Back to legal hub

Privacy Policy

Information on the collection, use, disclosure, retention, and protection of personal data

Last updated: 1 September 2026

Distinct roles

  • Rentify is the controller for the Platform, intermediation, accounts, bookings, support, security, and its own obligations.
  • The Provider identified before payment is normally an independent controller for data needed to perform the Main Service.
  • Acceptance of the Terms does not replace separate consent for marketing or non-essential cookies.

1. Controller and data protection contact

The controller for Platform operations is Rentify SRL, IDNO 1026023031842, with its registered office at MD-2009, mun. Chișinău, sector Centru, str. Pantelimon Halippa 6/G, ap. (of.) 13a, Republica Moldova. For questions, requests, or incidents concerning personal data: support@rentify.md, +373 60 650 806.

If Rentify appoints a data protection officer or specialist contact, their details will be published here. Until then, requests are handled through the contacts above.

3. Who this Policy applies to

  • visitors to the Platform;
  • persons who create accounts, request offers, or make bookings;
  • Customers, declared drivers, passengers, and contact persons;
  • persons who contact support or submit complaints;
  • representatives, drivers, guides, and personnel of Providers and partners.

4. Categories of data

Personal data categories and examples
CategoryExamples
Identification and contactFirst and last name, email, telephone, country, language, account data, and relationship to the booked person.
Booking and travelService, Provider, vehicle, dates, times, locations, route, duration, passengers, flight, options, accessibility requirements, notes, and changes.
Eligibility and documentsAge, date of birth, driving licence, identity card, passport, and, only where necessary, temporary copies of documents.
Payment and refundAmount, currency, method, date, transaction ID, status, refund, and masked data received from Paynet. Rentify does not store the full card number or CVV.
Communications and supportEmails, forms, chats, call notes, WhatsApp/Telegram, complaints, cancellations, incidents, and evidence.
Technical and securityIP address, browser, device, cookies, logs, session identifiers, version of accepted documents, acceptance date and time, and anti-fraud indicators.
Analytics and diagnosticsPage and product events, online identifiers, browser and device information, error diagnostics, and the internal account ID after sign-in.
Provider dataLegal details, representatives, licences, authorisations, insurance, qualifications, settlement accounts, and verification documents.

5. Sources of data

  • directly from the data subject or from a Customer booking for other persons;
  • from the Provider, driver, guide, or their representative;
  • from Paynet, the bank, and payment systems in the form of confirmations and masked data;
  • automatically through the Platform, logs, and cookies, according to the user's choices;
  • from public registers and official sources to verify Providers and authorisations where necessary.

6. Purposes and legal bases for processing

Processing purposes and principal legal bases
PurposePrincipal legal basis
Account, offer, booking, and contractsPerformance of a contract and pre-contractual steps.
Disclosure of data to the ProviderPerformance of contracts, pre-contractual steps, and the legitimate interest in intermediating the booking.
Payment, refund, and reconciliationPerformance of a contract, legal obligations, and legitimate interests in record keeping and fraud prevention.
Support, complaints, and disputesPerformance of a contract, legal obligations, and defence of rights.
Security, anti-fraud, and chargebacksLegitimate interests, legal obligations, and defence of rights; decisions with significant effects are not made solely by automated means.
Accounting, tax, and archivingLegal obligation.
Provider verificationLegitimate interest in the legality, safety, and quality of the network; legal obligations where applicable.
Product analytics and diagnosticsConsent for non-essential cookies and technologies.
Direct marketingSeparate optional consent or another basis expressly permitted by law.

This Policy is a notice. “Acknowledgement” does not constitute consent to all processing. Data needed for a contract, payment, security, or legal obligations is not processed solely on the basis of consent.

7. The Provider and data-related roles

The Provider's identity is displayed before payment. Rentify discloses only the data required to verify eligibility and perform the booking. The Provider is normally an independent controller for data it uses under its own contract, for safety, insurance, tax, and its legal obligations.

In certain flows, Rentify and the Provider may jointly determine certain purposes, or one may process data on behalf of the other. The specific role is established by the cooperation agreement and communicated to the data subject where necessary.

8. Copies of documents and data that is sensitive in practice

Rentify requests copies of a driving licence, identity card, passport, or other documents only where verification cannot be completed by a less intrusive method and the document is required for the booking, safety, fraud prevention, or Provider obligations.

  • Copies are uploaded through the secure channel identified by Rentify or sent directly to the Provider. Sending them by unprotected email, WhatsApp, or Telegram is not recommended.
  • Rentify limits access to personnel who need the data and keeps access logs where the system permits.
  • Rentify keeps the copy for profile verification and reuse in future bookings while the account is active and the copy remains necessary for those purposes. After the account is closed or the copy is no longer necessary, Rentify deletes it unless a dispute, suspected fraud, legal obligation, or documented Provider requirement justifies longer retention.
  • Residual backup data is isolated and removed through the ordinary overwrite cycle; it is not used in current operations.
  • Rentify does not request, and the Customer must not send, a full card number or CVV.

9. Data about other persons

If the Customer supplies data about passengers, drivers, or other persons, the Customer must have the right to disclose it, provide only the data needed, and inform those persons about this Policy. Children's data is supplied by a parent, representative, or person legitimately organising the journey.

10. Data recipients

  • the Provider, driver, vehicle operator, guide, agency, or service organiser;
  • Paynet Services S.R.L., banks, payment systems, and providers involved in anti-fraud and refunds;
  • hosting, infrastructure, email, SMS, notification, security, support, signature, or secure-storage providers;
  • WhatsApp and Telegram service providers where the Customer chooses those channels; messages may be processed under their policies;
  • a service provider for product analytics and error diagnostics when analytics is active;
  • accountants, lawyers, auditors, insurers, and consultants, to the extent necessary;
  • authorities, courts, and law-enforcement bodies where there is a legal basis.

Rentify requires providers to meet confidentiality, security, and limited-use obligations according to their role and applicable law.

11. Paynet and card data

Payments are processed by Paynet Services S.R.L., NBM licence series no. 000586. Paynet's information and safeguards also apply on the payment page. Rentify receives confirmations, transaction IDs, amount, status, and masked data, but not the full card number or CVV.

12. Cookies and product analytics

When analytics is active, the analytics service provider may receive page URLs, product and page events, timestamps, browser and device information, online identifiers, the IP address seen by the service, and error diagnostics. After sign-in, Rentify may send the internal account ID. It does not send the account name or email as identification properties.

Rentify does not currently install advertising or campaign-measurement tags. Preferences are managed through Cookie settings, as described in the Cookie Policy.

13. International transfers

Some technology providers, communication services, and Providers may process data outside the Republic of Moldova. Rentify assesses providers, limits the data, uses appropriate clauses and safeguards under applicable law, and provides additional information on request to the extent permitted by law.

14. Retention periods

Data retention periods or criteria
DataPeriod / criterion
Unconfirmed requests and offers without a contractUp to 12 months unless a legal or anti-fraud reason requires a longer period.
Document copies held by RentifyWhile the account is active and the copy remains necessary for profile verification and future bookings. After the account is closed or the copy is no longer necessary, it is deleted unless a dispute, suspected fraud, incident, or legal obligation justifies longer retention.
AccountWhile active and normally for up to 3 years after closure for security and defence of rights; mandatory data is retained separately.
Contracts, bookings, payments, and fiscal recordsFor the period required by civil, accounting, tax, and fraud-prevention law.
Complaints, support, and disputesUntil resolution and normally for 3 years after closure, or longer where there is litigation or a relevant statutory period.
Technical and security logsNormally 12 months; longer where required to investigate an incident.
Product analyticsBrowser identifiers may last up to one year. Server-side event retention follows the period configured for the analytics service.
MarketingUntil consent is withdrawn or the person unsubscribes; evidence of consent may be retained for a further 3 years for compliance.
Cookies and evidence of choiceThe preference cookie lasts 183 days. Rentify does not currently create a separate account-level consent record.

The periods are reviewed regularly. On expiry, data is deleted, anonymised, or isolated if continued retention is still mandatory.

15. Rights of the data subject

  • information and access to data;
  • rectification and updating;
  • erasure, subject to the law;
  • restriction or blocking where applicable;
  • objection, including to direct marketing;
  • withdrawal of consent without affecting earlier processing;
  • data portability, subject to the law;
  • not to be subject to a solely automated decision producing legal or similarly significant effects, subject to the law;
  • lodging a complaint with the National Centre for Personal Data Protection and applying to a court.

A request must be sent to support@rentify.md. Rentify may request proportionate information to verify identity. The ordinary response period is one month from receipt of the request and may be extended subject to the law and notice to the person.

16. Automated decisions and fraud prevention

Rentify may use technical indicators to detect risk, such as data mismatches, repeated attempts, or Paynet signals. Rentify does not make decisions with legal or similarly significant effects on the Customer solely by automated means. A suspension or verification request may be reviewed by a person on request.

17. Security

  • access controls and the need-to-know principle;
  • authentication, logging, and access review;
  • encryption of communications and infrastructure protection;
  • backup, continuity, and restoration;
  • confidentiality and data-protection agreements with providers and Providers;
  • procedures for incidents, data-subject requests, and document deletion.

No system can guarantee absolute security. In the event of an incident, Rentify investigates, limits the effects, preserves evidence, and notifies the authority and individuals where required by law.

18. Marketing

Rentify sends promotional messages only on the basis of separate optional consent or another basis expressly permitted by law. An unsubscribe option is available in every message or by contacting Rentify. Operational messages about a booking, payment, contract, driver, cancellation, or security are not marketing.

19. Minors

The Platform is not intended for minors to enter contracts independently. Data about children travelling as passengers is provided by a parent, representative, or authorised person only to the extent required for the service. Rentify does not intentionally use children's data for advertising profiling.

20. Changes, contact, and supervisory authority

The Policy may be updated for legal, technical, or operational changes. The last updated date is displayed on the Platform, and material changes may be communicated by email or notification.

Rentify SRL; support@rentify.md; +373 60 650 806; MD-2009, mun. Chișinău, sector Centru, str. Pantelimon Halippa 6/G, ap. (of.) 13a, Republica Moldova.

Personal data complaints may be addressed to the National Centre for Personal Data Protection of the Republic of Moldova. Current details and procedures are available at datepersonale.md.