Skip to content

Privacy Policy

Last updated 15 July 2026

This policy explains how [LEGAL_NAME] ("ifaha", "we") handles personal data when you use the ifaha car rental platform at ifaha.com. It is written to be read, not to hide behind legal language. ifaha is operated by [LEGAL_NAME], registered in [JURISDICTION], [ADDRESS].

1. Two kinds of data

ifaha serves car rental companies, which creates two different relationships. For a rental company and its staff who sign up and use ifaha, we are the data controller. For the renters (end customers) whose details a rental company enters into ifaha, the rental company is the controller and ifaha only processes that data on the company's behalf, under its instructions.

In plain terms: we decide how we handle a rental company's own account data; the rental company decides how its customers' data is used and is responsible for having a lawful basis to enter it.

2. What we collect

We collect only what the service needs:

  • Account data — the name, email, phone and company details you give us when you register and set up your account.
  • Operational data you enter — vehicles, availability, reservations, customer records, documents, rates, payments and deposits. For renter records the rental company is the controller.
  • Technical data — basic server logs (IP address, request time, browser) kept for security and troubleshooting, and one session cookie that keeps you signed in.

3. Cookies

ifaha uses a single cookie: a session cookie that keeps you signed in. It is essential for the service to work and clears when your session ends. There are no analytics, advertising or cross-site tracking cookies, and we do not sell data to anyone.

4. Processors we rely on

To run the service we use a small number of trusted providers. Each receives only the data it needs:

  • Stripe — processes ifaha's own subscription billing, when paid plans apply.
  • Your own Stripe or Tap Payments account — when you take payments from your renters, the funds and card data flow through the rental company's own payment account, directly to the company. ifaha never holds those funds.
  • Neon — hosts the database where your data is stored.
  • Vercel — hosts and serves the application.
  • Meta (WhatsApp) — delivers the WhatsApp notifications a rental company chooses to send to its customers.

5. Where data is stored

Your data is stored with the infrastructure providers listed above and may be processed in the regions where they operate. We choose providers that offer appropriate safeguards for the data they handle.

6. How long we keep it

We keep your account and operational data for as long as your account is active. If Early Access ends and you choose not to continue on a paid plan, your account becomes read-only rather than deleted — you keep full viewing and export access. We delete data on request, subject to records we must retain by law.

7. Your rights and data export

You can access and export your data from within ifaha at any time; export stays available even on a read-only account. You can ask us to correct or delete personal data, or to explain how it is handled. Renters who want their data corrected or removed should contact the rental company that holds their booking, since that company is the controller.

8. Security

Access to the platform requires authentication, data is transmitted over encrypted connections, and each company's data is isolated from every other company's. No system is perfectly secure, but we take reasonable measures to protect your data.

9. Changes to this policy

If we make a material change we will update this page and, where appropriate, notify you. The date at the top always reflects the current version.

10. Contact

Questions about this policy or your data? Reach us through the contact page — we're happy to answer.