Last updated 19 September 2026
This agreement covers the personal data we handle on your behalf when you use DrumFleet. It applies automatically when you accept the Terms of Service. Nothing needs to be signed.
1. What this is
This agreement is part of the Terms of Service between DrumFleet LLC (“DrumFleet”, “we”, “us”) and the operator (“you”).
If it conflicts with the terms, this agreement wins on how personal data is handled. Everything else in the terms applies to this agreement too.
The limits on liability in section 14 of the terms apply to this agreement. Claims under this agreement and claims under the terms count together toward the single cap in that section. This agreement does not create a separate or additional cap.
This agreement is between you and us only. Your renters and team members have no rights under it.
2. Who is who
For the personal data you hold about your renters, you are the controller and we are the processor. You decide what to collect and why. We hold and process it on your instructions, which in practice means operating the software you are using. Where a privacy law uses different words, you are the “business” and we are your “service provider”.
Your instructions to us are the terms, this agreement, and the way you configure and use the Service. If we believe an instruction breaks the law, we will tell you.
For your own account data, we are the controller. That is covered by our privacy policy.
3. What we process, and why
Whose data. Your renters and applicants, other people named on an agreement or at an install address such as landlords and property managers, and the team members you invite.
What data.
- Identity and contact: name, email address, phone number, install and billing addresses.
- Identification: images of government ID, where you choose to collect them.
- Agreements: signed rental agreements, signatures and initials, and the signing record, including time and IP address.
- Payments: amounts charged, paid, failed and owed, deposit and fee history, the card brand and last four digits, and identifiers from the payment processor. Full card numbers do not reach our servers.
- Messages: emails sent through the Service, delivery status, and opt-outs. The Service sends no text messages.
- Equipment and service: which machines are at which address, condition photos, service requests and notes.
- Technical data: session cookies, and IP addresses in server logs.
Why. We process this data to run the Service for you, to keep it secure, to prevent fraud and abuse, to find and fix faults, and to comply with law. We may also produce aggregated, de-identified statistics as described in section 9 of the terms.
We do not sell it. We do not share it with advertising platforms, and we do not market to your renters. We do not use one operator’s renter data to benefit another. We do not keep, use or disclose it for any purpose other than those above, and we do not combine it with personal data from other sources except where the law allows a service provider to do so. If we find we can no longer meet these obligations, we will tell you.
4. Your side
As controller, you are responsible for the following.
- Having the right to collect your renters’ data and to give it to us, including anything you import.
- Giving your renters the privacy notice the law requires, and getting any consent the law requires, including for ID images and for emails and texts.
- Deciding whether to collect ID images, who on your team can see them, and when they are deleted.
- Keeping prohibited data out of the Service: Social Security numbers, full card numbers, bank account numbers, health information, and data about children.
- Not using the Service to report renters to credit bureaus or to screen renters with consumer reports.
- Making sure your instructions to us are lawful.
- Answering your renters’ requests about their data, and deciding who to notify after a breach.
- Securing your own accounts, devices and exported files.
Section 15 of the terms (indemnity) applies to claims that arise because you did not meet these responsibilities.
5. Separation between operators
The Service is built so that each operator’s data is scoped to that operator. It is designed so that another operator cannot read your renters, agreements, machines or payments. Signed agreements and ID images are held in private storage and served only through an authorisation check.
6. Sub-processors
You authorise us to use third-party providers to run the Service. Each is engaged under written data protection terms no less protective than this agreement, and each may process your renters’ personal data only to deliver the function it is listed for. Our responsibility to you for what they do with that data is the same as for what we do ourselves, and is subject to the limits on liability in the terms.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Laravel Cloud | Application hosting, databases, object storage, backups, CDN and TLS | All application data, including signed agreements and ID images | United States |
| Resend | Sending email on your behalf | Name, email address, message content | United States |
| Stripe | Subscription billing for your own DrumFleet plan | Business and contact details, plan and payment status | United States |
Changes. Before a new sub-processor starts handling your renters’ data, we will update this list and tell you by email or in the app at least 14 days ahead. If you object on reasonable data-protection grounds, tell us within that time. If we cannot resolve it, you may cancel, and we will refund any fees you prepaid for the period after cancellation.
Stripe. Your renters’ payments are processed by Stripe under your own Stripe account and your own agreement with Stripe. Card details go directly from your renter to Stripe. For those payments Stripe is your provider, not our sub-processor.
7. Security
We maintain reasonable technical and organisational measures to protect your renters’ data. Those measures currently include the following.
- Traffic is encrypted in transit, including on custom domains.
- Passwords are hashed, never stored recoverably.
- Signed agreements and ID images are kept in private storage and served only after an authorisation check.
- Card details are handled by the payment processor and are not stored on our servers.
- Access to production data is limited to people who need it, and they are bound by confidentiality obligations.
- Activity inside an account is logged, and backups are taken regularly.
We may change these measures as long as the overall level of protection does not fall. No system is perfectly secure. This section describes our practices; it is not a promise that an incident will never happen.
8. Your renters’ rights
Because you are the controller, requests from your renters for access, correction, deletion or a copy of their data come to you. The software gives you what you need to answer them: renter records are visible and editable in your account, and renters, agreements and payments export as CSV.
If such a request reaches us directly and we can tell which operator it concerns, we will not action it ourselves. We will pass it to you promptly and give you reasonable help to respond. If you need help beyond what the software already lets you do yourself, we may charge a reasonable fee, which we will tell you first.
9. Retention and deletion
We hold your data for as long as your account is open, including while it is read-only under section 5 of the terms. After an account is closed, data is deleted from our live systems within 90 days, and backups are overwritten within a further 35 days. You may ask for earlier deletion.
Records we are required to keep for tax or accounting purposes, anything needed to resolve a dispute, and log entries recording that a deletion happened are retained separately for as long as needed. You can export your data at any time before deletion.
10. Breach notification
A breach means confirmed unauthorised access to, or loss or disclosure of, your renters’ personal data on systems we or our sub-processors control. Unsuccessful attempts, such as blocked logins and port scans, do not count. Access gained through your own compromised credentials or devices is yours to handle, though we will help.
If we confirm a breach, we will notify you without undue delay. We will tell you what we know about what happened, who is affected and what we are doing about it, and will update you as we learn more. A notice from us is not an admission of fault or liability.
Notifying your renters and any regulator is your decision as controller, and we will give you the information you reasonably need to make it. Any liability we have for a breach is subject to the limits in section 14 of the terms.
11. Information and audits
On reasonable written request, and no more than once a year, we will answer written questions and provide a summary of our security measures so you can confirm we are meeting this agreement. More frequent or more detailed requests may carry a reasonable fee. Because the platform is shared between operators, on-site inspections and testing of our systems are not available. If a law gives you an audit right that goes further, we will first agree its scope, timing, cost and confidentiality with you.
12. Legal requests
If a court or government body demands your renters’ data from us, we will tell you before responding unless the law forbids it, and we will disclose only what is required.
13. Where data is held
Data is stored and processed in the United States, on infrastructure operated by the providers listed in section 6.
This agreement is written for operators in the United States. It does not include the transfer terms that European or UK data protection law requires. If you are established in, or rent to customers in, the EEA or the UK, contact us before using the Service.
14. Term, changes and contact
This agreement lasts for as long as we hold your renters’ data. We may update it in the way section 17 of the terms describes.
Anything about this document, or a request that needs a human: hello@drumfleet.com.
Questions about anything here? hello@drumfleet.com