal RentalKey operations login on this website?

No. Internal staff access is intentionally excluded from the public sign-in chooser and is separated onto ops.therentalkey.com.