← Rental Unify

Privacy Policy

Effective date: July 20, 2026 · Last updated: August 26, 2026

Platform role

Rental Unify provides software for calendar synchronization and, when enabled, private Direct Booking pages. We are not the landlord or merchant for guest stays. When a booking is confirmed, we share host and guest contact details with each other so they can coordinate the stay outside our app. See our Terms of Service for the full disclaimer.

This Privacy Policy explains how Rental Unify (“Rental Unify,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you visit rentalunify.com or use our calendar synchronization, private Direct Booking pages, and related services (the “Service”). By using the Service, you agree to this Policy. If you do not agree, please do not use the Service.

1. Who we are

Rental Unify is a software service based in Norwalk, Connecticut, United States. We help short-term rental hosts aggregate and publish property availability across listing platforms using iCalendar (iCal) feeds, and - when enabled on a plan - offer private Direct Booking pages that hosts share by link or QR code. The Service is operated from Norwalk, CT and is available at rentalunify.com.

Privacy questions: privacy@rentalunify.com or our contact form.

2. Information we collect

We collect information in the following categories:

Account & profile data. Name, email address, password (stored as a one-way hash), optional profile image, phone number (when required for Direct Booking), and account preferences. If you change your email, we process confirmation tokens sent to your current address.

Property, listing & calendar data. Property names, addresses (required for each property), timezones, listing descriptions, photos, pricing, house rules, platform connection metadata, encrypted calendar export URLs you paste into the Service, availability/blocked-date events derived from connected feeds, manual blocks, Direct Booking blocks, sync health status, and conflict signals. Host-curated Local Recommendations store place names, addresses, phone numbers, websites, ratings, Google place IDs, map links, and optional host notes. When a host searches to add a place, we send the search text and (if set) the listing map location to Google so results can be biased nearby. When a host types a property address, we may send that text to Google Places so we can suggest a correctly formatted real-world address. For OTA sync we design the Service to sync availability, not OTA guest identity. We do not ask for or store your Airbnb, Vrbo, Booking.com, or other OTA passwords.

Direct Booking guest data. When a guest books (or starts checkout) on a private listing, we collect name, email, phone, stay dates, party size, and related booking selections (add-ons, pets, parking, coupons, referrals) needed to complete the stay and notify the host. Payment card numbers are collected and processed by Stripe; they are not stored on our servers. Guests may optionally create a guest account from a private listing link. Guest account data (name, email, phone, password hash) is used to sign in to the guest stay dashboard, autofill later bookings, and link prior stays that used the same email. Marketing-site registration is for hosts only and is not a guest signup path. Guests may also subscribe on a private listing for future discounts and coupons; we store first name, last name, and email for that listing’s host so they can send stay offers. When Birthday Offers are enabled for a listing, subscribe may also collect birthday month and day (not year). Guest registration always asks for birthday month and day so hosts can send surprise birthday offers when Birthday Offers are enabled for a listing. We do not use birth year or calculate age. Promotional offer and birthday emails include an unsubscribe link; unsubscribing stops marketing emails from that host and marks the guest do-not-contact in the host’s Guests list. Transactional emails about a booked stay may still be sent. For referral fraud prevention we may store a Stripe card fingerprint (not the full card number) on a booking so we can block self-referrals and abusive multi-account discounts. When a host enables Trust Kit options, we may also process: (a) security deposit hold and capture/release status via Stripe on the host’s Connect account; (b) identity verification session status via Stripe Identity; and (c) guest-uploaded check-in/check-out evidence photos stored for that booking so the host can review them. Deposit and identity outcomes are shared with the listing host as needed to manage the stay. Evidence photos are not used for advertising.

Billing & payouts data. Subscription plan, billing interval, status, and Stripe customer/subscription identifiers for your Rental Unify subscription. For Direct Booking hosts: Stripe Connect account identifiers and onboarding/payout readiness status. Sensitive payment credentials are handled by Stripe.

Support & business inquiries. Information you submit via forms (for example, Business plan inquiries), including name, email, company, property volume, and message content.

Usage, device & diagnostics. Log data such as IP address, browser/user agent, approximate request timing, pages or API routes accessed, and error/diagnostic events needed to operate, secure, and improve the Service - including abuse detection. We may also record product activity events in your account (for example, sync results, connection changes, or booking events). For Direct Booking listings we keep anonymous aggregate counters of QR scans and private-link opens (and may attribute a later booking to QR vs link, or to a host-named marketing campaign, using a short-lived cookie). These traction counts are not sold for advertising and are shown to the listing host.

Cookies & session data. Authentication and security cookies (including session tokens) required to keep you signed in and protect accounts. See Section 6.

3. How we use information

We use information to:

  • Provide, maintain, and improve the Service (including calendar sync, conflict detection, export feeds, private Direct Booking pages, optional Long Term inquiry and contract tools, and host-curated Local Recommendations);
  • Create and authenticate accounts, reset passwords, and verify email changes;
  • Process host subscriptions and Connect onboarding through Stripe;
  • Facilitate confirmed bookings, send transactional confirmation emails, and exchange host/guest contact details as described in Section 5;
  • Send service-related communications (security alerts, billing notices, transactional email);
  • Respond to support and sales inquiries;
  • Monitor abuse, detect fraud/scams, debug issues, and protect the security and integrity of the Service;
  • Comply with law, enforce our Terms of Service, and establish, exercise, or defend legal claims;
  • With your consent where required, send optional product updates or marketing (you may opt out).

We do not sell your personal information for money.

4. How we share information

We share information only as needed to run the Service:

  • Service providers / processors - hosting, email delivery, error monitoring, and similar vendors who process data on our instructions;
  • Stripe - subscription billing, Connect payouts, and checkout for Direct Booking (Stripe Privacy Policy);
  • Cloudflare Turnstile - when enabled by a Master Admin, public and guest forms (for example contact, signup, login, checkout, Message Host, reviews) may send a browser challenge token to Cloudflare to reduce spam and abuse. See Cloudflare Privacy Policy;
  • Google - when a host searches for or adds a Local Recommendation, we send the search query and optional map bias to Google Places. When a host enables the listing map, guests load a Google Maps embed for that location. Guests who tap a recommended place open Google Maps (Google’s own services and policies then apply). See Google Privacy Policy;
  • Hosts and guests (Direct Booking) - upon booking confirmation, we share each party’s required contact information with the other so they can coordinate the stay (see Section 5);
  • Listing platforms you connect - when you publish a Rental Unify export feed URL into a platform’s “import calendar” setting, that platform retrieves availability data from our feed according to its own policies;
  • Legal & safety - if required by law, regulation, legal process, or to protect rights, safety, or security (including scam investigations);
  • Business transfers - in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality.

Public calendar export URLs are designed to expose availability (“Unavailable” style blocks), not guest PII. Anyone with the URL can fetch the feed - treat feed links like secrets and rotate them if exposed. Private Direct Booking URLs are also sensitive; anyone with the link may view the listing.

5. Mandatory booking contact exchange

Rental Unify does not provide an in-app messaging inbox between hosts and guests. After a Direct Booking is confirmed, coordination happens by email and/or phone.

What we share. When a booking is confirmed, we disclose:

  • To the host: the guest’s name, email address, and phone number (and booking details);
  • To the guest: the host’s name or business name, contact email, and phone number (and booking details).

Providing this information is a condition of using Direct Booking (hosts) or completing a booking (guests). Do not submit false contact details. Hosts and guests must not misuse shared contacts for spam, harassment, or unrelated marketing.

6. Cookies and similar technologies

We use essential cookies and similar technologies for authentication (including separate host and guest sessions), security (including CSRF protection and, when enabled, Cloudflare Turnstile challenge tokens on public forms), preference storage, and anonymous Direct Booking traction counts (QR scans, private-link opens, and optional marketing campaign codes, with short-lived cookies so the same browser is not counted repeatedly). These are necessary for the Service to function. We do not use advertising cookies to track you across third-party sites for behavioral ads. Your browser settings may allow you to block cookies; doing so may prevent login or other features from working.

7. Retention

We retain account, property, calendar, booking, and billing-related information for as long as your account is active and as needed to provide the Service. After deletion or closure, we may retain limited information for a reasonable period for backups, fraud prevention, dispute resolution, audit, and legal compliance (for example, billing and booking records). Activity logs and diagnostics may be retained for shorter operational windows unless a longer period is required.

8. Security

We use industry-standard safeguards appropriate to the nature of the data, including HTTPS/TLS in production, hashed passwords, encrypted storage of sensitive calendar URLs, access controls, and secure session cookies. We also take steps to reduce abuse (for example, logging, verification requirements, and account review). No method of transmission or storage is 100% secure; we cannot guarantee absolute security. Please use a strong unique password and keep your account credentials and private booking links confidential.

9. Your rights and choices

Depending on applicable U.S. state law (including for California residents under the CCPA/CPRA), you may have rights to:

  • Access a copy of personal information we hold about you;
  • Correct inaccurate information;
  • Delete personal information (subject to legal and operational exceptions);
  • Export or port certain data;
  • Opt out of marketing emails (transactional/service messages may still be sent);
  • For California residents: rights to know, delete, correct, and not be discriminated against for exercising privacy rights. We do not “sell” or “share” personal information as those terms are commonly defined for cross-context behavioral advertising.

You can update profile details in Settings, disconnect calendar feeds in the dashboard, and manage billing via the Stripe customer portal. Guests without an account may email us regarding a booking confirmation. To request access, deletion, or other privacy rights, email privacy@rentalunify.com. We may need to verify your identity before fulfilling a request. Note that information already shared with a host or guest under Section 5 may remain with that party outside our control.

10. Children

The Service is directed to adults operating rental businesses and adult guests making bookings. It is not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will take appropriate steps to delete it.

11. Where we process data

Rental Unify is based solely in Norwalk, Connecticut, USA. We process and store Service information in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, which may have different privacy laws than your country of residence.

12. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Material changes may also be communicated by email or in-product notice. Continued use of the Service after an update constitutes acceptance of the revised Policy.

13. Contact us

Rental Unify
Norwalk, Connecticut, United States
Website: https://rentalunify.com
Email: privacy@rentalunify.com
Business inquiries: Contact form

Related: Terms of Service · Knowledge Base