Skip to main content

Trust & Security

Your rental. Your data. Protected end-to-end.

Road Vision Auto Rentals is built with modern security defaults so you can book, verify, and drive with confidence. This page explains the safeguards behind every reservation.

PCI-Compliant Payments

Payments are processed by Stripe, a PCI-DSS Level 1 service provider. We never see or store full card numbers — Stripe returns a token we use to charge deposits and balances.

Encryption in Transit & at Rest

All traffic to Road Vision uses HTTPS with TLS 1.2+. Databases, backups, and file storage are encrypted at rest using AES-256.

Identity Verification

Driver's licenses are verified through Persona with liveness checks. Phone numbers are confirmed with a Twilio one-time code before we send any booking SMS.

Access Controls

Row-level security policies gate every database read and write. Staff access is role-based, MFA-enforced, and audit-logged.

Resilient Infrastructure

We run on managed cloud infrastructure with automated daily backups, point-in-time recovery, and DDoS protection at the edge.

Continuous Monitoring

Error tracking, dependency scanning, and anomaly alerts run 24/7. Security patches are applied on a fixed cadence and out-of-band for critical CVEs.

How your data is handled

  • Personal information is collected only for the purposes described in our Privacy Policy.
  • Identity documents are retained only as long as required for insurance, fraud, and legal compliance — typically seven years.
  • We do not sell or rent your personal information to third parties.
  • All third-party processors (Stripe, Twilio, Persona, hosting) are bound by written data-processing agreements.

Responsible disclosure

If you believe you've found a security vulnerability, we'd like to hear from you. Please email security@roadvisionautorentals.com with a description, reproduction steps, and any proof-of-concept. We commit to:

  • Acknowledging your report within 2 business days.
  • Providing a triage update within 10 business days.
  • Not pursuing legal action against good-faith researchers who follow this policy.

Do not access data that isn't yours, disrupt the service, or use social engineering against our staff or customers.

Related policies