Skip to content

Privacy policy

What data Brega stores, what for, who it is shared with and for how long. It applies to the console, to the public catalog that comes out of it and to the app in your own brand.

Last updated · September 9, 2026

There are two kinds of data and two different roles. For your team account we are the controller. For your customers data you are: we process it on your instructions and on your behalf.

What we store about your team

The email and name of everyone with access, their password stored as a cryptographic hash —never in the clear—, their role and permissions, when they last signed in and what they did inside the console. Also the company billing details and its invoices. We need this for the account to exist and to be able to charge.

What the console stores about your customers

Whatever your company enters when renting: name, phone, email, document number and the license photo when it gets uploaded; the dates, the amounts and the state of each contract; the photos of the vehicle condition when it goes out and when it comes back; the fines and the payment receipts. If you have the app, also the device identifiers needed to send a notification and the points accumulated.

What it is used for

To provide the service and nothing else: to store what you write, to show it back to you, to send the emails and notifications the system has to send, to charge what is due and to fix what breaks. We do not sell data, we do not hand it over for commercial purposes and we do not use it to train models.

No third party tracking

Neither the console nor the catalog carries third party analytics, pixels or advertising cookies. The only things kept in your browser are the ones needed for it to work: the session cookie —which no script can read— and the language and theme you chose, in your own local storage.

Who it is shared with

Only with the providers the service needs to work, and each one sees nothing but its own part: Stripe for card payments —card details go to Stripe and never pass through us—, Resend for email, Google Firebase Cloud Messaging for push notifications, S3 compatible storage for photos and documents, and DigitalOcean for hosting and the database. Beyond that, only when a competent authority requires it.

How long it is kept

While your account is active, everything you put in. Ninety days after you leave we delete it, except for whatever the law requires us to keep longer —invoices, mainly—. The audit log cannot be edited or deleted while the account lives: it is what makes it possible to know who touched what, and a log that can be corrected is no good for that.

Security

Traffic is encrypted, passwords are stored as hashes and not in the clear, and each person only sees the screens their permission allows. One company data is never crossed with another: the server separates them on every query, not on the screen. No measure makes an incident impossible; if one happens that affects you, we tell you.

Your rights, and your customers rights

You can ask us for access to your data, its correction, its portability or its deletion by writing to the address below. If the one asking is a customer of yours, you are the one who has to attend to them —the data is yours and the console lets you correct it and delete it—; we help you with whatever is needed and we do not answer on your behalf. In the Dominican Republic, Law 172-13 on personal data protection applies.

Changes

If this policy changes in anything that matters, we tell you by email before it takes effect. The date above says when it was last changed.

Contact

Any question about this document gets answered by email.

[email protected]