RentalOps

by Quoriven

Back to homepage

Legal

Privacy Policy

Effective and last updated: July 23, 2026

This Privacy Policy explains how Quoriven ("Quoriven," "we," "us," or "our") handles personal information when you use RentalOps, our rental-operations platform, website, and related services (the "Service").

1. Who we serve

RentalOps is provided to rental companies and production teams ("Customers"). A Customer generally controls the business and crew information it enters into RentalOps, and Quoriven processes that information to provide the Service. Quoriven controls information used to operate our website, administer accounts, secure the Service, bill Customers, and manage direct communications with us.

If a Customer entered your information as a crew member or other business contact, direct requests about that Customer's records to the Customer first. We will assist the Customer as required.

2. Information we collect

  • Account and contact information, such as name, email address, phone number, role, organization, and login identifiers.
  • Customer business data, including inventory, locations, events, assignments, schedules, rates, quotes, packing, dispatch, and return records.
  • Billing and subscription information. Our payment processor handles payment-card details; we receive transaction and subscription status.
  • Technical and usage information, such as IP address, browser and device data, pages visited, timestamps, diagnostics, and security logs.
  • Communications and support requests you send to us.
  • Integration data you choose to connect, including the Google Calendar data described below.

3. Google Calendar data

Google Calendar connection is optional. When an authorized Customer administrator connects a crew member's Google Calendar, RentalOps requests the https://www.googleapis.com/auth/calendar.events scope. Google describes this permission as allowing an application to view and edit events on calendars the user can access.

RentalOps uses this permission only to synchronize RentalOps crew assignments with the connected account's primary Google Calendar. We create, update, retrieve when needed, and delete events created by RentalOps. We do not list, import, analyze, or display the user's unrelated existing calendar events.

Calendar information handled

  • Sent to Google: assignment or event name, crew role, location, start and end times, time zone, and a RentalOps attribution.
  • Received from Google: OAuth access and refresh tokens, token-expiry information, authorization errors, and identifiers or details for RentalOps-created calendar events when needed for synchronization.
  • Stored by RentalOps: an encrypted refresh token, connection status, access-token expiry metadata, and identifiers for calendar events created by RentalOps. Short-lived access tokens are used in server memory and are not stored in our database.

RentalOps's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell Google user data or use it for advertising, audience profiling, credit decisions, or unrelated purposes. We do not permit humans to read Google user data except with the user's affirmative agreement for support, when necessary for security or abuse investigation, to comply with law, or when the data has been aggregated and anonymized for internal operations.

4. How we use information

  • Provide, maintain, support, and improve the Service.
  • Authenticate users and administer Customer workspaces.
  • Process subscriptions and send transactional communications.
  • Protect users, investigate misuse, and maintain service reliability.
  • Comply with law and enforce our agreements.

Where applicable, our legal bases include performance of a contract, legitimate interests in operating and securing the Service, consent, and compliance with legal obligations.

5. How we disclose information

We disclose information only as needed to provide and protect the Service, including to:

  • Google, when a user chooses Calendar synchronization.
  • Supabase for authentication, database, and infrastructure services.
  • Vercel for application hosting and performance measurement.
  • Axiom for application logging and diagnostics.
  • Resend for transactional email delivery.
  • Stripe for subscription billing and payment processing.
  • Professional advisers, authorities, or other parties when reasonably necessary for legal compliance, safety, fraud prevention, or a corporate transaction.

Service providers may process information only for contracted services and subject to applicable confidentiality and data-protection obligations. We do not sell personal information.

6. Retention and deletion

  • Google refresh tokens are retained until the Calendar connection is disconnected, the token becomes invalid, the crew member is deleted, or the Customer account is closed.
  • Google event identifiers are retained while the related assignment and Calendar connection remain active. On disconnect, RentalOps attempts to delete its synced events, revokes the Google grant, and deletes its stored token and event identifiers. If Google is unavailable or an event cannot be removed, the user may need to delete that event manually in Google Calendar.
  • Customer records are retained while the Customer account is active and ordinarily deleted or de-identified within 30 days after account closure, unless law, a dispute, or a written agreement requires longer retention.
  • Security and diagnostic logs are ordinarily retained for up to 30 days. Deleted information may remain in restricted backups for up to 30 additional days before being overwritten.

7. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information, and to withdraw consent. Contact us or the Customer that manages your RentalOps record to make a request. We may need to verify your identity.

An authorized administrator can disconnect Google Calendar in RentalOps. A Google account holder can also revoke access at any time from Google Account permissions. Revocation stops future access but does not automatically remove calendar events already stored in the Google account.

8. Security and international processing

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, tenant isolation, encrypted transport, and encryption of stored Google refresh tokens. No method of storage or transmission is completely secure.

Quoriven and our service providers may process information in the United States and other countries where they operate. Where required, we use legally recognized transfer mechanisms and contractual safeguards.

9. Cookies and analytics

We use essential cookies and similar technologies for authentication, session security, workspace routing, and preferences. We also collect limited performance and diagnostic information to understand service reliability. Browser controls may block cookies, but essential features may then stop working.

10. Children's privacy

RentalOps is a business service and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information to the Service.

11. Changes to this policy

We may update this policy as our practices or legal requirements change. We will post the updated policy here, revise the effective date, and provide additional notice when a change materially affects how we use Google user data or other personal information.

12. Contact us

For privacy questions or requests, contact Quoriven at hello@quoriven.com. Please include "Privacy Request" in the subject line.