// LEGAL
PRIVACY
POLICY
Last updated: April 2026
This Privacy Policy describes how London Rental Shop, a trading name of JRM Ventures Ltd (registered in England & Wales, company number 17191962, registered office Unit A558, 4–6 Greatorex Street, London E1 5NF) ("we", "us", "our") collects, uses, and protects your personal data when you use our website and rental services. We are the data controller for the personal data described below.
This policy is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you have questions about this policy or how we handle your data, please contact us at hello@londonrental.shop.
1. INFORMATION WE COLLECT
1.1 Account & contact details. When you create an account or place a booking, we collect your name, email address, phone number, billing address, and (where relevant) company name.
1.2 Identity verification. For first-time bookings we use Stripe Identity to verify your identity. You upload a government-issued photo ID and a selfie. The biometric matching is performed by Stripe on our behalf; we receive a pass/fail result plus the basic identity details (name, date of birth, ID document type). We may also request proof of address (utility bill, bank statement) which is stored securely on Cloudinary.
1.3 Payment information. Card details are processed directly by Stripe — we never see or store your full card number. We retain a payment-method token, the last four digits of your card, and the payment intent ID so we can match payments to your orders and process refunds.
1.4 Rental data. Order history, the equipment you've rented, pickup and return dates, condition photographs taken at handover, and any notes you or our team add to your booking.
1.5 Communications. Email, WhatsApp, or other messages exchanged with our team in connection with your rentals. We log these so we can respond consistently and audit conversations if a dispute arises.
1.6 Technical data. IP address, browser type, device information, pages visited, and timestamps. Used to keep the platform secure (e.g. detecting suspicious sign-ins) and to understand how customers use the site.
1.7 Public-profile links. If you provide an Instagram or portfolio link, we hold the URL only — we don't scrape or store the content of those pages.
2. HOW WE USE YOUR DATA
We process your personal data on the following lawful bases:
2.1 Performance of contract. To provide the rental service you've booked: confirm orders, process payments and refunds, arrange pickup and return, generate invoices and agreements, and contact you about your booking.
2.2 Legitimate interests. To verify your identity (preventing fraud and protecting our equipment), maintain condition records (resolving disputes), monitor service quality, and operate the business. We balance these interests against your privacy and limit data collection accordingly.
2.3 Legal obligation. To comply with tax, accounting, anti-money-laundering, and consumer protection laws. For example, we keep invoices for at least six years to satisfy HMRC requirements.
2.4 Consent. For optional marketing emails (newsletters, special offers). You can withdraw consent at any time using the unsubscribe link or by emailing us.
3. WHO WE SHARE DATA WITH
We share data only with service providers that help us run the business. Each is bound by data-processing agreements and complies with UK GDPR. We never sell your data.
- Stripe — payment processing and identity verification (Ireland, USA — adequacy / SCCs).
- Resend — transactional email delivery (USA — SCCs).
- Cloudinary — secure image storage for product photos and condition reports (USA — SCCs).
- Vercel — website hosting (USA — SCCs).
- Neon — database hosting (EU regions where possible).
- Anthropic — AI-assisted helpers for our admin team (e.g. drafting responses). Customer data is only sent on a per-request basis when needed; not used to train models.
- Hygglo — when bookings come via the Hygglo platform, basic order details flow back and forth as required by their platform.
- HMRC, accountants, auditors — when legally required for tax and compliance.
We may also disclose data when required by law (e.g. court order, police request) or to protect our rights, property, or safety.
4. INTERNATIONAL TRANSFERS
Some of our service providers process data outside the UK. Where this happens, we rely on UK adequacy decisions or Standard Contractual Clauses (SCCs) to ensure your data receives equivalent protection to UK GDPR.
5. HOW LONG WE KEEP DATA
Order and financial records: 6 years from the end of the financial year (HMRC requirement).
Identity verification records: 5 years from the end of the customer relationship (anti-money-laundering best practice).
Account and contact details: For as long as you have an active account; deleted within 12 months of account closure unless retention is required for legal reasons.
Marketing data: Until you unsubscribe.
Server logs and technical data: Up to 90 days.
6. YOUR RIGHTS
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify data that's inaccurate or incomplete.
- Erase your data (where we're not legally required to keep it).
- Restrict our use of your data.
- Port your data to another provider in a machine-readable format.
- Object to processing based on our legitimate interests.
- Withdraw consent at any time for processing based on consent.
- Complain to the Information Commissioner's Office (ICO — ico.org.uk) if you believe we've mishandled your data. We'd appreciate the chance to address your concerns first.
To exercise any of these rights, email hello@londonrental.shop. We'll respond within one month.
7. SECURITY
We use industry-standard security: HTTPS for all traffic, hashed passwords, encrypted data at rest, role-based access (only the admin team sees customer data), session cookies signed with a server-side secret, and Stripe's PCI-compliant infrastructure for payment data. Identity documents and proof-of-address files are stored on Cloudinary with restricted access.
No system is perfectly secure. If a breach occurs that's likely to result in a high risk to your rights and freedoms, we'll notify the ICO within 72 hours and inform affected customers as soon as practicable.
8. COOKIES
We use a small number of essential cookies: a session cookie to keep you logged in, a theme preference cookie (light/dark mode), and a few small localStorage entries to remember your shopping cart and recent searches. We don't use third-party advertising or analytics trackers.
9. CHILDREN
Our services are intended for adults aged 18 and over. We don't knowingly collect data from children. If you believe a child has provided us with their data, please contact us and we'll delete it.
10. CHANGES TO THIS POLICY
We may update this policy occasionally. The "Last updated" date at the top reflects when. For material changes (new categories of data, new third parties, substantially different uses), we'll email you and ask for fresh consent where required.
11. CONTACT US
For any data-protection question or to exercise your rights, contact:
JRM Ventures Ltd
Trading as London Rental Shop
Unit A558, 4–6 Greatorex Street
London E1 5NF
United Kingdom
hello@londonrental.shop