This Privacy Policy explains how rentusedbikes.com (“we”, “us”, “our”) collects, uses, stores, and protects your personal data when you use our website or rent a bicycle from us. We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR) and the Danish Data Protection Act (Databeskyttelsesloven).
1. Data Controller
rentusedbikes.com
Roskildevej 46, 2000 Frederiksberg, Denmark
Email: info@rentusedbikes.com
Website: rentusedbikes.com
2. What Personal Data We Collect
Data you provide directly: your name, email address, phone number, government-issued ID details (verified at rental), and payment card details.
Data collected automatically: IP address, browser and device information, and website usage data via cookies.
Data generated during your rental: rental history (dates, bicycle type, duration), deposit and payment transaction records, and any damage or incident reports.
3. Legal Basis for Processing
We process your data under the following GDPR bases:
- Contract performance (Art. 6(1)(b)): to fulfil your rental agreement, including bookings, payments, and returns.
- Legal obligation (Art. 6(1)(c)): to meet Danish tax and accounting requirements.
- Legitimate interests (Art. 6(1)(f)): to protect our property and operate our business.
- Consent (Art. 6(1)(a)): for non-essential cookies, which you may withdraw at any time.
4. How We Use Your Data
We use your data to process and manage your booking, verify your identity, handle payments and deposits, communicate with you about your rental, deal with damage or theft incidents, comply with Danish law, and improve our website and services. We will never sell your data or use it for unrelated purposes.
5. Third-Party Service Providers
We share data with the following providers who act as data processors on our behalf:
Booqable — our inventory and order management platform. Booking details, rental history, and payment records are stored within Booqable’s system. Booqable is GDPR-compliant.
Simply.com — our website and email hosting provider, based in Denmark, operating in accordance with Danish and EU data protection law.
Stripe — our payment processor. Card transactions are handled by Stripe in a PCI-DSS compliant environment. We do not store your full card number. Stripe is GDPR-compliant and certified under the EU-US Data Privacy Framework.
We do not share your data with any other third parties except where required by law.
6. International Data Transfers
We aim to keep your data within the EEA. Where any service provider processes data outside the EEA (such as Stripe), appropriate safeguards are in place, including EU Standard Contractual Clauses.
7. How Long We Keep Your Data
- Booking and rental records: 5 years, in accordance with Danish bookkeeping law (Bogføringsloven).
- Identity verification records: deleted promptly after your rental is complete, unless needed for an ongoing dispute.
- Email correspondence: up to 2 years from the last communication.
- Website and cookie data: per the retention periods described in Section 8.
After the applicable period, your data is securely deleted or anonymised.
8. Cookies
Our website uses cookies to ensure it functions correctly and to understand how visitors use it. We use strictly necessary cookies (required for the booking flow and cannot be disabled) and analytics cookies (anonymised, to improve our website). You can manage cookie preferences through your browser settings at any time.Necessary cookies
Cookie name Description wordpress_sec_e47f2a6ba9f4f60380b4ca84ca9475d3Security cookie used by WordPress to authenticate logged-in users. wp-settings-time-1Stores the time when WordPress user settings were last updated. wp-settings-1Stores user interface preferences for logged-in WordPress users. wordpress_test_cookieUsed by WordPress to check whether the browser accepts cookies. wordpress_logged_in_e47f2a6ba9f4f60380b4ca84ca9475d3Indicates when a user is logged in to the WordPress website. ccc_consentStores the user\\\'s cookie consent preferences. wp-settings-2Stores user interface preferences for logged-in WordPress users. wp-settings-time-2Stores the time when WordPress user settings were last updated. wp-settings-3Stores user interface preferences for logged-in WordPress users. wp-settings-time-3Stores the time when WordPress user settings were last updated. SignedInIndicates whether the user is authenticated. ASP_NET_SessionIdMaintains user session state on the server. BNES_ASP_NET_SessionIdLoad-balanced session cookie for ASP.NET applications. HandLtestDomainNameServerTechnical cookie used for domain/environment validation. TS0133ea21Security and load balancing cookie used by the server. Functional cookies
Cookie name Description _wpfuuidWPForms cookie used to identify unique visitors and improve form functionality. wpforms_fields_group_settings_advancedStores WPForms advanced field settings preferences. wpforms_fields_group_settings_notifications_advancedStores WPForms notification settings. wp_langStores the selected language of the user. wp-saving-postIndicates that a WordPress post is being saved (auto-save). GCsInternal tracking cookie used for system or analytics purposes. MISCGCsMiscellaneous tracking or system cookie. currencyStores the selected currency for the user. handl_ipStores visitor IP information for tracking or analytics purposes. handl_landing_pageStores the landing page of the visitor session. handl_urlStores the current page URL for tracking purposes. handl_url_baseStores the base URL of the website for tracking. shippingCountryStores the user’s selected shipping country. user_agentStores information about the user\\\'s browser and device. sbFacebook browser identifier cookie. datrFacebook security and fraud prevention cookie. wdStores browser window dimensions (used by Facebook). handl_original_refStores the original referral source of the visitor. handl_refTracks the latest referral source of the visitor. warningStores temporary warning or system notification state. __birdie_snippet_statusTracks the loading status of embedded scripts or widgets. Analytics cookies
Cookie name Description first_utm_campaignStores the first marketing campaign associated with the user. first_utm_mediumStores the first traffic medium (e.g. CPC, email). first_utm_sourceStores the first UTM source that brought the user to the website. organic_sourceTracks the organic traffic source (e.g. Google, Bing). organic_source_strStores detailed information about organic traffic source. referStores referral source information of the visitor. utm_campaignStores the campaign name for tracking purposes. utm_mediumStores the marketing medium of the visit. utm_sourceStores the traffic source of the current visit.
9. Your Rights
Under GDPR, you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email us at info@rentusedbikes.com. We will respond within 30 days.
10. Data Security
We use HTTPS encryption on our website, restrict access to personal data on a need-to-know basis, and rely only on GDPR-compliant service providers. In the event of a data breach posing a risk to your rights, we will notify Datatilsynet within 72 hours and inform affected individuals where required.
11. Changes to This Policy
We may update this policy from time to time. Changes will be posted here with a revised date. For material changes, we will notify you by email where we hold your contact details.
12. Contact
Questions or requests regarding this policy are welcome at info@rentusedbikes.com.