ResurveCentro legal

En esta página

1. Who this Privacy Policy covers2. Resurve’s role: controller, processor, and independent service provider2.1 When Resurve acts as a controller2.2 When Resurve acts as a processor for a Business2.3 Businesses remain responsible for their own privacy compliance2.4 Resurve may have a separate controller purpose for limited data2.5 Payment providers and other third parties may be independent controllers2.6 Written processing terms3. Personal data we collect or receive3.1 Identity and contact information3.2 Business and account information3.3 Customer, reservation, and transaction information3.4 Car-rental and vehicle-operation information3.5 Identity and verification data3.6 Payment and financial information3.7 Affiliate and referral information3.8 Communications and support information3.9 Device, network, usage, and technical information3.10 Storefront, listing, review, and public information3.11 Information from third parties4. Special-category, sensitive, and unnecessary data5. Where the information comes from6. Why we process personal data and the legal bases we may rely on6.1 Providing and operating the Services6.2 Facilitating Business-to-Customer transactions6.3 Payment coordination6.4 Verification, compliance, fraud prevention, and safety6.5 Service communications6.6 Product improvement, analytics, and research6.7 Aggregated and de-identified data6.8 Marketing and business development6.9 Legal, regulatory, and dispute purposes6.10 Corporate transactions and financing7. Business Customer Data7.1 Business instructions7.2 Business responsibility for collection and notices7.3 Requests concerning Business-controlled data7.4 Business access7.5 Imported data8. Lead provenance, referrals, marketplace attribution, and storefront modes9. Payment providers, acquiring banks, and financial information10. Messaging, WhatsApp, SMS, email, and communications10.1 Messages from Resurve10.2 Messages sent for a Business10.3 Communications platforms10.4 Message records11. Vehicle location, telematics, cameras, and tracking technologies12. AI, machine learning, analytics, and automated tools12.1 Human responsibility12.2 Solely automated significant decisions12.3 Product improvement and model development13. Cookies and similar technologies14. When we disclose personal data14.1 Businesses14.2 Customers14.3 Service providers and subprocessors14.4 Payment participants14.5 Integrations and third-party apps14.6 Affiliates and referral partners14.7 Professional advisers14.8 Authorities, regulators, courts, and legal recipients14.9 Protection of rights and safety14.10 Corporate transactions15. Selling, sharing, and advertising uses of personal data16. International transfers17. Data retention, deletion, and backups17.1 Business Customer Data17.2 Account closure17.3 Backups17.4 Legal holds17.5 De-identification instead of deletion18. Security19. Personal data breaches20. Your privacy rights20.1 How to make a request to Resurve20.2 Requests concerning a Business20.3 Time limits20.4 Manifestly excessive or abusive requests20.5 Complaints in Mauritius21. Marketing choices22. Children and minors23. Third-party websites, apps, services, and integrations24. Research, beta features, and optional programs25. Businesses using Resurve have independent privacy obligations26. Additional information for users in the EEA, United Kingdom, or jurisdictions with GDPR-style laws27. Additional information for United States residents28. Changes to this Privacy Policy29. Relationship with other Resurve terms30. Contact Resurve
← Todos los documentos legales

Privacy Policy

Última actualización el 23 August 2026 · Versión 2

Privacy Policy

Last updated: 23 August 2026

Company: RESURVE LTD, a company incorporated in Mauritius (Company No. 236684; Business Registration Number (BRN) C236684), with registered office at Lot 2, Robert Rey Street, Roches Brunes, Beau Bassin, Mauritius (“Resurve”, “we”, “us”, or “our”).

Privacy and legal contact: legal@resurve.net

Resurve is established in Mauritius and is subject to the Mauritius Data Protection Act 2017 where that law applies. Depending on where an individual is located, where a Business operates, and how the Services are used, other privacy and data-protection laws may also apply.

This Privacy Policy explains how Resurve collects, receives, uses, stores, discloses, transfers, protects, and otherwise processes personal data in connection with:

  • resurve.net and marketplace pages on resurve.net;
  • Business storefronts at {handle}.resurve.net;
  • dashboard.resurve.net;
  • affiliate.resurve.net;
  • ops.resurve.net;
  • Resurve mobile, tablet, point-of-sale, or other applications where offered;
  • Resurve APIs, integrations, developer features, and connected services;
  • emails, in-app notifications, WhatsApp, SMS, support communications, and other communications sent through or in connection with the Services; and
  • other Resurve products, features, websites, applications, or services that link to this Privacy Policy.

Together, these are the “Services”.

This Privacy Policy should be read together with our Terms of Service, Acceptable Use Policy, Cookie Policy, and any additional terms that apply to a particular Service.

Everyday-language summaries beginning with “Which means” are provided for convenience only. They do not replace, limit, or modify the legal wording of this Privacy Policy.

Nothing in this Privacy Policy is intended to waive, exclude, or restrict a privacy or data-protection right that cannot lawfully be waived, excluded, or restricted.


1. Who this Privacy Policy covers

Which means: This Policy covers people who interact with Resurve as Business users, Customers, affiliates, visitors, and other users, but Resurve’s legal role is not the same in every situation.

This Privacy Policy may apply to:

  1. Business users — owners, directors, employees, contractors, agents, staff, and administrators of businesses using Resurve (“Businesses”).
  2. Customers — people who browse, enquire, reserve, book, rent, purchase, pay, communicate with, or otherwise transact with a Business through or in connection with the Services (“Customers”).
  3. Affiliates and referrers — people and organisations participating in a Resurve affiliate, referral, partner, or similar program.
  4. Visitors and prospects — people who visit Resurve websites, request information, join a waitlist, participate in research, or communicate with us without creating a paid Business account.
  5. Developers and integration users — people who access an API, integration, developer tool, or connected application.
  6. Resurve staff and applicants — employees, contractors, applicants, and internal users. Additional employment, contractor, security, or recruitment notices may apply.
  7. Other individuals — people whose personal data is provided to Resurve in connection with a booking, rental, transaction, operating file, support matter, legal matter, or other authorised use of the Services.

If you interact with a Business that uses Resurve, that Business may have its own privacy notice. The Business’s privacy notice governs the Business’s independent processing of your personal data. This Privacy Policy does not replace a Business’s own privacy obligations.


2. Resurve’s role: controller, processor, and independent service provider

Which means: Sometimes Resurve decides why and how data is used. Sometimes we process data only for a Business. Separating those roles is important.

The terms “controller”, “processor”, “data subject”, “personal data”, “processing”, and similar terms have the meanings given to them by applicable data-protection law.

2.1 When Resurve acts as a controller

Resurve generally acts as a controller, or equivalent decision-maker, for personal data where we determine the purposes and essential means of processing. This may include processing for:

  • Business account registration, account administration, authentication, billing, and support;
  • Resurve Customer accounts, where offered;
  • affiliate and referral accounts;
  • visitors, prospects, research participants, and people who communicate directly with Resurve;
  • security, fraud prevention, platform integrity, abuse prevention, incident response, and enforcement;
  • service telemetry, product analytics, performance monitoring, and platform improvement;
  • marketplace discovery, Resurve-originated lead provenance, attribution, and marketplace analytics;
  • Resurve’s own transactional, administrative, legal, and marketing communications;
  • legal compliance, regulatory responses, audits, disputes, and the establishment, exercise, or defence of legal claims;
  • information required to verify a Business, account representative, affiliate, or user where Resurve determines the verification purpose;
  • aggregated, statistical, or de-identified information created by Resurve; and
  • other processing where Resurve is required or permitted by law to determine the purposes of processing.

2.2 When Resurve acts as a processor for a Business

Where a Business uses Resurve to collect, store, organise, retrieve, communicate, or otherwise process Customer personal data for the Business’s own rental, reservation, service, fulfilment, customer-management, or operational purposes, the Business generally acts as controller and Resurve generally acts as its processor or service provider.

Examples may include:

  • Customer contact records maintained by a Business;
  • reservations and rental records created through a Business’s storefront;
  • operating files;
  • pickup and return information;
  • vehicle assignments;
  • Business-created custom fields and notes;
  • Customer documents uploaded at the Business’s request;
  • Business-directed emails, reminders, WhatsApp messages, or other communications;
  • Business customer lists imported into Resurve;
  • incident, damage, inspection, or fulfilment records maintained on the Business’s instructions; and
  • other data the Business chooses to enter into, import into, or collect through the Services for its own purposes.

Where Resurve acts only as processor, the Business determines the purposes for which that Customer personal data is collected and used, subject to the Business’s agreement with Resurve and applicable law.

2.3 Businesses remain responsible for their own privacy compliance

A Business is responsible for its own processing of personal data, including, where applicable:

  • identifying an appropriate lawful basis;
  • providing legally required privacy notices;
  • obtaining valid consent where consent is required;
  • deciding what information it needs from Customers;
  • ensuring the accuracy, relevance, and lawfulness of information it uploads or collects;
  • configuring forms, custom fields, retention choices, integrations, staff access, and communications lawfully;
  • responding to Customer privacy requests for data the Business controls;
  • complying with direct-marketing, telecommunication, employment, surveillance, vehicle-tracking, insurance, consumer, rental, tourism, and other laws that apply to the Business;
  • ensuring that its employees, agents, and service providers are authorised to access Customer data; and
  • ensuring that it has authority to instruct Resurve to process the personal data it provides.

A Business must not use Resurve as a means of avoiding privacy or data-protection obligations that would otherwise apply to the Business.

2.4 Resurve may have a separate controller purpose for limited data

The fact that Resurve receives information as a processor does not prevent Resurve from acting as a controller for a separate and legally permitted purpose where applicable law allows it.

For example, Resurve may independently process limited account, event, security, fraud, technical, payment-reference, provenance, or audit information to secure the Services, prevent abuse, maintain platform integrity, comply with law, defend legal claims, prevent duplicate or fraudulent accounts, measure Resurve-originated marketplace activity, or operate Resurve’s own Customer-account features.

Where Resurve acts as controller for such a separate purpose, that processing is governed by this Privacy Policy.

2.5 Payment providers and other third parties may be independent controllers

Payment service providers, acquiring banks, banks, identity-verification providers, telecommunications providers, social-login providers, insurers, governmental bodies, and other third parties may process personal data as independent controllers under their own privacy notices and legal obligations.

Resurve does not control how an independent third-party controller processes personal data for that third party’s own purposes.

2.6 Written processing terms

Where Resurve acts as a processor for a Business, the data-processing provisions incorporated into the Business’s agreement with Resurve and, where applicable, a separate Data Processing Addendum (“DPA”) govern that processing in addition to this Privacy Policy.

Where Mauritius law applies, the Business and Resurve intend the applicable written Business agreement and any DPA to constitute the written controller-processor arrangement required by law for the processing it covers.

If there is a conflict between this Privacy Policy and an executed DPA regarding processor obligations, the DPA controls to the extent of that conflict.


3. Personal data we collect or receive

Which means: The data depends on how you use Resurve. A simple visitor gives us much less information than a Business operator or a Customer completing a rental file.

We may collect or receive the categories below. We do not necessarily collect every category from every person.

3.1 Identity and contact information

This may include:

  • full name;
  • email address;
  • telephone or mobile number;
  • billing, residential, registered-office, pickup, return, delivery, or other address;
  • country, region, city, nationality, or preferred language where relevant;
  • profile photo or account avatar;
  • date of birth where required for a lawful feature, verification, booking, or rental process;
  • business role, job title, employer, or organisation;
  • emergency or authorised-contact details where a lawful operational workflow requires them; and
  • other contact information you choose to provide.

3.2 Business and account information

For Business users, this may include:

  • legal entity name and trading name;
  • company, business, tax, tourism, rental, licence, or registration numbers;
  • registered office and operating addresses;
  • business type and operating market;
  • director, owner, authorised representative, beneficial-owner, or staff information where required;
  • business licences, permits, certificates, proof of address, or similar onboarding records;
  • account plan, subscription, invoices, billing details, and account status;
  • usernames, account identifiers, authentication information, role permissions, and security settings;
  • storefront handle and domain information;
  • Business policies, cancellation rules, operating hours, fleet information, pricing, and public listing information; and
  • information provided during onboarding, support, compliance, research, or account verification.

3.3 Customer, reservation, and transaction information

Depending on the Business and vertical, this may include:

  • reservation or booking dates and times;
  • requested service, rental, product, vehicle, or resource;
  • pickup, delivery, fulfilment, and return locations;
  • booking status, changes, cancellations, extensions, no-shows, refunds, or other lifecycle events;
  • quoted and final prices, fees, deposits, taxes, discounts, extras, balances, and payment status;
  • Customer preferences or lawful operational notes;
  • communications connected to the booking;
  • signed acknowledgements or records;
  • fulfilment evidence;
  • service history;
  • complaint, refund, dispute, chargeback, or support information; and
  • other information reasonably required by the Business to provide the requested service.

3.4 Car-rental and vehicle-operation information

For car-rental or mobility Businesses, information processed through the Services may include:

  • driving-licence information, including licence number, issuing jurisdiction, issue date, expiry date, and licence class;
  • identity-document information where the Business lawfully requires it;
  • Customer age or date of birth where required to verify rental eligibility;
  • additional-driver information;
  • vehicle registration number, VIN or chassis number, make, model, category, year, odometer, fuel or charge level, and vehicle status;
  • pickup and return inspection information;
  • vehicle photos and videos;
  • pre-existing and post-rental damage records;
  • signatures and acknowledgements;
  • maintenance and service information;
  • fines, tolls, citations, traffic or parking records where lawfully processed;
  • accident or incident reports;
  • insurance, claim, recovery, or roadside-assistance information;
  • police, reference, or case information where lawfully required;
  • vehicle location or telematics information where a Business integrates such information and applicable law permits it; and
  • other operational evidence a Business chooses to maintain in a rental file.

A Business is responsible for determining whether it is legally permitted to collect and use this information and for giving Customers any notice or obtaining any consent required by law.

3.5 Identity and verification data

Where verification is required, Resurve or a Business may request or receive information such as:

  • government-issued identification;
  • driving licence;
  • passport or national identity document;
  • proof of address;
  • business-registration documentation;
  • photographs used for verification;
  • verification result, status, or risk signal; and
  • information obtained from an authorised verification or compliance provider.

We may use third-party providers to perform verification. A provider may separately process information under its own legal obligations and privacy notice.

Unless a specific Resurve feature expressly supports it and applicable law permits it, users should not submit biometric templates, facial-recognition templates, health information, criminal-history information, or other special-category or highly sensitive personal data through ordinary notes, free-text fields, uploads, or custom fields.

3.6 Payment and financial information

When payments are enabled, Resurve may receive or process information such as:

  • transaction amount and currency;
  • payment status;
  • payment method category;
  • payment-provider or acquiring-bank reference;
  • tokenised payment reference;
  • partial payment-card information such as card brand, expiry information, or last digits where supplied by the payment provider;
  • authorisation, capture, refund, reversal, void, deposit, chargeback, dispute, or settlement status;
  • invoice or billing details;
  • bank or payout details for Resurve subscription billing or affiliate payments where applicable; and
  • reconciliation and settlement metadata.

Card payment credentials may be collected directly by a payment service provider or acquirer. Unless expressly stated otherwise for a particular payment flow, Resurve is designed so that full payment-card numbers and card security codes are handled by authorised payment providers rather than stored by Resurve.

Payment providers may perform their own fraud-prevention, authentication, compliance, sanctions, anti-money-laundering, dispute, or risk processing.

3.7 Affiliate and referral information

For affiliates, referrers, or partners, we may process:

  • identity and contact information;
  • affiliate account information;
  • referral links, codes, campaign identifiers, and attribution data;
  • referred Business or account status;
  • qualifying-event and commission information;
  • payout information;
  • tax or compliance information where required; and
  • anti-fraud and program-integrity information.

Affiliates generally receive only the information reasonably necessary to administer attribution and commissions. They are not automatically entitled to Customer personal data merely because a Customer or Business was referred through an affiliate link.

3.8 Communications and support information

We may process:

  • emails, tickets, forms, chat messages, WhatsApp messages, SMS messages, and in-app messages;
  • communications between a Business and Customer where the communication feature is provided through Resurve;
  • support history and troubleshooting information;
  • attachments;
  • call details and, where lawful and appropriately disclosed, call recordings or transcripts;
  • feedback, reviews, research interviews, survey responses, and product suggestions; and
  • information you provide when reporting suspected fraud, abuse, a security issue, or a legal concern.

3.9 Device, network, usage, and technical information

We may automatically receive information such as:

  • IP address;
  • device type;
  • browser type and version;
  • operating system;
  • app version;
  • device identifiers;
  • language and time-zone settings;
  • approximate location inferred from IP address;
  • login date, time, and authentication events;
  • pages or screens viewed;
  • referring and exit pages;
  • search and navigation events;
  • feature interactions;
  • error, crash, diagnostic, and performance information;
  • API requests;
  • security events;
  • session identifiers; and
  • cookies and similar technologies described in our Cookie Policy.

Where a feature requires precise device location, we will request device permission or otherwise provide notice where required by law.

3.10 Storefront, listing, review, and public information

Businesses may provide information intended to be displayed publicly, such as:

  • business name;
  • trading name;
  • public address or service area;
  • contact details;
  • opening hours;
  • vehicle or service listings;
  • prices;
  • photographs;
  • policies;
  • descriptions;
  • availability;
  • reviews or ratings where enabled; and
  • other marketplace or storefront content.

Where Resurve offers public profiles, reviews, marketplace listings, or similar features, information intentionally published through those features may be visible to the public.

Information deliberately made public may be viewed, copied, cached, indexed, archived, syndicated, or otherwise processed by search engines and third parties beyond Resurve’s control.

Locked Business storefronts and indexed Resurve marketplace pages may have different discovery and indexing rules.

3.11 Information from third parties

We may receive information from:

  • Businesses;
  • Customers;
  • authorised staff users;
  • payment service providers, acquirers, banks, and payment networks;
  • social-login or identity providers;
  • verification, compliance, fraud, or security providers;
  • affiliates and referral partners;
  • connected applications and integrations;
  • public registers and lawful public sources;
  • governmental or regulatory bodies;
  • professional advisers;
  • counterparties to disputes or legal claims; and
  • other third parties where collection is lawful.

We may combine information received from third parties with information we already hold where lawful.


4. Special-category, sensitive, and unnecessary data

Which means: Do not turn Resurve’s notes or upload fields into a storage place for highly sensitive information that the workflow does not actually need.

Certain laws impose additional restrictions on information such as health data, biometric data used for unique identification, genetic data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, sexual-orientation information, or criminal-offence information.

Unless a particular Resurve feature expressly supports the processing and the processing is lawful:

  1. Businesses and users must not use general notes, custom fields, free-text fields, messaging, or ordinary uploads to collect or store unnecessary special-category personal data.
  2. Businesses are responsible for determining whether a lawful basis and any additional legal condition exists before instructing Resurve to process sensitive information.
  3. Businesses must not collect information merely because a field can technically accept it.
  4. Users should redact irrelevant sensitive information from documents before uploading them where practical.
  5. Resurve may restrict, reject, quarantine, remove, or require deletion of data that we reasonably believe creates an unlawful or disproportionate privacy or security risk.

This section does not prohibit lawful identity, driving-licence, accident, insurance, or other information reasonably necessary for a legitimate rental or service workflow, but users should collect only what is necessary and legally permitted.


5. Where the information comes from

Which means: We get information from you, from the Business you deal with, automatically from the Services, and from service providers or lawful third-party sources.

We may obtain personal data:

  1. Directly from you, when you create an account, make a booking, complete a form, upload a document, pay, contact support, join an affiliate program, or otherwise interact with the Services.
  2. From a Business, when the Business creates or imports a Customer record, booking, operating file, document, note, communication, or other record.
  3. Automatically, through the use of the Services, cookies, logs, APIs, security tools, and similar technologies.
  4. From payment and financial providers, in connection with authorisation, payment status, refunds, disputes, settlements, verification, or fraud prevention.
  5. From integrations and connected services, where a Business or user authorises a connection.
  6. From affiliates or referral partners, for attribution and program administration.
  7. From public or official sources, where lawful and relevant to verification, compliance, safety, fraud prevention, or legal claims.
  8. From professional advisers, authorities, or counterparties, where necessary for legal, regulatory, security, or dispute purposes.

Where applicable law requires us to tell you the source of information obtained indirectly, we will do so unless a lawful exception applies.


6. Why we process personal data and the legal bases we may rely on

Which means: We process personal data to operate Resurve, secure it, support bookings and Businesses, comply with law, and improve the platform. The legal basis depends on the exact activity.

Where a law requires a lawful basis, Resurve may rely on one or more of the following, depending on the processing:

  • performance of a contract or steps requested before entering into a contract;
  • compliance with a legal obligation;
  • legitimate interests pursued by Resurve or a third party, where those interests are not overridden by the individual’s rights and freedoms;
  • consent;
  • protection of vital interests where legally applicable;
  • establishment, exercise, or defence of legal claims; or
  • another lawful basis available under applicable law.

6.1 Providing and operating the Services

We may process personal data to:

  • create and administer accounts;
  • authenticate users;
  • provide storefronts, bookings, operating files, dashboards, POS features, analytics, accounting-related features, and other functionality;
  • route information between a Business and a Customer;
  • maintain reservations and transaction states;
  • provide Customer and Business support;
  • manage subscriptions and billing;
  • provide API or integration functionality; and
  • fulfil other requested features.

Typical basis: contract, steps before contract, legitimate interests, or processor instructions from a Business.

6.2 Facilitating Business-to-Customer transactions

We may process data to enable a Business to:

  • accept and manage reservations;
  • communicate with Customers;
  • allocate vehicles or other resources;
  • manage pickup, delivery, return, fulfilment, cancellation, extension, or refund workflows;
  • create and maintain operating files;
  • store lawful evidence;
  • handle disputes; and
  • provide the Business’s service.

Typical basis: where Resurve acts as processor, the Business determines the lawful basis. Where Resurve has a separate controller purpose, contract, legitimate interests, consent, or another lawful basis may apply.

6.3 Payment coordination

We may process payment and transaction information to:

  • initiate or support payment flows;
  • display payment status;
  • reconcile bookings and payments;
  • support refunds, deposits, reversals, disputes, and chargebacks;
  • support settlement reporting;
  • prevent duplicate or fraudulent transactions; and
  • communicate with payment providers.

Typical basis: contract, legitimate interests, legal obligation, or processor instructions.

6.4 Verification, compliance, fraud prevention, and safety

We may process information to:

  • verify accounts or authorised representatives;
  • prevent impersonation;
  • detect account takeover;
  • detect fraudulent or abusive bookings;
  • protect Businesses, Customers, Resurve, payment providers, and third parties;
  • investigate suspicious activity;
  • comply with sanctions, anti-money-laundering, know-your-customer, court, regulatory, or other legal requirements where they apply to Resurve; and
  • enforce our Terms and policies.

Typical basis: legal obligation, legitimate interests, contract, or consent where required.

A payment provider or Business may separately perform its own verification and compliance checks.

6.5 Service communications

We may send administrative and transactional communications such as:

  • account verification;
  • security alerts;
  • booking confirmations;
  • payment-status notices;
  • reminders;
  • operational updates;
  • account notices;
  • service changes;
  • support responses; and
  • legally required notices.

Typical basis: contract, legal obligation, or legitimate interests.

These messages are not necessarily marketing communications and may continue even if you opt out of marketing where they are necessary to provide or secure the Services.

6.6 Product improvement, analytics, and research

We may process information to:

  • understand how features are used;
  • measure performance and reliability;
  • identify errors;
  • improve workflows;
  • develop new features;
  • conduct research;
  • evaluate user experience;
  • forecast capacity;
  • understand marketplace performance; and
  • improve security and fraud controls.

Typical basis: legitimate interests, consent where required, or processor instructions where the activity is performed only for a Business.

Where appropriate, we use aggregated, statistical, pseudonymised, or de-identified information for these purposes.

6.7 Aggregated and de-identified data

We may create aggregated, statistical, or de-identified information from data processed through the Services and use that information for lawful purposes, including:

  • analytics;
  • benchmarking;
  • market and industry insights;
  • business intelligence;
  • product development;
  • forecasting;
  • fraud prevention;
  • research;
  • security;
  • service improvement; and
  • commercial planning.

Where information has been de-identified so that it is no longer personal data under applicable law, this Privacy Policy does not restrict our use of that information as personal data. Where applicable law imposes obligations on de-identified data, we will comply with those obligations.

We do not acquire ownership of a Business’s underlying Customer personal data merely by creating aggregated or de-identified information from it.

6.8 Marketing and business development

Where permitted, we may use Business-user, affiliate, prospect, or Customer account information to:

  • send Resurve product updates;
  • explain new features;
  • send newsletters;
  • invite users to research;
  • market Resurve products or related Resurve services;
  • measure campaign effectiveness; and
  • administer referral or affiliate programs.

Typical basis: consent or legitimate interests, depending on the jurisdiction, relationship, and communication.

You may opt out of marketing as described below.

6.9 Legal, regulatory, and dispute purposes

We may process and retain information to:

  • comply with laws, court orders, subpoenas, regulatory requests, or governmental demands;
  • respond to law-enforcement requests where lawful;
  • maintain corporate, accounting, tax, and compliance records;
  • investigate complaints;
  • establish facts;
  • preserve evidence;
  • enforce agreements;
  • recover amounts owed;
  • protect legal rights; and
  • establish, exercise, or defend legal claims.

Typical basis: legal obligation or legitimate interests, including the establishment, exercise, or defence of legal claims.

6.10 Corporate transactions and financing

We may process and disclose information in connection with an actual or proposed:

  • financing;
  • investment;
  • merger;
  • acquisition;
  • restructuring;
  • sale of shares;
  • sale of assets;
  • insolvency;
  • due-diligence process; or
  • similar corporate transaction.

We will use safeguards appropriate to the stage and sensitivity of the transaction where required by law.

Typical basis: legitimate interests, legal obligation, or another lawful basis.


7. Business Customer Data

Which means: Businesses control the Customer data they collect for their own operations. Resurve processes it to provide the software, subject to limited uses required to run and protect the platform.

For this Policy, “Business Customer Data” means Customer personal data submitted to the Services by or for a Business, or collected through the Services primarily for that Business’s own service, rental, reservation, fulfilment, customer-management, or operational purposes.

7.1 Business instructions

Where Resurve acts as processor, we process Business Customer Data:

  • to provide the Services;
  • on documented instructions from the Business;
  • as reasonably necessary to secure, maintain, support, troubleshoot, and provide the Services;
  • as required by law; or
  • as otherwise permitted by the applicable DPA or Business agreement.

7.2 Business responsibility for collection and notices

The Business is responsible for:

  • ensuring that it may lawfully provide Business Customer Data to Resurve;
  • ensuring that its Customer-facing notices accurately describe the Business’s use of Resurve where required;
  • responding to Customer rights requests for data controlled by the Business;
  • ensuring that any direct marketing it sends through Resurve is lawful;
  • configuring retention and access appropriately; and
  • preventing staff from using Business Customer Data for unauthorised purposes.

7.3 Requests concerning Business-controlled data

If a Customer contacts Resurve about information controlled by a Business, we may:

  • direct the Customer to the relevant Business;
  • forward the request to the Business;
  • assist the Business as required by our DPA or applicable law; or
  • separately respond to the extent Resurve controls other personal data about the Customer.

We may preserve information despite a deletion request where retention is required or permitted by law, necessary to protect legal rights, necessary to prevent fraud or abuse, or otherwise subject to a lawful exception.

7.4 Business access

The Business and its authorised staff may access Business Customer Data according to permissions configured in the Business account.

Businesses should promptly remove access for people who no longer require it and should give users only the permissions reasonably required for their work.

Resurve is not responsible for a Business granting access to the wrong employee, contractor, branch, agent, or integration where Resurve correctly follows the Business’s instructions and permission configuration, except to the extent liability cannot lawfully be excluded.

7.5 Imported data

A Business may be able to import Customer lists or other records into Resurve.

The Business is responsible for ensuring that imported information was collected lawfully, may lawfully be used for the intended purpose, and may lawfully be disclosed to Resurve.

Resurve does not independently verify the lawful provenance of every record imported by a Business.


8. Lead provenance, referrals, marketplace attribution, and storefront modes

Which means: Resurve may record where a booking came from. Attribution can affect analytics and future commercial programs, but it does not change who the Business is.

Resurve may record acquisition and provenance information associated with a visit, enquiry, Customer, booking, or transaction.

Examples may include:

  • business_link — demand originating from a Business-controlled or Business-shared Resurve storefront or link;
  • marketplace — demand originating from Resurve marketplace discovery;
  • affiliate or similar referral attribution — demand associated with a valid referral or affiliate source; and
  • campaign, source, medium, referral, click, or other attribution information.

Provenance may persist through booking, payment status, the operating file, analytics, reporting, attribution, commission logic, fraud controls, marketplace measurement, and other legitimate platform functions.

Resurve may use provenance and aggregated performance information to distinguish demand generated by Resurve from demand brought by a Business, to administer marketplace or commercial programs, and to understand the performance of distribution channels.

The use of provenance does not by itself make Resurve the merchant, rental operator, service provider, or contracting party for the underlying Business-to-Customer service.

Where a locked Business storefront is configured not to be indexed, Resurve may implement technical measures designed to reduce search-engine indexing. Search engines and third parties operate independently, however, and Resurve cannot guarantee that information will never be cached, copied, indexed, archived, or otherwise discovered by a third party.


9. Payment providers, acquiring banks, and financial information

Which means: Resurve coordinates payment workflows, but payment providers and banks may have their own legal duties and privacy rules.

Where a payment function is available, Resurve may transmit information to or receive information from payment service providers, acquirers, banks, payment networks, fraud providers, wallet providers, or other payment participants.

Information may be shared as necessary to:

  • create or maintain a merchant integration;
  • initiate or process a payment;
  • authenticate a payment;
  • route payment instructions;
  • display payment status;
  • manage a refund, void, deposit, reversal, chargeback, or dispute;
  • prevent fraud;
  • reconcile and report transactions;
  • support settlement;
  • verify a Business;
  • comply with legal or payment-scheme requirements; or
  • provide payment-related support.

A payment provider may act as an independent controller for some processing, including fraud prevention, legal compliance, transaction monitoring, sanctions screening, anti-money-laundering checks, card-network compliance, dispute handling, or other purposes required by its own legal or contractual obligations.

If a Customer provides payment-card information directly to a payment provider through an embedded, hosted, tokenised, or redirected payment flow, the provider’s privacy policy also applies to its processing.

Resurve does not control an independent payment provider’s retention periods, risk decisions, compliance obligations, service availability, or security practices.


10. Messaging, WhatsApp, SMS, email, and communications

Which means: Resurve may deliver messages for itself or for a Business. The sender and purpose matter.

The Services may support transactional, operational, support, and marketing communications through email, in-app notifications, WhatsApp, SMS, push notifications, or other channels.

10.1 Messages from Resurve

Resurve may send:

  • account and security notices;
  • service communications;
  • support responses;
  • legal notices;
  • product updates; and
  • marketing where permitted.

10.2 Messages sent for a Business

Where a Business instructs Resurve to send a Customer communication, the Business is responsible for ensuring that:

  • it has the right to contact the Customer;
  • the content is lawful;
  • consent has been obtained where required;
  • required sender identification and unsubscribe mechanisms are included; and
  • applicable anti-spam, direct-marketing, privacy, and telecommunications laws are followed.

Resurve may impose technical or policy restrictions on messaging to prevent spam, abuse, fraud, excessive messaging, or unlawful communications.

10.3 Communications platforms

Telecommunications, email, WhatsApp, SMS, push-notification, or similar providers may receive message-routing information and other data necessary to deliver communications. Their own privacy notices may apply where they act independently.

10.4 Message records

Where communications occur through the Services, Resurve may store message metadata and, where the feature requires it, message content for:

  • delivery;
  • conversation history;
  • customer support;
  • evidence of instructions;
  • abuse prevention;
  • troubleshooting;
  • legal compliance; and
  • dispute handling.

The Business is responsible for ensuring that messages it sends or stores through the Services do not contain unnecessary sensitive information.


11. Vehicle location, telematics, cameras, and tracking technologies

Which means: Car-rental Businesses may use trackers or telematics, but they—not Resurve merely because it provides software—are responsible for making that use lawful.

A Business may use vehicle technologies such as:

  • GPS or location trackers;
  • original-equipment-manufacturer vehicle systems;
  • telematics devices;
  • odometer or fuel data feeds;
  • remote locking systems;
  • dash cameras;
  • interior or exterior cameras;
  • audio-recording systems; or
  • other vehicle sensors.

If a Business transmits information from such systems into Resurve, Resurve may process that information as part of the Services.

Unless Resurve expressly provides and controls the relevant device or tracking purpose, the Business is responsible for:

  • determining whether use of the technology is lawful;
  • giving Customers required notice;
  • obtaining consent where required;
  • determining whether continuous or precise tracking is proportionate and necessary;
  • complying with surveillance, telecommunications, employment, rental, insurance, and privacy laws;
  • securing access to the device and data;
  • defining retention periods; and
  • responding to Customer rights relating to the information.

A Business must not use an interior camera, audio recorder, or other intrusive monitoring technology through or in connection with Resurve in violation of applicable law.

Resurve may restrict an integration or use of tracking data if we reasonably believe it creates a security, privacy, or legal risk to the Services or other users.


12. AI, machine learning, analytics, and automated tools

Which means: Resurve may use automated tools to help run and improve the platform, but Businesses remain responsible for decisions they make using Resurve’s outputs.

Resurve may offer or use automated tools, machine learning, statistical models, or AI-assisted features for purposes such as:

  • fraud or abuse detection;
  • anomaly detection;
  • search and ranking;
  • recommendations;
  • forecasting;
  • document or data extraction;
  • summarisation;
  • workflow assistance;
  • customer-support assistance;
  • operational alerts;
  • business intelligence;
  • accounting or financial categorisation assistance;
  • analytics; and
  • other product features.

12.1 Human responsibility

Unless a specific Resurve product expressly states otherwise, AI-assisted or automated outputs are intended to support human users, not replace the Business’s legal, financial, accounting, safety, insurance, rental, employment, or compliance judgment.

Businesses are responsible for reviewing outputs before relying on them for consequential decisions.

12.2 Solely automated significant decisions

Where Resurve acts as controller and applicable law gives an individual the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects, Resurve will provide the safeguards required by applicable law.

Where a Business configures or uses the Services to make decisions about its Customers or staff, the Business is responsible for determining whether automated-decision-making rules apply to it.

12.3 Product improvement and model development

Resurve may use telemetry, service events, feedback, support information, and aggregated or de-identified information to develop and improve automation, analytics, and AI-assisted features.

Where identifiable Business Customer Data is processed by Resurve solely as processor, Resurve’s use of that data is governed by the Business agreement and applicable DPA, except for separate controller processing permitted by applicable law and described in this Policy.

We do not treat the mere storage of Business Customer Data as unrestricted permission to sell identifiable Customer data or use identifiable Customer data to train unrelated third-party general-purpose AI models.

Where we use an external AI or machine-learning service to process personal data, we will treat that provider according to the role it performs and applicable processor, subprocessor, transfer, security, and confidentiality requirements.


13. Cookies and similar technologies

Which means: Cookies keep sessions working, remember preferences, measure use, and may support marketing. Non-essential cookies are handled according to applicable consent rules.

Resurve and service providers may use:

  • cookies;
  • local storage;
  • pixels;
  • software development kits;
  • tags;
  • device identifiers; and
  • similar technologies.

These technologies may be used for:

  • authentication;
  • account security;
  • load balancing;
  • fraud prevention;
  • remembering preferences;
  • session continuity;
  • functionality;
  • analytics;
  • performance;
  • attribution;
  • affiliate tracking;
  • measurement; and
  • advertising or marketing where used and legally permitted.

Further information, including choices relating to non-essential technologies, is provided in our Cookie Policy.

Browser “Do Not Track” signals do not have a universally accepted legal or technical meaning. Where applicable law requires us to recognise a legally defined opt-out preference signal, we will handle that signal as required by that law.


14. When we disclose personal data

Which means: We disclose data when it is needed to run Resurve, fulfil a booking, process payments, use integrations, comply with law, or protect the platform.

We may disclose personal data to the following categories of recipients.

14.1 Businesses

Where a Customer interacts with a Business, we may provide that Business with information reasonably necessary to:

  • respond to the Customer;
  • manage the reservation or rental;
  • identify the Customer;
  • provide the service;
  • communicate;
  • manage payments, refunds, disputes, deposits, or claims;
  • maintain an operating file; and
  • comply with the Business’s lawful obligations.

The Business’s own privacy notice applies to its independent processing.

14.2 Customers

We may provide Customers with information about the Business, booking, payment status, reservation, vehicle, service, pickup, return, fulfilment, or communication that is necessary for the Customer’s transaction.

14.3 Service providers and subprocessors

We may use third parties to provide services such as:

  • cloud hosting;
  • infrastructure;
  • database services;
  • authentication;
  • email delivery;
  • messaging;
  • customer support;
  • analytics;
  • error monitoring;
  • security;
  • fraud prevention;
  • identity verification;
  • payment support;
  • document processing;
  • communications;
  • backups;
  • business operations; and
  • other technical or professional services.

Where a provider acts as Resurve’s processor or subprocessor, we seek contractual and organisational safeguards appropriate to the nature of the processing and applicable law.

Resurve may add, remove, or replace providers as the Services evolve. A current subprocessor list may be published through the Resurve Legal Center or otherwise made available where required by law or contract.

14.4 Payment participants

We may disclose information to payment service providers, acquirers, banks, card networks, wallets, fraud providers, or other payment participants as described above.

14.5 Integrations and third-party apps

If a Business or user enables an integration, API connection, external app, or third-party service, we may disclose information needed to operate that connection.

Once information is transmitted to an independent third party at the user’s direction, the third party’s own privacy practices may apply.

A Business is responsible for evaluating the privacy and security implications of integrations it enables.

14.6 Affiliates and referral partners

We may disclose limited information necessary to:

  • validate a referral;
  • prevent affiliate fraud;
  • calculate commissions;
  • administer a partner relationship; and
  • resolve attribution disputes.

Affiliates are not entitled to unrestricted information about a Business’s Customers.

14.7 Professional advisers

We may disclose information to lawyers, accountants, auditors, insurers, bankers, consultants, and other professional advisers where reasonably necessary for their professional services.

14.8 Authorities, regulators, courts, and legal recipients

We may disclose information where we reasonably believe disclosure is required or permitted by law, including in response to:

  • court orders;
  • warrants;
  • subpoenas;
  • statutory notices;
  • regulatory requests;
  • law-enforcement requests;
  • tax requirements;
  • data-protection authorities; or
  • other lawful governmental demands.

Where legally permitted and appropriate, we may challenge, narrow, or seek clarification of a request.

14.9 Protection of rights and safety

We may disclose information where reasonably necessary to:

  • prevent fraud or abuse;
  • protect the security of the Services;
  • protect a person from harm;
  • investigate suspected unlawful activity;
  • enforce our agreements;
  • protect Resurve, Businesses, Customers, or third parties; or
  • establish, exercise, or defend legal claims.

14.10 Corporate transactions

We may disclose information to actual or prospective investors, lenders, buyers, sellers, advisers, or counterparties in a corporate transaction, subject to appropriate confidentiality or legal safeguards where practicable.


15. Selling, sharing, and advertising uses of personal data

Which means: We do not treat Business Customer Data as a product to sell to data brokers. Some privacy laws, however, use broad definitions of “sale” or “sharing”.

Resurve does not sell Business Customer Data to data brokers for the data broker’s independent use merely because a Business uses Resurve.

We may disclose personal data to service providers, Businesses, payment providers, integrations, affiliates, analytics providers, advertising providers, or other recipients for the purposes described in this Privacy Policy.

Some jurisdictions define “sale”, “sharing”, “targeted advertising”, or similar activity broadly enough to include certain advertising, analytics, or cross-context disclosures even where no money is paid for the data. If Resurve engages in activity covered by such a definition and applicable law gives you an opt-out right, we will provide the legally required notice and choice.

Resurve may use first-party account, marketplace, provenance, interaction, and aggregated information to promote Resurve products and related Resurve services where permitted by law.

We do not use the existence of a Business’s private Customer list as permission to sell that list to unrelated third parties for their independent marketing.


16. International transfers

Which means: Resurve and its providers may process data outside Mauritius or outside your home country. We use lawful transfer mechanisms where required.

Resurve is established in Mauritius, but the Services may rely on personnel, infrastructure, subprocessors, payment providers, communications providers, and other service providers located in other countries.

As a result, personal data may be transferred to or accessed from countries whose data-protection laws differ from those of the country in which the data was originally collected.

Where a transfer is subject to the Mauritius Data Protection Act 2017, Resurve will use a transfer basis permitted by that Act and will make any filing, notification, authorisation request, or demonstration of safeguards required by applicable law.

Depending on the circumstances, transfer safeguards or lawful transfer grounds may include:

  • appropriate contractual safeguards;
  • standard contractual clauses where an applicable legal regime recognises them;
  • adequacy decisions or recognised adequate jurisdictions;
  • explicit consent where valid and appropriate;
  • transfers necessary for a contract, legal claim, or another statutory ground; or
  • another mechanism permitted by applicable law.

Where the GDPR, UK GDPR, or another law requires a particular cross-border transfer mechanism, we may use the mechanism appropriate to the recipient, location, type of data, and applicable legal regime.

Businesses are separately responsible for the lawfulness of international transfers they initiate through integrations, exports, remote staff access, downloads, or other Business instructions.


17. Data retention, deletion, and backups

Which means: We keep data while it is needed for the purpose it was collected for, legal requirements, security, and disputes. We do not promise instant deletion from every backup.

We retain personal data for no longer than is reasonably necessary for the purposes for which it is processed, subject to legal, regulatory, accounting, fraud-prevention, security, backup, contractual, and dispute requirements.

The retention period varies according to:

  • the type and sensitivity of the information;
  • whether Resurve is controller or processor;
  • the Business’s lawful retention instructions;
  • the duration of the account or customer relationship;
  • the lifecycle of a booking, rental, payment, or dispute;
  • fraud, security, and abuse-prevention needs;
  • applicable statutory limitation periods;
  • tax, accounting, corporate, payment, or other recordkeeping duties;
  • ongoing or anticipated legal claims;
  • regulatory or court requirements; and
  • technical backup and disaster-recovery cycles.

17.1 Business Customer Data

Where Resurve acts as processor, the Business generally determines how long Business Customer Data should be retained, subject to:

  • the Business agreement;
  • Resurve’s technical retention functionality;
  • applicable law;
  • security and anti-fraud needs;
  • legal holds; and
  • Resurve’s separate controller obligations.

A Business may be required by law to retain rental agreements, invoices, identity verification, accounting information, incident records, or other records for a particular period. Resurve does not determine every Business’s legal retention obligation.

17.2 Account closure

Closing or terminating an account does not necessarily result in immediate deletion of all data.

We may retain information after closure where reasonably necessary to:

  • complete an orderly termination;
  • comply with law;
  • maintain financial or transaction records;
  • resolve disputes;
  • prevent fraud or repeated abuse;
  • enforce contractual rights;
  • preserve security logs;
  • respond to authorities; or
  • establish, exercise, or defend legal claims.

17.3 Backups

Deleted information may remain in encrypted, isolated, or otherwise controlled backups for a limited period until those backups expire under normal retention cycles.

Backup systems may not support selective deletion of individual records without compromising backup integrity. Information retained only in backup may remain unavailable for ordinary use and may be overwritten or deleted according to backup schedules.

If a backup is restored for disaster recovery, we will take reasonable steps to re-apply applicable deletions or restrictions where required.

17.4 Legal holds

Where information is subject to a legal hold, investigation, regulatory requirement, or reasonably anticipated dispute, we may suspend ordinary deletion until the relevant matter is resolved.

17.5 De-identification instead of deletion

Where legally permitted and appropriate, Resurve may irreversibly de-identify information instead of retaining it in identifiable form. Once information is no longer personal data under applicable law, it may be retained and used for lawful statistical, analytical, security, research, or product-improvement purposes.


18. Security

Which means: We use technical and organisational safeguards appropriate to risk, but no internet service can promise absolute security.

Resurve uses technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access.

Depending on the system, risk, and type of data, measures may include:

  • access controls;
  • authentication controls;
  • role-based or least-privilege access;
  • encryption in transit and, where appropriate, at rest;
  • logging and monitoring;
  • backup and recovery controls;
  • separation of environments or duties where appropriate;
  • vendor and subprocessor controls;
  • staff confidentiality obligations;
  • incident-response procedures;
  • security testing and review; and
  • other measures appropriate to the nature, scope, context, and risk of processing.

Security measures evolve over time and may vary by Service.

No method of transmission, storage, software, network, device, or security control is completely secure. Resurve therefore does not guarantee that unauthorised access, loss, misuse, or a security incident can never occur.

Users and Businesses also have security responsibilities. They must:

  • protect passwords and authentication methods;
  • use appropriate credentials;
  • limit staff access;
  • promptly remove access for former staff;
  • secure devices;
  • protect API credentials;
  • configure integrations carefully; and
  • promptly report suspected unauthorised access to Resurve.

To the extent permitted by law, Resurve is not responsible for a compromise caused by a Business or user voluntarily disclosing credentials, misconfiguring permissions, enabling an unsafe third-party integration, failing to secure its own systems, or otherwise acting outside Resurve’s reasonable control.


19. Personal data breaches

Which means: If a legally reportable breach occurs, we follow the notification rules that apply to our role.

Where Resurve acts as controller and becomes aware of a personal data breach, we will assess the incident and make regulatory or data-subject notifications where required by applicable law.

Under the Mauritius Data Protection Act 2017, a controller must notify the Data Protection Commissioner without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach. Where a breach is likely to result in a high risk to an individual’s rights and freedoms, communication to affected individuals may also be required, subject to applicable legal exceptions.

Where Resurve acts as processor for a Business, Resurve will notify the relevant Business of a personal data breach without undue delay as required by applicable law and the applicable DPA or Business agreement, so that the Business can assess its own controller obligations.

A Business must promptly provide Resurve with information and cooperation reasonably necessary to investigate incidents arising from the Business’s users, integrations, devices, credentials, instructions, or systems.

Nothing in this Privacy Policy requires Resurve to publicly disclose security information that would itself create a security risk, prejudice an investigation, expose another person’s confidential information, or violate law.


20. Your privacy rights

Which means: Depending on the law and Resurve’s role, you may have rights to see, correct, delete, restrict, or object to our use of your data.

Depending on applicable law and the circumstances, you may have some or all of the following rights:

  1. Access — to ask whether personal data about you is being processed and to receive a copy or related information.
  2. Correction or rectification — to correct inaccurate or incomplete personal data.
  3. Erasure or deletion — to request deletion where the legal conditions are met.
  4. Restriction — to request restriction of processing in circumstances provided by law.
  5. Objection — to object to certain processing, including direct marketing.
  6. Withdrawal of consent — where processing is based on consent, to withdraw consent without affecting processing lawfully carried out before withdrawal.
  7. Automated-decision rights — where applicable, not to be subject to certain decisions based solely on automated processing that produce legal or similarly significant effects, subject to legal exceptions.
  8. Data portability — where a law that applies to the processing provides this right.
  9. Complaint — to complain to an applicable data-protection or privacy regulator.
  10. Authorised-representative rights — where applicable law permits another person to exercise rights on your behalf.

These rights are not absolute. Exceptions may apply, including where information must be retained to comply with law, protect the rights of another person, maintain security, prevent fraud, preserve evidence, or establish, exercise, or defend legal claims.

20.1 How to make a request to Resurve

For personal data for which Resurve acts as controller, contact:

legal@resurve.net

Please describe the request clearly and identify the account, booking, Business, email address, or other context relevant to locating the information.

We may request information reasonably necessary to verify identity or authority before fulfilling a request. We are not required to disclose information to a person who cannot reasonably establish that they are the relevant data subject or an authorised representative.

20.2 Requests concerning a Business

If your request concerns Customer information controlled by a Business, you should normally contact that Business directly.

If you send the request to Resurve, we may refer or transmit the request to the Business and assist it as required by law or the applicable DPA.

Resurve will separately address any part of the request relating to information for which Resurve is itself controller.

20.3 Time limits

We aim to respond within the period required by the law applicable to the request.

Different laws impose different response periods and may permit extensions for complex or numerous requests.

20.4 Manifestly excessive or abusive requests

Where applicable law permits, Resurve may refuse, limit, or charge an authorised fee for a request that is manifestly unfounded, repetitive, excessive, technically disproportionate, or made in circumstances where a lawful exception applies.

20.5 Complaints in Mauritius

Where Mauritius law applies, you may contact the:

Data Protection Commissioner
Data Protection Office
5th Floor, SICOM Tower
Wall Street
Ebene Cyber City
Ebene, Republic of Mauritius
Email: dpo@govmu.org
Telephone: +230 460 0251

You may also complain to another competent supervisory authority where applicable law gives you that right.


21. Marketing choices

Which means: You can opt out of Resurve marketing. Service and security messages may still be sent.

You may opt out of Resurve marketing emails by using the unsubscribe mechanism in the message or by contacting legal@resurve.net.

Where marketing is sent by a Business using Resurve, the Business is responsible for its own marketing list, lawful basis, consent, sender identity, and opt-out obligations.

If you object to direct marketing where applicable law gives you that right, we will stop using the relevant personal data for that direct-marketing purpose.

Opting out of marketing does not prevent us from sending non-marketing messages that are reasonably necessary for:

  • account administration;
  • bookings;
  • payments;
  • security;
  • fraud prevention;
  • legal notices;
  • support; or
  • provision of the Services.

Cookie and advertising preferences are addressed in our Cookie Policy.


22. Children and minors

Which means: Resurve’s Business and affiliate accounts are for adults. Businesses must not collect children’s data through Resurve without a lawful reason and any required parental or guardian consent.

Resurve Business accounts and affiliate accounts are not intended for children.

The Services are not designed as services directed to children under 16.

Under the Mauritius Data Protection Act 2017, personal data of a child below 16 generally must not be processed unless consent is given by the child’s parent or guardian, and the controller must make reasonable efforts to verify that consent.

A Business must not use Resurve to collect personal data from children in violation of applicable law.

If a Business has a legitimate need to process information relating to a child, the Business is responsible for:

  • determining whether the processing is lawful;
  • obtaining and verifying parental or guardian consent where required;
  • collecting only information that is necessary; and
  • providing any required notice.

If you believe a child’s personal data has been unlawfully provided to Resurve, contact legal@resurve.net.


23. Third-party websites, apps, services, and integrations

Which means: If you leave Resurve or connect another service, that third party has its own privacy rules.

The Services may contain links to, embed, integrate with, or permit connections to third-party websites, software, payment providers, social networks, map providers, communications platforms, analytics tools, vehicle systems, or other services.

This Privacy Policy does not govern an independent third party’s processing of personal data.

We are not responsible for a third party’s privacy practices merely because:

  • the third party is linked from Resurve;
  • the integration is available through Resurve;
  • a Business chooses to connect the third party; or
  • Resurve transmits information to the third party at the Business’s or user’s direction.

Before enabling an integration, Businesses should evaluate the third party’s terms, privacy practices, security, data location, permissions, and legal compliance.

Disabling an integration may stop future data exchange but may not delete information already received and independently retained by the third party.


24. Research, beta features, and optional programs

Which means: Research and beta programs may collect extra information, but participation-specific notices may apply.

If you participate in:

  • user research;
  • interviews;
  • surveys;
  • testing;
  • Research Beta programs;
  • product previews;
  • experiments; or
  • optional feature trials,

we may collect information relevant to that program, such as feedback, recordings where disclosed, usage observations, responses, or contact information.

We may provide additional notices or request consent where required.

Beta or research participation does not give Resurve unrestricted rights over personal data beyond what applicable law, this Privacy Policy, and any specific program terms permit.


25. Businesses using Resurve have independent privacy obligations

Which means: Resurve cannot make a Business privacy-compliant simply by providing software. The Business must configure and use the platform lawfully.

A Business using Resurve must take responsibility for its own privacy program and use of Customer information.

Without limiting the Terms of Service, a Business is responsible for:

  1. publishing any Customer privacy notice required by law;
  2. identifying the Business as controller where that is its legal role;
  3. explaining the categories and purposes of Customer data it collects;
  4. obtaining any consent required for direct marketing, cookies, surveillance, tracking, telematics, sensitive data, or other regulated processing;
  5. not collecting information that is excessive for the Business’s purpose;
  6. maintaining accurate contact and legal identity information;
  7. ensuring staff have appropriate access;
  8. responding to privacy requests directed to the Business;
  9. configuring third-party integrations lawfully;
  10. complying with applicable retention and deletion duties;
  11. independently assessing whether a data-protection impact assessment, prior consultation, regulatory registration, notification, or other compliance step is required;
  12. notifying Resurve promptly where the Business becomes aware of a privacy or security incident involving the Services;
  13. maintaining any records of processing, notices, consents, or policies required by law; and
  14. not instructing Resurve to process personal data in a manner the Business knows or reasonably should know is unlawful.

Resurve may provide product settings, templates, or information that assist a Business with privacy compliance. Those tools do not constitute legal advice and do not transfer the Business’s legal obligations to Resurve.

Where Resurve reasonably believes a Business instruction violates applicable data-protection law, our Terms, the AUP, or the rights of another person, we may refuse, suspend, restrict, or require modification of the instruction or affected processing.


26. Additional information for users in the EEA, United Kingdom, or jurisdictions with GDPR-style laws

Which means: If GDPR-style law applies to Resurve’s processing of you, additional rights and transfer rules may apply.

Where the EU GDPR, UK GDPR, or a materially similar law applies to Resurve as controller:

  1. the lawful bases described in this Privacy Policy apply according to the specific processing activity;
  2. legitimate-interest processing is subject to the balancing required by applicable law;
  3. consent may be withdrawn where consent is the applicable basis;
  4. you may have rights of access, correction, erasure, restriction, objection, and portability, subject to legal conditions and exceptions;
  5. you may have the right to complain to a supervisory authority;
  6. international transfers will use a lawful mechanism required by the applicable regime; and
  7. where solely automated decision-making produces legal or similarly significant effects, legally required safeguards will apply.

If you are a Customer of a Business and Resurve is processing the relevant information only on that Business’s behalf, the Business is normally the appropriate controller to contact first.


27. Additional information for United States residents

Which means: Some US states define privacy rights differently. These rights apply only where the relevant law applies to Resurve and to the processing.

Depending on your state and whether the relevant law applies, you may have rights to:

  • know or access categories or specific pieces of personal information;
  • correct inaccurate information;
  • delete certain personal information;
  • obtain a portable copy;
  • opt out of certain sales, sharing, targeted advertising, or profiling;
  • limit certain uses of sensitive personal information; or
  • appeal certain privacy-request decisions.

Resurve will not unlawfully discriminate against an individual for exercising a privacy right protected by applicable law.

Some US privacy laws define “sale” or “sharing” more broadly than ordinary commercial usage. Our practices are described in Section 15.

If applicable law recognises an authorised agent, we may require evidence that the agent is authorised and may separately verify the identity of the person concerned.

If a US state law does not apply to Resurve because an applicability threshold, exemption, or other legal condition is not met, this section does not voluntarily extend that statute to Resurve.


28. Changes to this Privacy Policy

Which means: We may update this Policy as Resurve, the law, and our Services change.

We may amend this Privacy Policy from time to time to reflect:

  • changes to the Services;
  • new features;
  • new processing activities;
  • new providers or integrations;
  • changes in law or regulatory guidance;
  • security or fraud-prevention needs; or
  • changes in our business operations.

The “Last updated” date at the top indicates when this Privacy Policy was most recently revised.

Where required by law, we will provide additional notice of material changes and obtain consent where consent is legally required for the changed processing.

A change to this Privacy Policy does not retroactively make unlawful processing lawful and does not eliminate rights that applicable law gives an individual.


29. Relationship with other Resurve terms

Which means: This Policy explains data practices. The Terms of Service govern the commercial use of Resurve, and a DPA may govern processor obligations.

This Privacy Policy is intended to provide transparency about Resurve’s processing of personal data.

It does not by itself:

  • make Resurve a party to a Business-to-Customer rental or service contract;
  • make Resurve the controller of personal data merely because a Business stores that information in the Services;
  • transfer a Business’s legal obligations to Resurve;
  • create a warranty that the Services can never experience a security incident;
  • expand Resurve’s liability beyond obligations imposed by applicable law or an applicable written agreement; or
  • restrict any non-waivable right under applicable privacy or data-protection law.

The Terms of Service govern the Business’s use of the Services. Where applicable, a DPA or other written processing agreement governs Resurve’s processor obligations.


30. Contact Resurve

Which means: Privacy requests and legal privacy questions should go to one address so they can be tracked properly.

For privacy questions, data-subject requests, data-protection complaints, or legal notices concerning this Privacy Policy, contact:

RESURVE LTD
Company No. 236684
Business Registration Number (BRN) C236684
Lot 2, Robert Rey Street
Roches Brunes, Beau Bassin
Mauritius

Email: legal@resurve.net

Resurve’s data-protection compliance contact may be reached through legal@resurve.net.

Where your request concerns personal data controlled by a Business using Resurve, we may direct or forward the request to that Business as described in this Privacy Policy.