Last updated: July 9, 2026
Korent ("the Service") is a rental-business management platform. Depending on whose data is involved, we act in one of two distinct roles:
To make in-person handoffs safer, renters upload a government ID photo and a live selfie before booking. These images are stored in a private bucket and are viewable only by (a) the seller at handoff through short-lived links so they can visually confirm you are you, and (b) Korent personnel when a dispute requires it. A human compares the photos. We do not use facial recognition and do not create biometric templates, faceprints, or scans of face geometry — from these images or any others. Verification photos are retained while your account is active because they are used at each rental handoff, and are deleted within 30 days of an account-deletion request.
We use collected information to:
Legal bases (operators and site visitors in the EEA/UK).Where Korent acts as controller (see section 1), we rely on the following lawful bases under Article 6 of the GDPR/UK GDPR for each purpose. For renter/customer data that we process on an operator's behalf, the operator (as controller) is responsible for the lawful basis.
| Purpose | Lawful basis |
|---|---|
| Create and operate your account; provide, maintain, and support the Service; process your subscription and billing | Performance of a contract (Art. 6(1)(b)) |
| Send transactional messages to you about your account (billing, security, service status) | Performance of a contract (Art. 6(1)(b)) |
| Send product updates and service announcements (with opt-out); enforce our Terms; prevent fraud, abuse, and security incidents; keep the Service secure and reliable | Our legitimate interests (Art. 6(1)(f)) |
| Product analytics to understand and improve the Service (see section 7) | Consent (Art. 6(1)(a)), given via the cookie banner |
| Keep records and meet tax, accounting, and other legal obligations | Compliance with a legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, you may object at any time (see section 11); where we rely on consent, you may withdraw it at any time without affecting prior processing.
The dashboard includes an AI assistant ("Copilot") operators can use to ask questions about their business. When an operator uses the Copilot, we send the operator's message, the recent conversation history, and a snapshot of the operator's business context — which can include order details, operational status, and customer names, email addresses, and recent message excerpts — to an AI model provider: OpenAI (our primary Copilot provider) or Anthropic (used as a fallback). Anthropic also powers optional translation of operator-authored email template copy, and automated categorization of marketplace listing text (titles and descriptions). The public storefront can additionally offer an optional AI Booking Desk; when a website visitor uses it, their typed messages — questions about availability, products, and delivery, plus any contact details they choose to share — are sent to the same providers (OpenAI, with Anthropicas a fallback) to generate a grounded answer from the operator's published catalog.
We access both providers through their business APIs, under terms which state that data submitted via the API is not used to train their models. AI features that involve customer data are used only to provide the Service to the operator — we do not sell this data or use it for advertising.
We do not sell your personal information. We share data only with the service providers below, each processing data under their own privacy policies and a data-processing agreement or equivalent terms. The current list is always published at korent.app/subprocessors.
| Provider | Purpose | Data shared | Region / transfer basis |
|---|---|---|---|
| Stripe | Payment processing and subscription billing | Names, emails, payment amounts; card data goes directly to Stripe | US; EU-US Data Privacy Framework (DPF) |
| Supabase | Database, authentication, and file storage | All application data | Region of our deployment; SCCs where applicable |
| Vercel | Application hosting | Request data (IP addresses, request logs) | US/global edge; DPF |
| Resend | Transactional email delivery | Recipient email addresses and message content | US; SCCs |
| Twilio | SMS and WhatsApp notifications | Recipient phone numbers and message content | US; DPF |
| OpenAI | AI Copilot and Storefront AI Booking Desk (primary provider) | Operator messages and business-context snapshots (may include customer names/emails, see section 5); anonymous storefront visitor messages via the Booking Desk | US; DPF; not used for model training |
| Anthropic | AI Copilot and Booking Desk (fallback), email-template translation, listing categorization | Same as OpenAI for Copilot/Booking Desk; template copy; listing text | US; DPF; not used for model training |
| PostHog | Product analytics (only after cookie consent, see section 7) | Usage events, page views, user ID | US (us.i.posthog.com); DPF |
| OpenStreetMap / Nominatim | Geocoding postal codes for delivery-distance checks | Postal codes and country only — no names or street addresses | EU-hosted public service |
| Open-Meteo | Weather forecasts for event dates | Geographic coordinates only — no personal data | EU-hosted public service |
| Intuit (QuickBooks) / Xero | Accounting sync — only if the operator connects it | Invoice and payment records, customer names on invoices | Per the operator's own accounting account |
Identity-verification photos are shared with no one beyond the handoff and dispute uses described in section 3. We may also disclose information when required by law, to protect our rights or the safety of users, or as part of a merger or acquisition (with notice to you).
We use two categories of cookies:
korent_analytics_consent) for about 12 months. Declining changes nothing about how the Service works — we simply collect no usage data.To change your choice, delete the korent_analytics_consent cookie in your browser settings (the banner will re-appear on your next visit), or contact privacy@korent.app. We do not use advertising cookies and do not permit third parties to track you across other sites.
We implement industry-standard security measures including encrypted connections (TLS), row-level security policies on all database tables, rate limiting on authentication endpoints, and secure session management. Sensitive operations are recorded in an append-only internal audit log.
Korent is operated from the United States and our subprocessors are primarily US-based. Where personal data of EEA, UK, or Swiss residents is transferred to the US, we rely on the EU-US Data Privacy Framework (for providers that are certified) and on Standard Contractual Clauses (SCCs) or equivalent safeguards otherwise.
Depending on where you live, you have some or all of the following rights. To exercise any of them, email privacy@korent.app— we respond within the timeframe required by your jurisdiction's law. If you are a rental customer of a business that uses Korent, contact that business first (see section 1).
EEA / UK: the rights above reflect the GDPR and UK GDPR. You may also lodge a complaint with your local supervisory authority.
California: we do not sell or share personal information as defined by the CCPA/CPRA, and we do not use sensitive personal information beyond what is necessary to provide the Service — so no opt-out of sale/sharing is needed. You may exercise your access, deletion, correction, and portability rights via privacy@korent.app, including through an authorized agent, and we will never discriminate against you for doing so.
Quebec (Law 25): Quebec residents have equivalent rights of access, rectification, and de-indexing. Our designated person in charge of the protection of personal information can be reached at privacy@korent.app.
Australia: we handle personal information of Australian users consistent with the Australian Privacy Principles; complaints may be raised with us first and then with the OAIC.
The Service is a business tool for rental operators aged 18 and older and is not directed to children. We do not knowingly collect personal information from children. Waiver and participant forms may record information about minors (e.g., a child attending an event), but that information is provided by an adult — a parent, guardian, or the operator — never collected from the child directly.
We may update this policy periodically. Material changes will be communicated via email or in-app notification. Continued use of the Service after changes constitutes acceptance.
For privacy-related questions or data requests, contact us at privacy@korent.app.