1. Your own database
Every RentDesk account runs on its own database and its own server process. One SQLite database and one process per subscriber: your clients, quotes, reservations, payments, users and settings are written there and nowhere else.
There is no shared customer table with a filter on it. Another account cannot reach your records by changing a number in a web address, because your records are not in its database at all.
2. Your company codes and credentials
Corporate discount codes, travel-agent numbers and rental-company logins are entered per account and used only for that account's checkout links and bookings. They are never shared with another account, and no account starts with someone else's codes filled in. If a code is missing, RentDesk asks you to add yours instead of borrowing one.
3. What is shared and what is not
Prices come from one search engine that every account reads from: the same branch, car and day show the same searched price. That is the only data accounts have in common.
Your contracts are not shared. Your clients are not shared. Nothing about who you quoted, booked or charged ever leaves your database to inform another account.
4. Payment cards for reservations
Some rental companies need a card to hold a reservation. Cards saved for that purpose are stored encrypted in a vault, with an encryption key that belongs to your account alone. The app never shows a saved card in full: you see the last four digits and the expiry date. The full number is decrypted only at the moment a booking you started needs it.
5. Card desk credentials
If you connect a card desk (Ramp, Mercury or Rho) to fund client cards, its access credentials are kept in a separate file for your account on the server, not in the app's settings. Once saved, they are not shown again, to you or to anyone on your team. An account that does not use card desks has none stored.
6. Who sees what
Each person signs in with their own login, and each login has a role: owner, admin, employee or subcontractor.
- The owner decides who can see clients, reservations, billing and settings, person by person.
- An employee sees their own clients and reservations unless the owner grants more.
- A subcontractor works in a separate book and sees only their own clients.
- Access can also be limited to particular rental companies for each person.
- Money settings, user management and card desks are owner-only by default.
7. Passwords, sessions and the sign-in log
Passwords are stored only as salted hashes (scrypt). Nobody at RentDesk can read your password, and we will never ask you for it.
A session lasts 30 days, then you sign in again. Changing your password signs out your other devices.
Every sign-in is recorded in an activity log with the time, the device and the IP address, so the owner can see who signed in and from where.
8. Email
Quotes, confirmations and reminders to your clients are sent either from your account's own mailbox, using the mail server details you enter, or through RentDesk in your business's name. You choose in Settings.
9. What we do not claim
RentDesk does not hold a security certification today. We do not claim SOC 2, ISO 27001 or PCI compliance, and we would rather tell you that than put a badge on this page. If your business needs a specific control described, write to us and we will answer in plain terms.
10. Report a security issue
If you find a weakness in RentDesk, write to hello@carentdesk.com with what you found and how to reproduce it. Please do not access other people's data or disrupt the service while testing. We will reply and keep you informed while we fix it.