ToteRentalSuite legal information
Privacy Policy
- Effective date
- 2026-07-16
- Last updated
- 2026-07-16
- Version
- 2026-07-16.3
This policy applies from the effective date shown above. Mandatory rights and laws that cannot be excluded always prevail.
1. Who we are and our data-protection roles
ToteRentalSuite provides ToteRentalSuite as an independently operated SaaS service under the trading name ToteRentalSuite. The service provider may operate as an individual and is not represented as an incorporated company.
ToteRentalSuite is an independent controller for Operator account registration, subscription billing, platform security, fraud prevention, support, legal acceptance and platform-usage data. Each Operator is normally the independent controller for personal data about its own End Customers, personnel and rental operations. For that Operator-managed data, ToteRentalSuite normally acts as processor or service provider under the Operator’s instructions. The Operator must provide its own notice and respond to its customers’ rights requests; we assist it as required.
2. Categories and sources of personal data
- Account and business data: name, business name, role, email, phone, password hash, business/service addresses, country, website/domain, user status and last login.
- Subscription data: plan, billing email/address, Stripe customer/subscription/checkout references, subscription state, payment dates, invoices, discounts and refund records. Full card details remain with Stripe.
- Operator-managed customer and operations data: customer name, email, phone, delivery and pickup addresses, booking dates and windows, notes, products, invoices, payments, communications, delivery/pickup events and QR scan/location notes.
- Support and communications: feedback, support requests, email delivery state, campaign preferences, unsubscribe state and communications content.
- Technical and security data: session identifiers, CSRF tokens, IP address and user agent in administrator audit records, request and application logs, timestamps, consent choices, and aggregate daily/hourly page-view counters by named route, broad device category and acquisition channel. The counters store no raw IP address, full referrer URL, user agent, cookie or visitor identifier.
- Integration data: Stripe Connect account ID, onboarding/readiness flags, account email/country, payment and webhook metadata; and SMTP delivery information.
Data comes directly from users and Operators, automatically from browsers and servers, from End Customers completing an Operator booking form, and from Stripe or email/infrastructure providers. Providing account, authentication and billing fields is contractual where needed to create or pay for an account. Optional profile, marketing, feedback and booking notes are voluntary, although an Operator may require particular booking details.
3. Purposes and GDPR legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Create accounts, authenticate users, provide plans and platform features | Account, business, security and usage data | Contract; steps requested before contract |
| Platform subscription billing, Stripe Checkout, invoices, cancellation and refunds | Account, billing and Stripe references | Contract; legal obligation for tax/accounting records |
| Provide Stripe Connect and Operator booking/payment workflows | Connected-account and Operator-managed customer data | Operator instructions/contract as processor; ToteRentalSuite legitimate interests for secure integration |
| Support, feedback and transactional email | Account and communication content | Contract; legitimate interests in customer service and improvement |
| Security, tenant isolation, abuse and fraud prevention, audits and legal claims | Technical, account, payment and audit data | Legitimate interests; legal obligation where applicable |
| Aggregate service usage measurement and capacity planning | Daily/hourly route-level page-view totals, broad device category and acquisition channel | Legitimate interests in reliability and product improvement |
| Optional product marketing | Email and preference history | Consent where required; otherwise only another lawful basis confirmed for the recipient and location |
| Google Analytics measurement | Consent Mode signals, and cookie/device identifiers and fuller page interaction data when enabled | Denied-state cookieless measurement signals by default; consent for Analytics cookies and fuller measurement |
Our legitimate interests include keeping the service secure, preventing cross-tenant access and payment fraud, supporting customers, improving reliability, enforcing agreements and defending claims. We consider necessity, reasonable expectations and impact, and provide objection rights where applicable. Consent is not used as a catch-all for processing necessary to provide the contract.
No solely automated decision produces legal or similarly significant effects. Refund eligibility indicators and fraud signals support human administrator review; they do not automatically approve or reject a refund.
4. Public booking customers and Operator notices
When an End Customer uses an Operator’s public booking site, widget or invoice-payment page, the Operator normally decides why and how rental data is used and is the controller. ToteRentalSuite hosts and processes the data for the Operator. The Operator must configure its legal identity, privacy notice, rental terms and refund/cancellation link. ToteRentalSuite’s SaaS Refund Policy does not apply to the rental.
End Customers should first direct access, correction, deletion, objection or marketing questions to the relevant Operator. We will reasonably help the Operator respond. ToteRentalSuite may independently process limited security, payment-integrity and platform log data for its own legitimate interests and legal obligations.
5. Recipients, subprocessors and international transfers
Data may be shared with authorised Operator users; ToteRentalSuite administrators who need access; Stripe for platform billing and Stripe Connect; configured email, hosting, database, storage, logging and backup providers; Google Analytics for denied-state Consent Mode signals and, when enabled, fuller analytics measurement; professional advisers; and authorities where legally required. We limit access to what each recipient needs for its role.
Stripe, Google and other service providers may process data outside the EEA. Where GDPR transfer rules apply, we rely on an adequacy decision, approved contractual clauses with appropriate supplementary measures, or another lawful transfer mechanism.
6. Retention, account closure and deletion
We retain data only while needed for the purpose, contract, security, disputes and legal obligations. Our standard periods are 30 days for ordinary account data after approved closure, 90 days for security logs, 730 days for support records, 10 years for financial records, and 6 years for rights-request evidence. A record may be kept longer where law, an active dispute, fraud prevention or a legal hold requires it; otherwise it is deleted or anonymised when its period expires.
Account closure is not the same as subscription cancellation. A deletion request is confirmed and administrator-reviewed. We may restrict or close the account while retaining invoices, refunds, tax/accounting evidence, fraud/security records and legal claims material where required. Remaining personal data is deleted or anonymised after applicable periods; backup copies age out under the verified backup schedule.
7. Data-subject rights
Depending on applicable law, a person may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests; withdraw consent at any time without affecting prior processing; and complain to the competent supervisory authority. Identity and authority may be verified proportionately. Rights can be limited by legal exceptions and the rights of others.
8. Cookies, browser storage and analytics
Strictly necessary Laravel session and CSRF technologies support authentication, security and continuity. Local browser storage remembers the dark theme and authenticated tab selection. In production, Google Consent Mode sends limited denied-state cookieless measurement signals by default; Google Analytics cookies and fuller measurement require Analytics consent. Choices are versioned and can be changed using “Cookie preferences”. See the Cookie Policy.
9. Security
Measures in the current application include password hashing, CSRF protection, encrypted cookies, secure/HTTP-only production session settings, rate limiting, signed Stripe webhooks, webhook duplicate detection, server-side Stripe secrets, connected-account separation, tenant ownership checks, security headers, upload validation, and restricted administrator/operator middleware. No system is risk-free. We maintain incident handling and will support legally required breach notifications without exposing sensitive defensive details.
10. Children
The Platform is intended for business users aged at least 18. It is not directed to children. Operators must ensure their customer collection is lawful, including any age-related duties relevant to their rental service.
11. Changes and contact
We version this Policy and retain prior acceptance/presentation evidence. Material changes will be communicated through the Platform or account email and may require a new acknowledgement where appropriate.
You may lodge a complaint with or another supervisory authority competent for your location.
