Privacy Notice
Version 1.2 · Effective: Jul 28, 2026 · Last updated: Jul 28, 2026
1. Who we are
The RUMA property-management portal (the "Service") is operated by StatGazer LLC, a New York limited liability company. This Privacy Notice explains how we collect, use, and protect information across the Service — the website, the app, workspaces, invitations, subscription billing, and support. Registered address: 418 Broadway, STE R, Albany, NY 12207, USA. Privacy requests: privacy@ruma.rent. Legal notices: legal@ruma.rent.
2. Our roles: controller and processor
RUMA is a two-sided service, so our role depends on the processing activity — we are not "only a controller" or "only a processor":
| Processing activity | Our role |
|---|---|
| Account registration, authentication, security, and subscription billing | StatGazer acts as controller (business) |
| Workspace content a Customer and its users enter (properties, leases, charges, documents, messages) | StatGazer processes it on the Customer's behalf (service provider / processor) |
| A tenant's own account settings and requests made directly to us | StatGazer acts as controller |
| Fraud prevention, abuse handling, security logs, legal compliance | StatGazer acts as controller |
Where we process Workspace content on a Customer's behalf, the Customer decides what is stored and why, and we act on the Customer's instructions under our Data Processing Addendum, which applies automatically to business Customers whose Customer Data includes personal data.
3. Information we collect
- Account details — your name, email address, optional company name, and (if you upload one) a profile photo.
- Workspace data you enter — properties, leases, tenants you invite, rent obligations and payment records, utility charges, documents, messages, and internal notes.
- Files you upload — lease documents, receipts, and message attachments.
- Security data — a hashed password, optional two-factor (TOTP) settings, and active session records (device/browser label and timestamps).
- Subscription billing data — if you buy a paid plan, our payment processor (Stripe) collects your card details directly; RUMA receives your plan, billing status, subscription period, invoice amounts and dates, and limited card metadata (brand, last four digits, expiry — so you can recognize the card in Settings) — never the full card number.
- Technical data — a session cookie required to keep you signed in, and basic request logs used for security and reliability.
Rent itself is never processed by RUMA: rent payments are recorded on an honor-system basis (a tenant reports a payment and the landlord confirms it), and no rent money, card number, or bank credential passes through the Service.
4. How we use information; legal bases
We use the information to operate the Service: authenticate you, run your workspace, deliver rent reminders and notifications, generate reports and receipts, process your subscription, provide support, keep the Service secure, and comply with law. We do not use your data for advertising, and we do not train machine-learning models on your workspace content.
Where a legal basis is required: we process account and workspace data to perform our contract with you; security, fraud-prevention, and product-integrity processing rests on our legitimate interests; tax and accounting records are kept under legal obligation; and we ask for consent only where it is genuinely needed (it is not the blanket basis for this Notice).
5. Product analytics (announced — not yet active)
RUMA is introducing first-party product analytics to understand how the Service is used — which features help, where sign-up and set-up stall, and whether the product is reliable. As of this version of the Notice, analytics collection is not active: no analytics identifier is set and no analytics events are collected or shared.
When activated, it works like this. Usage events are sent to RUMA itself first — no third-party analytics script runs on RUMA pages and no third-party cookie is set. Events describe actions, never content: they do not include message or document text, uploaded files, names, email addresses, street addresses, precise location, or payment details. Before any analytics processor sees an event, account-level identifiers are replaced with keyed pseudonyms that the processor cannot reverse.
The analytics processor will be PostHog, Inc. (hosted in the United States), announced in advance on the Subprocessors page and engaged only when analytics activates. RUMA is used globally, and analytics is not limited to any one country: collection is enabled region by region only as applicable law permits, and where consent is required it will be obtained before activation in that region.
Retention: raw analytics events are kept at most 12 months at the analytics processor; operational counters at most 90 days; anything kept longer exists only in de-identified, aggregate form.
Your choice, honored from day one: RUMA treats Global Privacy Control (Sec-GPC), the Do Not Track browser signal, and a manual analytics opt-out as one analytics preference. Opting out stops collection, removes the local analytics identifier and stored campaign attribution, and is never overridden or silently reset. Security, fraud-prevention and reliability logging (section 11) is separate from product analytics and continues — it is what keeps accounts safe and the Service running.
Deletion: when you opt out or erase an account, RUMA derives the analytics pseudonyms and carries a deletion obligation through to the analytics processor. Requests and questions: privacy@ruma.rent.
7. Service providers (subprocessors) & international transfers
We share information only with the processors that make the Service work:
| Provider | Function | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, and object storage for uploaded files | USA / global edge network |
| Resend, Inc. | Transactional email (invitations, reminders, security emails) | USA |
| Stripe, Inc. | Subscription payment processing (card details collected by Stripe directly) | USA |
| PostHog, Inc. | Product analytics (pseudonymized usage events) — announced ahead of activation; not yet processing Service data | USA |
These providers process data on our behalf under their own terms and are not permitted to use it for their own purposes. We do not sell your personal information. The Service is operated from the United States; if you access it from elsewhere, your data may be processed in the United States and other countries where these providers operate. The canonical, always-current list — with data categories, privacy links, and our update-before-adding commitment — lives at Subprocessors.
8. Tenants, invitees & landlord-entered data
A landlord may enter information about a tenant (name, email, lease terms, charges) before that tenant ever signs in. For that data, the landlord decides what is stored and why, and RUMA processes it on the landlord's behalf to operate their workspace.
If you received an invitation: the invitation email names the workspace that invited you and explains that RUMA uses your email address only to deliver and complete the invitation. Invitations are single-use and expire automatically; if you don't accept, the invitation (and its contact data) is pruned and no account is created for you.
If you are a tenant: once you accept an invitation you can see your own lease, balance, documents, and messages directly in the app, and you can delete your RUMA account at any time from Settings. For corrections to records your landlord created (for example a charge you dispute), contact your landlord first — those are their business records. You can always reach us at privacy@ruma.rent about data RUMA itself controls.
9. Data retention & deletion
Your records (obligations, documents, and every report) export to CSV throughout the app, and tenants can download their own statement. Tenants can delete their account and workspace owners can close their workspace from Settings; for other account-removal requests (for example a team member's account), contact us.
| Data | Retention |
|---|---|
| Unaccepted invitations | Expire automatically; invitee contact data is pruned with the invitation |
| Active accounts & workspaces | Kept while the account/workspace is active |
| Deleted tenant account / closed workspace | Soft-deleted for a 30-day restore window, then permanently anonymized/erased |
| Subscription billing records | Kept as required for tax, accounting, and fraud-prevention purposes |
| Security & request logs | Kept for a limited security-review period, then rotated |
| Backups | Deleted on the backup cycle's rolling schedule after production deletion |
| Records under a legal hold or dispute | Kept until the hold or dispute is resolved |
| Product analytics events (announced; not yet collected) | Once active: at most 12 months at the analytics processor; operational counters at most 90 days; longer-lived aggregates only in de-identified form |
Deleting your account does not automatically delete Shared Records lawfully held by the other side of your lease (see the Terms), and some records may be retained where required for legal, tax, or fraud-prevention purposes. Backups are deleted on a rolling schedule rather than instantly.
10. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. RUMA provides CSV export of your records and self-service deletion (tenant accounts and owner workspaces) directly in the app; for any other request, contact us at privacy@ruma.rent — we will verify your identity and respond within the timeframe applicable law requires. You may also lodge a complaint with your local supervisory authority.
California residents: the CCPA/CPRA gives you the right to know what personal information we collect (see section 3), to delete it, to correct it, and to not be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is no sale or sharing to opt out of. When first-party product analytics activates, RUMA will honor Global Privacy Control as an analytics opt-out signal everywhere (see section 5). Requests: privacy@ruma.rent.
11. Security
Passwords are hashed, traffic is encrypted in transit, optional two-factor authentication is available, and you can review and revoke active sessions from Settings. We follow least-privilege access, keep audit and security logs, and maintain backups and an incident-response process. No system is perfectly secure, but we work to protect your data and to notify you of material incidents as required by law.
12. Children
The Service is intended for businesses and adults. It is not directed to children, and we do not knowingly collect data from anyone under 18.
13. Changes
We may update this Notice. Each version carries a version number and effective date; material changes will be announced by in-app or email notice before they take effect.
14. Contact
Questions about this Notice or your data: privacy@ruma.rent. Operator: StatGazer LLC, a New York limited liability company, 418 Broadway, STE R, Albany, NY 12207, USA.
See also our Terms of Service.
- Version 1.2current· effective Jul 28, 2026
- Version 1.1· effective Jul 11, 2026
