Privacy policy

In effect from: 11 October 2026

Rentora LK rents camera and production equipment in Sri Lanka. Handing over expensive gear means we have to know who is taking it, so we ask for more identity information than an ordinary shop would. This page explains what we collect, why we collect it, who else sees it, and how to get it removed.

Rentora LK trades under Omenfield Enterprises (PVT) LTD, registered in Sri Lanka under company number PV00373996.

This policy is written under the Personal Data Protection Act No. 9 of 2022 of Sri Lanka.

1. What we collect

When you make an account

When you rent

When you verify your identity (KYC)

We cannot release equipment worth lakhs to someone we cannot identify. Our insurance will not cover it and the loss falls on us. For verification we collect:

You can skip verification and still place an order. If you skip it, you complete it in person at our premises when you collect the equipment. We do not release equipment to anyone who has not been verified.

When you refer a friend

Your referral code, who used it, and the reward points earned on both sides.

If you are an asset partner or an investor

Bank or payment details for payouts, payout records, the equipment you own, and your earnings statements.

Automatically, as you browse

Pages you visit, how long you stay, your device and browser, and an approximate location worked out from your IP address.

2. How your ID photos are stored

Your ID photos and selfie get different treatment from everything else on the site.

Before a photo is saved, our server re-encodes it, strips the hidden metadata a camera writes into the file, and then encrypts it with OpenPGP. The key that unlocks it is held offline by the owner of Rentora. It is not on the server, not in the database, and not in any backup.

What that means in practice:

The limit of this is worth stating plainly. The information you type into the verification form, meaning your name, ID number, address, and contacts, is not encrypted the same way. It sits in a database kept separate from the rest of the site, with access restricted to our team, because verification and support work needs us to search it.

3. Why we use it

4. Who else sees it

Running a rental business means some data passes through other companies. Each one gets only the part it needs to do its job.

Asset partners and investors never learn who rented their equipment. Their portal shows the item, the dates, and the money, and nothing about the renter.

We do not sell your data. We do not pass it to advertisers, data brokers, or credit agencies.

We will hand your data to the Sri Lanka Police or to a court in three cases: theft of our equipment, fraud, or damage where the compensation we agreed with you has not been paid within the time we set.

5. Signing in with Google

You can sign in to Rentora with your Google account instead of an email code. This section covers what Google gives us when you do that, and what we do with it.

What we receive

We ask Google for these basic profile details only (the openid, email, and profile permissions). We do not ask for access to your Gmail, contacts, calendar, Drive files, or anything else in your Google account.

How we use it

We use these details to create your Rentora account or find the one you already have, and to sign you in. If you work for Rentora, your name and Google profile photo also appear next to the changes you make in our booking system, so the rest of the team can see who did what.

Each time you sign in, Google hands us a sign-in token. We use it once to confirm who you are and then discard it. We do not store it, and we cannot reach into your Google account afterwards.

If your Google email address already belongs to a Rentora account, we do not link the two on our own. We show you the account we found and ask you to confirm first. If Google cannot vouch for that address (it is not a Gmail or Google Workspace address), we also send a code to it before linking.

Where it is stored and who sees it

We keep your name, email address, and Google account ID with the rest of your profile in our account database. We keep the profile photo only for Rentora staff accounts. Only the Rentora team can reach that database.

We do not sell Google user data and we do not share it with anyone else. The only exceptions are the legal cases listed in section 4.

We do not use Google user data for advertising. We do not use it to develop, improve, or train artificial intelligence or machine learning models.

Rentora's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy

Removing it

You can remove Rentora's access at any time from the Third-party apps section of your Google account (myaccount.google.com/connections). To delete the details Google gave us, delete your Rentora account or write to [email protected], as described in sections 8 and 9.

6. Analytics and cookies

We do not show a cookie banner. Here is what runs instead, so you can decide for yourself.

Cookies the site needs

Analytics

Google Analytics, PostHog, and Umami load on every page. They record page views, device type, and rough location. PostHog honours the Do Not Track setting in your browser. If you would rather not be counted at all, turn on Do Not Track, or block these scripts in your browser or with an extension. Blocking them does not break the site.

7. Promotional messages

We send offers and news by SMS, WhatsApp, and email unless you tell us to stop. Booking confirmations, invoices, and reminders keep coming either way, because you need those.

To stop the promotional ones: reply STOP on WhatsApp, write to [email protected], or call +94 72 280 0069.

8. How long we keep it

If you delete your account, we remove your profile, your verification documents, your verification data, your contacts, and your message preferences straight away. Invoices and payment records stay, because the law requires us to keep them, with your name replaced by a reference number.

9. Your rights

Under the Personal Data Protection Act you can ask us to:

Write to [email protected], message +94 72 280 0069, or ask any member of the Rentora team. We answer within 14 days.

If we handle your request badly, you can complain to the Data Protection Authority of Sri Lanka.

10. Age

You need to be 16 or older to hold a Rentora account. We do not knowingly collect data from anyone younger. If you believe a child has given us their data, write to [email protected] and we will remove it.

11. Changes to this policy

When we change this policy we update the date at the top. If a change affects how we use your data, we tell you by email or SMS before it takes effect.

12. Which version applies

This policy is published in Sinhala and English. If the two versions ever disagree, the English version is the one that applies.