Skip to content
TenancyVaults
Evidence LockerDispute packs
Sign inDashboard

01

Products.

  • Evidence Locker
  • Dispute packs
  • How dispute packs work
  • Deadline calculator
  • Pricing
  • See a sample case

02

Guides.

  • TDS disputes
  • DPS disputes
  • mydeposits disputes
  • Fair wear and tear
  • Blog

03

Help.

  • FAQs
  • Contact
  • Accessibility
  • Not legal advice

04

Your case.

Start a caseSign inDashboard

Your deposit dispute, calmly resolved.

help@tenancyvaults.co.uk

Evidence preparation tool, not legal advice.

Privacy notice

Last updated 6 October 2026

Draft. This page hasn’t been reviewed by a solicitor yet, and may change before TenancyVaults takes payments.

On this page

  1. Who we are
  2. Our role
  3. What we collect
  4. Why we use it
  5. How AI is used
  6. Who we share it with
  7. How long we keep it
  8. Your rights
  9. Cookies
  10. Changes
On this page
  1. Who we are
  2. Our role
  3. What we collect
  4. Why we use it
  5. How AI is used
  6. Who we share it with
  7. How long we keep it
  8. Your rights
  9. Cookies
  10. Changes

This notice explains what personal data TenancyVaults collects, why, who it’s shared with, how long it’s kept and your rights. It covers this website and the TenancyVaults app.

Who we are

TenancyVaults is run by Andy Lewis, a landlord and software developer. Contact us at help@tenancyvaults.co.uk.

Our role

For your account (your email address, sign-in and payments) we decide how your data is used, so we are its controller.

The evidence you upload for a case can include other people’s personal data, such as your tenant’s name on an inventory or an invoice. You decide what to upload and why, so for that data you are the controller and we are your processor: we use it only to prepare your evidence pack, as you ask us to.

What we collect

  • Your account: your email address, and when you signed in.
  • Your cases: what you tell us about a tenancy (the property’s address, the dates, the deposit, the scheme and its deadlines), the deductions you claim, and the files you upload. We remove location data from photos’ hidden details when we make copies of them.
  • Payments: the amount, the date and a reference. Your card details go straight to Stripe; we never see them.
  • Emails we send you: sign-in links, receipts and reminders, and whether they were delivered.
  • How the site is used: pages visited and what was clicked, only if you accept analytics cookies (see Cookies).
  • Errors: technical details when something goes wrong, so we can fix it.

We don’t ask for your tenant’s contact details, and you don’t need to give us any personal data beyond what your evidence already contains.

Why we use it

  • To provide the service you pay for (our contract with you): your account, reading your evidence, preparing your pack, taking payment and emailing you about your case.
  • To keep the service secure and working (our legitimate interests): preventing misuse, fixing errors and keeping records of what happened to your case.
  • To tell you about TenancyVaults (our legitimate interests, and the “soft opt-in” for emails to people who have used our service): now and then, emails about TenancyVaults and similar services. You can say no when you sign in, and every one of these emails has an unsubscribe link.
  • To understand how the site is used (your consent): analytics, only after you accept them. You can withdraw consent at any time.
  • To meet our legal obligations: for example, keeping payment records for tax.

How AI is used

We use Anthropic’s Claude to read and sort your evidence: to say what kind of document each file is, to describe photos, to compare check-in and check-out photos, and to draft the wording of your pack. It sees the contents of your files (small copies of photos, without their location data), never your email address or payment details.

Anthropic doesn’t use this data to train its models. It deletes what we send within 30 days, unless something is flagged under its usage policy (kept for up to 2 years) or the law requires it to keep it. Its processing may take place outside the UK.

The AI describes your evidence; it doesn’t decide anything about you or your tenant. You check everything before you submit it, and you can change any of it.

Who we share it with

Only the services we need to run TenancyVaults, each under a contract that limits what it can do with your data:

  • Railway (hosting and our database), in the EU (the Netherlands).
  • Amazon Web Services (file storage), in the UK (London).
  • Anthropic (AI, as above), which may process data outside the UK.
  • Stripe (payments).
  • Resend (sending emails), in the EU (Ireland).
  • Sentry (error reports), in the EU.
  • PostHog (analytics, only with your consent), in the EU.
  • Cloudflare (our domain’s name servers).
  • Zoho (our own email, if you write to us), in the EU.

We don’t sell your data, and we don’t share it for advertising.

Where data leaves the UK, it’s protected by the UK’s adequacy decisions (for the EU) or by the standard data protection clauses in each provider’s data processing agreement.

How long we keep it

  • Your cases: until you delete them, or 24 months after you last used them. When you delete a case, its files are removed from storage at once and the rest within 30 days.
  • Your account: until you delete it.
  • Payment records: 6 years, for tax.
  • Error reports and analytics: for as long as each provider keeps them by default.

Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to have it in a format you can take elsewhere. Where we rely on your consent, you can withdraw it at any time. Email help@tenancyvaults.co.uk; we’ll reply within a month.

For data in your evidence that belongs to someone else, such as your tenant, we’ll pass any request to you as the controller and help you answer it.

If you’re unhappy with how we’ve handled your data, you can complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint.

Cookies

We use a few cookies, and similar storage in your browser, to make the site work. Analytics cookies are set only if you accept them.

Needed for the site to work

  • tv.session_token: keeps you signed in. Deleted when you sign out.
  • tv_signed_in: remembers whether you’re signed in, to show the right menu.
  • tv_consent: remembers your cookie choice, for a year.
  • tv-theme (stored in your browser, not a cookie): your choice of light or dark.

Analytics (only if you accept)

  • PostHog (ph_…_posthog): counts visits and shows how the site is used, so we can improve it. It records the pages you visit and steps such as starting a case or paying, never what you type or upload. Kept for up to a year.

Stripe sets its own cookies on its payment page, which is on Stripe’s site; see Stripe’s privacy policy.

To change your choice at any time, use “Cookie settings” at the foot of any page. If you withdraw consent, analytics stop and their cookies are removed.

Changes

If we change this notice, we’ll update the date at the top, and tell you by email if the change affects you.

Site footer

TenancyVaults

Evidence preparation for self-managing landlords in TDS, DPS and mydeposits deposit disputes.

Check your deadline →

Products

  • Evidence Locker
  • Dispute packs
  • How it works
  • Deadline calculator
  • Pricing
  • See a sample case
  • Sign in

Resources

  • Blog
  • TDS disputes
  • DPS disputes
  • mydeposits disputes
  • Fair wear and tear

Help

  • Contact
  • FAQs
  • Accessibility

Legal

  • Terms
  • Privacy
  • Cookies
  • Refunds
  • Not legal advice

© 2026 TenancyVaults. All rights reserved.

Evidence preparation tool, not legal advice. You review and submit everything.

England and Wales · Not affiliated with TDS, DPS or mydeposits.