Skip to content
Privacy Notice

Your data, handled with care.

Last updated 24 September 2026 · Draft for legal review before launch

What personal data CeeRent collects, why, who we share it with, how long we keep it, and your rights under the Data Privacy Act. Diretso lang: we don’t sell data, and renters’ data belongs to the operator they book with.

01Who we are

CeeRent (“we”, “us”) makes booking, payment and handover software for car and motorcycle rental operators in the Philippines. We follow the Data Privacy Act of 2012 (RA 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (NPC).

Company[Registered business name — added at launch], SEC reg. no. [SEC registration no. — added at launch]
Address[Registered address — added at launch]
Data Protection Officerdpo@ceerent.com · [Data Protection Officer — added at launch]
NPC registrationWe are registering with the NPC under NPC Circular 2022-04 before launch. [NPC registration no. — added when issued]

02Our two roles

We handle personal data in two different ways, and the law treats them differently:

  • As a controller (a “personal information controller” or PIC), we decide why and how data is used. This covers rental operators who use CeeRent, their staff users, and visitors to ceerent.com.
  • As a processor (a “personal information processor” or PIP), we handle data only on an operator’s instructions. This covers renters who book through an operator’s booking site. The operator is the controller for its renters and decides what to collect and how long to keep it.
Whose dataOur roleWho to ask
Operators, owners and staff usersControllerUs — dpo@ceerent.com
Visitors to ceerent.com and people who contact usControllerUs — dpo@ceerent.com
Renters booking with an operatorProcessor for the operatorThe operator first (see their booking site). We help them answer.
A renter’s reusable “verify once” recordController, with the renter’s consentUs — dpo@ceerent.com

Renters: if you rented from an operator that uses CeeRent, that operator’s own privacy notice applies to you. You can still write to us and we will pass your request to the operator and help them handle it. How operators and CeeRent share responsibility is set out in our Data Processing Agreement.

03What we collect

From operators and their staff

  • Business details: registered name, trade name, TIN, address, branches, and payout set-up status (Xendit handles the payout verification itself).
  • User accounts: name, email, mobile number, role, password (stored as a secure hash), 2FA settings, sign-in history and device/session details.
  • Billing: plan, add-ons, payment method type and last four digits, invoices, payment history.
  • Support: messages and calls with us, and support access you approve.
  • Ownership recovery: if you ask us to recover or transfer an account, the documents you send to show who controls the business.
  • Usage and security data: activity inside CeeRent (in the audit log), IP address, browser and error logs.

From visitors to ceerent.com

  • What you type into forms — for example a walkthrough request or a contact message.
  • Basic technical data (IP address, browser, pages visited) for security and aggregate analytics.

About renters, on behalf of operators

What is collected depends on how each operator sets up CeeRent. It can include:

  • Identity and contact: name, email, mobile number, address, date of birth.
  • Sensitive personal information: driver’s licence details and photo, government ID, and a selfie for the licence check.
  • Bookings: dates, vehicle, pickup and return places, flight number for airport meet-ups, add-ons, price and payments.
  • Handover records: pickup and return photos (which can show people nearby), odometer and fuel readings, damage notes, claims.
  • Signed rental agreements, including the e-signature and when and where it was signed.
  • Messages with the operator, including Messenger if the operator connects it.
  • GPS data for the rented vehicle, if the operator uses the GPS add-on. GPS tracks the vehicle, and so shows where the renter drives it.

04Why we use it, and on what legal basis

For data we control, we rely on the grounds in sections 12 and 13 of the Data Privacy Act:

PurposeLegal basis
Creating your account and providing CeeRentContract (sec. 12(b))
Billing, BIR invoices, tax and accounting recordsLegal obligation (sec. 12(c)) and contract
Security, fraud prevention, audit logs, sign-in protectionLegitimate interest (sec. 12(f)) and our duty to secure data
Support, service emails and important notices (e.g. changes to terms, failed payments)Contract
Improving CeeRent using usage statisticsLegitimate interest, using aggregated or de-identified data where we can
Newsletters, promos and product newsConsent (sec. 12(a)) — optional
Answering regulators, courts, and legal claimsLegal obligation; establishing or defending legal claims (sec. 13(f))
Reusing a renter’s verification with another operator (“verify once”)The renter’s consent, given per operator

For renters’ data, the operator decides the purposes and the legal basis. We use renters’ data only to provide CeeRent to that operator — for example, to show bookings, take payments, send reminders and store handover records. We don’t use it for our own marketing, and we don’t sell it.

AI features only suggest. Staff confirm before anything is saved or charged. We don’t make decisions about people using only automated processing.

06Who we share it with

We share personal data only with:

  • The operator you book with (for renters) — they control your data.
  • Service providers (subprocessors) that help us run CeeRent, listed below. Each is bound by a contract that limits what they can do with the data and requires them to keep it secure.
  • Authorities when the law requires it — for example a court order or a lawful request from the NPC or BIR. We check each request and share only what is required.
  • A buyer or successor if CeeRent is merged or sold, under the same protections, and with notice to you.

Subprocessors

ProviderWhat forWhat dataWhere
XenditPayments: renter payments to operators, deposit holds, refunds, and operators’ CeeRent subscription paymentsName, email, mobile number, amount and booking reference; card and wallet details are entered on Xendit’s side, not oursPhilippines and other Xendit locations
Amazon Web Services (incl. Amazon Bedrock)Hosting, file storage (photos, IDs, signed agreements), and AI features using Claude on BedrockAll data stored in CeeRent. For AI: only the photos or text needed for that feature (e.g. a dashboard photo, pickup and return photos, a message to draft a reply to)[AWS hosting region — confirmed at launch]
SupabaseDatabase and sign-inAccount, booking, customer and vehicle records; sign-in details (passwords are stored only as secure hashes)[Supabase region — confirmed at launch]
ResendSending emails (booking confirmations, invoices, reminders, sign-in codes)Email address, name, and the content of the emailUnited States
SemaphoreSending SMS (booking updates, reminders, sign-in codes)Mobile number and the text of the messagePhilippines
Meta Messenger PlatformAuto-replies on the operator’s Facebook Page — only if the operator connects MessengerMessages sent to the operator’s Page and the sender’s Page-scoped ID and public nameUnited States / Ireland
MeshyMaking 3D models of vehicles — only if the operator orders oneVehicle photos only. We ask operators not to include people or plates they don’t want shown[Meshy data location — confirmed at launch]
Traccar (self-hosted)GPS tracking — only if the operator turns on the GPS add-onVehicle location, speed, trips and tracker ID. Runs on our own servers; no separate company receives the dataSame as our AWS hosting

We tell operators at least 30 days before we add or replace a subprocessor that handles renters’ data, so they can object (see the DPA).

07Data sent outside the Philippines

Some of our providers store or process data outside the Philippines (see the “Where” column above). We stay accountable for that data under section 21 of the Data Privacy Act. We only use providers that commit by contract to protect it to a standard comparable to Philippine law, and we send only what each provider needs.

08How long we keep it

DataHow long
Operator account and business dataWhile you subscribe, then 90 days after the account closes. Then deleted.
Our subscription invoices and payment records5 years from filing, the BIR record-keeping period after the Ease of Paying Taxes Act (RA 11976). Kept even after the account is deleted.
Renter ID, licence and selfie imagesPer the operator’s retention setting. Default: deleted 90 days after the rental ends, unless a damage or payment claim is still open.
Bookings, handover photos, signed agreementsPer the operator’s settings while they subscribe; deleted 90 days after the operator’s account closes. Operators must keep their own tax records.
GPS trips and locations (if the operator uses GPS)Per the operator’s GPS retention setting. Default: deleted 30 days after the rental ends.
Audit logs1 year.
Support requests and emails with usWhile your account is open, then 90 days.
Marketing-site analytics13 months, in aggregate.
Marketing contacts (if you opted in)Until you unsubscribe or withdraw consent.
BackupsRolling copies that expire automatically on a fixed cycle ([Backup retention window — confirmed at launch]). Deleted data leaves backups when that cycle ends.

When the time is up, we delete the data or anonymise it so it can no longer identify anyone. Where tax law requires booking or invoice records to be kept, the operator’s renter records are anonymised rather than kept in full.

09How we protect it

In short:

  • Encryption in transit (HTTPS/TLS) and at rest.
  • Role-based access, and 2FA required for owners and managers.
  • Licence and ID images are visible only to the operator’s authorised staff.
  • Our support team can see inside an account only when the operator approves, for a limited time, and every action is logged in the operator’s audit log.
  • Audit logs, backups, and staff access on a need-to-know basis.

Details, including what is still planned, are on our Security page.

10Your rights, and how to use them

Under the Data Privacy Act you have the right to:

  • Be informed that your data is being processed and how — this notice is part of that;
  • Access your data and get a copy;
  • Object to processing, including marketing and processing based on legitimate interest;
  • Correct (rectify) data that is wrong or incomplete;
  • Erasure or blocking of data that is no longer needed, was unlawfully obtained, or that you withdrew consent for;
  • Data portability — get your data in a common electronic format (we use CSV or JSON);
  • Damages if you are harmed by inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorised use of your data;
  • File a complaint with the National Privacy Commission.

How to make a request

  1. Operators and staff: many requests you can do yourself — edit your profile, export data from Settings, or turn marketing off. For anything else, email dpo@ceerent.com from the email on your account.
  2. Renters: sign in to your account on the operator’s booking site and use “Your personal data → Make a request”, or contact the operator. You can also email us and we will forward it to the operator and help them respond.
  3. We may need to confirm who you are before acting, so we don’t give your data to someone else.
  4. We confirm we received your request within 5 working days and aim to complete it within 30 days. If it will take longer, or if we can’t do it (for example because the law requires us to keep invoices), we’ll tell you why.

Making a request is free. If requests are clearly excessive or repeated, we may charge a reasonable fee or decline, and we’ll explain why.

Complaints to the NPC

Please tell us first so we can fix it. You can also go to the National Privacy Commission at any time: privacy.gov.ph · complaints@privacy.gov.ph. Under NPC rules, a complaint usually needs to show that you raised the issue with the controller first.

11If there is a data breach

If a breach involves sensitive personal information (or data that could enable identity fraud) and is likely to cause real risk of serious harm, we notify the NPC and the affected people within 72 hours of learning about it, as required by NPC rules. We tell you what happened, what data was involved, what we are doing, and what you can do to protect yourself.

For renters’ data, we tell the operator without undue delay — and in any case within 72 hours — and help them notify the NPC and their renters. See the DPA.

12Cookies

By default we use essential cookies only. Without them, signing in and booking won’t work:

Cookie typeWhat it doesHow long
Sign-in sessionKeeps you signed in to the dashboard or a booking site accountUntil you sign out or the session expires
SecurityProtects forms and payments from forgery and abuseSession
PreferencesRemembers choices like Filipino or EnglishUp to 12 months

We don’t use advertising or cross-site tracking cookies. Our marketing-site analytics count visits in aggregate. If we ever want to use non-essential cookies, we will ask first and you can say no.

13Children

CeeRent is for businesses, and our dashboard is for adults. We don’t knowingly collect data from children. Operators set their own minimum renter age and licence rules. If you think a child’s data was given to us, email dpo@ceerent.com and we’ll help remove it.

14Changes to this notice

We’ll update this notice when our practices change. The date at the top shows the latest version. For important changes — new purposes, new kinds of data, or new subprocessors for renters’ data — we email operators at least 30 days before and show a notice in the dashboard.

15Contact

Questions about this page? Email privacy@ceerent.com or see Contact.