Legal

Updated 6 August 2026

Privacy & Security

This page explains what information we collect, why we collect it, and what we do with it. We've kept the language simple on purpose.

Who we are

Estate Portal ("we", "us") provides lettings management software for letting agencies. You can contact us about anything in this policy at our contact page.

Two kinds of data

It helps to separate two situations:

What we collect about you

Why we use it

Who we share it with

We never sell personal data. We share it only with the service providers we need to run the platform — hosting, file storage, email delivery, error monitoring, payment processing (Stripe — card details are entered on Stripe's own secure pages and never touch our servers; we hold only the card's brand, last four digits and expiry for reminders) and bot protection on our public forms (Cloudflare Turnstile) — under contracts that limit what they can do with it. Some providers may process data outside the UK; where they do, recognised safeguards (such as standard contractual clauses) apply.

How long we keep it

Account data is kept while the account exists. Records an agency deletes in the product are recoverable from its recycle bin until the agency purges them. When an agency asks to close its workspace, the request is reviewed, the workspace becomes read-only (with full data export still available), and the data is then permanently deleted; the agency can change its mind up to that final deletion. Unfinished sign-ups are removed after 7 days. Backups expire on a rolling schedule. Server logs are kept for a short operational period.

Your rights

Under UK data protection law you can ask us to: show you the personal data we hold about you, correct it, delete it, restrict how we use it, or give you a copy. To exercise any of these, contact us.

Cookies

The app uses strictly necessary cookies only: signing you in, protecting forms, and — only if you tick "trust this device" at sign-in — a 30-day cookie that lets that browser skip the emailed code. The public website additionally uses Google Analytics cookies, and our public forms use Cloudflare Turnstile to tell people from bots. We don't use advertising cookies.

How the platform is protected

Reporting a vulnerability

If you believe you've found a security weakness, we genuinely want to hear about it.

We'll acknowledge your report, keep you informed, and credit you for the find if you'd like.

Bug bounty

We pay rewards of up to £1,000 for verified reports of major security vulnerabilities. The amount depends on the severity and real-world impact of the issue, judged at our reasonable discretion once we've reproduced and confirmed it. One reward per unique issue, paid to the first person who reports it; an issue we already know about, or one in a third-party service we use, doesn't qualify. We'll tell you what we've assessed and why.

Your part

Security is shared: use a strong, unique password, don't share logins, and remove staff accounts promptly when people leave. Agency admins can manage users from their settings at any time.

Changes

If we change this policy in a way that matters, we'll update this page and the date at the top.