RentalOps
FeaturesPricingHow it works
Add app to Shopify
Legal

Privacy Policy

This policy explains what personal data the RentalOps app processes when it is installed on a Shopify store, how and why we process it, how long we keep it, and how it is deleted.

Last updated: 2026-09-12 · Applies to the RentalOps Shopify app and the pages under rentalops.dilight.website.

1. Who we are

RentalOps is operated by DiLight Entertainment UG (haftungsbeschränkt) ("RentalOps", "we", "us"). For questions about this policy or about the data we process, contact us at privacy@dilight.website.

When RentalOps is installed on a merchant's Shopify store, the merchant is the data controller for their customers' personal data, and RentalOps acts as a data processor on the merchant's behalf, processing store data only to provide the app's rental-operations features. For our own account and billing records, we act as the controller.

2. Data we process

RentalOps turns paid Shopify orders into rental bookings and keeps a live availability calendar. To do that it reads and stores the minimum data needed:

  • Store & account data — your .myshopify.com domain, the OAuth access token issued at install (stored encrypted and never shown to us in plain text in the UI), your plan and billing status, and app settings (which products are rentable, pool sizes, buffer times, deposit and reminder configuration).
  • Product & inventory data — the products, variants, locations and inventory you make rentable, so the calendar can block conflicts and (optionally) write booking status back to Shopify.
  • Order & booking data — for each rental we process the linked Shopify order id, the requested rental start/end dates, line items, deposit amount and the booking's lifecycle status (reserved → prepared → out → returned, with overdue flags).
  • Customer data — the only customer personal data we store is the customer's name taken from the order, so staff can identify a booking on the handout/return board. We do not store customer email addresses, postal addresses or payment/card details.

The QR / customer status page shows a single booking (dates, deposit and pickup information) to whoever holds its unguessable link; it never enumerates other bookings. Access to store data is limited to the Shopify scopes granted at install (read_customers, read_inventory, read_locations, read_orders, read_products, write_products).

3. How we use data

  • Create rental bookings from paid orders and hold deposits recorded against the order.
  • Maintain a live availability calendar across your fleet, blocking conflicts and honouring buffer times.
  • Advance bookings through their lifecycle and flag overdue returns.
  • Send pickup and return reminders over the channel you enable, and serve the QR booking-status page.
  • Optionally write booking status back to your Shopify products/variants (write_products).
  • Produce aggregate utilization, revenue-per-item and overdue insights for the merchant.
  • Operate billing, enforce plan limits, and provide support.

4. Legal basis (GDPR)

Where the GDPR applies, we process data on the basis of performance of a contract (Art. 6(1)(b)) with the merchant and our legitimate interest (Art. 6(1)(f)) in providing and securing the service. For customer personal data, the merchant's own privacy policy and legal basis govern the underlying processing; we act only on the merchant's documented instructions.

5. Sharing & sub-processors

We do not sell personal data. We share data only with the providers needed to run the service:

  • Shopify — the platform the app is installed on and the source of order, product and inventory data.
  • Our hosting/infrastructure provider — to host the application and its database.
  • Notification channels you enable (e.g. the signed webhook channel used for pickup and return reminders). Reminder payloads are PII-free (booking id, type, status-page link, dates and status).
  • TraceOps (optional) — if you enable the serial-level tracking bridge, RentalOps exchanges per-unit identifiers and condition status with your TraceOps instance. RentalOps keeps no serial registry of its own; the integration is off by default.

6. Data retention

Terminal bookings (returned or cancelled) are automatically deleted by a retention sweep after 365 days by default (configurable by the merchant); active and overdue bookings are never auto-deleted. Aggregated, non-identifying statistics may be kept longer. In general we keep data only as long as needed to provide the service, and we purge a store's data when the app is uninstalled or on a Shopify shop/redact request, as described below.

7. GDPR / data-deletion requests

RentalOps implements Shopify's mandatory compliance webhooks (verified by HMAC over the raw request body):

  • customers/data_request — we report the bookings matching the requested order ids so the merchant can fulfil the data-subject access request. RentalOps does not keep a customer profile beyond the booking data described above.
  • customers/redact — we anonymize the stored customer name on matching bookings (cleared and flagged as redacted); the operational booking record survives without the personal data.
  • shop/redact — we purge all of the store's data: bookings, rental items, and its billing record, notification outbox and back-write records. This runs after the store uninstalls the app.

Store customers should direct data-subject requests to the merchant (the controller). Merchants can reach us at privacy@dilight.website for assistance.

8. Security

The app uses Shopify's OAuth for install, verifies inbound webhooks with HMAC signatures over the raw body, stores access tokens encrypted, signs outbound reminder payloads, and serves all traffic over TLS. The customer status page is protected by an App Proxy signature (with an unguessable, rate-limited token fallback). Access to store data is scoped to the permissions granted at install.

9. Cookies

The embedded admin relies on Shopify App Bridge session tokens rather than tracking cookies. These marketing pages may set a small preference cookie to remember your chosen language. We do not use advertising cookies.

10. Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected on this page with a new "Last updated" date.

11. Contact

DiLight Entertainment UG (haftungsbeschränkt) · privacy@dilight.website · dilight.website

← Back to RentalOps

RentalOps
FeaturesPricingHow it worksPrivacy
Native Shopify app
© 2026 RentalOps by DiLight Entertainment UG (haftungsbeschränkt). Rental operations for Shopify.
RentalOps is not affiliated with or endorsed by Shopify Inc. “Shopify” is a trademark of Shopify Inc.