Skip to content

Deleting an account and erasing data

How to have a rental company account, a staff account, or a renter personal information removed from RentnRide — who to ask, what goes, what has to stay, and how long it takes.

In effect from
Last updated

Section 1First, which of these are you

Most deletion pages assume there is one kind of user. This platform has three, the route is different for each, and picking the wrong one is the usual reason a request goes nowhere. Find yourself here and jump to your section.

A rental company
You or your business holds the account. You signed up, you pay for it, and your vehicles and bookings are in it. Section 2.
A staff member
You sign into the mobile app or the console with a phone number and a PIN, on a device your employer paired. You did not sign yourself up. Section 3.
Someone who rented a vehicle
You never had an account and never chose a password — but a rental company holds your name, your phone number, probably a fingerprint of your identity document, and your booking history. Section 4.

Section 2A rental company account

The OWNER of the company account can ask for the whole account to be deleted. That request has to come from the owner, at the address the account is registered to — a request to erase an entire business book of records is exactly the one that must never be honoured on trust, and a staff member, a competitor or a disgruntled ex-employee asking for it will be told no.

Deleting the account removes the company record and everything hanging off it: staff accounts and their paired devices, vehicles, bookings, handovers, customer records, the fingerprints of identity numbers, and the photographs and documents in storage.

Financial records and the audit archive are the exception and are kept for the period set out in the privacy policy — as long as you must keep business records under Bangladeshi tax law, which we treat as six years unless you tell us the period that applies to your registration. That is not us keeping your data for our own use; it is the bookkeeping you are separately obliged to be able to produce.

Section 3A staff account in the mobile app

Staff accounts are CREATED BY THE COMPANY OWNER, not self-registered in the app. There is no sign-up screen: an owner adds a person in the console, pairs their device, and that is how the account comes to exist.

So removing one is the owner action. The owner deactivates or removes the staff member in the console, which ends that person access immediately and revokes the refresh token on every device they were paired on. If you are a staff member who wants your account removed, ask your employer first — they can do it in a few seconds and we cannot do it faster.

This is the employer-provisioned account case that the App Store account-deletion guideline carves out. That guideline requires an in-app deletion path for accounts a person creates in the app; where accounts are provisioned for someone by their employer, it allows the app to direct them to their administrator or to a support contact instead. Nobody creates an account inside this app, so that is the position here.

If your employer will not act, write to us. We will take it up with the company, and where the law requires us to act on your personal information directly, we will — your employment relationship does not remove your rights under the Personal Data Protection Act 2023.

Section 4A renter — no account, but your data is here

You never had an account, so there is nothing to close. What exists is a record the rental company created about you: your name and phone number, a one-way fingerprint of your national identity or licence number, your bookings and payment history, and possibly photographs from a handover. The number itself was never stored, and a photograph of your identity document is deleted when your booking closes unless that company has barred you.

Section 16 of the Personal Data Protection Act 2023 gives you the right to have that erased. Send the request to the RENTAL COMPANY you booked with. They are the controller of your data — see the privacy policy — and they are also the only party that can tell it is really you asking, because they met you at the counter and we did not.

If the company does not respond, or tells you it does not know how, write to us. We will take it up with them and help them carry it out, and where the law requires us to act directly we will do so. Our first step is always to go through the company, and that is a protection for you: a platform that erased a customer record on the word of anyone who could send a message would be a platform where anyone could erase yours.

Bookings and payment entries you appear in are financial records of that company business and stay for the retention period described in section 6, the same as they would if the counter had written them in a paper ledger.

Section 5How to send the request

There is NO button in the app or the console that deletes an account today. This page describes what actually happens rather than what we would like to have built — an in-app route is planned and is not here yet, and pointing you at a control that does not exist would waste your time and mislead a store reviewer about the product.

The route is a written request, sent to our data protection contact below. Include all three of these or we will have to come back and ask:

  • Who you are and which of the three sections above applies to you. A company or staff account request must come FROM the registered address of the company owner.
  • The company rentnride address — the one your counter signs in at — so the account can be identified without guessing.
  • What you want removed: everything, or a named part of it. Section 7 explains why asking for part is often what you actually want.

We acknowledge a request within seven days and complete it within thirty. If part of it has to be refused — a financial record still inside its retention period, an audit entry — we tell you which part and why, and carry out the rest rather than refusing the whole request. Where a WhatsApp number is published on this site, a request may be started there too; we will still confirm it in writing before acting.

There is deliberately NO FORM on this page. No page on this site takes a submission of any kind, which is what keeps it a site with no intake to secure, no store of half-finished requests, and no public write path for somebody to flood. A written request from an address we can recognise is also far better evidence of who asked than a box on a page anyone can fill in.

Section 6What is deleted and what is kept

Deletion here means the records are gone from the live system, not hidden behind a flag.

Deleted
The company record; staff accounts and their paired devices; vehicles; bookings; handovers and their condition photographs; customer records with names and phone numbers; the fingerprints of identity and licence numbers; and the documents and images in storage under that company.
Kept — financial records
Bookings, payments, deposits and refunds, for as long as the company must keep business records under Bangladeshi tax law, treated as six years unless the company sets its own period. Excluded from a deletion request until that period ends.
Kept — the audit log
Not deleted. It records which staff account did what and when, and a record the person it describes can erase is not a record. It holds actions, not customer documents.
Kept — technical error reports
One row per distinct software fault with a count. These contain no personal information by construction, so there is nothing in them to erase.
Already gone before you ask
Photographs of identity documents are deleted when each booking closes at the return handover, unless the company has barred that rider. For most renters there is no identity photograph left to delete by the time they think to ask.

Section 7Asking for part of it

You do not have to close an account to have something removed. A company can keep trading and still ask for one customer records to be erased, for stored photographs to be cleared, or for a staff member who has left to be removed entirely. Say in the request which part you mean.

This is what a renter usually wants: your own information gone, with no interest in the rental company account, which is not yours to close in the first place.

Section 8Changing your mind, and what cannot be undone

A request can be withdrawn at any point before it is carried out — write again from the same address and say so. Because the work is done by a person on a written request rather than by a timer, there is a real window here, and it lasts until we act.

Once carried out, deletion is NOT reversible. The rows are gone and the stored files are gone, and we do not keep a shadow copy to restore from — a copy kept so that deletion could be undone would mean the data was never deleted. If you might want an export, take it BEFORE you send the request, not after.

Deleted records may persist for a short period in routine platform backups before those age out in the ordinary course. They are not returned to the live system and are not used for anything.

A published contact address for this domain is not live yet. Until it is, renters should contact the rental company they booked with, and rental companies should use the channel their account was opened through.

About this document

This page describes what this software actually does today, including the part where an in-app deletion route does not exist yet. It was written by the team that builds RentnRide and has not been reviewed by a lawyer qualified in Bangladesh; that review is planned. The engineering follow-ups needed to replace the written-request route with an in-app one are written down rather than left implied.

Back to top