VroomOS Privacy Policy
Last updated: September 1, 2026 · Effective for the VroomOS platform at https://vroomos.net and VroomOS mobile apps
Who we are. VroomOS (“we”, “us”, “our”) provides car-rental operations software—fleet, bookings, customers, payments ledgers, inspections, documents, public storefronts, and team tools—via the web and mobile applications (Apple App Store and Google Play where published).
Who this policy covers. Visitors, account holders (owners, admins, staff), organizations using VroomOS, and—where applicable—end renters who interact with a rental company’s VroomOS-powered booking or portal experience.
Important role split. VroomOS is multi-tenant software. When a rental company stores driver/customer data in VroomOS, that company is typically the data controller (or local equivalent) for that business data, and VroomOS acts as a service provider / processor. For VroomOS accounts, subscription billing, security logs, and platform administration, VroomOS is the controller.
Global product. VroomOS is not limited to one country. App Store availability in a region does not change this policy’s purpose: explain how VroomOS handles personal data across the product.
1. Quick summary
| Topic | In plain language |
|---|---|
| Product data | Your org’s fleet, bookings, customers, payments records, docs, and settings live in VroomOS so your team can run rentals. |
| Account data | We use your email/login and org membership to authenticate you and enforce roles. |
| Renters | Most renter privacy questions should go to the rental company that took the booking; we host their data as the platform. |
| Selling data | We do not sell personal data. |
| Mobile | Camera, photos, contacts (optional), location, and notifications are requested only for product features you can control in system settings. |
| App Store privacy | Data we collect is used for app functionality (accounts, rental operations, security, subscriptions)—not third-party advertising tracking. |
| Contact | support@vroomos.net |
2. Information we collect
2.1 Account and organization data (VroomOS users)
- Name, email address, authentication identifiers (including OAuth such as Google sign-in if you choose it)
- Role in an organization (for example owner, admin, staff) and membership history needed for access control
- Business profile details you configure: trade/legal name, phones, addresses, branding, logo, website, locations/branches, language, currency, time zone, and similar settings
- Subscription plan, limits, invoices, payment status, and processor metadata (we do not store full card numbers on VroomOS servers when a processor tokenizes payments)
- In-app subscription status and product identifiers needed to activate your plan when you purchase through the Apple App Store or Google Play (store checkout is handled by Apple or Google; card numbers for store billing are not collected by VroomOS)
- Support tickets, emails, and messages you send to VroomOS
2.1a Google user data (Sign in with Google)
If you choose Sign in with Google (or similar Google OAuth authentication), VroomOS receives limited Google account information so you can access the VroomOS service securely. This typically includes basic profile information and email address (for example name, email, and a stable account identifier provided by Google).
This sign-in is used in two places: (1) staff signing in to the VroomOS workspace to operate a rental company, and (2) customers / renters signing in on a rental company’s public VroomOS website to book and manage reservations.
Purpose of the request: VroomOS requests this Google user data only for authentication and account administration—not for selling personal information or unrelated advertising.
How VroomOS uses Google user data:
- Authenticate you as a VroomOS user (staff workspace or customer storefront)
- Create or match your VroomOS account to your Google email
- Display your identity inside the product (staff collaboration and access control, or the customer account on that company’s site)
- Send account-related service messages when needed (security, booking updates, invites, support)
VroomOS’s use of Google user data is limited to providing and securing the Service, consistent with Google’s API Services User Data Policy (including Limited Use requirements where applicable). You can review product purpose and features without signing in on the public homepage: https://vroomos.net/home.
2.1b Google user data (Gmail sending / Company Email)
If an organization owner or admin chooses Connect with Google under Settings → Company Email, VroomOS requests the Gmail send scope (https://www.googleapis.com/auth/gmail.send) plus basic account identity (email and name) so booking and operational emails can be sent from that company’s Gmail or Google Workspace address.
Purpose of the request: send transactional company email that the organization initiates in VroomOS (for example booking confirmations and connection tests). VroomOS does not request permission to read, search, modify, or delete mailbox contents.
How VroomOS uses this Google user data:
- Identify the connected sender address and display name
- Send emails the organization explicitly triggers through VroomOS
- Refresh the send authorization when it expires, until the organization disconnects Google
What VroomOS does not do with Gmail data: VroomOS does not read your inbox, contacts, or message history; does not use Gmail data for advertising; does not sell Google user data; and does not transfer Gmail data to unrelated third parties. Access tokens are stored encrypted and used only to send mail. You can disconnect Google in Company Email settings at any time, which revokes VroomOS sending access.
This use is limited to providing the Company Email feature, consistent with Google’s API Services User Data Policy, including Limited Use requirements where they apply.
2.2 Operator business content stored in VroomOS
Depending on features your organization uses, VroomOS may process:
- Fleet: vehicles, plates, VINs, photos, odometer, status, expenses, maintenance/reminders, GPS/telematics references
- Customers / renters: names, phones, emails, addresses, dates of birth or age-related eligibility fields if you store them, driving licences, passports or national IDs, insurance information, notes, status flags (VIP, blacklist, etc.), and uploaded document images
- Bookings & operations: reservations, rates, extras, pickup/return workflows, inspections, damage records, fuel/odometer readings, barcodes, signatures, contracts, communications, and related files
- Payments & deposits: amounts, methods, statuses, ledger entries, and payment-provider references
- Public storefront / domains: published site content, offers, custom hostnames, and online checkout or portal data submitted by end customers
- Team & automation: collaborator invites, message templates, email-sending domain settings, import/export files, audit-relevant activity
- Integrations you enable: data exchanged with GPS providers, email infrastructure, DNS/domain providers, OAuth identity providers, and payment gateways
2.3 End customers of rental companies
If you rent a vehicle from a company that runs on VroomOS (including a public storefront or booking link), that company collects your information for its rental. VroomOS hosts and processes that data to provide the software to the company. Questions about a specific rental, deposit, fine, damage claim, or contract should go to the rental company first. You may also contact VroomOS if you need help identifying the organization that controls your data or exercising rights we can assist with.
2.4 Technical, device, and security data
- IP address, approximate location derived from IP, device/browser or app type, OS version, app version, language, timestamps
- Device identifiers used for product features, including push notification tokens and related device registration identifiers when notifications are enabled
- Diagnostic and crash logs, performance signals, and security logs
- Authentication events, session metadata, rate-limit and abuse-prevention signals
- On-device storage or cookies needed for sessions, preferences, and security (see Cookies)
2.5 Device contacts (optional mobile feature)
If you enable device contacts for bookings in VroomOS settings, the mobile app may read selected name and phone number fields from your device address book so you can fill a customer or booking form. That information is stored as customer/booking records for your organization in VroomOS—not for advertising, not for building marketing lists for third parties, and not for tracking you across other companies’ apps. You can turn the feature off and revoke Contacts permission in system settings.
2.6 AI features (Vroom AI Manager and related tools)
Vroom AI Manager is a business operations assistant for rental companies—not a companion chatbot. When an operator uses it, VroomOS may send the operator’s question and relevant business data the operator can already access (for example booking summaries, vehicle status, customer names and phone numbers returned by in-app tools) to configured cloud model providers so the assistant can answer. Identity document images (passports, licenses) are not attached to chat. Spreadsheet import mapping may send column headers and sample cells to a model if that feature is used.
Configured providers at the time of this update include Google Gemini and Groq, called from VroomOS servers. Optional import mapping may use Gemini and, if configured, OpenAI. On-device Apple Intelligence may be used on supported devices. AI output can be wrong; operators must verify before acting. VroomOS does not use operator renter databases to train public consumer models as a product feature. Provider-side retention and training settings should be confirmed in each provider’s console.
In-app: Settings → Privacy & AI describes these features. Do not paste government ID numbers, full card numbers, or passwords into chat.
3. VroomOS mobile apps (App Store / Google Play)
VroomOS mobile apps may request device permissions only to deliver product features. You can deny or revoke permissions in system settings; related features may stop working.
| Permission | Why VroomOS may use it |
|---|---|
| Camera | Scan vehicle VINs and license plates; capture booking and verification photos |
| Photo library | Select existing vehicle or customer verification images; optionally save captures |
| Contacts | Optional: read a contact you choose to fill booking/customer fields (name/phone). Not used for advertising tracking |
| Location | Show nearby pickup/return points and related operational context (not advertising tracking) |
| Notifications | Operational reminders and alerts you or your organization enable; may use a push token stored with your account/organization |
| Network | Sync with VroomOS cloud services so organization data works across devices |
Store subscriptions. When you buy or restore a VroomOS subscription through the Apple App Store or Google Play, Apple or Google process the payment. VroomOS (and, where used, subscription partners such as RevenueCat) may receive purchase status, product identifiers, and account identifiers needed to activate your organization’s plan. Card numbers for store checkout are not collected by VroomOS. This is for app functionality (subscription entitlements), not third-party advertising.
Apple and Google may collect install, diagnostics, and store-purchase data under their privacy policies. Store billing is handled primarily by the store when you pay there.
VroomOS does not sell personal data collected through the apps. We do not use data collected from the apps for third-party advertising networks or for “tracking” as defined by Apple (linking data with other companies’ data for advertising across apps and websites). If we introduce advertising tracking that requires an App Tracking Transparency (ATT) prompt on iOS, we will request permission first. Core VroomOS features are for accounts, operations, and security—not third-party ad networks.
4. How VroomOS uses information
- Provide, operate, maintain, secure, and improve the VroomOS Service (including multi-tenant isolation, backups, troubleshooting, and product development)
- Authenticate users, enforce roles and organization boundaries, and prevent fraud or abuse
- Process subscriptions, plan limits, invoices, and related customer support
- Send service, security, and transactional messages (marketing only where permitted, with opt-out where required)
- Comply with law, enforce the VroomOS Terms of Service, and protect the rights, safety, and property of VroomOS, operators, and others
- Produce de-identified or aggregated statistics that do not reasonably identify individuals or a specific operator’s confidential commercial secrets
We do not sell personal data. We do not use operator customer databases to market unrelated third-party products.
5. Legal bases (where applicable)
Depending on your location, VroomOS may rely on one or more of the following for platform-level processing:
- Contract: to provide the Service you signed up for
- Legitimate interests: security, fraud prevention, product improvement, and limited analytics—balanced against your rights
- Consent: where required (for example certain cookies or optional marketing)
- Legal obligation: tax, accounting, lawful requests
Rental companies are responsible for their own legal bases when they collect renter data (identity documents, signatures, marketing to drivers, etc.).
6. Roles, customer data, and responsibilities
- Operators decide what renter and fleet data to put in VroomOS and must have a lawful basis, provide required notices to drivers, obtain consents where needed, and limit staff access to trusted people.
- Operators control much of retention and deletion inside the product, subject to legal holds and technical backup/security retention.
- Operators must not upload data they are not allowed to process, and must not use VroomOS to violate privacy, transport, consumer, or anti-money-laundering laws.
- VroomOS processes operator-controlled content to run the product, prevent abuse, comply with law, or with authorization (for example support with your permission). We do not use your renter database as an advertising list.
7. How we share information
VroomOS may share data with:
- Infrastructure & subprocessors used to run VroomOS (including hosting/auth/storage, email delivery, CDN/DNS). As of this update that includes Supabase, Cloudflare, Resend, and—when you enable them—Apple, Google, Microsoft, RevenueCat, Stripe, GPS/telematics vendors you connect, and AI providers named in section 2.6
- Payment processors for subscriptions or payment features you use
- App store platforms and subscription partners (Apple, Google, and where used RevenueCat) for in-app purchase verification and plan activation
- Identity providers (for example Google) if you choose that sign-in method
- Integrations you enable (GPS/telematics, custom email domains, domain connection APIs, and similar)
- Your organization members according to roles you assign
- Professional advisors under confidentiality when needed
- Authorities when required by law, valid legal process, or to protect rights and safety; where legally permitted we aim to notify the affected operator of content demands about their data
- Business transfers (merger, acquisition, financing) with continued protection of personal data
Public storefront content and vehicle offers you choose to publish are visible on the internet (including on custom domains you connect).
8. Security
VroomOS implements technical and organizational measures appropriate to a multi-tenant SaaS product, including:
- Authentication and session controls; organization/tenant scoping of data access
- Encrypted transport (HTTPS/TLS) for the Service
- Access controls for production systems and least-privilege practices for VroomOS staff
- Logging and monitoring aimed at detecting abuse and unauthorized access
No method of transmission or storage is 100% secure. You must use strong unique passwords (or SSO where available), protect devices, limit collaborator invites, revoke access when staff leave, and treat exported reports and ID images as sensitive. Operators remain responsible for their staff’s use of credentials and for lawful handling of renter identity documents.
9. Retention
- Account and billing records: while your organization is active and for a reasonable period afterward for accounting, disputes, fraud prevention, and legal compliance
- Operator business content: until an authorized user deletes it or the organization is closed, subject to backup cycles, security logs, and legal retention
- Security and diagnostic logs: limited periods unless needed for investigations
After deletion, residual copies may remain in encrypted backups until rotated. We may keep minimal records showing that a deletion or legal request was handled.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing, to portability, and to withdraw consent. How to exercise them:
- VroomOS account holders: delete your login in the app: Settings → Delete account (also under Privacy & AI, the account menu, and My Profile). Type your account email and confirm. This permanently deletes the login; it is not a temporary deactivation. You may also email support@vroomos.net
- Renters / end customers: contact the rental company that took your booking first. If you cannot reach them, contact us and we will help route the request where feasible
We may verify identity and authority (for example organization owner) before acting. We may decline requests that are unlawful, abusive, or that would compromise others’ privacy or security.
If local law provides a supervisory authority complaint right, you may use it; we encourage contacting us first so we can try to resolve the issue.
11. International availability and transfers
VroomOS apps and the website may be used from many countries. We and our subprocessors may process data in countries other than where you or your customers are located (hosting, auth, storage, email, payments, and similar). Where required, we use appropriate safeguards (such as contractual protections) for cross-border transfers. By using the Service, operators instruct VroomOS to process data as needed to provide a global cloud product.
Laws that apply to your rental business (including notices you must give drivers) remain your responsibility regardless of which App Store country the app was downloaded from.
12. Cookies and similar technologies
- Essential: login sessions, security, load balancing, remembering basic preferences
- Functional: language or UI preferences where stored on device
- VroomOS legal pages themselves are static and do not load advertising trackers
- Third-party sign-in (for example Google) may set cookies under that provider’s policy
You can control cookies in your browser; blocking essential cookies may break sign-in.
13. Children
VroomOS is designed for business use by rental operators and adult drivers. It is not directed at children. Operators must not knowingly collect children’s data except as required by law for a legitimate rental purpose and with appropriate safeguards.
14. Changes to this policy
We may update this Privacy Policy to reflect product, legal, or security changes. The current version is always posted at https://vroomos.net/privacy with a revised “Last updated” date. Material changes may also be communicated through VroomOS or email where appropriate. Continued use after the effective date constitutes acceptance where permitted by law.
15. Contact VroomOS
- Privacy / data requests: support@vroomos.net
- Website: https://vroomos.net
- Terms: https://vroomos.net/terms
- Pricing: https://vroomos.net/pricing
- Refunds: https://vroomos.net/refund
This policy explains VroomOS platform practices. It is not a substitute for each rental company’s own privacy notice to drivers, nor is it legal advice for your jurisdiction.