Privacy notice

Platform & CMS

How information is handled across client accounts, guest services, messaging, operations, reporting, and connected providers.

Effective date: September 12, 2026

Who this notice is for: Rental AutoPilot clients, account users, owners, staff, guests, and other people whose information is processed through the platform, CMS, guest pages, messages, or integrations. Native Staff App permissions and background location are explained separately in the Staff App Privacy Notice.

Legal entity: PT Rental AutoPilot

Address: Jalan Sriwijaya 32, Legian, Kuta, Bali 80361

Privacy contact: admin@rentalautopilot.com

Who determines how platform data is used

For guest, owner, staff, property, reservation, message, and operational information entered into or connected to a client's account, the client generally determines why the information is used and which authorized users may access it. Rental AutoPilot processes that information to provide the configured service and follow the client's instructions, subject to our contract and applicable law. Rental AutoPilot separately determines how it handles account administration, security, abuse prevention, service diagnostics, billing, and legal records. The exact legal role depends on the circumstances.

If your data was supplied by a villa, employer, property manager, or other Rental AutoPilot client, that client may be best placed to explain why it was collected or correct the underlying reservation, employment, or operational record.

Information processed through the platform

How the information is used

Guest messaging and automations

Rental AutoPilot may process guest messages, WhatsApp conversations, email, templates, translations, attachments, delivery status, and conversation history for client-configured communications. A configured automation may evaluate reservation or operational data and prepare or send a message within the client's rules. Message content may pass through the hosting, messaging, email, translation, or AI provider needed to perform that workflow. Authorized users remain responsible for reviewing settings and using messaging features lawfully.

Guest guidebook location

A guest-facing guidebook may offer location-aware directions. Precise location is requested only when the visitor chooses the location option and grants browser permission. Coordinates, accuracy, capture status, time, and related guidebook-open context may be recorded to provide directions and maintain an operational or consent audit. Google Maps receives the coordinates needed when the visitor opens the map or directions feature.

Connected providers and sharing

We do not sell personal data. Information is made available to authorized users in the relevant client account according to their permissions. We share information with service providers only when needed to operate the service or follow a client's configuration, and require those providers to provide equivalent protection consistent with this notice and applicable requirements. These may include hosting and security providers, Google Cloud Storage for protected media, PMS and channel managers, WhatsApp and email providers, Apple Push Notification service, Firebase Cloud Messaging, accounting and payment services, smart-lock and utility providers, Google Maps, translation services, and configured OCR or AI providers such as OpenAI.

We may also disclose information to professional advisers, authorities, or other parties where required by law or necessary to protect rights, safety, security, or service integrity. Providers may process information in Indonesia or other countries. Where required, we take reasonable steps to protect personal data processed internationally.

Google Workspace and Gmail API data

Connection and permissions

If a client chooses Gmail as its email provider, an authorized client user may connect a Google account through Google OAuth. Rental AutoPilot requests gmail.readonly to read Gmail messages and mailbox metadata and gmail.send to send email from the connected account. The read-only permission technically applies across the selected mailbox, but Rental AutoPilot limits its automated reading to payout-email searches using the sender, subject, and lookback period configured by the client. We do not receive or store the Google password. These permissions do not let Rental AutoPilot modify or delete existing Gmail messages or change Gmail settings.

Google user data accessed and stored

We access and store the connected Gmail address, granted permissions, connection and audit timestamps, and an encrypted OAuth refresh token. For matching payout emails, we access message identifiers, sender, subject, date, and message content. We store extracted text and HTML plus parsed payout information, which may include account identifiers, amounts, currencies, reservation confirmation codes, guest or listing details, dates, and reservation-matching results. The payout processor does not store Gmail attachment files.

When Rental AutoPilot sends an email, it transmits the recipient, subject, body, and any selected outgoing attachment to Gmail. Gmail retains the sent message in the connected account. Rental AutoPilot may retain the Gmail message identifier, delivery result, and error details needed to operate and troubleshoot sending.

Use, sharing, and Google Limited Use

Google user data is used only to provide the client-facing Gmail features the client enables: sending login codes, notifications, and client-routed operational email; finding and parsing matching payout emails; associating payout lines with reservations; displaying payout information to authorized users; preparing accounting records; and sending relevant derived invoice details to the client's connected Xero account when an authorized user chooses that action.

Google user data is not sold, used for advertising, shared between clients, or used to train generalized artificial-intelligence or machine-learning models. Human access is limited to cases where the client asks for support, access is necessary for security or abuse investigation, access is required by law, or the data has been aggregated or de-identified for internal operations. Rental AutoPilot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Gmail retention and deletion

The encrypted OAuth refresh token is retained only while the Gmail connection is active. Disconnecting stops future mailbox checks and Gmail sending, clears the stored refresh token and Gmail address, and attempts to revoke the token with Google. A user can also revoke Rental AutoPilot in Google Account settings. Disconnecting does not delete messages from Gmail.

Raw text and HTML copied from matching payout emails is automatically removed after 365 days by default and may be removed sooner. Minimum parsed accounting records may be kept longer for accounting, legal, security, dispute, backup, or audit requirements. Gmail connection audit events are removed after 365 days by default. After disconnecting, an authorized client user can select Delete Gmail data in Email settings to permanently remove stored Gmail connection history and imported payout-email records.

Retention and deletion

Platform data is kept while needed to provide the client's configured service, maintain operational and financial records, secure the account, resolve disputes, and meet contractual or legal obligations. Retention can vary by record type, client configuration, and applicable law. Deletion from an active screen may not immediately remove protected backups, audit evidence, financial records, or provider-side copies that must be retained.

A logged-in user can request account deletion from Settings > Account. Confirmed account deletion is scheduled after a 14-day grace period, subject to legally required records, legitimate security or dispute records, and ordinary backup cycles. Staff App location, proof-media, device, and delivery-history periods are described in the Staff App retention section.

Security and access controls

We use technical and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. Client users should protect credentials and connected provider accounts, grant only necessary permissions, and promptly remove access that is no longer needed. No system can be guaranteed completely secure.

Optional analytics choice

Rental AutoPilot automatically counts aggregate page requests without setting a cookie, storing a visitor identifier, or retaining the visitor's raw IP address in that counter. More detailed browser analytics runs only after optional analytics cookies are accepted.

Disable optional analytics for this browser.

Your choices and rights

Depending on applicable law and your relationship with Rental AutoPilot, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Some requests must be handled by the client responsible for the relevant guest, owner, staff, employment, reservation, or property record. We may need to verify your identity and authority before acting.

Changes and contact

We may update this notice from time to time. Material changes may also be communicated through the CMS or directly where appropriate. For privacy questions or requests, email admin@rentalautopilot.com.