Privacy notice
Ren Mester AS · Org. no. 837 980 232 · Skiringsalgaten 6 B, 3116 Tønsberg, Norway · post@renmester.no · Last updated 20 September 2026 · English courtesy translation; the Norwegian version is the binding one
This privacy notice sets out how Ren Mester AS processes personal data about you when you visit renmester.no, book a service, contact us, apply for work with us, or enter into an agreement for the cleaning of a rental property. It is drawn up in accordance with Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and with the Norwegian Personal Data Act.
Storage in your browser — cookies and equivalent technologies — is described separately in our cookie policy, which forms an integral part of this notice.
1. Controller
The controller for the personal data described here is:
Ren Mester AS Skiringsalgaten 6 B, 3116 Tønsberg, Norway Company registration number 837 980 232 Email: post@renmester.no
The company is not required to designate a data protection officer under Article 37 of the GDPR, and has not designated one voluntarily. Enquiries regarding data protection should therefore be directed to the address above and are answered by the management.
2. What personal data we process
2.1 Data you provide when booking
In order to calculate a price and carry out the work, we process your contact details (name, telephone number, email address) and the address at which the work is to be performed. In addition we process the data necessary for the service in question:
- Car detailing: the vehicle's make, model, registration number and size class. The registration number is used for a lookup against the Norwegian Public Roads Administration's open vehicle register in order to retrieve make, model and size class, so that the price is correct without you having to enter the details manually. The lookup is performed from our server.
- Residential cleaning: floor area in square metres, number of rooms, number of bathrooms, number of floors and the desired frequency.
- Commercial cleaning: company name, company registration number, contact person, the address and floor area of the premises, and the desired frequency.
- All services: the desired date and time, any add-on services, any discount code, and whatever notes you choose to write.
The address field retrieves suggestions from the Norwegian Mapping Authority's open address register as you type. The request is sent directly from your browser, so the Mapping Authority receives your IP address and the characters you have entered. If you use the function to find your address automatically, the browser first asks for your express permission before your position is sent to the same service. The completed address is then used by our server to calculate driving distance from our base, so that any travel supplement is correct.
2.2 Images you upload
You may upload images of the home, the premises or the vehicle so that we can assess the scope of the work before we arrive. The images are stored in a closed storage area that is not accessible from the internet, and are made available to our staff solely through time-limited links. The images are used for price calculation, planning and quality assurance of the work, and for nothing else.
2.3 Payment data
Payment is carried out by Stripe on Stripe's own payment page. We never receive or store card numbers, expiry dates or security codes. From Stripe we receive references to the payment — identifiers for the checkout session and for the payment intent — together with the status and amount of the payment, which we store alongside the booking.
If you enter into a continuing agreement for the cleaning of a rental property and choose to store a payment card for future assignments, we additionally store Stripe's customer and payment method references together with the card's brand and its last four digits. These are the details necessary for you and for us to identify which card is registered. The card details themselves remain with Stripe.
2.4 Communication
When you contact us through the contact form, by email or by telephone, we process your name, your contact details and the content of your enquiry, together with our reply to it. The same applies to enquiries regarding commercial cleaning.
After work has been carried out we send a receipt and any status notifications. To customers we additionally send a request for feedback, one reminder of that request, and at a later point a reminder that it may be time for further work. You may at any time ask us to stop sending such messages by replying to the email or writing to post@renmester.no.
As a customer you may also receive reminders and offers for similar services from us by email. Such marketing rests on section 15 second paragraph of the Norwegian Marketing Control Act on existing customer relationships — not on separate consent — because you provided your email address in connection with a booking. Every such email carries an unsubscribe link that opts you out with a single tap, and you may also unsubscribe by writing to post@renmester.no. We never share or sell your details, and the marketing concerns our own services only.
2.5 The rental-property service
For customers who book cleaning between guest stays in a rental property, we process contact details (name, email address, telephone number), details of the property (address, floor area, number of bedrooms, number of bathrooms, linen arrangement, the letting platform on which the property is advertised) and any images of the property.
In order to schedule cleaning between stays, we use the calendar link from the letting platform. The calendar feed does not contain guest names. The letting platforms removed guest names and reservation codes from the calendar export in 2019, and we retrieve and store the dates only: when a stay begins, when it ends, when the next stay begins, and whether the cleaning window is short. We therefore process no personal data about your guests. The calendar link itself is treated as a confidential access credential: it is recorded only by us, is never displayed on the website, and is not disclosed.
2.6 Job applications
If you apply for work with us, we process your name, email address, telephone number, the position applied for, the message you write, and the CV you may choose to upload. The CV is stored in a closed storage area and is made available to the person handling the application through a short-lived link. We ask that you do not provide special categories of personal data within the meaning of Article 9 of the GDPR, including health data, in your application.
2.7 Data arising from use of the website
- Usage statistics. If you have consented to the "Analytics" category, we record which pages are visited, in what order, and which buttons and forms are used. Where consent to analytics is given, usage patterns on the pages may be recorded, including movement, clicks and the completion of form fields, but not passwords or payment details; the recordings are processed in PostHog on servers within the EU and are not linked to payment information. In addition, Google Analytics is used for aggregate traffic statistics, likewise only after consent. The purpose is to understand where visitors get stuck, so that we can put it right. If you have not consented, the tool is not loaded and no such recording takes place. See the cookie policy.
- Advert measurement. If you have consented to the "Marketing" category, Meta (Facebook and Instagram) and TikTok record that you opened a page, opened the booking form, pressed "Pay" and, where applicable, completed a booking, with the amount in kroner and the name of the service. The sole purpose is to see which adverts lead to work. For paid bookings our server additionally sends one copy of the purchase to the same providers, in which your e-mail address and phone number appear only as a one-way cryptographic digest (SHA-256), never in the clear — and only for bookings where consent had been given. If you have not consented, the tools are not loaded and no copy is sent. See section 4.3 of the cookie policy.
- Error reporting. If a technical fault occurs, an error report is sent to our error monitoring. Transmission of personal data from the browser is switched off in the configuration: the report contains no IP address, no cookies and none of the content of the form you were completing, only technical information about the fault itself.
- Security logs. Our hosting provider maintains access logs for the website as part of normal operation and security.
We do not use personal data for automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 of the GDPR.
3. Purposes and legal bases
We process personal data for the following purposes and on the following legal bases:
| Processing | Purpose | Legal basis |
|---|---|---|
| Booking, price calculation, scheduling and performance of the work | To deliver the service you have ordered | GDPR Art. 6(1)(b) — necessary for the performance of a contract with you |
| Payment, receipts, refunds and subsequent invoicing | To carry out the financial settlement | Art. 6(1)(b) |
| Vehicle lookup by registration number | To calculate the correct price for the correct vehicle | Art. 6(1)(b) |
| Handling enquiries and requests | To reply to you | Art. 6(1)(b), or (f) where you are not a customer |
| Accounting and retention of sales documentation | To meet obligations under the Norwegian Bookkeeping Act | Art. 6(1)(c) — legal obligation |
| Follow-up after completed work and reminders of further work | To obtain feedback and to offer repeat service to existing customers | Art. 6(1)(f) — legitimate interest, within the scope of section 15 of the Norwegian Marketing Control Act on existing customer relationships |
| Marketing of our own, similar services to existing customers (reminders and offers by email) | To offer you relevant services you may benefit from as a customer | Art. 6(1)(f) — legitimate interest, read with section 15 second paragraph of the Marketing Control Act. The basis is not consent ((a)). You may opt out at any time via the unsubscribe link in every email or by contacting us, and the data is never shared or sold |
| Checklist downloads and the follow-up series that follows | To provide the material you requested, and information about the service it concerns | Art. 6(1)(a) — consent |
| Usage statistics | To improve the content and structure of the website | Art. 6(1)(a) — consent, given through the consent panel |
| Advert measurement (Meta and TikTok) | To see which adverts lead to a booking, so that we do not pay for adverts that do not work | Art. 6(1)(a) — consent to the "Marketing" category in the consent panel. Covers both the measurement in the browser and the copy the server sends for a paid purchase |
| Troubleshooting, operational security and fraud prevention | To keep the website and the payment solution secure and functional | Art. 6(1)(f) — legitimate interest |
| Handling job applications | To assess your application | Art. 6(1)(b) — steps prior to entering into a contract at your request |
Where processing rests on legitimate interest, we have assessed that our interest in operating and improving the business is not overridden by your interests or fundamental rights, in particular because the scope of the data is limited, because the processing is foreseeable in light of the customer relationship, and because you may object at any time. You may request a fuller account of that assessment by contacting us.
Where processing rests on consent, that consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before the withdrawal.
To be able to demonstrate that consent was given, as GDPR Art. 7(1) requires, we keep a consent log on our own server each time you make an active choice in the consent panel. The log holds the choice you made (whether analytics was allowed), the time, which version of the consent panel applied, a random browser ID that carries no name, your browser (user agent) and a one-way hashed form of your IP address — never the IP address in clear text. The log is used solely as evidence of the consent and is not shared. The legal basis is Art. 6(1)(c), read with Art. 7(1).
For marketing to existing customers we likewise keep a separate opt-out log. It records when a customer unsubscribes — whether through the link in an email or by our registering the opt-out manually — and holds the email address, the time, where the opt-out came from, which version of the informational notice applied, your browser (user agent) and a one-way hashed form of your IP address. The log is used solely to demonstrate that the opt-out was carried out, and is not shared.
4. Where the data comes from
As a rule the data comes from you, through the forms on the website or in correspondence with us. In addition we obtain:
- vehicle data from the Norwegian Public Roads Administration's open vehicle register, on the basis of the registration number you provide,
- address and position data from the Norwegian Mapping Authority's open address register, on the basis of the address you type,
- payment status and payment references from Stripe, as part of completing the payment,
- dates of guest stays from the calendar link you have provided, for customers of the rental-property service.
5. Processors and other recipients
We do not sell personal data, and we do not disclose it to anyone other than those necessary to deliver the service or those to whom we are legally obliged to disclose it. The following providers process personal data on our behalf, under a data processing agreement pursuant to Article 28 of the GDPR:
| Provider | Role | Place of processing and transfer basis |
|---|---|---|
| Supabase | Database and file storage | EU (eu-west-2) |
| Vercel Inc. | Website hosting | Served from an EU region; the company is established in the USA. Transfer on the basis of the EU standard contractual clauses (SCC) |
| Stripe Payments Europe, Ltd. | Payment processing | Ireland, with Stripe, Inc. (USA) as a sub-processor. Transfer on the basis of the EU standard contractual clauses, supplemented by the EU–US Data Privacy Framework. Stripe is an independent controller for processing relating to fraud prevention and its own legal obligations |
| Resend | Email delivery | USA. Transfer on the basis of the EU standard contractual clauses |
| PostHog | Usage statistics, only where consent is given | EU region |
| Google Analytics (Google Ireland Ltd.) | Aggregate usage statistics, only where consent is given | May be transferred to Google LLC in the US — EU-US Data Privacy Framework and standard contractual clauses |
| Meta Platforms Ireland Ltd. | Advert measurement for Facebook and Instagram, only where consent is given | Ireland, with Meta Platforms, Inc. (USA). Transfers on the basis of the EU–US Data Privacy Framework and standard contractual clauses. E-mail and phone number are transferred only as a one-way cryptographic digest |
| TikTok Technology Limited | Advert measurement for TikTok, only where consent is given | Ireland. Transfers outside the EEA on the basis of the EU standard contractual clauses. E-mail and phone number are transferred only as a one-way cryptographic digest |
| Sentry | Error monitoring | EU region (Germany). Transmission of personal data from the browser is switched off in the configuration |
| Mapbox | Calculation of driving distance for the travel supplement | USA. Called from our server; only the address is transmitted, not your IP address. Transfer on the basis of the EU standard contractual clauses |
| Norwegian Mapping Authority (Geonorge) | Address lookup | Norway. Called directly from your browser, as described in section 2.1 |
| Norwegian Public Roads Administration | Vehicle data lookup | Norway. Called from our server |
| Anthropic, Inc. | Language model used to draft editorial content and to classify technical error messages | USA. Transfer on the basis of the EU standard contractual clauses. The service is not used to process booking data or customer records |
Data may additionally be disclosed to our accountant and auditor as part of bookkeeping and audit, and to a public authority, court or debt collection agency where we are legally obliged to do so or where it is necessary to establish, exercise or defend a legal claim.
6. Retention periods
We retain personal data for as long as it is necessary for the purpose for which it was collected, unless a longer retention period follows from law.
| Category | Retention period |
|---|---|
| Sales documents and other accounting records | Five years after the end of the financial year, pursuant to section 13 of the Norwegian Bookkeeping Act |
| Booking data and service history | For as long as the customer relationship subsists and it is necessary for the purposes of warranty, complaints and follow-up. Thereafter the data is deleted or anonymised, save for what must be retained under the Bookkeeping Act |
| Images of homes, premises or vehicles | Deleted no later than 90 days after the work is completed |
| Enquiries and correspondence | For as long as it is necessary to follow up the enquiry and any subsequent questions |
| Job applications and CVs | Up to six months after the application is received, unless you consent to longer retention |
| Data in the rental-property service | For as long as the agreement subsists. Dates of guest stays are deleted once the assignment in question has been carried out and invoiced |
| Consent log | For as long as the consent is valid and a reasonable period afterwards, so that we can demonstrate the consent was given |
| Marketing status and opt-out log | For as long as the customer relationship lasts and a reasonable period afterwards, so that we can demonstrate any opt-out from marketing |
| Form drafts | 24 hours, stored locally in your own browser and never transmitted to us |
| Your consent choice | 400 days in the cookie, renewed on every page view, and without expiry in the browser's local storage. See the cookie policy |
| Usage statistics | Cookies up to one year. Event data is deleted once it no longer serves the purpose |
7. Your rights
Under Chapter III of the GDPR you have the following rights in relation to us:
- Access (Art. 15). You may ask whether we process personal data concerning you and, if so, obtain a copy of that data together with information about the processing.
- Rectification (Art. 16). You may require inaccurate data concerning you to be rectified and incomplete data to be completed.
- Erasure (Art. 17). You may require data concerning you to be erased where it is no longer necessary for the purpose, where you withdraw the consent on which the processing is based, or where the processing is unlawful. The right does not extend to data we are legally obliged to retain, including accounting records.
- Restriction (Art. 18). You may require processing to be restricted, for instance while the accuracy of the data is verified.
- Data portability (Art. 20). For data you have provided to us yourself and which is processed on the basis of consent or a contract, you may ask to receive it in a structured, commonly used and machine-readable format, or to have it transmitted directly to another controller where technically feasible.
- Objection (Art. 21). You may object to processing based on legitimate interest. Where you object to direct marketing, processing for that purpose ceases immediately and without further justification.
- Withdrawal of consent (Art. 7(3)). Consent may be withdrawn at any time, and must be as easy to withdraw as it was to give. Consent to analytics is withdrawn by selecting Change consent at the foot of the page.
Requests should be directed to post@renmester.no. We reply without undue delay and within one month of receiving the request at the latest. Where a request is complex, that period may be extended by up to two further months, in which case you will be notified within the first month. Handling the request is free of charge. We may ask for further information to confirm your identity where there is reasonable doubt as to who is making the request.
If you consider that our processing of personal data concerning you infringes the rules, you may lodge a complaint with the Norwegian Data Protection Authority. We would welcome the opportunity to put matters right first, but that is not a precondition for complaining.
8. Information security
We have implemented technical and organisational measures to ensure a level of security appropriate to the risk, pursuant to Article 32 of the GDPR. These measures include:
- All traffic to and from the website is encrypted with TLS.
- Card details never pass through our systems, but are handled in full by Stripe, which is PCI DSS certified.
- The database is protected by row-level access control, and all changes are made through controlled server-side interfaces. The browser has write access to no table.
- Uploaded images and CVs are stored in closed storage areas without public access, and are made available through time-limited links.
- Access to customer data is restricted to those employees who need it in order to carry out their work, and is protected by individual sign-in.
- Error monitoring is configured not to transmit personal data from the browser.
In the event of a personal data breach entailing a risk to your rights and freedoms, we notify the Norwegian Data Protection Authority within 72 hours, and notify you directly where the breach is likely to result in a high risk, pursuant to Articles 33 and 34.
9. Changes to this notice
We update this notice when our services, our supply chain, or the law and its interpretation change. The current version is always available on this page, and the date at the top states when it was last amended. Where a material change affects you as a customer, we give notice by email or by a clear message on the website before the change takes effect.
Ren Mester AS — One Master, for all your cleaning needs