Legal

Privacy Policy

This Privacy Policy explains how Lend handles personal data for accounts, listings, bookings, payments, verification, chat, reports, reviews, recommendations, and admin dispute workflows.

Effective date: June 17, 2026

Last updated: August 26, 2026

Lend is a rental marketplace that lets owners list assets for rent and lets renters browse listings, book date ranges, pay through supported payment channels, use QR handover and return checkpoints, chat about bookings, and complete post-return settlement flows.

The operator and personal information controller for this service is Lendly Marketplace, DTI Registration No. 8323919. You may contact us at privacy@getlend.dev.

Personal data we collect

  • -Account and profile data: name, email address, phone number, date of birth, profile photo, account type, verification level, account status, sign-in provider identifiers, and account timestamps.
  • -Verification and safety data: identity and KYC submission details, face or selfie verification status, verification provider session identifiers, review status, submitted documents or photos where applicable, business registration or compliance documents such as DTI, BIR, permits, and tax or invoice acknowledgements where requested, Lend Protect ownership proof, item identifiers, identifier hashes, Unit QR and seller proof records, safety check events, risk status, and admin review notes or decisions.
  • -Location data: approximate or selected locations used to show nearby rentals, set listing or pickup locations, and support booking logistics, reports, support, safety review, and dispute handling.
  • -Listing data: asset title, category, description, inclusions, photos, pricing, availability, location, security deposit settings, owner information, ratings, reviews, and listing status. Listing data may be shown in public browsing, shared listing links, and QR previews while the listing is available. Listing submissions and edits may be processed by automated and AI-assisted moderation tools before publication.
  • -Booking and transaction data: selected dates, booking status, lifecycle events, pending request and owner approval records, checkout date locks, QR or contactless handover and return checkpoints, contactless schedules and automation results, payment method category, payment provider identifiers, checkout records, payout destination records, saved payment method records, subscription or invoice identifiers, recurring-cancellation approvals and disputes, billing schedule status, settlement status, refund or payout status, payment recovery records, payout-fee entitlement and waiver records, and security deposit or damage deduction details.
  • -Communications and user content: chat messages, media messages, support or account feedback, booking Support/“Need help” cases and payment requests, reports, dispute evidence, reviews, listing-review submissions and cancellation records, ratings, saved listings, listing promotion selections, promotion metrics, promotion credit balance records, in-app purchase references, and recommendation engagement events.
  • -Safety preferences: records of users you block and reciprocal exclusion records used to limit discovery, bookings, messaging, saved listings, and recommendations between affected accounts.
  • -Device and technical data: Firebase Cloud Messaging tokens, app or browser logs, IP-derived technical data, device and network information, Crashlytics crash reports, non-fatal errors, stack traces, breadcrumbs, diagnostics, crash-session identifiers, share link open or scan context, web request metadata such as IP address and user agent where applicable, and security audit metadata.

Why we use personal data

  • -To create and manage accounts, authenticate users, maintain sessions, and protect account access.
  • -To operate the marketplace, including listing creation, browsing, search, recommendations, saved listings, booking calendars, and owner or renter dashboards.
  • -To create, resolve, measure, and protect shareable listing links and QR codes.
  • -To verify users, determine eligibility to list or rent, detect fraud, reduce marketplace risk, and support user safety.
  • -To operate Lend Protect, including proof review, Unit QR pages, seller proof checks, safety checks, ownership transfer, risk review, and fraud prevention.
  • -To process bookings, payment checkout, security deposits, owner payouts, deposit returns, refunds, QR handover or return checkpoints, and post-return settlement.
  • -To process recurring subscription billing and cancellation requests, including participant approvals, disputes, subscription cancellation status, future billing, eligible deposit returns, and provider reconciliation.
  • -To apply eligible founding-owner payout-transfer-fee waivers and maintain the associated entitlement and usage records.
  • -To reveal contactless access and return instructions at the permitted time, record automated check-in or checkout, schedule post-return completion, and process automated damage-response decisions where enabled.
  • -To process promotion credit purchases, purchase restore or sync, promotion credit balances, listing promotion redemption, promoted placements, and promotion performance metrics.
  • -To send operational notifications about bookings, chat, payment status, verification, reports, reminders, and account changes.
  • -To support users, respond to account feedback, investigate reports, moderate content, resolve disputes, and enforce our terms.
  • -To receive and manage in-app “Need help” requests, payment-support cases, listing-review cancellation requests, and related conversations, evidence, decisions, and notifications.
  • -To apply user blocking preferences, limit unwanted future interactions, and preserve access needed to complete existing bookings or resolve disputes.
  • -To comply with legal, tax, accounting, consumer protection, anti-fraud, data protection, and lawful request obligations.
  • -To improve service reliability, pricing transparency, marketplace recommendations, abuse prevention, and product performance.

We process personal data in line with applicable Philippine data protection principles, including transparency, legitimate purpose, and proportionality. Depending on the context, processing may be necessary to perform our agreement with you, comply with law, protect users and the marketplace, pursue legitimate business interests that do not override your rights, or rely on your consent where consent is required.

Third-party services and sharing

We share personal data only when needed to operate Lend, comply with law, protect users, or support the purposes described in this policy. These providers process data under their own controls or under instructions from Lend, depending on the service.

  • -Firebase and Google Cloud: authentication, Firestore database, file storage, hosting, cloud functions, remote configuration, push notifications, logs, Crashlytics crash and error reporting, and operational infrastructure.
  • -Google Maps: map display, place selection, and location support for nearby browsing and pickup or listing locations.
  • -PayMongo: payment intents, subscriptions, invoices, cards, e-wallets, QR Ph, online banking channels, checkout status, subscription cancellation, wallet payouts, refund or payout references, and payment webhook processing.
  • -RevenueCat, Apple App Store, and Google Play: in-app purchase products, product IDs, app user IDs, transaction IDs, purchase dates, purchase restore or sync status, webhook events, platform billing, taxes, refunds, and promotion credit purchase validation.
  • -Resend: delivery of transactional emails such as email verification, booking updates, payment or refund status, payout updates, and verification decisions. Resend receives the recipient email address and the operational email content needed for delivery.
  • -Didit or other verification providers: identity, face KYC, session status, and verification decision support for account safety and eligibility checks.
  • -Apple, Google, and Facebook: sign-in or platform account services where you choose those login methods.
  • -App stores, device platforms, and messaging services: app distribution, push delivery, device permissions, and platform security features.
  • -Other users and admins: information necessary for a booking, listing, chat, review, report, handover, return, payout, or dispute may be visible to the relevant renter, owner, or Lend admin. After a booking is confirmed, this may include names, phone numbers, listing or pickup location details, booking dates, chat records, handover or return status, reports, evidence, and settlement details needed to coordinate or review the rental. Public listing previews may also be visible to anyone with a share link or QR code and may include listing title, description, photo, category, price, general location, and owner display details. Listing content and photos may also be shared with service providers that help Lend perform automated or AI-assisted safety and policy review.
  • -Authorities, advisers, or transaction parties: where required by law, legal process, compliance obligations, dispute resolution, investigation, or business transfer.

Payments, payouts, and financial data

Lend uses payment providers such as PayMongo to process payment methods and money movement. Full card or bank credentials should be handled by the payment provider and not stored by Lend unless a supported provider feature explicitly returns limited, tokenized, or masked payment data. We may store provider identifiers, checkout IDs, payment intent IDs, subscription IDs, invoice or billing schedule identifiers, payout destination metadata, transaction status, amounts, fees, refund status, and settlement records to operate bookings and resolve disputes.

Lend Protect data

Lend may collect and process Lend Protect information, including listing IDs, owner IDs, category details, ownership proof photos or documents, owner notes, item identifiers, identifier hashes, public identifier summaries, Unit QR codes, seller proof tokens, QR scan events, safety check inputs, risk status, review status, admin decisions, rejection reasons, transfer records, and timestamps.

Private ownership proof and full identifiers are used for Lend review, fraud prevention, safety checks, ownership transfer, support, dispute handling, and policy enforcement. Public or limited Lend Protect information may be shown in the app, listing previews, Unit QR pages, certificates, or safety check results, but private documents and full identifiers are not intended to be shown publicly.

In-app purchases, promotions, and recommendations

Lend uses RevenueCat and app store services to support promotion credit purchases, purchase restore, purchase sync, purchase validation, webhook processing, and promotion credit balance updates. RevenueCat and app stores may process app user IDs, product IDs, transaction IDs, purchase dates, platform information, entitlement or purchase status, and related purchase metadata. Lend may store purchase references, credited promotion amounts, credit balance changes, and related audit records.

Lend may process listing promotion status, promotion package selections, placement choices, promotion score, active promotion dates, promotion credit balances, purchase records, impressions, taps, views, search or recommendation engagement events, and related analytics to operate promoted placements, measure performance, prevent abuse, and improve discovery.

Passkeys and device authentication

If passkeys are enabled, Lend may store passkey credential IDs, public key material, display names, credential metadata, timestamps, and sign-in challenge records needed to register, authenticate, list, or remove passkeys. Device biometrics or screen lock may be used locally by the device or platform credential manager. Lend does not receive or store your biometric template.

Location, camera, photos, notifications, and biometrics

  • -Location permission helps show nearby rentals and set listing or pickup locations. Listing locations may be based on your profile location or a custom pinned location and may be shown where needed for discovery, confirmed bookings, handover, return, support, safety, reports, or disputes. You may continue with less precise or manually selected locations where the app allows it.
  • -Camera and photo library access support listing photos, profile photos, chat media, verification photos, and QR code scanning or saving.
  • -Notifications support booking requests, chat replies, confirmations, verification updates, settlement updates, and reminders.
  • -Notification settings let you manage push notification categories and optional booking or payment emails. Important account, safety, verification, security, legal, and required service emails may still be sent even if optional email notifications are turned off.
  • -Device biometrics, when enabled by you, are used locally for protected sign-in or account actions. Lend does not receive your device biometric template.

Retention

We keep personal data only as long as needed for the purposes described in this policy, including active account use, marketplace operations, payment and settlement records, dispute handling, fraud prevention, audit logs, accounting, legal compliance, and lawful claims. Some data may be kept after account closure where necessary for unresolved bookings, payment records, security incidents, legal obligations, or legitimate business records. When data is no longer needed, we delete, anonymize, aggregate, or securely restrict it.

Account deletion or deactivation requests may be recorded with their eligibility checks, requested and completed times, task status, reconciliation results, and reason for any delay or retention. Closing an account does not necessarily erase records that Lend must keep for an active transaction, payment or payout reconciliation, support or dispute review, fraud prevention, security, or law.

Security

We use reasonable organizational, technical, and administrative safeguards appropriate to the sensitivity of the data and the risks of the service. These may include authentication controls, role-based admin access, Firebase security rules, server-side validation, secure payment provider flows, logging, review workflows, and restricted access to operational data. No system is completely secure, so users must also protect their accounts, devices, and login credentials.

International processing

Our service providers may process or store data in the Philippines or other countries where they operate infrastructure. Where personal data is transferred or accessed internationally, we take steps intended to preserve appropriate protection, accountability, and service security.

Your privacy rights

Subject to applicable law and valid limitations, you may have rights to be informed about processing, access your personal data, correct inaccurate data, object to certain processing, withdraw consent where processing depends on consent, request erasure or blocking, request data portability where applicable, file a complaint with the proper authority, and seek damages for violations of your rights. To exercise these rights, contact privacy@getlend.dev. We may need to verify your identity before acting on a request.

Children and minors

Lend is not intended for children. Users must meet the eligibility requirements in our Terms and Conditions. If we learn that a minor has provided personal data without required consent or authority, we may restrict the account and take reasonable steps to delete or block the data, subject to legal and safety requirements.

Changes to this policy

We may update this Privacy Policy when our product, providers, legal obligations, or business practices change. Material updates will be posted in the app or on our website, and where required we will provide additional notice or request consent.

Contact

For privacy requests, complaints, or questions, contact Lendly Marketplace at privacy@getlend.dev. Please include enough information for us to identify your account and understand your request.