Ride.Rent
Legal

Data deletion policy

This global policy outlines how Ride.Rent manages, retains, transfers, and deletes personal data in line with international privacy standards including GDPR, CCPA, UAE PDPL, and India's DPDP Act.

1. Policy Overview

Ride.Rent is committed to protecting the privacy and rights of individuals whose data we collect. This policy describes our approach to data lifecycle management — including collection, retention, storage, and deletion — ensuring alignment with global data protection frameworks.

2. Legal Basis and Global Compliance Alignment

Ride.Rent operates in compliance with international privacy laws such as:

  • GDPR (EU/EEA): Articles 5, 6, and 17 for lawful processing and right to erasure.
  • CCPA (United States): Sections 1798.105–1798.120 for consumer rights and deletion requests.
  • PDPL (UAE): Federal Decree-Law No. 45 of 2021 governing lawful data handling.
  • DPDP Act (India): Chapter II (Rights of Data Principals) for retention and deletion obligations.

We ensure all personal data processing is fair, lawful, and transparent across jurisdictions.

3. Data Controller Identity

  • Data Controller: Ride.Rent FZ-LLC
  • Registered in the UAE with subsidiary operations in India.
  • Contact: data-compliance@ride.rent

4. What Personal Data We Collect

  • Identification and contact details (name, phone, email)
  • Payment and billing data for rental transactions
  • Supplier verification and business registration data
  • Device, browser, and activity logs for security monitoring
  • Location data for service optimization
  • Communication records and customer support interactions

5. How and Why We Process Personal Data

We process data only where necessary to:

  1. Deliver rental services and manage customer relationships
  2. Verify supplier identities and ensure contractual compliance
  3. Prevent fraud, misuse, or unauthorized access
  4. Fulfill legal, financial, and regulatory obligations
  5. Improve service quality and user experience
  6. Send important updates and service notifications

6. Data Retention and Minimization Principles

Ride.Rent follows a data minimization principle, ensuring personal data is retained only for the period necessary to fulfill its purpose or as mandated by law. Data is periodically reviewed and securely deleted or anonymized once it becomes redundant.

7. Global Data Storage and Transfer

Data is securely stored in ISO 27001–certified cloud infrastructures with data centers in the UAE, EU, and India. Cross-border transfers are performed only under adequate safeguards, including Standard Contractual Clauses (SCCs) and regionally approved mechanisms.

8. Data Deletion Procedures

  1. Deletion requests can be initiated by users via their account settings or email
  2. All requests are verified for identity and legitimacy to prevent misuse
  3. Approved requests trigger secure erasure from active databases within 30 days
  4. Confirmation of deletion is provided to the requester via registered email
  5. Complete audit trail maintained for compliance verification

9. Backup Retention and Hard Deletion

Encrypted system backups are retained for up to three years to maintain business continuity and meet compliance obligations. These backups remain segregated, access-restricted, and are subject to irreversible deletion (hard delete) after the retention period expires.

10. Exceptions to Data Deletion

Ride.Rent may retain limited data under lawful exceptions, including:

  • Legal or regulatory retention requirements (e.g., tax and accounting)
  • Pending disputes, fraud investigations, or claims resolution
  • Historical transactional logs needed for compliance verification
  • Data required for public health or safety purposes
  • Archived data for statistical or research purposes

11. Rights of Data Subjects

Under global privacy regulations, individuals have the following rights:

  • Right to access, correct, or update personal data
  • Right to data portability and restriction of processing
  • Right to withdraw consent at any time
  • Right to erasure (Right to be Forgotten)
  • Right to lodge complaints with relevant authorities
  • Right to know how data is processed and shared
  • Right to object to automated decision-making
  • Right to data minimization and purpose limitation

12. Children's Data

Ride.Rent does not knowingly collect personal data from individuals under the age of 18. If such data is inadvertently collected, it will be deleted immediately upon verification.

13. Third-Party Sharing and Processors

We share data only with trusted service providers for hosting, payments, analytics, and marketing. Each processor operates under a strict Data Processing Agreement ensuring confidentiality, limited use, and compliance with global data protection standards.

14. Security and Access Controls

Ride.Rent uses multi-layered technical and organizational measures including encryption, intrusion detection, and limited employee access to secure all personal data. Access logs and controls are reviewed periodically by the Data Protection Officer.

15. Policy Governance and Audits

Compliance with this policy is monitored through internal audits, external reviews, and vendor assessments. The Ride.Rent Data Protection Office ensures all team members are trained annually in data privacy and security practices.

16. Contact and Supervisory Authority

  • Email: data-compliance@ride.rent
  • Address: Ride.Rent/ Data Protection Officer, Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah, UAE. License Number: 2434340.

If you have questions or requests regarding this policy, please contact our Data Protection Officer at data-compliance@ride.rent.