Effective privacy policy

Privacy Policy

This policy explains how the RentCars24 website and booking system process personal data, including booking, payment, communication and security data.

Version:
2026-08-11
Effective:
11 August 2026

Effective privacy policy

Approved for production processing from 11 August 2026. Privacy requests can be sent to the published RentCars24 email address.

Privacy summary

  • RentCars24 uses booking data to take pre-contractual steps and perform rental contracts, not for unrelated marketing.
  • Hostinger infrastructure, Stripe, the configured email provider and consent-controlled Google services are the principal service-provider categories.
  • Transfers outside the EEA use an adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses.
  • Operational data is kept for defined short periods; accounting records are retained for the statutory seven-year period.
  • Customers may exercise GDPR rights through the published email address.

1. Controller and contact

Khaled Mamahmadi, operating under the business designation RentCars24 is the data controller and rental provider. RentCars24 is a business designation and is not a separate legal person.

Address: Logistikstraße 7, 7D, 2201 Hagenbrunn, Austria. Email: rentcars24austria@gmail.com. Telephone: +43 688 6072 6075.

No data protection officer has been appointed. Privacy requests are handled through the contact details above.

2. Personal data we process

  • Account data: name, email address, password hash, role and authentication-session information.
  • Renter and driver data: name, email, telephone number, date of birth, driving-licence number, issuing country and expiry date.
  • Booking data: vehicle, pickup and return locations and times, rental duration, selected rate plan, price, cancellation deadline, pre-pickup extension requests, old and requested return times, administrator initiating the request, and booking-change history.
  • Payment data: Stripe checkout and payment identifiers for the original booking and any extension, amount, currency, authorization, capture, refund and failure status. Card details are entered on Stripe-hosted pages and are not stored by RentCars24.
  • Communication data: contact-form name, email address and message; booking, access, confirmation and cancellation emails; delivery status and support correspondence where applicable.
  • Technical and consent data: necessary session cookies, consent choices, security and rate-limit identifiers, request metadata and operational event identifiers.

3. Purposes and legal bases

  • Contract steps and performance — Article 6(1)(b) GDPR: quotes, availability, driver validation, checkout, payment authorization, booking administration, vehicle handover, cancellation and customer support.
  • Legal obligations — Article 6(1)(c) GDPR: accounting, tax, regulatory and legally required recordkeeping or disclosures.
  • Legitimate interests — Article 6(1)(f) GDPR: service security, fraud prevention, access control, troubleshooting, payment reconciliation, establishment or defence of legal claims and operational reporting. The relevant balancing assessments must be documented internally.
  • Consent — Article 6(1)(a) GDPR and Section 165(3) TKG 2021: optional analytics and marketing technologies. Consent can be refused or withdrawn without affecting booking functionality.

A privacy policy is a notice, not a request for blanket consent. Booking data that is necessary for the contract should not be presented as consent-based processing.

4. Booking and payment processing

During checkout, renter and driver details are encrypted before temporary storage. Following a successful Stripe authorization, the booking retains the required renter snapshot and an encrypted driving-licence number. Only the last four licence characters are available for routine display.

Stripe receives the amount, currency, vehicle description and internal booking or checkout identifiers. The application stores provider identifiers and financial status, but not full card numbers or security codes.

5. Recipients and service providers

  • Hostinger for the website, API, database, backups and related hosting infrastructure, including the application’s Redis service.
  • Stripe for hosted card checkout, authorization, capture, refunds and payment fraud controls.
  • The email/SMTP provider configured by RentCars24 for transactional messages and contact inquiries.
  • Google services only after the applicable analytics or marketing consent is granted.
  • Professional advisers, insurers, public authorities or courts where necessary and legally permitted.

6. Cookies, local storage and Google tags

Necessary HttpOnly cookies are used for customer, administrator, checkout-attempt and guest-booking sessions. Their typical lifetimes range from approximately 15 minutes to 7 days depending on the session purpose.

The browser stores the consent record under rc24-cookie-consent-v1. It contains the selected analytics and marketing categories, policy version and update time. Users can reopen Cookie settings in the footer at any time.

Google Tag Manager is blocked until analytics or marketing consent is granted. Google Consent Mode defaults analytics_storage, ad_storage, ad_user_data and ad_personalization to denied. Only the consented categories configured in the production container may be activated.

7. International data transfers

Some service providers or their subprocessors may process data outside the European Economic Area. Such transfers take place only where an adequacy decision applies or appropriate safeguards are used, including European Commission Standard Contractual Clauses where required. Further information is available on request.

8. Retention and deletion

  • Accounting records, payment records and related booking documents are retained for seven years from the end of the relevant calendar year where Austrian tax law requires this.
  • Expired, cancelled or abandoned checkout holds and their encrypted renter payloads are deleted or irreversibly anonymised within 30 days after expiry or cancellation unless a payment-reconciliation or legal issue requires temporary restriction.
  • Driving-licence details that are not required for accounting are deleted or irreversibly anonymised within 90 days after the rental ends or the booking is finally cancelled, unless an accident, damage case, dispute or legal obligation requires longer restricted retention.
  • Delivered transactional-email outbox content and ordinary support correspondence are retained for up to 12 months after the matter is closed. Secure access links expire substantially earlier according to their technical lifetime.
  • Security and operational logs are normally retained for up to 90 days. Account data is retained while the account is active and may be removed after 24 months of inactivity, while legally required booking and accounting records remain restricted.
  • Data required for an active legal claim may be restricted and retained until the applicable claim period ends.
  • Website contact messages are sent directly to the configured email provider and are not stored in the application database. Ordinary inquiries are deleted from the mailbox within six months after the last substantive contact unless needed for a booking, dispute or legal obligation.

9. Your GDPR rights

Depending on the circumstances, individuals may request access, correction, deletion, restriction, portability or object to processing. Consent can be withdrawn at any time without affecting processing that occurred lawfully before withdrawal. Requests may be sent to rentcars24austria@gmail.com.

Individuals may also complain to the Austrian Data Protection Authority. The controller generally must respond to a rights request within one month, subject to the GDPR’s permitted extensions and exceptions.

Austrian Data Protection Authority

10. Security measures

Implemented safeguards include encrypted renter and licence payloads, hashed passwords and one-time tokens, short-lived and HttpOnly session cookies, rotating refresh tokens, same-origin checks, role-based administration, request validation, rate limiting, contact-form spam filtering, signed Stripe webhooks and restricted public booking projections.

No online service can guarantee absolute security. RentCars24 also maintains access reviews, backups, incident response, processor oversight and a personal-data-breach procedure.

11. Automated checks

The service automatically checks availability, pricing, minimum driver age, licence validity, payment status and cancellation eligibility. It does not use those checks for advertising profiling. Customers may contact rentcars24austria@gmail.com to ask questions or request human review of an automated rejection.

12. Changes to this notice

This notice displays an effective date and stable version. Material changes apply prospectively and are communicated where required. The version presented during checkout is retained with the booking record.