Review draft — not approved for production

Privacy Policy

This draft explains how the RentCars24 website and booking system currently handle personal data. It must be completed with verified processor, transfer and retention details before checkout is enabled in production.

Draft version:
DRAFT-2026-07-30
Prepared:
30 July 2026

Review draft — not approved for production

This text is based on the implemented application. It is not yet a final Article 13 GDPR notice and must not be presented as approved legal advice.

Required before publication

  • Cross-check the proprietor details against the GISA extract, insert the GISA number and competent trade authority, and confirm that the published email is monitored for privacy requests.
  • Confirm every production processor, its hosting region, data-processing agreement, subprocessors and international-transfer mechanism.
  • Approve and implement retention and deletion periods, especially for driving-licence data, expired checkout holds, email records and technical logs.
  • Replace the provisional Google section with the final GTM tag and cookie inventory after the container is configured.
  • Create an operational process for access, correction, deletion, restriction, portability and objection requests.

1. Controller and contact

Khaled Mamahmadi, operating under the business designation RentCars24 is the data controller and rental provider. RentCars24 is a business designation and is not a separate legal person.

Address: Logistikstraße 7, 7D, 2201 Hagenbrunn, Austria. Email: rentcars24austria@gmail.com. Telephone: +43 688 6072 6075.

If a data protection officer is appointed or legally required, the officer’s contact details must also be provided here.

These controller details were confirmed by the proprietor. Before production, cross-check them against the GISA extract and confirm that the email address is actively monitored for GDPR rights requests.

2. Personal data we process

  • Account data: name, email address, password hash, role and authentication-session information.
  • Renter and driver data: name, email, telephone number, date of birth, driving-licence number, issuing country and expiry date.
  • Booking data: vehicle, pickup and return locations and times, rental duration, selected rate plan, price, cancellation deadline and booking history.
  • Payment data: Stripe checkout and payment identifiers, amount, currency, authorization, capture, refund and failure status. Card details are entered on Stripe-hosted pages and are not stored by RentCars24.
  • Communication data: contact-form name, email address and message; booking, access, confirmation and cancellation emails; delivery status and support correspondence where applicable.
  • Technical and consent data: necessary session cookies, consent choices, security and rate-limit identifiers, request metadata and operational event identifiers.

3. Purposes and legal bases

  • Contract steps and performance — Article 6(1)(b) GDPR: quotes, availability, driver validation, checkout, payment authorization, booking administration, vehicle handover, cancellation and customer support.
  • Legal obligations — Article 6(1)(c) GDPR: accounting, tax, regulatory and legally required recordkeeping or disclosures.
  • Legitimate interests — Article 6(1)(f) GDPR: service security, fraud prevention, access control, troubleshooting, payment reconciliation, establishment or defence of legal claims and operational reporting. The relevant balancing assessments must be documented internally.
  • Consent — Article 6(1)(a) GDPR and Section 165(3) TKG 2021: optional analytics and marketing technologies. Consent can be refused or withdrawn without affecting booking functionality.

A privacy policy is a notice, not a request for blanket consent. Booking data that is necessary for the contract should not be presented as consent-based processing.

4. Booking and payment processing

During checkout, renter and driver details are encrypted before temporary storage. Following a successful Stripe authorization, the booking retains the required renter snapshot and an encrypted driving-licence number. Only the last four licence characters are available for routine display.

Stripe receives the amount, currency, vehicle description and internal booking or checkout identifiers. The application stores provider identifiers and financial status, but not full card numbers or security codes.

5. Recipients and service providers

  • Hostinger or the finally selected hosting provider for the website, API, database and operational infrastructure.
  • Stripe for hosted card checkout, authorization, capture, refunds and payment fraud controls.
  • The finally selected email/SMTP provider for transactional email delivery.
  • The managed Redis provider used for short-lived security rate limits.
  • Google services only after the applicable analytics or marketing consent is granted.
  • Cloudinary only if vehicle-image storage is enabled; vehicle images should not contain customer personal data.
  • Professional advisers, insurers, public authorities or courts where necessary and legally permitted.

Every processor must be verified against the production configuration and covered by an Article 28 GDPR agreement before launch.

6. Cookies, local storage and Google tags

Necessary HttpOnly cookies are used for customer, administrator, checkout-attempt and guest-booking sessions. Their typical lifetimes range from approximately 15 minutes to 7 days depending on the session purpose.

The browser stores the consent record under rc24-cookie-consent-v1. It contains the selected analytics and marketing categories, policy version and update time. Users can reopen Cookie settings in the footer at any time.

Google Tag Manager is blocked until analytics or marketing consent is granted. Google Consent Mode defaults analytics_storage, ad_storage, ad_user_data and ad_personalization to denied. The final policy must list every tag, cookie, purpose, recipient and duration configured in GTM.

7. International data transfers

Some providers may process data outside the European Economic Area. Before production, the controller must document the actual locations and safeguards, such as an adequacy decision or European Commission Standard Contractual Clauses, and make the relevant information available on request.

8. Retention and deletion

  • Accounting records and related documents may need to be retained for seven years from the end of the relevant calendar year under Austrian tax rules.
  • Authentication, access and checkout credentials have technical expiry periods, but expired database records also require a deletion schedule.
  • Renter, driving-licence, booking, email-outbox, cancellation-audit and operational-log retention periods must be approved by purpose and implemented before production.
  • Data required for an active legal claim may be restricted and retained until the applicable claim period ends.
  • Website contact messages are sent directly to the configured email provider and are not stored in the application database. A mailbox deletion rule still has to be approved and enforced for ordinary inquiries.

The application does not currently implement automated renter-document retention or deletion. A final policy must not promise deletion periods until the system and operations enforce them.

9. Your GDPR rights

Depending on the circumstances, individuals may request access, correction, deletion, restriction, portability or object to processing. Consent can be withdrawn at any time without affecting processing that occurred lawfully before withdrawal. Requests may be sent to rentcars24austria@gmail.com.

Individuals may also complain to the Austrian Data Protection Authority. The controller generally must respond to a rights request within one month, subject to the GDPR’s permitted extensions and exceptions.

Austrian Data Protection Authority

10. Security measures

Implemented safeguards include encrypted renter and licence payloads, hashed passwords and one-time tokens, short-lived and HttpOnly session cookies, rotating refresh tokens, same-origin checks, role-based administration, request validation, rate limiting, contact-form spam filtering, signed Stripe webhooks and restricted public booking projections.

No online service can guarantee absolute security. The controller must also maintain access reviews, backups, incident response, processor oversight and a personal-data-breach procedure.

11. Automated checks

The service automatically checks availability, pricing, minimum driver age, licence validity, payment status and cancellation eligibility. It does not currently use those checks for advertising profiling. Customers must be given a contact route for questions or review of an automated rejection.

12. Changes to this notice

The published notice should display an effective date and stable version. Material changes should apply prospectively and be communicated where required. The version presented during checkout should be retained with the booking record.