Skip to content
Legal · PrivacyEffective 03 July 2026

Privacy Policy

How we collect, use, and protect personal data — and the rights you have over it. We've written this to be readable, not just compliant.

This Privacy Policy explains how Future Point Consult (Pty) Ltd (trading as “LetLoose”, and referred to in this policy as “LetLoose”, “we”, “us” or “our”) handles personal data in connection with LetLoose — a rental-property operations platform that connects property owners, managers, cleaners, and service providers (“the Service”), available at www.letloose.run.

LetLoose is a global product. Our operations are based in South Africa, and our customers manage properties, owners, and guests across regions including the European Union, so this policy is written with the EU General Data Protection Regulation (GDPR) in mind — including the UK GDPR where it applies — and is also aware of South Africa's Protection of Personal Information Act (POPIA). Where one of these laws applies to you, we aim to honour the rights it gives you.

This policy works alongside our Terms of Service. If anything here is unclear, please reach out at privacy@letloose.run.

1.Who we are, and our role

The operator of the Service is Future Point Consult (Pty) Ltd, registered at 298 Glenwood Rd, Lynnwood Park, Pretoria, 0081. You can contact our privacy team at any time at privacy@letloose.run. We have not appointed a dedicated Data Protection Officer; for all data-protection matters, please use the address above.

Controller vs. processor

Under data-protection law, the role we play depends on whose data is involved:

We are the controller

For your own account data and your use of our website — for example your name, email, login details, and how you interact with the Service — LetLoose decides why and how the data is processed. For this data, we are the controller.

We are the processor

For data you enter about other people — your guests, vendors, property owners, and staff — you are the controller and we process that data on your behalf, under your instructions. We did not collect this data from those people directly; it was provided to us by our customer, who remains responsible for telling them how it is used. Our Data Processing Agreement (DPA) governs this relationship for business customers and forms part of our Terms.

2.What personal data we collect

We collect only the data needed to run a property-operations platform. The categories below cover everything we hold.

  1. 1. Account & identity

    For team members and account holders: display name, email address, phone number, profile photo or avatar, and either a hashed password (managed by Supabase Auth) or a Google account identifier when you sign in with Google. We also store your organization membership and role (owner, manager, cleaner, or provider).

  2. 2. Contacts you store

    Details you record about vendors, property owners, and guests saved as contacts: name, company name, email, phone, postal address, and tax number.

  3. 3. Guest booking details

    Information you enter about your guests: guest name, email, phone, number of guests, stay dates, and booking amounts.

  4. 4. Property information

    Property name, street addresses, and configuration or capacity details.

  5. 5. Financial & operational records

    Bookings, invoices, expenses, payment requests, budget rules, maintenance quotes, cleaning tasks, and owner statements — including monetary amounts and, where you enter them, tax or VAT numbers and payment references.

  6. 6. Uploaded files

    Expense receipts, task photos, profile avatars, and property images. Receipts and task photos are stored in private storage buckets accessible only to authenticated members of your organization. Avatars and property images are stored in buckets that are publicly readable by anyone who has the file's unguessable link, so the app can display them quickly — please do not upload anything confidential as an avatar or property image.

  7. 7. Technical & usage data

    IP address, browser and device information, server logs, and cookies or browser local storage used for authentication sessions and interface preferences.

3.How and why we use your data, and our legal bases

We use personal data to operate, secure, and improve the Service — for example to create and manage accounts, deliver core features (bookings, expenses, invoices, tasks, owner statements), send transactional emails, keep your data isolated and secure, and respond to your requests.

Where the GDPR applies, we rely on the following legal bases under Article 6:

  • Performance of a contract — to provide the Service you signed up for.
  • Legitimate interests — to secure the Service, prevent fraud and abuse, and improve the product, balanced against your rights and freedoms.
  • Consent — where required, such as for any future non-essential cookies or marketing email. You can withdraw consent at any time.
  • Legal obligation — to retain financial and tax records where the law requires it.

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

The emails we send to run the Service — such as invoices, owner statements, and account notices — are transactional, not marketing. We send product or marketing email only with your consent or where a soft opt-in applies, always with a one-click unsubscribe; opting out of marketing does not affect transactional or service messages.

4.Cookies & local storage

We keep our use of cookies and browser storage minimal and functional:

  • Essential authentication cookies set by Supabase Auth, which are required to keep you signed in.
  • Browser local storage for interface preferences — your theme selection (key letloose-theme), whether the sidebar is collapsed (key letloose-sidebar-collapsed), and when you last viewed your notifications (key letloose-notifications-read-at).

We do not currently use any third-party advertising or cross-site tracking cookies. If we ever introduce a non-essential or analytics cookie, we will ask for your consent first.

5.Sub-processors & service providers

We rely on a small number of trusted providers to run the Service. These are the third parties that process personal data on our behalf as part of delivering it:

Supabase

Application database, authentication, and encrypted file storage — our primary data host. Hosting region: Ireland (AWS eu-west-1), selected to support EU data residency where required.

Vercel

Application hosting and global content delivery.

Resend

Transactional email delivery — for example invoices, owner statements, and notifications — sent from a LetLoose address.

Google

Google Sign-In / OAuth authentication, only when you choose to sign in with Google.

We will give business customers at least 30 days' advance written notice of any addition or replacement of a sub-processor before it takes effect, with the opportunity to object, as set out in our Data Processing Agreement.

Other recipients & disclosures

Beyond the providers above, we share personal data only in these limited situations:

  • Professional advisors — such as our lawyers, accountants, or auditors, where reasonably needed and under a duty of confidentiality.
  • Authorities and legal process — where required by law or valid legal process, or where reasonably necessary to enforce our Terms, prevent fraud or abuse, or protect the rights and safety of others. Where the data belongs to one of our business customers and the law permits, we will notify that customer before responding.
  • Business transfers — if LetLoose is involved in a merger, acquisition, financing, reorganisation, or sale of assets, personal data may transfer to the successor, which will remain bound by protections at least as protective as this policy. We will notify affected users of any such change.

We do not sell your personal data, and we do not share it for advertising.

6.International data transfers

Because our sub-processors operate globally, your data may be processed in countries outside your own. Where data leaves the European Economic Area (EEA), we put appropriate safeguards in place — such as the EU Standard Contractual Clauses — to protect it to the standard required by the GDPR. Where data leaves the United Kingdom, we rely on the UK International Data Transfer Addendum to those clauses. Where South African personal information is transferred outside South Africa, we do so in accordance with the conditions for transborder information flows under POPIA — for example, the recipient being bound by comparable safeguards, or with your consent where applicable.

7.How we protect your data

We take security seriously and apply the following measures:

  • Encryption in transit (HTTPS/TLS) and at rest.
  • Row-Level Security in the database, isolating each organization's data from every other organization.
  • Role-based access control, and private, organization-scoped storage for sensitive uploads such as receipts and task photos.

No method of transmission over the internet or method of electronic storage is 100% secure, so while we work hard to protect your data we cannot guarantee absolute security.

If a personal-data breach affects your data, we will act promptly to investigate and contain it, and will notify the relevant supervisory authority and affected individuals without undue delay where the law requires. Where we process data on behalf of a business customer, we will notify that customer so they can meet their own obligations.

8.How long we keep your data

We retain account and operational data for the life of your account. When your account is closed, you have a 30-day window to export your data (see our Terms of Service). We then delete or anonymise personal data from our active systems within 90 days, and any copies held in encrypted backups are purged within at most 180 days, except where longer retention is legally required — for example tax or accounting records, which may be kept for at least 7 years (and up to 10 years in some countries) as required by applicable law.

9.Your rights

Depending on where you are, data-protection law gives you a number of rights over your personal data.

If the GDPR applies to you

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection. You may withdraw consent at any time where we rely on it, and you have the right to lodge a complaint with a supervisory authority — in the EU, the authority in your country of residence, place of work, or where the alleged infringement occurred — whether or not you have first raised your concern with us. The same rights apply under the UK GDPR, where the supervisory authority is the UK Information Commissioner's Office (ICO).

If POPIA applies to you

You have the right to access, correction, deletion, and objection, and — where we rely on your consent — the right to withdraw it at any time. You also have the right to complain to the Information Regulator (South Africa) at any time, whether or not you have first raised your concern with us. For POPIA matters you may also contact our Information Officer at privacy@letloose.run.

How to exercise your rights

A self-service data-export feature is on our roadmap. Until then, please send your request to privacy@letloose.run and we will respond, normally within 30 days. Where data you want to access or remove was entered about you by one of our business customers, that customer is the controller of it and we may need to direct your request to them.

10.Children

The Service is intended for businesses and adults. It is not directed to children, and we do not knowingly collect personal data from anyone under 18 (the age of majority, and the threshold for a child under South Africa's POPIA). If you believe a child has provided us with personal data, please contact us and we will take appropriate steps.

11.Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will communicate them and update the effective date shown at the top of this page.

12.Contact us

If you have any questions about this policy or how we handle your data, please get in touch:

Future Point Consult (Pty) Ltd (trading as LetLoose)

298 Glenwood Rd, Lynnwood Park, Pretoria, 0081

Email: privacy@letloose.run

See also our Terms of Service.