Privacy Policy
Last updated: July 25, 2026
1. Who we are
Renvia is provided by moovit, s.r.o., IČO 45240639, IČ DPH SK2022919415, Bobuľová 11/B, 900 28 Ivanka pri Dunaji, Slovakia. Privacy requests can be sent to privacy@renvia.app.
2. Our roles under the GDPR
Renvia is the controller for account registration, authentication, subscription administration, billing records received from Stripe, security, support communications, website operation and consent-based website analytics.
A Customer is normally the controller for property, guest, tenant, reservation, payment, expense, service and document data that the Customer or its team enters into Renvia. For that Customer Data, Renvia acts as processor under the DPA. Customers must provide their own notices and establish an appropriate legal basis for personal data they place in the Service. Consent is not the only possible legal basis and should not be requested where another basis is appropriate.
3. Personal data we process
- Account and access: name, email, user ID, roles, memberships, authentication and passkey metadata.
- Subscription and billing: plan, status, billing cycle, Stripe customer/subscription references and invoice-related metadata. Renvia does not store full card numbers or CVV.
- Customer Data: properties, reservations, guest or tenant details, financial records, expenses, payments, services, uploaded files and related notes.
- Integrations: identifiers and event data required when a Customer enables Google Calendar integration.
- Support and security: messages, request metadata, IP address and technical or security logs generated by the Service and its infrastructure.
- Website preferences and analytics: language preference and, only after the required consent, Google Analytics data. We also retain a pseudonymous record of the analytics choice; it contains no account identifier, email, IP address or user-agent.
4. Purposes and legal bases
- Creating accounts, authenticating Users and providing subscriptions: performance of a contract (Art. 6(1)(b)).
- Securing the Service, preventing misuse and diagnosing faults: legitimate interests (Art. 6(1)(f)).
- Accounting, tax, legal requests and compliance: legal obligation (Art. 6(1)(c)).
- Support and essential service communications: contract and legitimate interests.
- Non-essential website analytics: consent (Art. 6(1)(a)); analytics is not required to use the Service.
- Customer Data: the Customer's documented instructions and the legal basis determined by that Customer as controller.
5. Payments, cloud services and integrations
Stripe processes checkout, payment credentials, recurring billing, invoices and fraud-prevention data. Amazon Web Services hosts the application, authentication, databases, object storage, queues, logs and transactional email. Google services are used for consent-based website analytics and, where enabled by a Customer, Google Calendar. Current providers and purposes are listed on the Service Providers page.
6. Sharing and international transfers
We disclose personal data only to authorized service providers, to a Customer's authorized Users, where a Customer enables an integration, or where disclosure is required by law. We do not sell personal data. Some providers may process data outside the EEA. Where required, the relevant provider terms, adequacy decisions, Standard Contractual Clauses or another lawful Chapter V mechanism are used.
7. Security
Renvia uses measures appropriate to the risk, including encrypted transport, cloud-provider encryption at rest where configured, authenticated API access, tenant/portfolio isolation, role checks, rate limiting, restricted infrastructure permissions, passkey support, security logging and controlled deployments. No online system is completely secure, and Renvia does not promise a specific SLA, backup retention, recovery objective or certification unless agreed in writing.
8. Retention
Account and Customer Data is normally retained while the relevant account or portfolio remains active. Users can delete individual records using available Service controls. An owner can request deletion of a portfolio and its related active-system data; an account can be deleted after the User no longer owns a portfolio. Job-status records for these deletion operations expire automatically after approximately one year.
Some information may be retained or anonymized where necessary for accounting, tax, fraud prevention, security, legal claims or compliance. Versioned copies of uploaded files are retained for up to 30 days for operational recovery and are then removed automatically. Database point-in-time recovery follows the configured AWS recovery window. Infrastructure logs follow the lifecycle of the applicable AWS service. Customers remain responsible for setting appropriate retention periods for Customer Data.
Analytics-consent audit records are retained for two years. They use a random browser identifier and record the decision, category, policy version, language, source and server-generated time; they are not linked to a Renvia account.
9. Account and portfolio deletion
Authenticated Users can start account deletion in Settings. A User who owns a portfolio must first transfer ownership or delete that portfolio. Portfolio deletion is owner-only, requires confirmation using the portfolio name, cancels an associated Stripe subscription where applicable, and removes related database records and supported stored files through a background process. Account deletion removes the User's memberships, passkeys, authentication account and direct profile data, and anonymizes references that must remain in shared operational records.
A deletion or data-rights request may also be submitted to privacy@renvia.app. Identity and authority will be verified. Legal retention exceptions may apply.
10. Data subject rights
Subject to the GDPR conditions and exceptions, individuals may request access, rectification, erasure, restriction, portability or objection, and may withdraw consent at any time. Renvia does not use Customer Data to make solely automated decisions producing legal or similarly significant effects. Where Renvia is processor, requests concerning guest, tenant or other Customer Data should normally be directed to the relevant Customer, and Renvia will assist that Customer as required.
Requests can be sent to privacy@renvia.app. We generally respond within one month, subject to permitted extensions.
11. Supervisory authority
You may complain to the supervisory authority in your habitual residence, place of work or place of the alleged infringement. In Slovakia, the authority is the Úrad na ochranu osobných údajov Slovenskej republiky, dataprotection.gov.sk.
12. Children
Renvia is a business property-management service and is not directed to children. Customers must not create Service accounts for children. Customer Data may concern guests or tenants of different ages; the Customer is responsible for the lawfulness and minimization of that data.
13. Changes and contact
We may update this policy to reflect changes in the Service or law. The current date is shown above. Renvia has not appointed a Data Protection Officer because it has determined that Article 37 does not currently require one. Privacy matters and DPA requests should be sent to privacy@renvia.app.