Renza · renza.me
Privacy policy
This policy explains how Renza collects and uses personal information when you visit renza.me, use our virtual-staging service or contact us.
Last updated 5 September 2026
About Renza and this policy
Renza is the controller responsible for the account, business administration and website information described here.
Contact the Renza team using our privacy enquiry form or email contact@renza.me.
Renza is intended for adult business users. If an agency supplies photographs or your details, that agency is also responsible for explaining its own use of your information. This policy does not replace an agency’s privacy notice or a data-processing agreement.
Information we collect
- Account and sign-in information: your name, email, profile photo, email verification status, provider account identifiers, authentication tokens and session records supplied through the sign-in provider you choose.
- Agency information: business name and email domain, membership, roles, approvals, invitations, joining requests and image allowances. An agency colleague may provide your email when inviting you.
- Staging information: uploaded photographs, room and style choices, generated images, and records of requests, results, errors, timings and credit usage. Photographs may contain personal information or embedded metadata; do not assume uploading removes it.
- Purchase information: where you purchase credits, transaction references, payment status, amounts, credits and refund or dispute records received from Stripe. Card details are entered on Stripe’s checkout, not stored in Renza’s application database.
- Messages: your name, reply email, topic, message, reference and our correspondence and handling records.
- Technical information: request and error information processed by our services and hosting providers, which may include IP address, browser and device details. Renza does not store IP addresses or browser strings in its account-session records. Our public-form rate counters do not identify individual visitors.
We receive information from you, your sign-in provider, agency colleagues, payment notifications and your use of the service. Without sign-in information we cannot provide an account; without a photograph we cannot stage a room. You can browse the public pages without signing in.
Why we use information
- Providing the service: creating accounts, carrying out staging requests, managing credits and answering purchase enquiries. Where you are our contracting customer, this is necessary to perform our contract or take steps you request before entering one.
- Working with agency users: our legitimate interests in delivering the service to your agency, managing access and supporting its authorised staff. These interests also support routine enquiries and account administration.
- Security and reliability: our legitimate interests in preventing misuse, investigating errors, maintaining accurate usage records and protecting the service and its users.
- Legal responsibilities: meeting applicable accounting, tax and data-protection obligations. We may also retain relevant records for our legitimate interests in establishing or defending legal claims.
- Consent: where we ask for permission for a separate optional use, we explain that use when asking. Signing in or contacting us is not consent to marketing.
Your right to object: you can object to processing based on legitimate interests. You can also withdraw consent at any time, without affecting the lawfulness of earlier processing.
Photographs and artificial intelligence
When you request staging, the photograph and instructions pass through our staging service to Google’s Gemini API for room analysis and image generation. Renza does not operate its own model-training pipeline using your uploads. Google’s handling of API content is governed by the applicable Gemini service terms, including safety and abuse monitoring; this is not a promise of zero provider retention.
Only upload photographs you are authorised to use. Remove identifiable people, private documents and sensitive details first. Contact the supplying agency or Renza if an image includes your personal information and you have a concern.
AI creates images; it does not verify the condition of a property. Check every result before publishing it. Renza does not use staging to make decisions about individuals that have legal or similarly significant effects.
Who receives information
- Hosting and storage: Vercel for the website, Neon for database records, and the infrastructure running our staging service.
- Authentication: Google or Microsoft when you choose an available sign-in option. Loading a provider-hosted profile photo also makes a request to that provider.
- Image processing: Google Gemini receives the photographs and instructions needed for staging.
- Account email: Resend handles invitation and agency-notification messages when those email features are used.
- Payments: Stripe handles hosted checkout and payment events when you purchase credits.
- Your agency: members can see colleagues’ profile and membership details; authorised managers can manage access and view agency usage and allowances.
Authorised Renza personnel may access records to provide support and administer the service. We may disclose relevant information to professional advisers or authorities where needed for legal obligations or claims. We do not sell personal information or send contact details to furniture retailers for marketing.
International processing
Our providers operate internationally, so information may be processed outside the UK. You can ask us about processing locations and obtain information about applicable transfer safeguards. A provider’s location is not necessarily the same as the location of its servers, support teams or subprocessors.
How long information is kept
- Images: the workbench keeps original and generated images in browser memory during use. Renza’s account database stores generation records, not an image library. Download images you need; they are not restored after refreshing the page. This does not determine retention by the AI or infrastructure providers, or of copies you download or publish.
- Accounts and agency records: retained while needed to provide access and administer the agency relationship. When access ends, retention depends on outstanding support, security, payment and legal matters. Request deletion through our contact route; signing out does not delete your account.
- Generation and financial records: retained as needed to explain usage, reconcile credits, resolve refunds or disputes and meet applicable record-keeping obligations. Deleting an account does not necessarily delete these records.
- Enquiries and complaints: our retention procedure removes closed ordinary enquiries and privacy requests after 12 months, and closed data-protection complaints after 24 months. Open matters remain while they are handled. Expired public-form rate counters are removed during maintenance after their one-day lifetime.
Backups and operational logs have separate retention arrangements. Contact us for details relevant to your request. We consider any legal reason to retain information when handling deletion requests and explain applicable limits.
Your data-protection rights
Depending on the circumstances, you can request access to your personal information, correction, deletion, restricted use or a portable copy. The right to object and withdraw consent is explained above. Use our privacy contact route; you do not need a Renza account to make a request.
We may ask for information needed to confirm your identity or clarify the request. We normally respond within one calendar month, subject to the rules for identity checks, clarification and extensions. We will explain any applicable extension or refusal.
Complaints
If you are concerned about our handling of your information, make a data-protection complaint. We will acknowledge it within 30 days, investigate without undue delay, keep you informed and explain the outcome. This is separate from the deadline for responding to a data-rights request.
You can also raise a concern with the UK Information Commissioner’s Office through its complaints service.
Cookies and policy changes
Our cookie policy explains sign-in cookies and other browser storage. We update this policy when our practices change and show the revision date above. For a materially different use of information, we will provide the information and obtain any permission required before that use begins.