Privacy policy
In effect from: 11 October 2026
Rentora LK rents camera and production equipment in Sri Lanka. Handing over expensive gear means we have to know who is taking it, so we ask for more identity information than an ordinary shop would. This page explains what we collect, why we collect it, who else sees it, and how to get it removed.
Rentora LK trades under Omenfield Enterprises (PVT) LTD, registered in Sri Lanka under company number PV00373996.
- Registered address: J/22, Palugampala Road, Sannasgama, Lellopitiya, Ratnapura, Sri Lanka
- Service location: 88/3A/1, Galwatta Road, Kudabuthgamuwa, Angoda, Sri Lanka
- Contact: [email protected], +94 72 280 0069 (calls and WhatsApp)
This policy is written under the Personal Data Protection Act No. 9 of 2022 of Sri Lanka.
1. What we collect
When you make an account
- Name, email address, phone number
- If you sign in with Google: the name and email address Google shares with us, and the account ID Google uses for you (see section 5)
- The language you read the site in
When you rent
- What you rented, the dates, and the pickup or delivery address
- Invoices, payments, deposits, late fees, and refunds
- Photos taken when equipment goes out and comes back, which record its condition
- Notes our staff add to the booking
When you verify your identity (KYC)
We cannot release equipment worth lakhs to someone we cannot identify. Our insurance will not cover it and the loss falls on us. For verification we collect:
- Full name and date of birth
- ID type and number (NIC, driving licence, or passport)
- Phone number and home address
- Two emergency contacts, each with a name, a relationship, and a phone number
- Your company name, if you rent for a production house
- At least one social media profile (Facebook, Instagram, or TikTok)
- Photos: both sides of your ID or your passport page, a selfie, and one proof of address or income such as a utility bill or a paysheet
- A record that you agreed to our terms, with the date and time
- Your browser type, and a scrambled (hashed) form of your IP address
You can skip verification and still place an order. If you skip it, you complete it in person at our premises when you collect the equipment. We do not release equipment to anyone who has not been verified.
When you refer a friend
Your referral code, who used it, and the reward points earned on both sides.
If you are an asset partner or an investor
Bank or payment details for payouts, payout records, the equipment you own, and your earnings statements.
Automatically, as you browse
Pages you visit, how long you stay, your device and browser, and an approximate location worked out from your IP address.
2. How your ID photos are stored
Your ID photos and selfie get different treatment from everything else on the site.
Before a photo is saved, our server re-encodes it, strips the hidden metadata a camera writes into the file, and then encrypts it with OpenPGP. The key that unlocks it is held offline by the owner of Rentora. It is not on the server, not in the database, and not in any backup.
What that means in practice:
- Staff cannot open your documents from the server
- If someone steals our storage or our database, they get scrambled files and nothing else
- To view a document, an authorised person has to load the private key into their own browser, and the unlocked key is thrown away after ten minutes
The limit of this is worth stating plainly. The information you type into the verification form, meaning your name, ID number, address, and contacts, is not encrypted the same way. It sits in a database kept separate from the rest of the site, with access restricted to our team, because verification and support work needs us to search it.
3. Why we use it
- To confirm you are who you say you are before equipment leaves our hands
- To take the booking, collect payment, and issue an invoice
- To reach you about your booking by SMS, WhatsApp, or email
- To record the condition of equipment and settle damage or loss
- To pay asset partners and investors what they are owed
- To send birthday messages and reward updates
- To see which pages and products people use, so we fix what is broken
- To meet our tax, accounting, and legal duties
5. Signing in with Google
You can sign in to Rentora with your Google account instead of an email code. This section covers what Google gives us when you do that, and what we do with it.
What we receive
- Your name
- Your email address
- Your profile photo
- The account ID Google uses to recognise you
We ask Google for these basic profile details only (the openid, email, and profile permissions). We do not ask for access to your Gmail, contacts, calendar, Drive files, or anything else in your Google account.
How we use it
We use these details to create your Rentora account or find the one you already have, and to sign you in. If you work for Rentora, your name and Google profile photo also appear next to the changes you make in our booking system, so the rest of the team can see who did what.
Each time you sign in, Google hands us a sign-in token. We use it once to confirm who you are and then discard it. We do not store it, and we cannot reach into your Google account afterwards.
If your Google email address already belongs to a Rentora account, we do not link the two on our own. We show you the account we found and ask you to confirm first. If Google cannot vouch for that address (it is not a Gmail or Google Workspace address), we also send a code to it before linking.
Where it is stored and who sees it
We keep your name, email address, and Google account ID with the rest of your profile in our account database. We keep the profile photo only for Rentora staff accounts. Only the Rentora team can reach that database.
We do not sell Google user data and we do not share it with anyone else. The only exceptions are the legal cases listed in section 4.
We do not use Google user data for advertising. We do not use it to develop, improve, or train artificial intelligence or machine learning models.
Rentora's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy
Removing it
You can remove Rentora's access at any time from the Third-party apps section of your Google account (myaccount.google.com/connections). To delete the details Google gave us, delete your Rentora account or write to [email protected], as described in sections 8 and 9.
7. Promotional messages
We send offers and news by SMS, WhatsApp, and email unless you tell us to stop. Booking confirmations, invoices, and reminders keep coming either way, because you need those.
To stop the promotional ones: reply STOP on WhatsApp, write to [email protected], or call +94 72 280 0069.
8. How long we keep it
- Verification documents and KYC data: until you ask us to delete them.
- Bookings, invoices, and payments: two years in the live system, then moved to archive storage and kept for as long as Rentora LK trades. Tax and company law require this.
- Analytics: 14 months.
- Support conversations: as long as your account stays open.
- Details from Google sign-in: as long as your account stays open.
If you delete your account, we remove your profile, your verification documents, your verification data, your contacts, and your message preferences straight away. Invoices and payment records stay, because the law requires us to keep them, with your name replaced by a reference number.
9. Your rights
Under the Personal Data Protection Act you can ask us to:
- Show you what we hold about you
- Correct anything that is wrong
- Delete your data
- Stop using it for a particular purpose
- Give you a copy in a form you can take elsewhere
Write to [email protected], message +94 72 280 0069, or ask any member of the Rentora team. We answer within 14 days.
If we handle your request badly, you can complain to the Data Protection Authority of Sri Lanka.
10. Age
You need to be 16 or older to hold a Rentora account. We do not knowingly collect data from anyone younger. If you believe a child has given us their data, write to [email protected] and we will remove it.
11. Changes to this policy
When we change this policy we update the date at the top. If a change affects how we use your data, we tell you by email or SMS before it takes effect.