Legal · First draft
Privacy Policy
Effective date: . This Privacy Policy is a first draft pending lawyer review; do not rely on it as final text before production launch.
1. Overview
This Privacy Policy explains what data RentYourCompute (“we,” “us”) collects when you use our marketplace, why we collect it, how long we keep it, and the limited set of third parties we share it with. It applies to rentyourcompute.com and our subdomains (api., id., net., etc.). It does not cover data handled by third-party sites linked from our pages.
2. What we collect
We collect the following categories of data:
- Account information— the email address you register with, your display name, and (where applicable) a profile picture URL provided by your identity provider. We do not collect or store your password; authentication is delegated to our identity provider.
- Device telemetry— for devices you enroll: hardware specifications (CPU, RAM, storage, virtualization capability), operating system, network reachability, and uptime/last-seen timestamps.
- Usage metrics— for rentals you take: bytes proxied (egress), slice-hours consumed, and connection counts, measured on our gateway infrastructure (the authoritative numbers for billing).
- Billing data— invoice amounts and status, the last four digits of any payment instruments on file, payout destinations for Providers, and tax identifiers you supply.
- Operational data— standard web-server logs (IP address, user agent, request URL, response code) for abuse detection and rate limiting.
3. How we use your data
We use the data above to:
- Operate the marketplace (matching listings with renters, routing payments).
- Detect and prevent fraud, abuse, and violations of the Acceptable Use Policy.
- Generate invoices, process payments, and disburse payouts.
- Send essential service emails (account, security, billing, policy updates).
- Comply with applicable law and respond to valid legal process.
We do not sell personal data. We do not use your data for advertising or behavioral profiling.
4. Legal bases (EEA / UK)
If you are in the European Economic Area or the United Kingdom, we process your data under the following GDPR legal bases:
- Contract— to provide the Service you signed up for.
- Legitimate interests— to operate, secure, and improve the Service (for example, fraud detection).
- Legal obligation— to comply with tax and accounting rules, and with valid legal process.
- Consent— where we rely on consent (for example, optional marketing communications), which you can withdraw at any time.
5. Third parties we share with
We share limited data with the following categories of service provider:
- Lago (open-source billing engine, self-hosted) — invoice line items and amounts.
- Zitadel (open-source identity, self-hosted) — authentication, email-verification, and account profile data.
- Stripe— payment processing and payout disbursement (we send only the data Stripe needs; they may store additional data under their own policy).
- Cloudflare— DNS and edge routing (Cloudflare sees the source IP and requested hostname as part of normal traffic).
- Oracle Cloud Infrastructure— hosting of all our servers. Oracle handles physical data-center security but has no access to our databases.
We also share data with law-enforcement authorities when served with a valid subpoena, court order, or equivalent legal process (see Acceptable Use Policy).
6. Cookies and similar technologies
We set the following first-party cookies:
ryc_session— encrypted session cookie that identifies you after sign-in. Strictly necessary.ryc_oidc_state— short-lived (10-minute) cookie holding PKCE state during sign-in. Strictly necessary; deleted on completion.theme— remembers your light/dark preference. Functional; optional.ryc_signup_intent— carries your role-intent choice and consent timestamp from signup into the sign-in step. Deleted after signup completes.
We do not use third-party analytics or advertising cookies.
7. How long we keep your data
We retain data only as long as needed for the purposes above:
- Billing records— minimum 7 years (tax and accounting law).
- Device telemetry— 30 days for raw time-series; aggregated statistics kept longer.
- Operational logs (web server)— 30 days.
- Account profile— for the life of the account, deleted within 30 days after account closure.
8. International transfers
We are headquartered in the United States. If you are located in the EEA, UK, or Switzerland, your data is transferred to the United States under the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum. Our sub-processors (listed above) may operate in additional countries; their own policies apply to data they process.
9. Your rights (GDPR / CCPA)
Depending on where you live, you may have some or all of the following rights:
- Access— request a copy of the personal data we hold about you.
- Deletion— request that we delete your account and personal data, subject to our legal retention obligations.
- Portability— receive your data in a portable, machine-readable format.
- Correction— fix inaccurate data.
- Objection / restriction— object to certain processing or ask us to restrict it.
- Withdraw consent— where we rely on consent.
To exercise any of these rights, email privacy@rentyourcompute.com from the address on your account so we can verify your identity. We respond within 30 days. If you are unhappy with our response, you may lodge a complaint with your local data protection authority.
10. Children’s privacy
The Service is not directed to children under 16 (or higher where required by local law). We do not knowingly collect personal data from children. If you believe a child has created an account, contact privacy@rentyourcompute.com and we will delete the account.
11. Security
We use industry-standard controls to protect your data: TLS in transit, encryption at rest for our primary databases, scoped access for staff, and audited change management. Credentials you paste into our rotation forms (NetBird PATs, Stripe keys, etc.) are write-only and never displayed, logged, or placed in a URL after submission. No system is perfectly secure; if you discover a vulnerability, please report it to security@rentyourcompute.com.
12. Changes to this Privacy Policy
Material changes will be announced by email at least 30 days before they take effect. The current version and its effective date are always shown at the top of this page.
First draft — pending lawyer review. Do not deploy as final legal text.