Privacy Policy.
What data we hold, how we process it, and your rights under UK GDPR.
Last updated: 22 June 2026
Who we are
Registered office: PropertyGoose LTD, Unit 3b, Aquila House, Pierhead Street, Cardiff, CF10 4PH. General enquiries: info@propertygoose.co.uk.
The data we collect
Depending on how you use PropertyGoose, we may collect:
- Tenant & guarantor data — name, contact details, date of birth, current and previous addresses, identity documents, credit and affordability data, employment and previous-landlord references, income, Right to Rent status, and AML / PEP / sanctions results.
- Landlord data — name and contact details, identity data (for AML where required), property and tenancy details.
- Agent data — account and user details, agency information, and billing contacts.
- Technical & usage data — IP address, device and browser information, and how you interact with our website and platform, collected via cookies and similar technologies.
How we use your data
We use personal data to:
- carry out tenant referencing, including credit, affordability, identity and fraud checks;
- produce tenancy agreements, register deposits and manage the tenancy lifecycle;
- meet our legal and regulatory obligations, including anti-money-laundering and Right to Rent;
- prevent and detect fraud, and keep our service and your account secure;
- provide customer support and administer your account; and
- send service messages and, where you have consented, marketing communications.
Lawful bases for processing
Credit reference and affordability checks
To help assess applications, verify identity, prevent fraud and meet our legal and regulatory obligations, we obtain information about applicants and guarantors from credit reference agencies (CRAs).
We obtain this data through Creditsafe, which uses its data partner TransUnion to supply consumer credit and identity data. For enhanced references we may also use Experian. Both Creditsafe and TransUnion are authorised and regulated by the Financial Conduct Authority:
- Creditsafe Business Solutions Limited — FCA Firm Reference Number 742313.
- TransUnion International UK Limited — FCA Firm Reference Number 805757.
The information we receive may include data relating to your identity, credit commitments, payment history and public-record information. It is used solely for legitimate business purposes — creditworthiness and affordability assessment, identity verification and fraud prevention — in accordance with applicable data protection laws.
More information about how these CRAs process your personal data:
Automated decision-making and profiling
Who we share your data with
Every third party that processes personal data on our behalf is listed, with what it does and where it operates, on our sub-processor page.
We share data only as necessary to deliver the service, with our referencing and tenancy partners — including the credit reference agencies Creditsafe and TransUnion (and Experian, for enhanced references), the deposit schemes TDS, mydeposits and DPS, and partners such as Reposit, Just Move In and Alan Boswell Insurance — and with the infrastructure providers that host and secure our platform. We may also disclose data to law enforcement or regulators where required by law. We never sell your data.International transfers
Data retention
We keep personal data only for as long as necessary. Our standard period for referencing and tenancy data is six years from the last activity on the file, which matches the ordinary limitation period under the Limitation Act 1980 — the window in which a claim about the tenancy could still be brought. After that it is deleted automatically, including any documents you uploaded.
Some records have their own statutory periods — anti-money-laundering records are kept for 5 years from the end of the business relationship, and Right to Rent checks for 1 year after the tenancy ends. Information attached to a tenancy that is still running is kept until that tenancy ends.
Full detail, including a table by record type, is in our Data Retention Policy.
How we protect your data
We aim to process personal data to the highest standard available to us, not merely the minimum the law requires. Our controls are built to the principles of ISO/IEC 27001 and the SOC 2 Trust Services Criteria, and to NCSC guidance.
- Encrypted at rest with AES-256-GCM. Your name, contact details, date of birth, addresses, income, bank and identity data are encrypted at field level before they reach our database — never stored as readable text. GCM is authenticated encryption, so tampering is detected as well as prevented.
- Encrypted in transit with TLS using modern cipher suites. The platform is not reachable over unencrypted HTTP.
- Documents are private. Anything you upload is held in storage that is never publicly addressable, and released only through links that expire in minutes.
- Row-level security in the database means one agency can never reach another's data, even if an application check were missed.
- Two-factor authentication is available to every user and can be enforced across an agency.
- Access is logged. Activity on references, offers, tenancies and contracts is audit-logged, and every subject-access search or export is recorded against the person who ran it.
- Card details never reach us — payments are handled directly by Stripe on their own infrastructure.
Full detail is on our security page.
Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data rectified;
- request erasure of your data, where applicable;
- restrict or object to our processing;
- data portability; and
- withdraw consent at any time, where we rely on it.
To exercise any right, contact our Data Protection Officer (below) or email info@propertygoose.co.uk. We will respond within one month.
Data Protection Officer
Matthew Ryder, Director
Email: matt@propertygoose.co.uk