Rental AutoPilot

Privacy Policy

How PT Rental AutoPilot handles personal data across Rental AutoPilot websites, CMS tools, guest messaging, and connected services.

Effective date: August 9, 2026

This Privacy Policy explains how PT Rental AutoPilot ("Rental AutoPilot", "we", "us", or "our") collects, uses, shares, and protects personal data when you visit our websites, use our CMS, communicate with us, or use services connected to Rental AutoPilot.

This policy is prepared with reference to applicable Indonesian laws and regulations, including Law No. 27 of 2022 on Personal Data Protection, Law No. 11 of 2008 on Electronic Information and Transactions as amended by Law No. 19 of 2016 and Law No. 1 of 2024, Government Regulation No. 71 of 2019 on Electronic Systems and Transactions, and other applicable implementing regulations as amended from time to time.

Legal entity: PT Rental AutoPilot

Address: Jalan Sriwijaya 32, Legian, Kuta, Bali 80361

Email: admin@rentalautopilot.com

1. Information we collect

Depending on how you use Rental AutoPilot, we may collect and process:

2. How we use information

We use personal data to provide, secure, support, and improve Rental AutoPilot. This includes:

3. Legal bases

Where a legal basis is required, we process personal data as needed to perform a contract, comply with legal obligations, protect legitimate business and security interests, or with consent where consent is required. Clients are responsible for making sure they have the rights and notices needed for the guest, owner, staff, property, and operational data they submit to Rental AutoPilot.

4. Guest messaging and automations

Rental AutoPilot may process guest messages, WhatsApp conversations, templates, translations, attachments, and delivery data to support client-configured messaging workflows. Automated or translated messages are used only where the relevant service settings and integrations allow them. Message content may be processed by the messaging, translation, hosting, and automation providers required to deliver the configured service.

5. Sharing information

We do not sell personal data. We share information only when needed to operate the service, follow a client's configuration, or meet legal obligations. Recipients may include:

6. Google Workspace and Gmail API data

Connection and permissions. If a client chooses Gmail as its email provider, an authorized client user may connect a Google account through Google OAuth. Rental AutoPilot requests the gmail.readonly permission to read Gmail messages and mailbox metadata and the gmail.send permission to send email from the connected account. Google's read-only permission technically applies across the selected mailbox. Rental AutoPilot limits its automated reading to payout-email searches using the sender, subject, and lookback period configured by the client. We do not receive or store the Google account password, and these permissions do not allow Rental AutoPilot to modify or delete existing Gmail messages or change Gmail settings.

Google user data we access and store. We access and store the connected Gmail address, granted permissions, connection and audit timestamps, and an OAuth refresh token. For payout emails matching the configured search, we access message identifiers, sender details, subject, date, and message content. Rental AutoPilot stores the extracted text and HTML content and parsed payout information, which may include payout account identifiers, amounts, currencies, reservation confirmation codes, guest or listing details, dates, and reservation-matching results. The Gmail API may return other MIME content within a matching raw message, but Rental AutoPilot's payout processor does not store Gmail attachment files. When Rental AutoPilot sends email, it transmits the recipient, subject, message body, and any attachment selected for that outgoing message to Gmail; Gmail keeps the sent message in the connected account. Rental AutoPilot may retain the Gmail message identifier, delivery result, and error information needed to operate and troubleshoot sending.

How we use Google user data. We use this data only to provide the client-facing Gmail features the client enables: sending login codes, notifications, and other client-routed operational emails; finding and parsing matching payout emails; associating payout lines with reservations; displaying payout information to authorized users; preparing accounting records; and, when an authorized user selects that action, sending relevant derived invoice details to the client's connected Xero account.

Storage and security. Google API requests are transmitted using HTTPS. OAuth refresh tokens are encrypted at rest using AES-256-GCM. Access is client-scoped and controlled through Rental AutoPilot authentication, roles, and permissions. Access tokens are generated when needed and are not stored as persistent connection credentials.

Sharing and human access. We do not sell Google user data. We disclose it only as needed to provide the Gmail and payout/accounting features described above: to authorized users in the same client account according to their permissions; to infrastructure providers that host, secure, or operate Rental AutoPilot under appropriate confidentiality and data-protection obligations; to email recipients selected by the client; to Xero when an authorized user directs Rental AutoPilot to create or update accounting records; or where necessary for security or required by law. Rental AutoPilot personnel do not read Gmail message content unless the user has explicitly asked for help with and agreed to access to specific data, or access is necessary for security or legal compliance. The general sharing descriptions elsewhere in this policy do not authorize any broader use or disclosure of Google user data.

Retention and user control. We retain the encrypted OAuth refresh token only while the Gmail connection remains active. Disconnecting Gmail stops future mailbox checks and Gmail sending, clears the locally stored refresh token and Gmail address, and attempts to revoke the token with Google. A user can also revoke Rental AutoPilot under Google Account → Security → Third-party access. Disconnecting does not delete messages from Gmail. Raw text and HTML copied from matching payout emails are automatically removed after 365 days by default; this period may be shortened where operationally appropriate. The minimum parsed accounting record may be retained longer where needed for accounting, applicable legal obligations, security, disputes, and backup or audit requirements. Gmail connection audit events are removed after 365 days by default. After disconnecting, an authorized client user can use Delete Gmail data in Email settings to permanently remove the stored Gmail connection history and all payout-email records imported through Gmail. A client may also request deletion at admin@rentalautopilot.com or use Rental AutoPilot's account-deletion process. Before a confirmed account deletion is completed, Rental AutoPilot attempts to revoke any remaining Google authorization; confirmed account deletion is otherwise scheduled after the stated 14-day grace period, subject to data that must be retained by law and ordinary backup-retention cycles.

Limited Use. Rental AutoPilot's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use or transfer Google user data for advertising, retargeting, sale to data brokers or information resellers, surveillance, credit-worthiness, lending, or to create, train, or improve generalized or non-personalized artificial intelligence or machine-learning models.

7. Cookies and analytics

We automatically keep aggregate daily page-request totals by public page. Request headers and a cookieless page-load confirmation are used to separate likely browser pageviews, known automation, internal referrals, and unclassified traffic, but the aggregate totals do not store an IP address, device detail, referrer, or persistent visitor identifier. The demo form uses a separate essential, HTTP-only session cookie limited to the demo path to protect form submissions; it does not enable optional analytics. Our websites and services may separately use optional cookies and similar technologies for detailed analytics. Optional analytics starts only after you allow it, and you can change that choice for this browser from this page.

Disable optional analytics for this browser.

8. Retention

We keep personal data for as long as needed to provide the service, respond to and document commercial inquiries, maintain records, resolve disputes, comply with legal obligations, and support legitimate operational needs. Demo-request details are kept only while needed for the inquiry, reasonable sales follow-up, security, and related business records. Retention periods otherwise vary depending on the type of data, client configuration, connected providers, legal requirements, and backup or audit needs.

9. Security

We use technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. No system is completely secure, so clients and users should also protect their credentials, devices, provider accounts, and integration access.

10. International processing

Rental AutoPilot is based in Indonesia. The systems and providers used to deliver the service may process data in Indonesia or other countries. Where required, we take reasonable steps to protect personal data when it is transferred or processed internationally.

11. Your choices and rights

Depending on applicable law and your relationship with Rental AutoPilot, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Some requests may need to be handled by the client that controls the relevant account or guest data. We may need to verify your identity before acting on a request.

12. Children's privacy

Rental AutoPilot is not intended for children and we do not knowingly collect personal data from children through our websites or CMS.

13. Changes to this policy

We may update this Privacy Policy from time to time. The effective date above shows when this version took effect. Material updates may also be communicated through the CMS or by direct notice where appropriate.

14. Contact

For privacy questions or requests, contact PT Rental AutoPilot at admin@rentalautopilot.com.