Legal

Privacy policy

Effective . This policy explains what we collect on renting.berlin and why.

Who operates this site

renting.berlin is a rental marketplace for Berlin. For privacy questions or data requests, open an issue on GitHub or contact us through the channels listed there.

Data we collect

  • Account data — name, email, password hash (or OAuth provider ID), public @handle, profile photo, and listing or seeker profile content you publish.
  • Messages — conversation content between users on the platform.
  • Usage data — anonymous page views and events via our analytics provider (see below). We do not link analytics to your account.
  • Technical data — IP address and browser user agent in server logs and session records, used for security, abuse prevention, and keeping you signed in.

How we use your data

  • Provide the marketplace: listings, search, messaging, saved searches, and notifications you opt into.
  • Authenticate you and keep your session secure.
  • Send transactional and notification emails according to your preferences.
  • Improve the product with aggregated, anonymous analytics.
  • Prevent fraud, spam, and abuse.

We do not sell your personal data. We do not use third-party ad trackers.

Cookies and local storage

We use a small number of cookies and browser storage entries. We do not show a cookie consent banner because we avoid non-essential tracking cookies.

  • Session cookie — set when you log in so you stay authenticated. Strictly necessary for the service you requested.
  • Preference cookies — when signed in, we may store your search view (cards, list, map) so the site opens the way you left it.
  • Local storage — UI preferences such as table column layout and last-used sign-in method. Stored only in your browser.

Analytics

We use Rybbit for privacy-oriented web analytics. It records page views and custom events (for example, when someone starts sign-up) to understand how the product is used. Rybbit does not use advertising cookies and identifies visitors with a short-lived, hashed signal rather than a persistent profile. We do not pass your account ID or email to analytics.

Analytics runs on all pages via a script loaded from our analytics host. You can block it with a browser extension or network filter; the site will still work.

Third parties

  • OAuth providers — Google or GitHub if you choose social sign-in.
  • Email delivery — SMTP provider to send account and notification emails.
  • Hosting — servers and databases that run the application.

Each processor handles data only as needed to provide the service.

Retention

We keep account and listing data while your account is active. You can delete conversations you participate in, close listings, and adjust notification settings in your account. Contact us to request account deletion; we will remove or anonymize personal data unless we must retain it for legal or security reasons.

Your rights

If you are in the EU/EEA or UK, you may have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. You may also lodge a complaint with your local data protection authority. To exercise these rights, contact us via GitHub.

Changes

We may update this policy as the product evolves. The effective date at the top will change when we do.