Skip to content
Security & privacy

How we protect your business and your renters.

Your bookings, your money trail and your renters’ licences are the heart of your business. Here’s what we do to keep them safe — and, honestly, what’s still on the way.

A quiet rental office at dusk: a locked key cabinet, a closed laptop and a signed agreement under a paperweight
19:10 · office closed, cabinet locked
01The basics

Locked down by default.

No settings to hunt for. These are on for every operator, on every plan.

In transit

Encrypted on the way

Every page, app screen and API call goes over HTTPS (TLS). Your booking site, dashboard and handover app all use it — including your own domain.

At rest

Encrypted where it’s stored

Databases, photos, licence images and signed agreements are encrypted on disk. Backups are encrypted too.

Separation

Your data is only yours

Every operator’s records are kept apart at the database level. Another operator on CeeRent can’t see your fleet, bookings or renters.

Roles

Staff see what their job needs

Front desk, field staff, drivers and your accountant each get their own sign-in and role. Drivers see their jobs, not your revenue.

2FA

Two-step sign-in for the keys

Owners and managers must turn on two-step sign-in. Anyone with access to money, payouts or staff settings is protected by more than a password.

Sessions

Sign out everywhere

See where you’re signed in. Lost a phone or a staff member left? One tap signs them out of every device.

02Support access

We only come in when you open the door.

Our support team can’t browse your account. If you need help with something inside it, you approve access — and you can see everything we did.

Step 1

You approve

An owner or manager approves a support request — or grants access first when asking for help. No approval, no access.

Step 2

Time-limited

Access lasts 2 hours, then closes by itself. You can end it early at any time.

Step 3

Every action logged

Everything our team does is written to your audit log, marked as support, with a name and a reason.

Exception

Account recovery

If an owner is locked out, we restore access only after checking documents that show who controls the business. Never on a phone call alone.

03Audit log & exports

A record of who did what.

Discounts given, deposits kept, refunds sent, renters approved, settings changed — each one is logged with a name and a time.

  • Staff and support actions

    Money, bookings, customers, settings and support sessions are logged. Kept for 1 year.

  • Export any time

    Owners can export bookings, customers, vehicles, invoices and the audit log to CSV or JSON — no need to ask us.

  • Nothing held hostage

    If you leave, your export still works for 90 days after closing. Then we delete your data.

04Renter IDs & licences

The most sensitive thing you hold.

Licence and ID photos are sensitive personal information under the Data Privacy Act. We treat them that way.

Who sees it

Only your authorised staff

Licence, ID and selfie images are visible only to roles you allow. They are never shown on your booking site or to other operators.

How it’s kept

Encrypted, and logged

ID images are stored encrypted and served only to signed-in staff. Every approval or rejection of a check is written to your audit log with a name and a reason.

How long

Retention you control

By default, ID and licence images are deleted 90 days after the rental ends — unless a damage or payment claim is still open. You can set a shorter period.

Renters’ rights

Requests built in

Renters can ask to see, correct or delete their data from their account. You get a notice and finish it in a few clicks — tax records are anonymised, not lost.

05Payments

Card numbers never touch our servers.

GCash, Maya, QR Ph, cards, online banking and over-the-counter payments are handled by Xendit, a licensed payment provider. Renters enter card and wallet details on Xendit’s side. We only get the result — paid, held, refunded — and the last four digits.

PCI-DSS compliance for card data is Xendit’s. Money settles to your Xendit account, not ours, and every refund or deposit you keep is logged with who approved it.

06Backups & availability

Honest about uptime.

We run on Amazon Web Services and Supabase, with encrypted backups taken automatically. We aim to keep CeeRent up around the clock and do maintenance outside peak rental hours.

We’re not going to promise a “99.99%” we can’t yet prove. Recovery targets and a public status page are planned; we’ll publish them once we’ve tested restores for real. Until then, planned downtime is announced in advance, and your data export works whenever the dashboard does.

07Where we are

What’s done, and what’s next.

We don’t claim certifications we don’t have — no ISO or SOC 2 badges here. This is the real list.

  • HTTPS everywhere and encryption at restIn place
  • Role-based access and 2FA for owners and managersIn place
  • Support access only with your approval, time-limited and loggedIn place
  • Audit log with exportIn place
  • Automatic deletion of renter IDs by your retention settingBefore launch
  • Encrypted backupsIn place
  • Named Data Protection Officer and NPC registrationBefore launch
  • Written incident and breach response plan; staff privacy trainingBefore launch
  • Independent penetration testBefore launch
  • Logging every time staff open a licence or ID imagePlanned
  • Tested restore drills and published recovery targetsPlanned
  • Public status pagePlanned
08Data Privacy Act

Built around RA 10173.

You are the controller of your renters’ data; we are your processor. For your own account data, we’re the controller.

  • A Data Protection Officer you can reach at dpo@ceerent.com.
  • We are registering with the National Privacy Commission before launch, as NPC Circular 2022-04 requires.
  • A Data Processing Agreement for your renters’ data, accepted at sign-up — no extra paperwork.
  • Breaches reported to you without undue delay and within 72 hours, with what you need to notify the NPC and your renters.
  • Marketing consent kept separate and optional, as NPC Circular 2023-04 requires.
09Responsible disclosure

Found a hole? Salamat — tell us.

Email security@ceerent.com with what you found and how to reproduce it. We reply within 3 working days and keep you updated until it’s fixed.

  • Test only against your own account or a demo site — never other operators’ data.
  • Don’t access, change or keep renters’ personal data beyond what proves the issue.
  • No denial-of-service, spam or social engineering of our team or operators.
  • Give us reasonable time to fix it before telling anyone else.

If you follow these rules in good faith, we won’t pursue legal action against you for your research. We don’t run a paid bug bounty yet, but we’ll credit you if you’d like.

Safe to start today.

14 days free, no card needed. Questions about security or privacy before you sign up? Email dpo@ceerent.com — a real person answers.