Legal
What we collect, why we are allowed to, how long we keep it, and what you can ask us to do about it.
1. Data we collect
We collect only what a rental actually needs. Everything below is grouped by why it exists.
1.1 Identity & contact information
Your name, email address and phone number. Where you connect a payout account, Stripe collects and holds the identity details its own checks require — those never reach our servers.
1.2 Listing & transaction data
Item descriptions, photos, prices, availability, approximate pickup areas, booking dates and payment records. Card details are handled by Stripe and never reach our servers.
1.3 Communications
Messages between renters and owners, and anything you send to support. We read these only when a dispute or safety report requires it.
2. Legal basis for processing
Under Article 6 GDPR each piece of processing has one named basis. We rely on four:
- Contract — creating your account, taking bookings, moving payments, handling disputes.
- Legal obligation — tax records, anti-money-laundering checks, responding to lawful requests.
- Legitimate interests — fraud prevention, platform safety, keeping the service working.
- Consent — analytics and marketing cookies, and optional emails. Withdrawable at any time.
3. How we use your data
To run rentals: match renters with items, confirm bookings, release exact addresses at the right moment, take payment and pay owners out.
To keep people safe: verify members, detect fraudulent listings and payments, and give a human enough context to settle a dispute fairly.
To improve the product: understand which categories are missing in which cities. This is aggregated and never sold.
4. Third-party processors
We use a small number of processors, each under a data-processing agreement:
- Stripe — payments, payouts and card storage (PCI-DSS Level 1).
- Supabase — database and authentication, hosted in the EU.
- Vercel — website hosting and delivery.
5. Retention and your rights
Account data is kept while your account is open. Completed bookings and invoices are kept as long as tax law requires, then deleted.
You can access, correct, export, restrict or delete your data, object to processing, and complain to a supervisory authority. Write to legal@donotgetit.com and we answer within 30 days.
1. About this service
donotgetit.com is a peer-to-peer rental marketplace operated by [REGISTERED COMPANY NAME], registration number [NUMBER], Sepapaja 6, 15551 Tallinn, Estonia. We provide the platform; the rental agreement is between the renter and the owner.
2. Accounts
You must be at least 18 and provide accurate details. You are responsible for activity on your account.
We may suspend or close an account that breaks these terms, and will tell you why unless the law prevents it.
3. Listing rules
You may only list items you own outright and are legally allowed to rent out.
- Weapons, ammunition and anything requiring a licence you do not hold.
- Prescription medicines and medical devices.
- Live animals.
- Counterfeit goods, or anything you do not own.
- Anything a court order or local law prevents you from renting out.
4. Bookings, deposits and cancellations
A booking is a request until the owner confirms it. Your card is authorised on request and charged at pickup.
A deposit is held on the renter's card, never taken, and released after a confirmed return unless a damage claim is opened within 48 hours.
The cancellation policy shown on the listing at the time of booking is the one that applies.
5. Fees and payouts
Our service fee is 10% of the rental total, deducted from the owner's payout. Payouts land 2–3 business days after a confirmed return.
Owners are responsible for declaring their own rental income.
6. Liability
We are not a party to the rental agreement and do not own, inspect or insure the items listed. Nothing here limits liability that cannot be limited by law.
Governing law is Estonian law, and the courts of Estonia have jurisdiction, without affecting any right you have as a consumer to bring a claim where you live.
1. Your rights at a glance
Under GDPR you have the following rights over your personal data:
- Access (Art. 15) — a copy of what we hold.
- Rectification (Art. 16) — correct anything wrong.
- Erasure (Art. 17) — deletion, where no legal duty requires us to keep it.
- Restriction (Art. 18) — pause processing while a dispute is resolved.
- Portability (Art. 20) — your data in a machine-readable format.
- Objection (Art. 21) — object to processing based on legitimate interests.
- Withdraw consent — at any time, for anything we do on consent.
2. How to exercise them
Email legal@donotgetit.com from the address on your account. We answer within 30 days and can extend by two months for complex requests, telling you why.
We do not charge for this unless a request is manifestly excessive.
3. Complaints
You can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or to the supervisory authority where you live.
1. What we set
Cookies are small files stored by your browser. We use as few as we can.
- Strictly necessary — your login session, security tokens, and the cookie choice itself. These have no consent requirement.
- Functional — your city, language and currency, so you do not reset them every visit.
- Analytics — aggregate page views, set only if you accept. No cross-site tracking.
- Marketing — none at present. If that changes, the banner will ask first.
2. Managing them
Change your choice any time from the cookie banner, or clear and block cookies in your browser settings. Blocking strictly necessary cookies will stop you being able to log in.
3. Third parties
Stripe sets cookies during checkout for fraud prevention. Embedded maps are served by OpenStreetMap tiles.
