Privacy Policy

What data we collect, why we collect it, who we share it with and how long we keep it.

Effective date: August 22, 2026 · Version 1

PRIVACY AND THE PROTECTION OF PERSONAL DATA: As "CARENT" MMC, we guarantee the security of our users' personal data at the highest level. This Privacy Policy provides detailed and transparent information about the collection, processing and protection of your personal data and about your rights.

This Privacy Policy ("Policy") governs the rules for collecting, processing, storing and protecting the personal data of all natural and legal persons (Renters, Individual Hosts, Rent-a-Car companies, citizens of Azerbaijan and foreign visitors) who use the carent.az website and the Carent mobile app ("Carent App", "Platform", "Services"), which belong to "CARENT" MMC (limited liability company) ("Carent", "we", "our").

This Policy has been prepared in full compliance with the Law of the Republic of Azerbaijan "On Personal Data" and with international data security principles.

Data Controller: "CARENT" MMC, Baku, Republic of Azerbaijan.
Privacy Requests and Contact: destek@carent.az | https://carent.az | +994 70 984 85 81


Contents

  1. Introduction and Scope
  2. Categories of Data We Collect
  3. Purposes of Data Use and Legal Bases
  4. Sharing of Data and Disclosure
  5. Data Security and Encryption
  6. Retention Period of Personal Data (Data Retention)
  7. User Rights and Control
  8. Cookies and Tracking Technologies
  9. Privacy of Children
  10. Updates to the Policy and Notifications
  11. Official Contact and Company Details

1. Introduction and Scope

Carent is a digital car sharing marketplace that brings car owners together with trustworthy drivers. In order for our services to operate with a high level of security and transparency, the accurate verification of the parties' identity, right to drive and vehicle documents is an essential condition.

By registering on the Platform or using our services, you consent to your personal data being collected and processed in the manner set out in this Policy.


2. Categories of Data We Collect

Carent collects only the data necessary for providing the services, ensuring security and meeting the requirements of the legislation:

2.1. Data You Provide Directly

  1. Account and Contact Data:

    • First name, last name, patronymic;
    • Email address and mobile phone number;
    • Date of birth and gender;
    • Profile photo and country/address of residence.
  2. Documents Verifying Identity and the Right to Drive (Verification):

    • For Citizens of the Republic of Azerbaijan: Photographs of the front and back of the ID card, the FIN code, the document series and number;
    • For Foreign Citizens and Tourists: A photograph of the main data page of the foreign passport, the passport number, the country of citizenship and the validity date;
    • For All Drivers: Photographs of the front and back of the driving licence, the licence number, its category and the dates of issue and expiry;
    • Liveness Check (Selfie / Liveness Check): A facial photograph taken within the app to confirm that the documents belong to their genuine holder and to prevent fraud.
  3. Data for Hosts (Car Owners and Rent-a-Car Companies):

    • The vehicle registration certificate, the state registration plate, the BAN/VIN code;
    • The compulsory motor insurance certificate and, where applicable, the comprehensive (kasko) insurance certificate;
    • A notarial power of attorney (where the vehicle is operated under a power of attorney);
    • For official Rent-a-Car companies: the company's legal name, tax ID (VÖEN), an extract from the state register and the details of the authorised representative;
    • Bank details for the transfer of earnings (IBAN or bank card details).
  4. Financial and Transaction Data:

    • The date, amount, payment method and status of rental fee payments.
    • Important Note: The 16-digit number of the user's bank card and the CVV/CVC security code are NOT STORED on Carent servers. All card transactions are carried out directly by licensed bank processing centres holding the international PCI-DSS security certification.

2.2. Data Collected Automatically While Using the Platform

  1. Trip and Booking Data: The dates selected, the delivery and handover locations, payment and cancellation records.
  2. Digital Handover Photo Protocols: Photographs of the vehicle from all 4 sides taken at the beginning and end of the trip, photographs of existing scratches/dents, and photographs of the speedometer (odometer) and fuel readings.
  3. Geolocation (Location) Data: Your device's GPS coordinates, used to find nearby vehicles on the map, to set the delivery address and to confirm the handover location (only where you have granted permission on your device).
  4. In-App Communication and Messages: In-app chat messages between the Renter and the Host, customer support requests, user reviews and star ratings.
  5. Device and Technical Access Data: IP address, unique device identifier (Device ID), operating system, app version and error logs (crash logs).

The personal data collected is processed within the framework of the following specific purposes and legal bases:

  • Provision of Services and Performance of the Contract: Creating the user profile, searching for vehicles, booking, establishing contact between the parties, processing payments and drawing up the digital handover protocol.
  • Security and Prevention of Fraud: Official verification of identity, the driving licence and vehicle documents; preventing fake accounts, theft and unlawful use.
  • Resolution of Disputes and Claims: Objective investigation of damage, speed camera fines and deposit disputes by means of handover photo protocols, odometer/fuel records and messages.
  • Fulfilment of Legal Obligations: Compliance with the tax, accounting and financial legislation of the Republic of Azerbaijan, as well as with the lawful requests of law enforcement authorities.
  • Improving Service Quality: Ensuring the technical stability of the app, eliminating errors and improving the user experience.

4. Sharing of Data and Disclosure

Carent protects the confidentiality of users' personal data and shares it only in the following cases:

4.1. Sharing Between the Renter and the Host

Once a booking is confirmed, only the data necessary for carrying out the trip is disclosed to the parties:

  • The other party's name, profile photo, rating, contact number and trip details.
  • IMPORTANT SAFEGUARD: The ID card number, the FIN code, a full copy of the foreign passport or bank card details are NEVER SHOWN to other users under any circumstances.

4.2. Technology Partners and Service Providers

Data is shared with licensed suppliers only to the extent necessary for the operation of the platform:

  • Payment Processing: Licensed bank processing centres and international payment gateways;
  • Secure Cloud Infrastructure: Cloud storage where data and documents are held in encrypted form (e.g. AWS S3);
  • Communication Providers: Communication services delivering SMS verification codes and transaction notifications.

4.3. State and Law Enforcement Authorities

Data may be provided only in accordance with the legislation of the Republic of Azerbaijan — on the basis of court decisions or official lawful requests from competent state authorities in the course of investigating criminal or administrative offences (for example, a road traffic accident, theft, speed camera fines).

4.4. Prohibition on the Sale of Data

Carent DOES NOT SELL, rent out or transfer for commercial purposes the personal data of its users to any third party, marketing company or advertising agency.


5. Data Security and Encryption

To protect personal data, Carent applies the most modern technical and organisational security standards:

  • Encrypted Storage (AES-256): ID cards, passports, driving licences and vehicle documents are held on servers that are entirely closed to public access (private encrypted storage).
  • Encryption in Transit (TLS 1.3 / SSL): All data exchange is protected by the highest level of encryption protocols.
  • Temporary Access Tokens: Authorised moderators who check documents can view them only through special encrypted token links that remain valid for a few minutes.
  • Two-Factor Authentication (2FA): A mandatory 2FA security mechanism operates in administrative and internal management systems.

6. Retention Period of Personal Data (Data Retention)

Personal data is retained only for the purposes for which it was collected and for the period established by law:

  • Active Accounts: Your data is retained for as long as your account is active.
  • When an Account Is Deleted: After a user deletes their account, identity and driving documents are completely deleted or securely anonymised within 30 days.
  • Financial and Accounting Records: In accordance with the requirements of the tax and accounting legislation of the Republic of Azerbaijan, invoice and transaction data is retained for the mandatory statutory period (5 years).
  • Photo Protocols and Trip Messages: Retained in the archive until the period for claims and disputes that may arise after the trip has ended expires.

7. User Rights and Control

Under the Law of the Republic of Azerbaijan "On Personal Data", you have the following rights:

  1. Right to Information (Access): To obtain detailed information about the personal data we hold about you;
  2. Right to Rectification: To update incorrect or changed data from the in-app profile settings, or to request its correction;
  3. Right to Erasure of Data: To request the deletion of your account and personal data from the system. More details: Account Deletion Rules;
  4. Withdrawal of Consent: To withdraw at any time the consent you previously gave;
  5. Data Portability: To request a structured electronic copy of your data.

To exercise your rights, you may send a formal request to destek@carent.az from the email address with which you registered. Requests are answered within 30 days at the latest.


8. Cookies and Tracking Technologies

  • Carent App (Mobile App): There are no third-party advertising trackers or commercial behavioural tracking systems within the app.
  • carent.az (Website): Only functional technical cookies necessary for the uninterrupted operation of the site, security sessions and remembering your language choice are used. More details: Cookie Policy.

9. Privacy of Children

The Carent platform is intended only for persons who have reached the age of 18 and have full legal capacity. We do not knowingly collect data from persons under the age of 18. If it is discovered that the data of a person under the age of majority has been entered, that account and data are deleted immediately.


10. Updates to the Policy and Notifications

Carent reserves the right to amend this Privacy Policy at any time. The updated Policy takes effect from the moment it is published on carent.az and in the Carent App. Users are informed of significant changes by in-app notification or by email.


11. Official Contact and Company Details

You may contact us with any questions about the Privacy Policy, the processing of your personal data or your rights:

  • Legal Entity: "CARENT" MMC
  • Address: Baku, Republic of Azerbaijan
  • Official Website: https://carent.az
  • Privacy Email: destek@carent.az
  • Contact Phone: +994 70 984 85 81