Last updated: 18 March 2026
Privacy Policy
Note: This policy is provided as a starting point for our MVP. An updated version will be provided when we launch the full service.
1. Who we are
Renewar ("we", "us", "our") operates the website and service available at https://renewar.com (the "Service"). For data protection purposes, we act as the data controller of personal data we process about you when you use the Service, unless we act only as a processor on behalf of an organisation (e.g. a Teams customer)—in that case, that organisation is typically the controller and we process data under their instructions.
Contact: collinsorighose@outlook.com or via our contact page.
2. What data we collect
- Account & profile: email address, name (if provided), user ID, authentication identifiers from our identity provider (e.g. AWS Cognito or similar), and settings you choose in the app.
- Document & subscription data: information you enter about documents (e.g. names, types, expiry dates, reminders, optional notes, optional file references or uploads), and subscription or billing-related metadata.
- Payment data: payments are processed by our payment provider (e.g. Stripe). We do not store full card numbers on our servers; we receive limited billing identifiers and subscription status from the processor.
- Communications: messages you send us (e.g. support, contact form) and email delivery metadata when we send you service or marketing emails (where permitted).
- Technical & usage: IP address, device/browser type, approximate location derived from IP, timestamps, logs for security and reliability, and cookies or similar technologies as described below.
3. How we use your data (legal bases)
Depending on context, we rely on one or more of the following (UK/EU GDPR-style):
- Contract: to provide the Service, manage your account, process subscriptions you request, and send essential service emails.
- Legitimate interests: to secure the Service, prevent abuse, improve reliability, analyse aggregated usage, and communicate proportionate product updates (you can opt out of non-essential marketing where applicable).
- Legal obligation: where required by law (e.g. tax, regulatory requests).
- Consent: where we ask for it (e.g. certain cookies or marketing), you may withdraw consent at any time without affecting lawfulness of prior processing.
4. Sharing & processors
We share data with trusted third parties only as needed to run the Service, including:
- Cloud hosting and infrastructure (e.g. AWS or similar).
- Authentication and identity services (e.g. AWS Cognito).
- Payment processing (e.g. Stripe).
- Email delivery (e.g. Resend, Amazon SES, or similar).
- Professional advisers where required (lawyers, accountants).
We do not sell your personal data. We may disclose information if required by law or to protect rights, safety, and security.
5. International transfers
Your data may be processed in the United Kingdom, the European Economic Area, the United States, and other countries where our providers operate. Where we transfer personal data outside the UK/EEA, we use appropriate safeguards (such as Standard Contractual Clauses or adequacy decisions) where required by law.
6. Retention
We keep personal data only as long as needed for the purposes above, including legal, accounting, and dispute resolution. Account data is typically retained while your account is active and for a reasonable period afterwards unless you ask us to delete it sooner (subject to exceptions). Backup copies may persist for a limited technical period.
7. Your rights
If UK GDPR / EU GDPR applies, you may have rights to access, rectify, erase, restrict, object, and port your data, and to lodge a complaint with a supervisory authority. To exercise rights, contact us at the email above. You may also manage some information directly in your account settings where available.
9. Security
We implement appropriate technical and organisational measures to protect personal data. No method of transmission or storage is 100% secure; we encourage strong passwords and safeguarding your login credentials.
10. Children
The Service is not directed at children under 16 (or the minimum age in your country). We do not knowingly collect personal data from children. Contact us if you believe we have done so.
11. Changes
We may update this policy from time to time. We will post the updated version on this page and adjust the "Last updated" date. For material changes, we will provide additional notice where appropriate (e.g. email or in-app notice).