Skip to content

Privacy notice

Ren Mester AS · Org. no. 837 980 232 · Skiringsalgaten 6 B, 3116 Tønsberg, Norway · post@renmester.no · Last updated 20 September 2026 · English courtesy translation; the Norwegian version is the binding one

This privacy notice sets out how Ren Mester AS processes personal data about you when you visit renmester.no, book a service, contact us, apply for work with us, or enter into an agreement for the cleaning of a rental property. It is drawn up in accordance with Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and with the Norwegian Personal Data Act.

Storage in your browser — cookies and equivalent technologies — is described separately in our cookie policy, which forms an integral part of this notice.

1. Controller

The controller for the personal data described here is:

Ren Mester AS Skiringsalgaten 6 B, 3116 Tønsberg, Norway Company registration number 837 980 232 Email: post@renmester.no

The company is not required to designate a data protection officer under Article 37 of the GDPR, and has not designated one voluntarily. Enquiries regarding data protection should therefore be directed to the address above and are answered by the management.

2. What personal data we process

2.1 Data you provide when booking

In order to calculate a price and carry out the work, we process your contact details (name, telephone number, email address) and the address at which the work is to be performed. In addition we process the data necessary for the service in question:

  • Car detailing: the vehicle's make, model, registration number and size class. The registration number is used for a lookup against the Norwegian Public Roads Administration's open vehicle register in order to retrieve make, model and size class, so that the price is correct without you having to enter the details manually. The lookup is performed from our server.
  • Residential cleaning: floor area in square metres, number of rooms, number of bathrooms, number of floors and the desired frequency.
  • Commercial cleaning: company name, company registration number, contact person, the address and floor area of the premises, and the desired frequency.
  • All services: the desired date and time, any add-on services, any discount code, and whatever notes you choose to write.

The address field retrieves suggestions from the Norwegian Mapping Authority's open address register as you type. The request is sent directly from your browser, so the Mapping Authority receives your IP address and the characters you have entered. If you use the function to find your address automatically, the browser first asks for your express permission before your position is sent to the same service. The completed address is then used by our server to calculate driving distance from our base, so that any travel supplement is correct.

2.2 Images you upload

You may upload images of the home, the premises or the vehicle so that we can assess the scope of the work before we arrive. The images are stored in a closed storage area that is not accessible from the internet, and are made available to our staff solely through time-limited links. The images are used for price calculation, planning and quality assurance of the work, and for nothing else.

2.3 Payment data

Payment is carried out by Stripe on Stripe's own payment page. We never receive or store card numbers, expiry dates or security codes. From Stripe we receive references to the payment — identifiers for the checkout session and for the payment intent — together with the status and amount of the payment, which we store alongside the booking.

If you enter into a continuing agreement for the cleaning of a rental property and choose to store a payment card for future assignments, we additionally store Stripe's customer and payment method references together with the card's brand and its last four digits. These are the details necessary for you and for us to identify which card is registered. The card details themselves remain with Stripe.

2.4 Communication

When you contact us through the contact form, by email or by telephone, we process your name, your contact details and the content of your enquiry, together with our reply to it. The same applies to enquiries regarding commercial cleaning.

After work has been carried out we send a receipt and any status notifications. To customers we additionally send a request for feedback, one reminder of that request, and at a later point a reminder that it may be time for further work. You may at any time ask us to stop sending such messages by replying to the email or writing to post@renmester.no.

As a customer you may also receive reminders and offers for similar services from us by email. Such marketing rests on section 15 second paragraph of the Norwegian Marketing Control Act on existing customer relationships — not on separate consent — because you provided your email address in connection with a booking. Every such email carries an unsubscribe link that opts you out with a single tap, and you may also unsubscribe by writing to post@renmester.no. We never share or sell your details, and the marketing concerns our own services only.

2.5 The rental-property service

For customers who book cleaning between guest stays in a rental property, we process contact details (name, email address, telephone number), details of the property (address, floor area, number of bedrooms, number of bathrooms, linen arrangement, the letting platform on which the property is advertised) and any images of the property.

In order to schedule cleaning between stays, we use the calendar link from the letting platform. The calendar feed does not contain guest names. The letting platforms removed guest names and reservation codes from the calendar export in 2019, and we retrieve and store the dates only: when a stay begins, when it ends, when the next stay begins, and whether the cleaning window is short. We therefore process no personal data about your guests. The calendar link itself is treated as a confidential access credential: it is recorded only by us, is never displayed on the website, and is not disclosed.

2.6 Job applications

If you apply for work with us, we process your name, email address, telephone number, the position applied for, the message you write, and the CV you may choose to upload. The CV is stored in a closed storage area and is made available to the person handling the application through a short-lived link. We ask that you do not provide special categories of personal data within the meaning of Article 9 of the GDPR, including health data, in your application.

2.7 Data arising from use of the website

  • Usage statistics. If you have consented to the "Analytics" category, we record which pages are visited, in what order, and which buttons and forms are used. Where consent to analytics is given, usage patterns on the pages may be recorded, including movement, clicks and the completion of form fields, but not passwords or payment details; the recordings are processed in PostHog on servers within the EU and are not linked to payment information. In addition, Google Analytics is used for aggregate traffic statistics, likewise only after consent. The purpose is to understand where visitors get stuck, so that we can put it right. If you have not consented, the tool is not loaded and no such recording takes place. See the cookie policy.
  • Advert measurement. If you have consented to the "Marketing" category, Meta (Facebook and Instagram) and TikTok record that you opened a page, opened the booking form, pressed "Pay" and, where applicable, completed a booking, with the amount in kroner and the name of the service. The sole purpose is to see which adverts lead to work. For paid bookings our server additionally sends one copy of the purchase to the same providers, in which your e-mail address and phone number appear only as a one-way cryptographic digest (SHA-256), never in the clear — and only for bookings where consent had been given. If you have not consented, the tools are not loaded and no copy is sent. See section 4.3 of the cookie policy.
  • Error reporting. If a technical fault occurs, an error report is sent to our error monitoring. Transmission of personal data from the browser is switched off in the configuration: the report contains no IP address, no cookies and none of the content of the form you were completing, only technical information about the fault itself.
  • Security logs. Our hosting provider maintains access logs for the website as part of normal operation and security.

We do not use personal data for automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 of the GDPR.

3. Purposes and legal bases

We process personal data for the following purposes and on the following legal bases:

Processing Purpose Legal basis
Booking, price calculation, scheduling and performance of the work To deliver the service you have ordered GDPR Art. 6(1)(b) — necessary for the performance of a contract with you
Payment, receipts, refunds and subsequent invoicing To carry out the financial settlement Art. 6(1)(b)
Vehicle lookup by registration number To calculate the correct price for the correct vehicle Art. 6(1)(b)
Handling enquiries and requests To reply to you Art. 6(1)(b), or (f) where you are not a customer
Accounting and retention of sales documentation To meet obligations under the Norwegian Bookkeeping Act Art. 6(1)(c) — legal obligation
Follow-up after completed work and reminders of further work To obtain feedback and to offer repeat service to existing customers Art. 6(1)(f) — legitimate interest, within the scope of section 15 of the Norwegian Marketing Control Act on existing customer relationships
Marketing of our own, similar services to existing customers (reminders and offers by email) To offer you relevant services you may benefit from as a customer Art. 6(1)(f) — legitimate interest, read with section 15 second paragraph of the Marketing Control Act. The basis is not consent ((a)). You may opt out at any time via the unsubscribe link in every email or by contacting us, and the data is never shared or sold
Checklist downloads and the follow-up series that follows To provide the material you requested, and information about the service it concerns Art. 6(1)(a) — consent
Usage statistics To improve the content and structure of the website Art. 6(1)(a) — consent, given through the consent panel
Advert measurement (Meta and TikTok) To see which adverts lead to a booking, so that we do not pay for adverts that do not work Art. 6(1)(a) — consent to the "Marketing" category in the consent panel. Covers both the measurement in the browser and the copy the server sends for a paid purchase
Troubleshooting, operational security and fraud prevention To keep the website and the payment solution secure and functional Art. 6(1)(f) — legitimate interest
Handling job applications To assess your application Art. 6(1)(b) — steps prior to entering into a contract at your request

Where processing rests on legitimate interest, we have assessed that our interest in operating and improving the business is not overridden by your interests or fundamental rights, in particular because the scope of the data is limited, because the processing is foreseeable in light of the customer relationship, and because you may object at any time. You may request a fuller account of that assessment by contacting us.

Where processing rests on consent, that consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To be able to demonstrate that consent was given, as GDPR Art. 7(1) requires, we keep a consent log on our own server each time you make an active choice in the consent panel. The log holds the choice you made (whether analytics was allowed), the time, which version of the consent panel applied, a random browser ID that carries no name, your browser (user agent) and a one-way hashed form of your IP address — never the IP address in clear text. The log is used solely as evidence of the consent and is not shared. The legal basis is Art. 6(1)(c), read with Art. 7(1).

For marketing to existing customers we likewise keep a separate opt-out log. It records when a customer unsubscribes — whether through the link in an email or by our registering the opt-out manually — and holds the email address, the time, where the opt-out came from, which version of the informational notice applied, your browser (user agent) and a one-way hashed form of your IP address. The log is used solely to demonstrate that the opt-out was carried out, and is not shared.

4. Where the data comes from

As a rule the data comes from you, through the forms on the website or in correspondence with us. In addition we obtain:

  • vehicle data from the Norwegian Public Roads Administration's open vehicle register, on the basis of the registration number you provide,
  • address and position data from the Norwegian Mapping Authority's open address register, on the basis of the address you type,
  • payment status and payment references from Stripe, as part of completing the payment,
  • dates of guest stays from the calendar link you have provided, for customers of the rental-property service.

5. Processors and other recipients

We do not sell personal data, and we do not disclose it to anyone other than those necessary to deliver the service or those to whom we are legally obliged to disclose it. The following providers process personal data on our behalf, under a data processing agreement pursuant to Article 28 of the GDPR:

Provider Role Place of processing and transfer basis
Supabase Database and file storage EU (eu-west-2)
Vercel Inc. Website hosting Served from an EU region; the company is established in the USA. Transfer on the basis of the EU standard contractual clauses (SCC)
Stripe Payments Europe, Ltd. Payment processing Ireland, with Stripe, Inc. (USA) as a sub-processor. Transfer on the basis of the EU standard contractual clauses, supplemented by the EU–US Data Privacy Framework. Stripe is an independent controller for processing relating to fraud prevention and its own legal obligations
Resend Email delivery USA. Transfer on the basis of the EU standard contractual clauses
PostHog Usage statistics, only where consent is given EU region
Google Analytics (Google Ireland Ltd.) Aggregate usage statistics, only where consent is given May be transferred to Google LLC in the US — EU-US Data Privacy Framework and standard contractual clauses
Meta Platforms Ireland Ltd. Advert measurement for Facebook and Instagram, only where consent is given Ireland, with Meta Platforms, Inc. (USA). Transfers on the basis of the EU–US Data Privacy Framework and standard contractual clauses. E-mail and phone number are transferred only as a one-way cryptographic digest
TikTok Technology Limited Advert measurement for TikTok, only where consent is given Ireland. Transfers outside the EEA on the basis of the EU standard contractual clauses. E-mail and phone number are transferred only as a one-way cryptographic digest
Sentry Error monitoring EU region (Germany). Transmission of personal data from the browser is switched off in the configuration
Mapbox Calculation of driving distance for the travel supplement USA. Called from our server; only the address is transmitted, not your IP address. Transfer on the basis of the EU standard contractual clauses
Norwegian Mapping Authority (Geonorge) Address lookup Norway. Called directly from your browser, as described in section 2.1
Norwegian Public Roads Administration Vehicle data lookup Norway. Called from our server
Anthropic, Inc. Language model used to draft editorial content and to classify technical error messages USA. Transfer on the basis of the EU standard contractual clauses. The service is not used to process booking data or customer records

Data may additionally be disclosed to our accountant and auditor as part of bookkeeping and audit, and to a public authority, court or debt collection agency where we are legally obliged to do so or where it is necessary to establish, exercise or defend a legal claim.

6. Retention periods

We retain personal data for as long as it is necessary for the purpose for which it was collected, unless a longer retention period follows from law.

Category Retention period
Sales documents and other accounting records Five years after the end of the financial year, pursuant to section 13 of the Norwegian Bookkeeping Act
Booking data and service history For as long as the customer relationship subsists and it is necessary for the purposes of warranty, complaints and follow-up. Thereafter the data is deleted or anonymised, save for what must be retained under the Bookkeeping Act
Images of homes, premises or vehicles Deleted no later than 90 days after the work is completed
Enquiries and correspondence For as long as it is necessary to follow up the enquiry and any subsequent questions
Job applications and CVs Up to six months after the application is received, unless you consent to longer retention
Data in the rental-property service For as long as the agreement subsists. Dates of guest stays are deleted once the assignment in question has been carried out and invoiced
Consent log For as long as the consent is valid and a reasonable period afterwards, so that we can demonstrate the consent was given
Marketing status and opt-out log For as long as the customer relationship lasts and a reasonable period afterwards, so that we can demonstrate any opt-out from marketing
Form drafts 24 hours, stored locally in your own browser and never transmitted to us
Your consent choice 400 days in the cookie, renewed on every page view, and without expiry in the browser's local storage. See the cookie policy
Usage statistics Cookies up to one year. Event data is deleted once it no longer serves the purpose

7. Your rights

Under Chapter III of the GDPR you have the following rights in relation to us:

  • Access (Art. 15). You may ask whether we process personal data concerning you and, if so, obtain a copy of that data together with information about the processing.
  • Rectification (Art. 16). You may require inaccurate data concerning you to be rectified and incomplete data to be completed.
  • Erasure (Art. 17). You may require data concerning you to be erased where it is no longer necessary for the purpose, where you withdraw the consent on which the processing is based, or where the processing is unlawful. The right does not extend to data we are legally obliged to retain, including accounting records.
  • Restriction (Art. 18). You may require processing to be restricted, for instance while the accuracy of the data is verified.
  • Data portability (Art. 20). For data you have provided to us yourself and which is processed on the basis of consent or a contract, you may ask to receive it in a structured, commonly used and machine-readable format, or to have it transmitted directly to another controller where technically feasible.
  • Objection (Art. 21). You may object to processing based on legitimate interest. Where you object to direct marketing, processing for that purpose ceases immediately and without further justification.
  • Withdrawal of consent (Art. 7(3)). Consent may be withdrawn at any time, and must be as easy to withdraw as it was to give. Consent to analytics is withdrawn by selecting Change consent at the foot of the page.

Requests should be directed to post@renmester.no. We reply without undue delay and within one month of receiving the request at the latest. Where a request is complex, that period may be extended by up to two further months, in which case you will be notified within the first month. Handling the request is free of charge. We may ask for further information to confirm your identity where there is reasonable doubt as to who is making the request.

If you consider that our processing of personal data concerning you infringes the rules, you may lodge a complaint with the Norwegian Data Protection Authority. We would welcome the opportunity to put matters right first, but that is not a precondition for complaining.

8. Information security

We have implemented technical and organisational measures to ensure a level of security appropriate to the risk, pursuant to Article 32 of the GDPR. These measures include:

  • All traffic to and from the website is encrypted with TLS.
  • Card details never pass through our systems, but are handled in full by Stripe, which is PCI DSS certified.
  • The database is protected by row-level access control, and all changes are made through controlled server-side interfaces. The browser has write access to no table.
  • Uploaded images and CVs are stored in closed storage areas without public access, and are made available through time-limited links.
  • Access to customer data is restricted to those employees who need it in order to carry out their work, and is protected by individual sign-in.
  • Error monitoring is configured not to transmit personal data from the browser.

In the event of a personal data breach entailing a risk to your rights and freedoms, we notify the Norwegian Data Protection Authority within 72 hours, and notify you directly where the breach is likely to result in a high risk, pursuant to Articles 33 and 34.

9. Changes to this notice

We update this notice when our services, our supply chain, or the law and its interpretation change. The current version is always available on this page, and the date at the top states when it was last amended. Where a material change affects you as a customer, we give notice by email or by a clear message on the website before the change takes effect.


Ren Mester AS — One Master, for all your cleaning needs