Privacy Policy

Beta version · last updated September 21, 2026

This is a beta draft written for the Florida launch and has not yet been reviewed by an attorney. It will be replaced by a reviewed version before general availability.

This policy explains what Odomo collects, why, who helps us process it, and what you can do about it. It covers Hosts who use Odomo to run a rental business, the renters they deal with through Odomo, and visitors to our pages. It is a beta draft and will be replaced by an attorney-reviewed policy before general availability.

1. Two kinds of people, two roles

Hosts are our customers. A Host creates a workspace and enters information about their cars, their renters and their bookings. For that information the Host decides what is collected and why; Odomo stores and processes it on the Host's behalf.

Renters interact with a Host through pages Odomo provides: a booking page, a deposit page, an agreement to sign, a license check, and the Host's text and phone number. If you are a renter, the Host is the business you are dealing with. This policy tells you what Odomo does with your information on the Host's behalf; the Host may also have their own notice.

2. What we collect

From Hosts and their team:

  • Account: name, email, password (stored hashed by our authentication provider), optional profile photo, and, if you turn it on, a two-factor authentication secret.
  • Workspace: business name, plan, operating state and city, booking-page settings, deposit rules, message templates and the rental agreement template.
  • Fleet: year, make, model, color, plate, VIN, mileage, rates, photos, home address and parking notes, maintenance and expense records.
  • Payments setup: your Stripe connected account id and whether onboarding is complete. Bank and tax details are collected by Stripe, not Odomo.
  • Phone: the number provisioned for your workspace and its settings.
  • Device: push-notification subscriptions you opt into, the app version, and standard server logs (IP address, browser, timestamps).

About renters (entered by the Host or provided by the renter):

  • Contact: name, email, phone number.
  • Driver's license: number, issuing state and expiry as typed by the Host or renter, and a license photo if the Host uploads one.
  • Identity verification (only if the Host turns it on): the result of a Stripe Identity check, namely verified or not, the name, date of birth, document type and issuing state read from the document, and flags such as an expired document. We do not receive or store the document images or the selfie; Stripe holds those under its own policy.
  • Bookings: dates, vehicle, pickup and return locations, prices, deposits and their payment status. Card numbers never touch Odomo; Stripe processes them and we store the amount, status and Stripe's reference ids.
  • Agreements: the text of each rental agreement, the drawn signature, the signer's typed name and license details, and the time, IP address and device of signing. We also log when an agreement is opened and any screenshot or screen-recording attempts inside the app.
  • Messages: texts sent and received on the Host's number, and messages drafted or sent in the app, with delivery status. Phone calls answered by the AI receptionist are transcribed and the transcript is stored in the Host's inbox; audio is not retained by Odomo.
  • Inspections and damage: checklists, odometer and fuel readings, photos, videos and notes from pre- and post-trip inspections, and any damage reports.
  • Host notes, tags and an AI-generated risk summary based only on the Host's own records about that renter.
  • Leads: name, contact details and message left through a Host's booking page.

We do not use advertising trackers or third-party analytics on Odomo pages. We use a small number of cookies strictly to keep you signed in and to remember preferences like theme.

3. How we use it

  • To run the service: show a Host their fleet and bookings, take deposits, send agreements and links, deliver texts and emails, answer calls and texts on a Pro Host's behalf, and notify the Host.
  • To power AI features: when a Host uses the assistant, or the receptionist answers a renter, the relevant workspace data (for example availability, prices and the conversation so far) is sent to OpenAI to generate a reply. OpenAI's API terms prohibit it from training on this data.
  • To keep the service secure and reliable: authentication, abuse prevention, debugging, backups.
  • To meet legal obligations, including payment-network and tax rules that apply through Stripe.
  • To contact Hosts about the service. We do not send marketing to renters, and Hosts may only text renters who have asked to hear from them.

We do not sell personal information and we do not share it for cross-context behavioral advertising.

4. Who we share it with

Only providers that do a job for us, each limited to what that job needs:

  • Supabase (database, authentication, file storage) – all workspace data, in the United States.
  • Stripe (payments, payouts, identity verification) – payment amounts and references; for identity checks, the renter's document and selfie go directly to Stripe.
  • Callnode (phone numbers, texting, calls) – phone numbers and message contents on a Host's number; call audio is routed through Callnode to OpenAI for AI-answered calls.
  • OpenAI (AI assistant, receptionist, transcription, speech) – the text and workspace data needed for a given request, and audio for AI-answered calls.
  • Resend (email) – the recipient address and the contents of invites, agreements, pay links and confirmations.
  • U.S. National Highway Traffic Safety Administration (vehicle catalog) – VINs and make/model queries only; no personal data.
  • Hosting on servers in the United States.

We may also disclose information if the law requires it, to protect people or the service, or as part of a merger or sale of Odomo, in which case this policy continues to apply.

Within a workspace, owners and co-hosts can see renter records; inspectors can only see inspections for cars assigned to them.

5. If you are a renter

  • You can text STOP to a Host's number at any time and no further automated or bulk texts will be sent from it.
  • When you call a Host's number and an AI receptionist answers, it will say so and tell you the call may be transcribed. You can ask for a person at any time.
  • Identity verification is optional for the Host to require and for you to complete; if you do not complete it, contact the Host directly.
  • You receive an emailed summary of any agreement you sign. Ask the Host for a full copy.
  • To see, correct or delete information a Host holds about you, contact that Host first; they control it. If you cannot reach them, write to us and we will help.

6. How long we keep it

Workspace data is kept for as long as the workspace exists. Hosts can delete individual renters, bookings and files at any time. When a workspace is closed we delete its data within 30 days, except records that must be kept for legal, tax, payment-network or dispute reasons, which are kept for as long as those rules require and then deleted. Signed agreements and their signing records are kept while the booking they belong to exists, because they may be needed in a dispute.

Server logs are kept for up to 90 days. Backups roll off within 30 days of deletion.

7. How we protect it

Data is encrypted in transit. Every database query is scoped to the caller's workspace by row-level security, so one Host cannot read another's records. License photos, inspection media and agreements live in private storage reachable only through short-lived signed links. Secrets are stored only on our servers. Two-factor authentication is available to every account. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as Florida law requires.

8. Your choices and rights

  • Access and export: Hosts can download renters, fleet and finances as CSV from Settings at any time.
  • Correction: edit your profile and records in the app.
  • Deletion: delete records in the app, or write to us to close a workspace.
  • Notifications: push notifications are opt-in and can be turned off on the device or in Settings.
  • Do Not Track: we do not track you across sites, so there is nothing to opt out of.

If you live in a state with a consumer privacy law (for example California, Colorado, Virginia, Texas or Florida's Digital Bill of Rights, to the extent it applies), you may have rights to access, delete, correct and port your data and to opt out of sales or targeted advertising. We do not sell data or advertise, and you can exercise the other rights by writing to us. We will not treat you differently for doing so.

9. Children

Odomo is for adults running a business and for adult renters. We do not knowingly collect information from anyone under 18; if you believe we have, write to us and we will delete it.

10. Changes

We will update this policy as the product changes and before general availability. Material changes are announced to Hosts by email or in the app; the date at the top is the current version.

11. Contact

Privacy questions or requests: support@odomo.ai.