Privacy Policy

Last updated: August 25, 2026

What we collect, why, who it goes to, and what you can ask us to do with it.

Document Version: 2026-08-25 Last Updated: August 25, 2026 Effective Date: August 25, 2026

Penny Rental LLC, a Colorado limited liability company ("Penny," "we," "us," or "our"), is committed to safeguarding the privacy of individuals who interact with our bike rental management software platform, website located at https://www.penny.bike, booking widgets, customer kiosks, and administrative interfaces (collectively, the "Service" or "Platform").

This Privacy Policy explains what personal information we collect, how we process and protect it, with whom we share it, and the choices and rights available to you under applicable data privacy laws, including the Colorado Privacy Act (CPA), the California Consumer Privacy Act (CCPA/CPRA), and the General Data Protection Regulation (GDPR / UK GDPR).


TABLE OF CONTENTS

  1. Our Role: Data Controller vs. Data Processor
  2. Information We Collect
  3. How We Use Your Information
  4. How We Disclose and Share Information
  5. Sub-Processors and Service Providers
  6. Operator Impersonation for Support ("Masquerade")
  7. Data Security and Tenant Isolation
  8. Data Retention and Deletion
  9. Your Privacy Rights (Colorado CPA, California CCPA, GDPR)
  10. Cookies and Tracking Technologies
  11. Children's Privacy & Minor Participants
  12. International Data Transfers
  13. Changes to This Policy
  14. Contact Us

1. OUR ROLE: DATA CONTROLLER VS. DATA PROCESSOR

Depending on how you interact with Penny, we act as either a Data Controller (Business) or a Data Processor (Service Provider / Processor under CPA):

  • Data Controller: We act as a Data Controller for personal information collected directly from visitors to our public marketing website (`https://www.penny.bike`), prospective clients, and authorized account holders and staff of our bike shop clients ("Merchants" or "Shops").
  • Data Processor / Service Provider: When a customer ("Renter" or "End-User") books a bicycle rental, completes a digital waiver, or transacts through a shop's Penny booking widget or in-store kiosk, Penny processes that data on behalf of and under the instruction of the independent bike shop. The bike shop is the Data Controller responsible for the customer's personal data, and our processing is governed by our Data Processing Agreement (DPA).

2. INFORMATION WE COLLECT

2.1 Information Collected from Renters & Cyclists (on behalf of Shops)

When you make a reservation, book equipment, or sign a waiver:

  • Contact & Identity Information: Full name, email address, and mobile phone number. Phone numbers are used for in-person reservation lookup at shop counter kiosks and for direct communication by shop staff. *(Note: Penny does not collect or store physical mailing or billing addresses for renters; any billing address entered during payment checkout is processed directly by Stripe.)*
  • Rental & Equipment Preferences: Rental start and end dates/times, pickup/return locations, bicycle models, sizes, pedal preferences, helmet/accessory selections, and optional rider fit dimensions (e.g., rider height and weight required for suspension setup and bike sizing).
  • Electronic Waiver & Signature Data: Digital signature canvas data (base64 image), signer name, date and timestamp of signature, and optionally signer email and phone number.
  • Payment & Transaction Records: Transaction amounts, currency, line items, promo code usage, and Stripe transaction identifiers. *(Note: Full credit card numbers and CVV codes are processed directly by Stripe and are never received, stored, or transmitted through Penny servers.)*

2.2 Information Collected from Bike Shop Owners & Staff (Merchants)

When a shop creates an account or configures a tenant profile:

  • Business Profile: Business name, physical address, phone number, contact email, and business website URL. Tax identification numbers (EIN/SSN) are collected directly by Stripe during payment onboarding and are never received or stored by Penny.
  • Owner & Staff Credentials: Name, email address, authentication credentials, job titles, and system roles.
  • Integration Credentials: Stripe Connected Account IDs, Lightspeed POS OAuth tokens, catalog mappings, and inventory identifiers.
  • Subscription Billing Information: Billing contact details and Stripe subscription customer identifiers for Penny SaaS fees.

2.3 Automatically Collected Technical & Usage Data

When anyone visits our website, uses the admin dashboard, or interacts with our booking widget:

  • Device & Connection Data: IP address, browser type and version, operating system, language settings, and referring URLs.
  • Diagnostics & Error Logs: Application error and crash diagnostics (via Sentry), and standard server request logs. Penny does not operate behavioral analytics, session-recording, or cross-site tracking tools.

3. HOW WE USE YOUR INFORMATION

We process personal data for the following legitimate business purposes:

  • Fulfillment of Bookings: Allocating fleet inventory, calculating calendar-day and duration-tiered rental rates, applying store closure rules, and securing reservation holds.
  • Transactional Communications: Delivering automated booking confirmation emails, digital waiver signing links, and receipt notices via email.
  • Kiosk Lookup & Shop Operations: Enabling shop staff to quickly locate customer reservations at the counter using customer phone numbers or names.
  • POS & Maintenance Synchronization: Pushing inventory adjustments (e.g., helmet retail sales) and maintenance work orders to third-party POS systems (e.g., Lightspeed) under a generic shop account without transmitting individual renter records.
  • Legal Compliance & Record-Keeping: Maintaining version-controlled records of executed liability waivers and participant agreements to protect shops in equipment disputes.
  • Billing & Account Administration: Managing SaaS subscriptions, hibernation states, platform access, and customer support.
  • Security & System Reliability: Detecting malicious activity, unauthorized account access, payment fraud, and debugging application errors.

4. HOW WE DISCLOSE AND SHARE INFORMATION

We do not sell, rent, monetize, or trade personal data. We disclose personal information only in the following limited contexts:

  1. With the Designee Bike Shop: If you are a customer booking a rental, your personal details, reservation requests, fit specifications, and waiver signatures are shared directly with the specific bike shop where you made your reservation.
  2. With Authorized Sub-Processors: We share data with trusted infrastructure, communication, and payment vendors who process data strictly under our contractual instructions (see Section 5).
  3. Business Transfers: In connection with a merger, acquisition, reorganization, sale of company assets, or bankruptcy, personal data may be transferred as an acquired business asset, subject to standard confidentiality protections.
  4. Legal & Law Enforcement Obligations: When required by subpoena, court order, search warrant, or applicable statute, or to defend the legal rights, safety, and property of Penny, our partner shops, or the public.

5. SUB-PROCESSORS AND SERVICE PROVIDERS

Penny contracts with vetted third-party service providers ("Sub-Processors") to deliver core platform services:

Sub-ProcessorFunctionProcessing Location
Stripe, Inc.Payment processing, Connect merchant onboarding, subscription billingUnited States / Global
Vercel Inc.Web application hosting, serverless edge compute, and CDNUnited States / Global
Neon, Inc.Managed PostgreSQL database hosting (core customer and reservation data)United States
Google LLC (Firebase)User authentication and staff credential managementUnited States
Resend, Inc.Transactional email delivery (booking confirmations, waiver links)United States
Supabase, Inc.Media and file blob storage (shop logos, equipment images)United States
Functional Software, Inc. (Sentry)Application error monitoring and crash diagnosticsUnited States
Lightspeed Commerce Inc.Equipment catalog and maintenance work-order sync (opt-in; no renter PII transmitted)Canada / United States

All Sub-Processors are bound by written data processing agreements requiring industry-standard confidentiality, data protection, and security safeguards.


6. OPERATOR IMPERSONATION FOR SUPPORT ("MASQUERADE")

To provide technical support, assist with store configuration, and investigate software issues, authorized Penny administrative personnel may view or access a Shop's administrative interface using platform impersonation tools. This capability is used strictly for legitimate support requests, technical onboarding, or resolving reported system bugs. All administrative impersonation sessions are logged.


7. DATA SECURITY AND TENANT ISOLATION

We implement administrative, technical, and physical safeguards designed to protect personal data against accidental, unauthorized, or unlawful access, alteration, disclosure, or destruction:

  • Encryption: All data in transit is encrypted using modern TLS 1.3 / HTTPS encryption. Managed database volumes and stored media assets are encrypted at rest using industry-standard encryption.
  • Multi-Tenant Isolation: Database records are partitioned using strict tenant scoping (`shop_id`) to ensure no bike shop can access or view another shop's customer records, pricing, or rental data.
  • Access Controls & Code Enforcement: Access to production infrastructure is restricted to authorized personnel. Code changes undergo automated test and static-lint enforcement prior to deployment.
  • Payment Card Security: All payment card data is tokenized directly via Stripe Elements. Penny systems never store, process, or transmit raw credit card numbers or security CVV codes (PCI-DSS compliant architecture).

8. DATA RETENTION AND DELETION

  • Active Accounts: Personal data, customer booking history, and fleet records are retained for the duration of the Merchant's active subscription to provide historical reporting, customer lifetime value tracking, and repeat booking convenience.
  • Signed Liability Waivers: Signed liability waiver records (including signature images, timestamps, and signer names) are preserved to defend legal claims for the duration of the applicable statutory limitation period for personal injury claims.
  • Account Cancellation & Erasure: Upon termination or cancellation of a Shop subscription, the Shop may request a full export of its customer and reservation data. Following termination, the Shop may submit a written request to kyle@penny.bike to have its operational database records securely purged, subject to statutory record-keeping and waiver liability retention requirements.

9. YOUR PRIVACY RIGHTS (COLORADO CPA, CALIFORNIA CCPA, GDPR)

Depending on your geographic location, you may hold specific statutory privacy rights:

9.1 Colorado Resident Privacy Rights (Colorado Privacy Act - CPA)

If you are a Colorado resident, under the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.):

  • Right to Access & Portability: You have the right to confirm whether we process your personal data and access/obtain a copy in a portable format.
  • Right to Correction: You have the right to correct inaccuracies in your personal data.
  • Right to Deletion: You have the right to delete personal data provided by or obtained about you.
  • Right to Opt-Out: Penny does not sell personal data, process personal data for targeted advertising, or profile consumers in furtherance of decisions that produce legal or similarly significant effects.

9.2 California Privacy Rights (CCPA / CPRA)

If you are a California resident:

  • Right to Know / Access: You have the right to request the categories and specific pieces of personal information collected, sources, purposes, and third parties with whom it was shared.
  • Right to Delete: You have the right to request deletion of personal information, subject to statutory exceptions (such as maintaining executed waivers for liability defense or tax records).
  • Right to Correct: You have the right to request the correction of inaccurate personal information.
  • No Sale or Sharing for Cross-Context Advertising: Penny does not sell personal information or share personal data for cross-context behavioral advertising.
  • Non-Discrimination: We will not discriminate against you for exercising any of your statutory privacy rights.

9.3 European & UK Privacy Rights (GDPR / UK GDPR)

If you reside in the European Economic Area (EEA) or United Kingdom:

  • You have the right to access, rectify, erase, restrict processing of, and port your personal data, as well as the right to object to processing based on legitimate interests.
  • Where Penny processes your data as a Data Processor on behalf of a Bike Shop, please direct your request directly to the Bike Shop (the Data Controller). We will assist the shop in responding to your verified request.

9.4 How to Exercise Your Rights

To exercise any applicable privacy rights, please contact us at kyle@penny.bike.


10. COOKIES AND TRACKING TECHNOLOGIES

We use essential session cookies to maintain user logins, protect against cross-site request forgery (CSRF), and manage temporary 15-minute cart inventory holds. We do not use third-party cross-site tracking cookies for behavioral advertising.


11. CHILDREN'S PRIVACY & MINOR PARTICIPANTS

The Platform is not intended for direct use by individuals under eighteen (18) years of age, and we do not knowingly collect personal information directly from children. Where a bicycle rental involves a minor participant, the Shop is solely responsible for obtaining any parent or legal guardian authorization required by applicable law; the Platform records a single adult signer per waiver and does not itself verify guardian status.


12. INTERNATIONAL DATA TRANSFERS

Penny is operated in the United States (State of Colorado). If you access the Service from outside the United States, your personal data will be transferred to, stored, and processed in the United States. Where applicable, cross-border transfers are safeguarded by Standard Contractual Clauses (SCCs).


13. CHANGES TO THIS POLICY

We may update this Privacy Policy periodically to reflect enhancements to our platform, regulatory guidance, or operational practices. We will notify you of material changes by revising the "Last Updated" date and document version at the top of this page and providing prominent notice via our website or dashboard.


14. CONTACT US

If you have questions, comments, or concerns regarding this Privacy Policy or our data practices, please contact our Data Protection team at:

Penny Rental LLC Kyle Christian State of Organization: Colorado, USA Email: kyle@penny.bike Website: https://www.penny.bike