Your data, handled with care.
Last updated 24 September 2026 · Draft for legal review before launch
What personal data CeeRent collects, why, who we share it with, how long we keep it, and your rights under the Data Privacy Act. Diretso lang: we don’t sell data, and renters’ data belongs to the operator they book with.
01Who we are
CeeRent (“we”, “us”) makes booking, payment and handover software for car and motorcycle rental operators in the Philippines. We follow the Data Privacy Act of 2012 (RA 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (NPC).
| Company | [Registered business name — added at launch], SEC reg. no. [SEC registration no. — added at launch] |
|---|---|
| Address | [Registered address — added at launch] |
| Data Protection Officer | dpo@ceerent.com · [Data Protection Officer — added at launch] |
| NPC registration | We are registering with the NPC under NPC Circular 2022-04 before launch. [NPC registration no. — added when issued] |
02Our two roles
We handle personal data in two different ways, and the law treats them differently:
- As a controller (a “personal information controller” or PIC), we decide why and how data is used. This covers rental operators who use CeeRent, their staff users, and visitors to ceerent.com.
- As a processor (a “personal information processor” or PIP), we handle data only on an operator’s instructions. This covers renters who book through an operator’s booking site. The operator is the controller for its renters and decides what to collect and how long to keep it.
| Whose data | Our role | Who to ask |
|---|---|---|
| Operators, owners and staff users | Controller | Us — dpo@ceerent.com |
| Visitors to ceerent.com and people who contact us | Controller | Us — dpo@ceerent.com |
| Renters booking with an operator | Processor for the operator | The operator first (see their booking site). We help them answer. |
| A renter’s reusable “verify once” record | Controller, with the renter’s consent | Us — dpo@ceerent.com |
Renters: if you rented from an operator that uses CeeRent, that operator’s own privacy notice applies to you. You can still write to us and we will pass your request to the operator and help them handle it. How operators and CeeRent share responsibility is set out in our Data Processing Agreement.
03What we collect
From operators and their staff
- Business details: registered name, trade name, TIN, address, branches, and payout set-up status (Xendit handles the payout verification itself).
- User accounts: name, email, mobile number, role, password (stored as a secure hash), 2FA settings, sign-in history and device/session details.
- Billing: plan, add-ons, payment method type and last four digits, invoices, payment history.
- Support: messages and calls with us, and support access you approve.
- Ownership recovery: if you ask us to recover or transfer an account, the documents you send to show who controls the business.
- Usage and security data: activity inside CeeRent (in the audit log), IP address, browser and error logs.
From visitors to ceerent.com
- What you type into forms — for example a walkthrough request or a contact message.
- Basic technical data (IP address, browser, pages visited) for security and aggregate analytics.
About renters, on behalf of operators
What is collected depends on how each operator sets up CeeRent. It can include:
- Identity and contact: name, email, mobile number, address, date of birth.
- Sensitive personal information: driver’s licence details and photo, government ID, and a selfie for the licence check.
- Bookings: dates, vehicle, pickup and return places, flight number for airport meet-ups, add-ons, price and payments.
- Handover records: pickup and return photos (which can show people nearby), odometer and fuel readings, damage notes, claims.
- Signed rental agreements, including the e-signature and when and where it was signed.
- Messages with the operator, including Messenger if the operator connects it.
- GPS data for the rented vehicle, if the operator uses the GPS add-on. GPS tracks the vehicle, and so shows where the renter drives it.
04Why we use it, and on what legal basis
For data we control, we rely on the grounds in sections 12 and 13 of the Data Privacy Act:
| Purpose | Legal basis |
|---|---|
| Creating your account and providing CeeRent | Contract (sec. 12(b)) |
| Billing, BIR invoices, tax and accounting records | Legal obligation (sec. 12(c)) and contract |
| Security, fraud prevention, audit logs, sign-in protection | Legitimate interest (sec. 12(f)) and our duty to secure data |
| Support, service emails and important notices (e.g. changes to terms, failed payments) | Contract |
| Improving CeeRent using usage statistics | Legitimate interest, using aggregated or de-identified data where we can |
| Newsletters, promos and product news | Consent (sec. 12(a)) — optional |
| Answering regulators, courts, and legal claims | Legal obligation; establishing or defending legal claims (sec. 13(f)) |
| Reusing a renter’s verification with another operator (“verify once”) | The renter’s consent, given per operator |
For renters’ data, the operator decides the purposes and the legal basis. We use renters’ data only to provide CeeRent to that operator — for example, to show bookings, take payments, send reminders and store handover records. We don’t use it for our own marketing, and we don’t sell it.
AI features only suggest. Staff confirm before anything is saved or charged. We don’t make decisions about people using only automated processing.
05Consent
When we ask for consent, we follow NPC Circular 2023-04:
- Separate and specific. Agreeing to our Terms does not mean agreeing to marketing. Marketing is its own checkbox, unticked by default. Saying no doesn’t affect your account.
- Easy to withdraw. Unsubscribe from any marketing email in one click, or turn it off in your profile. Withdrawing doesn’t undo what was done before.
- Not used as a catch-all. Where we rely on another basis (like contract or legal obligation), we tell you so instead of asking for consent we don’t need.
- Recorded. We keep a record of when and how consent was given or withdrawn.
Verify once (for renters): a renter verified by one operator can choose to reuse that verification with another operator that uses CeeRent. It is only shared with an operator after the renter says yes to that operator. The renter can withdraw consent at any time, and an expired licence has to be uploaded again.
07Data sent outside the Philippines
Some of our providers store or process data outside the Philippines (see the “Where” column above). We stay accountable for that data under section 21 of the Data Privacy Act. We only use providers that commit by contract to protect it to a standard comparable to Philippine law, and we send only what each provider needs.
08How long we keep it
| Data | How long |
|---|---|
| Operator account and business data | While you subscribe, then 90 days after the account closes. Then deleted. |
| Our subscription invoices and payment records | 5 years from filing, the BIR record-keeping period after the Ease of Paying Taxes Act (RA 11976). Kept even after the account is deleted. |
| Renter ID, licence and selfie images | Per the operator’s retention setting. Default: deleted 90 days after the rental ends, unless a damage or payment claim is still open. |
| Bookings, handover photos, signed agreements | Per the operator’s settings while they subscribe; deleted 90 days after the operator’s account closes. Operators must keep their own tax records. |
| GPS trips and locations (if the operator uses GPS) | Per the operator’s GPS retention setting. Default: deleted 30 days after the rental ends. |
| Audit logs | 1 year. |
| Support requests and emails with us | While your account is open, then 90 days. |
| Marketing-site analytics | 13 months, in aggregate. |
| Marketing contacts (if you opted in) | Until you unsubscribe or withdraw consent. |
| Backups | Rolling copies that expire automatically on a fixed cycle ([Backup retention window — confirmed at launch]). Deleted data leaves backups when that cycle ends. |
When the time is up, we delete the data or anonymise it so it can no longer identify anyone. Where tax law requires booking or invoice records to be kept, the operator’s renter records are anonymised rather than kept in full.
09How we protect it
In short:
- Encryption in transit (HTTPS/TLS) and at rest.
- Role-based access, and 2FA required for owners and managers.
- Licence and ID images are visible only to the operator’s authorised staff.
- Our support team can see inside an account only when the operator approves, for a limited time, and every action is logged in the operator’s audit log.
- Audit logs, backups, and staff access on a need-to-know basis.
Details, including what is still planned, are on our Security page.
10Your rights, and how to use them
Under the Data Privacy Act you have the right to:
- Be informed that your data is being processed and how — this notice is part of that;
- Access your data and get a copy;
- Object to processing, including marketing and processing based on legitimate interest;
- Correct (rectify) data that is wrong or incomplete;
- Erasure or blocking of data that is no longer needed, was unlawfully obtained, or that you withdrew consent for;
- Data portability — get your data in a common electronic format (we use CSV or JSON);
- Damages if you are harmed by inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorised use of your data;
- File a complaint with the National Privacy Commission.
How to make a request
- Operators and staff: many requests you can do yourself — edit your profile, export data from Settings, or turn marketing off. For anything else, email dpo@ceerent.com from the email on your account.
- Renters: sign in to your account on the operator’s booking site and use “Your personal data → Make a request”, or contact the operator. You can also email us and we will forward it to the operator and help them respond.
- We may need to confirm who you are before acting, so we don’t give your data to someone else.
- We confirm we received your request within 5 working days and aim to complete it within 30 days. If it will take longer, or if we can’t do it (for example because the law requires us to keep invoices), we’ll tell you why.
Making a request is free. If requests are clearly excessive or repeated, we may charge a reasonable fee or decline, and we’ll explain why.
Complaints to the NPC
Please tell us first so we can fix it. You can also go to the National Privacy Commission at any time: privacy.gov.ph · complaints@privacy.gov.ph. Under NPC rules, a complaint usually needs to show that you raised the issue with the controller first.
11If there is a data breach
If a breach involves sensitive personal information (or data that could enable identity fraud) and is likely to cause real risk of serious harm, we notify the NPC and the affected people within 72 hours of learning about it, as required by NPC rules. We tell you what happened, what data was involved, what we are doing, and what you can do to protect yourself.
For renters’ data, we tell the operator without undue delay — and in any case within 72 hours — and help them notify the NPC and their renters. See the DPA.
13Children
CeeRent is for businesses, and our dashboard is for adults. We don’t knowingly collect data from children. Operators set their own minimum renter age and licence rules. If you think a child’s data was given to us, email dpo@ceerent.com and we’ll help remove it.
14Changes to this notice
We’ll update this notice when our practices change. The date at the top shows the latest version. For important changes — new purposes, new kinds of data, or new subprocessors for renters’ data — we email operators at least 30 days before and show a notice in the dashboard.
15Contact
- Data Protection Officer: dpo@ceerent.com
- General privacy questions: privacy@ceerent.com
- Security issues: security@ceerent.com
- Post: Data Protection Officer, [Registered address — added at launch]
Questions about this page? Email privacy@ceerent.com or see Contact.