Privacy policy
Last updated 19 August 2026
1. Who we are
StructuRent (“StructuRent”, “we”, “us”, “our”) is software for running rental businesses — fleet, bookings, team, pricing, and payments in one place. This policy explains what personal data we collect when you use StructuRent, why we collect it, who we share it with, and the rights you have over it.
The service is operated by PetarByte, obrt za usluge, vl. Petar Marče, a sole proprietorship (obrt) established in Croatia (OIB 66552443847, registered seat Put Mlikarica 28, 21300 Makarska). We are the data controller for the personal data described in this policy, except for the customer records that businesses enter into StructuRent (see “Data our business customers control” below).
For any privacy question or to exercise your rights, contact us at petarbyte@gmail.com.
2. Data we collect
- Account data. Your email address and name, the password hash for email sign-in, and — if you sign in with Google — the basic profile details Google shares (email, name, profile picture). We never receive or store your Google password.
- Business data. What you enter to run your business: business name, locations, fleet and inventory, pricing, working hours, rentals and bookings, workshop records, reports, and the team members you invite.
- Customer records. The customer details a business records against rentals and bookings (such as name and contact details). Where a business enters these, that business is the controller and we act as its processor — see section 7.
- Billing data. Your subscription plan, trial and renewal status, and billing history. Card payments are handled entirely by Stripe; full card numbers never reach our servers. For businesses that enable online payments through the booking widget, Stripe likewise processes the cardholder data.
- Support communications. The content of emails and messages you send us, so we can help and keep a record of the request.
- Technical data. Standard server and security logs (IP address, request time, user agent, and error diagnostics) needed to operate, secure, and troubleshoot the service.
3. How we use your data and our legal bases
We use personal data only to run StructuRent, and each use rests on a legal basis under the GDPR:
- To provide the service — authenticating you, storing and displaying your business data, and enabling bookings and payments. Basis: performance of our contract with you.
- To handle billing — managing subscriptions, trials, renewals, and receipts through Stripe. Basis: performance of contract and our legal obligations.
- To send transactional email — team invitations, sign-in and password-reset messages, and billing notices. Basis: performance of contract.
- To secure and improve the service — keeping logs, preventing abuse, and diagnosing problems. Basis: our legitimate interest in a safe, working product.
- To meet legal duties — retaining invoices and accounting records. Basis: compliance with a legal obligation.
We do not sell personal data, and we do not use it for advertising or profiling.
4. Cookies
StructuRent uses only strictly necessary cookies: the authentication session cookies that keep you signed in. There are no analytics, advertising, or cross-site tracking cookies, which is why you don't see a cookie consent banner. If we ever add non-essential cookies or analytics, we will update this policy and ask for your consent first.
5. Who we share data with (sub-processors)
We rely on a small number of trusted processors to run the service. Each processes data under its own terms and a data-processing agreement with us, and only as needed to provide its part of the service:
- Supabase — database, authentication, and file storage.
- Stripe — subscription billing and, where a business enables it, the online payments its customers make through the booking widget.
- Google — only if you choose to sign in with Google, to verify your identity.
We do not otherwise share your personal data, except where we are legally required to (for example, a valid legal request from a public authority) or as part of a business transfer, in which case any successor remains bound by this policy.
6. International transfers
Our processors may store or process data on servers located outside the European Economic Area (for example, in the United States). Where that happens, the transfer is protected by an approved safeguard — typically the European Commission's Standard Contractual Clauses or an equivalent adequacy mechanism — so your data keeps its GDPR-level protection.
7. Data our business customers control
If you run a business on StructuRent, the records you enter about your own customers (names, contact details, rental history) belong to your business. For that data you are the controller and we are your processor: we process it only on your documented instructions to provide the service, keep it confidential, and delete or return it when your account is closed. Your customers should direct any privacy requests about that data to your business.
As controller, you are responsible for having a lawful basis and, where required, providing your own privacy notice to those customers. A data-processing agreement is available on request at petarbyte@gmail.com.
8. Google user data
If you sign in with Google, StructuRent's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We request only the basic profile scopes needed to create and authenticate your account (your email, name, and profile picture), we use that information solely to provide sign-in, and we never sell it or use it for advertising.
9. Retention and deletion
We keep your data for as long as your account exists, so you can cancel and come back without losing anything. When you delete your account we permanently delete your personal and business data within 30 days, except billing and invoicing records, which we must retain to comply with Croatian tax and accounting law (generally up to eleven years). Backups are cycled out on a rolling basis.
10. How we protect your data
We apply appropriate technical and organisational measures to protect personal data: encryption in transit (HTTPS), access controls and role-based permissions, hashed passwords, and reputable infrastructure providers. No system is perfectly secure, but we work to keep the risk low and will notify affected users and the supervisory authority of a data breach where the law requires.
11. Your rights
If you are in the EU or EEA, the GDPR gives you the right to access, correct, delete, restrict, or object to our processing of your personal data, to receive a copy in a portable format, and — where we rely on consent — to withdraw it at any time. You can exercise any of these by emailing petarbyte@gmail.com; we respond within one month.
You also have the right to lodge a complaint with a supervisory authority. In Croatia that is the Agencija za zaštitu osobnih podataka (AZOP).
12. Children
StructuRent is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy
If this policy changes in a way that matters, we will update the date at the top of this page and, for significant changes, notify account owners by email before the change takes effect.
14. Contact
Questions about this policy or your data? Email petarbyte@gmail.com, or see our terms of service.