Security & Trust
How we protect your fleet, customer and payment data.
Your rental business runs on data — reservations, customers, vehicles, agreements, invoices and payments. This page explains the concrete steps we take to keep that data safe, and where we are on our compliance roadmap.
1. GDPR compliance
Bookrenia is built to help operators meet their obligations under the EU General Data Protection Regulation (Regulation (EU) 2016/679).
- Every organisation's data is isolated in a multi-tenant architecture — one operator cannot see another operator's records.
- You control your customers' data: export, correct or delete a customer record at any time.
- We honour data subject access requests (SARs) — email privacy@bookrenia.com and we respond within 30 days.
- All personal data is stored inside the EU (Frankfurt region) — no transfers outside the EEA without a Standard Contractual Clause in place.
- A Data Processing Agreement (DPA) is available on request for every paying customer — reply to your onboarding email or contact privacy@bookrenia.com.
2. Payment security — PCI DSS
We do not store, process or transmit card numbers ourselves. All payments run through certified processors:
- Stripe — PCI DSS Level 1 (the highest tier), used for card payments and Stripe Connect payouts.
- PayPal — PCI DSS Level 1, used for wallet checkout.
- Card details are entered directly into Stripe / PayPal fields hosted on their infrastructure. Bookrenia never sees the raw card number.
- We only store the last 4 digits, brand and expiry — enough to render "Visa •••• 4242" in your invoices.
3. Encryption
- In transit: TLS 1.2+ on every connection. HTTP requests are auto-redirected to HTTPS. HSTS is enabled on the primary domain.
- At rest: the production database uses AES-256 encryption at the storage layer. Nightly database snapshots are encrypted with the same key.
- Passwords: hashed with bcrypt (12 rounds). We never see or store your users' plain-text passwords.
- API tokens & session cookies: signed, HTTP-only, `SameSite=Lax`, rotated on every login.
4. Backups and disaster recovery
- Nightly full backups of the production database, retained for 30 days.
- Point-in-time recovery available for the last 7 days — we can restore your organisation's data to any minute in that window.
- Backups are stored in a separate region (Ireland) from the production database (Frankfurt) — a regional outage will not lose your data.
- Uploaded files (agreements, condition photos, driver documents) live on redundant object storage with 11 nines of durability.
- Restore drills are performed quarterly. Our current internal recovery time objective (RTO) is 4 hours; recovery point objective (RPO) is 24 hours.
5. Access controls
- Every user inside your organisation has a role (Owner, Manager, Agent, Driver, Customer, Agency) with scoped permissions.
- Only Owners can invite new users, change billing or export the full dataset.
- Failed-login rate limiting and IP throttling are enabled on all authentication endpoints.
- Internal Bookrenia engineers do not have standing access to your data — production access is time-limited, logged, and only granted when you open a support ticket asking for it.
6. Infrastructure
- Hosted on AWS (eu-central-1, Frankfurt) — the same region large European car rental groups already use.
- Web tier behind a WAF with automated OWASP Top 10 rule sets and DDoS protection.
- Application and database run inside a private VPC — the database is not reachable from the public internet.
- All infrastructure changes go through code review and CI before hitting production.
7. Application security
- Dependencies are scanned automatically on every commit; critical CVEs are patched within 72 hours.
- All user input is validated server-side. Database queries use parameter binding (no string concatenation) — protecting against SQL injection.
- Output escaping is enforced by the Blade templating engine — protecting against cross-site scripting (XSS).
- CSRF tokens on every state-changing request.
- Third-party penetration test scheduled for Q1 2027 — findings will be published in an updated version of this page.
8. Compliance roadmap
8+ years building car rental software taught us where the real risks are — that is why our compliance roadmap starts here. We are transparent about where we are and where we are going. Not everything is signed and sealed yet — these are the honest dates:
- GDPR: operational today, DPA available on request.
- PCI DSS: covered today via Stripe and PayPal (we are out of scope; they hold the certificate).
- SOC 2 Type I: audit planned for Q4 2026.
- SOC 2 Type II: observation period starts after Type I, targeted for Q3 2027.
- ISO 27001: under evaluation for 2027 — decision after SOC 2 Type I is complete.
9. Reporting a vulnerability
If you believe you have found a security issue in Bookrenia, please email security@bookrenia.com with a description of the issue and steps to reproduce. We ask you to give us a reasonable time to remediate before public disclosure. We will acknowledge every report within 2 business days.
10. Related documents
- Privacy Policy — what we collect, how we use it, and your rights.
- Terms of Service — the contract that governs your use of the platform.
- Data Processing Agreement (DPA) — available on request at privacy@bookrenia.com.