Privacy Policy
We would like to provide you with the following information in accordance with Article 13 of the General Data Protection Regulation (GDPR) and the UK General Data Protection Regulation (UK GDPR). This overview explains how we process, store, and use your personal data, as well as your rights under data protection law.
The specific data we process and how we use it depends on the actions you take (e.g., making a comparison, requesting a quote, booking a rental car) and/or the services you request or agree to. Therefore, not all sections of this notice may be relevant to you.Information provided in accordance with Article 13(1) GDPR
a. Name and address of the Data Controller
AurumCars GmbHErika-Mann-Str. 62-66, 80636 Munich, GermanyTel.: +49 (0) 89 9982 99 541Fax: +49 (0) 89 9982 99 542Email: kontakt@aurumcars.deRegistered office: MunichCommercial register number: HRB 227812 (Amtsgericht München)VAT ID: DE308244568Managing Director: Michael Trenkwalder, Gerrit Seidelb. Name and address of the Data Protection Officer
Data Protection Officer: Joachim HeerAurumCars GmbH80251 Munich, GermanyEmail: datenschutz@aurumcars.de
1. General Information
At this point, we would like to explain how we handle personal data that you provide to us when visiting our website, as well as some important information on data protection. We respect the data protection rights of every individual.Our services comply with the legal data protection regulations outlined in the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and relevant competition law.For any questions regarding these topics, please contact datenschutz@aurumcars.de. When you visit our website, various types of information are automatically collected in server log files. This includes, for example, the type and version of your web browser, your operating system, information about yourinternet service provider, and other similar technical details. These details are collected automatically for technical reasons and are necessary to ensure the proper functioning of the website. Such anonymous information may also be used for statistical analysis to optimize our website.
2. Data Storage, usage and Security
2.1. Data collection and storage by AurumCars GmbH (operating as Planet Rentalcars)
The data you enter into the booking funnel provided by AurumCars GmbH, Erika-Mann-Str. 62-66 in 80636 Munich, Germany, operating the website planetrentalcars.co.uk, (hereinafter referred to as "Planet Rentalcars") will be collected, processed, and stored by Planet Rentalcars for the purposes of creating offers, processing your request, and customer support.
We do not share your data with any unauthorized third parties, unless it is strictly necessary for fulfilling a contract you have entered into with us or for the preparation of an offer, or if we are legally required to do so. You may withdraw any consent you have previously given at any time and/or object to the future use of your data.
Planet Rentalcars also uses the data entered in pseudonymized form for statistical analysis, market research, and improving our online presence, unless you have exercised your legal right to object to such use. Within our company, those departments that require access to your data in order to fulfil our contractual and legal obligations will have access to it. Additionally, service providers and agents engaged by us may also receive data for these purposes within the framework of data processing agreements (pursuant to Art. 28 GDPR). These companies operate in the fields of IT services and accounting.
Once you enter personal data into our booking form, all communication is encrypted. We connect you to our secure server, ensuring that your data cannot be intercepted by unauthorized parties. Your data is encrypted using the 128-bit SSL encryption protocol and transmitted in a secure HTTPS mode. This security standard is widely used by banks and other financial institutions. The use of SSL encryption is also recommended by the German Federal Office for Information Security (BSI), the UK’s National Cyber Security Centre (NCSC), and the Information Commissioner’s Office (ICO).
2.2 External companies and service providers
Like many other companies, Planet Rentalcars also relies on the assistance of external service providers to process your personal data. These companies mainly operate in the areas of IT and internet services (hosting, housing, internet connectivity, etc.), telecommunications, call centers, and email services. We have carefully selected, reviewed, and contractually bound these external service providers to ensure compliance with all technical, organizational, and legal requirements.
Furthermore, when selecting direct external service providers—particularly those handling data storage, call center operations, and email distribution—we prioritize companies based primarily in Germany or within the EU. However, it cannot be completely ruled out that these service providers may themselves engage subcontractors whose headquarters are located in a third country as defined by the GDPR (i.e., outside the EU). Additionally, we may also engage other service providers with headquarters in a third country, and the same applies to any subcontractors used by these providers.
The legality of actively using service providers in a third country, and thus transferring personal data to them, has not been outright prohibited by the EU Parliament, the European Court of Justice (ECJ), or German legislators. However, companies that choose to do so must meet stringent legal requirements, conduct thorough assessments, and implement additional contractual agreements with the respective service providers, as outlined in Articles 44 to 49 of the GDPR. These measures ensure that, first, the level of data protection guaranteed by the GDPR is not undermined, and second, that the service provider can always guarantee an adequate level of protection in compliance with GDPR standards.
Consequently, we ensure that before any service provider in a third country is engaged—and before any personal data is transferred to them—all relevant legal requirements are carefully reviewed and, if necessary, additional contractual agreements are made in accordance with Articles 46 and beyond of the GDPR. These regulations also apply to subcontractors engaged by the service providers. In general, data transfers are permitted if the third country where the service provider is located has been deemed to provide an adequate level of data protection, as confirmed by an adequacy decision of the European Commission under Article 45 of the GDPR.
If no such adequacy decision exists for the respective country under Article 45(3) of the GDPR, then two key conditions must be met:
- Suitable contractual safeguards must be established between Planet Rentalcars and the service provider.
- Affected individuals must have enforceable rights and effective legal remedies.
We ensure compliance with these requirements. As suitable guarantees, the European Commission has defined the use of standard contractual clauses (current as of June 4, 2021; Article 46(2)(c) GDPR) and binding corporate rules under Article 47 GDPR. If these measures are insufficient on their own, Planet Rentalcars enters into individual contracts with companies in third countries to guarantee an adequate level of data protection in line with GDPR standards. However, Planet Rentalcars has not yet made use of this option to date.
2.3 When do we collect personal data?
We collect personal data in the following situations:
- When you visit our website and use our services
- When you make a booking or reservation
- When you contact customer support
- When you subscribe to our newsletter or marketing communications
- When you provide feedback or reviews
- When you participate in surveys, promotions, or competitions
- When you cancel your booking
Additionally, when you access our website, we automatically collect certain data necessary for the technical operation and security of our website.
2.4 What data do we process?
We may collect and process the following categories of personal data:
- Identification & Transaction Data
- Name, address, email, phone number, age
- Payment details (processed for transactions but not stored)
- Booking history
- Device & Usage Data (collected automatically)
- IP address
- Browser type and version
- Operating system
- Access date and time
- Requested page (specific URL)
- Access status / HTTP status code
- Amount of data transmitted
- Referring website (previously visited page)
- Customer account ID (if logged in)
- Cookies & Tracking Data
- Information collected via cookies and tracking technologies (see Section 3).
- Customer Interactions & Inquiries
- Customer service interactions (via email, phone, or chat)
- Location & Telematics Data
- Location data from connected vehicles
- Telematics data, where applicable
2.5 How do we use your data?
To clarify upfront: we never sell your data – that's a promise.
When you complete a car rental booking contract, we are required to transmit your data to the provider/rental company/insurer you have selected, and only to that entity. This is necessary for the provider/rental company/insurer to deliver the requested service to you.
Additionally, if you are the holder of a customer account, data may be transmitted as required to Auth0, Inc., a subsidiary of Okta, Inc (20 Farringdon Rd, London, EC1M 3HE, United Kingdom).
Furthermore, we rely on the expertise within our company as well as on centralized services within the CHECK24 Group. Like almost all companies worldwide, we also collaborate with various external service providers.
We process your data for the following purposes:
- Providing our services and fulfilling contracts (Article 6(1)(b) UK GDPR)
- Customer service and support (Article 6(1)(f) UK GDPR)
- Marketing and promotional activities (Article 6(1)(a) UK GDPR, with consent)
- Fraud prevention and security monitoring
- Compliance with legal obligations
- Vehicle damage and incident analysis
- Automated data analysis for service improvements
Additionally, data collected through log files are processed to:
- Ensure the security and stability of our website
- Prevent unauthorized access and fraudulent activities
2.6 Use of our website
When you acces our website, we automatically collect the following data, which is required for technical and security reasons:
- IP address
- Date and time of the request
- Requested content (specific page)
- Access status / HTTP status code
- Amount of data transferred
- Referring website (previously visited page)
- Operating system
- Browser type and version
- Customer account ID (if previously logged in)
These data are stored for a maximum of 3 months before being deleted or anonymized. If extended storage is required, IP addresses and customer account IDs are partially anonymized to prevent identification.
Legal Basis: Article 6(1)(f) UK GDPR (Legitimate Interest)
You have the right to object to this processing. However, in accordance with Article 21(1) UK GDPR, second sentence, we cannot honor such objections, as the collection of these data is necessary for the security and stability of our website.
If you have a registered customer account, our system checks via a cookie whether you have new messages in your account. This does not display the content of the messages but only signals their presence.
Legal Basis: Article 6(1)(b) UK GDPR (contractual necessity).
2.7 Use of car rental broker services
When using our broker website, we collect the following data:
- Driver’s age
- Pick-up and drop-off locations
- Pick-up and return dates and times
- Desired rental duration
These data are used for statistical purposes and are anonymized before analysis. No individual users can be identified.
If you have a registered account and are logged in, your comparison results will be linked to your account.
Legal Basis:
- Article 6(1)(f) UK GDPR (Legitimate Interest) for anonymous statistical analysis.
- Article 6(1)(b) UK GDPR (Contractual Necessity) if linked to a customer account.
2.8 Account holder
If you are the holder of a customer account, we will transmit data to Auth0, Inc., a subsidiary of Okta, Inc (20 Farringdon Rd, London, EC1M 3HE, United Kingdom) within the scope and extent of the applicable terms of use for the customer account and in order to fulfil this contract. This primarily occurs each time you log into your customer account.
2.9 Online booking
When making an online booking, we collect the following data:
- Full name
- Address
- Phone number
- Additional personal details (title, salutation, date of birth)
- Payment details (Credit Card, PayPal)
- Contract-related communication
- Promotional details (e.g., voucher codes)
Legal Basis: Article 6(1)(b) UK GDPR (Contractual Necessity).
If you are the holder of a customer account and are logged into your account at the time of using our car rental search, the transaction will be linked to your customer account. The legal basis for this processing is Article 6(1)(b) GDPR (or UK GDPR for UK users), as you have entered into a separate service contract with AurumCars GmbH in this case.
Additionally, we may send marketing emails about similar products unless you opt out. You can unsubscribe at any time via datenschutz@aurumcars.de.
Legal Basis: Article 6(1)(f) UK GDPR (Legitimate Interest).
2.10 Payment processing
We offer you various payment methods to process payments in the event of a booking completion. Planet Rentalcars collaborates with CHECK24 Zahlungssysteme GmbH, based in 80636 Munich (hereinafter referred to as "CHECK24 Zahlungssysteme"). This company is a subsidiary of CHECK24 GmbH, also based in 80636 Munich, and is certified according to the international security standards of the credit card industry (for more information, visit: https://de.pcisecuritystandards.org). The corresponding privacy policy of CHECK24 Zahlungssysteme can be found here.
Payment by credit card
If you select the credit card payment option, your credit card details will be entered directly with CHECK24 Zahlungssysteme. Planet RentalCars only receives a unique identifier (token) for the credit card data set from CHECK24 Zahlungssysteme. This allows access to masked credit card data, which includes the last four digits of the credit card number, the cardholder’s name, and the expiration date.
Upon booking completion, Planet RentalCars, through CHECK24 Zahlungssysteme, will generally conduct an initial validation of your credit card. This involves a so-called €0 authorization to verify the authenticity of the credit card used. This verification helps protect our customers and partners by preventing failed payments and fraud. There are no fees for this service, and your credit card will not be charged.
To provide this service, CHECK24 transmits your payment details (e.g., name, credit card data) to the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (hereinafter referred to as “Stripe”). Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses.
As a general rule, after a successful credit card validation, Planet Rentalcars transmits your credit card details (e.g., name, credit card number) and personal information (e.g., email address, IP address, home address) via CHECK24 Zahlungssysteme for the purpose of completing the booking and processing payment with the respective partner of your chosen offer (rental broker, car rental provider, insurance provider, etc.).
Partners of Planet Rentalcars that receive credit card data must annually confirm compliance with international credit card security standards through self-assessments or certifications (if applicable).
For most partners, Planet Rentalcars handles the payment processing of credit card transactions. In such cases, Planet Rentalcars, via CHECK24 Zahlungssysteme, transmits your payment data (e.g., name, credit card details, transaction amount) and personal information (e.g., email address, IP address, home address) to Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Data transfers to the USA are based on the EU Commission’s Standard Contractual Clauses.
You can find details here and here.
Payment by PayPal
We offer our customers the option to pay using the PayPal payment service provided by PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter referred to as “PayPal”).
When you choose PayPal as your payment method, Planet RentalCars, through CHECK24 Zahlungssysteme, transmits your payment data and personal information to PayPal for payment processing.
For details click here: https://www.paypal.com/uk/webapps/mpp/ua/privacy-full
2.11 Online check-in for car hire pickup
Planet Rentalcars offers you the option of completing an online check-in for your car rental pickup with certain rental companies. The use of this service is optional and not mandatory for you. Therefore, you are free to use this service if it is offered by the rental company and supported by Planet Rentalcars.
Planet Rentalcars has no influence on whether this service is offered by a rental company or not.
The essential prerequisites for using this service are:
- You are the holder of a customer account.
- The relevant booking is linked to your customer account.
Identification as part of the online check-in
If you voluntarily use this service, you will be required to provide a copy of your driver's license and ID card (i.e., photos of the front and back of each document) to an external identity verification service provider engaged by Planet Rentalcars. You may redact certain non-essential information on your ID card (e.g., CAN access number, signature, eye color, height, artistic name). Redacting these details does not affect the online check-in process. However, all other information on the ID card is required.
The external identity verification provider, acting on behalf of Planet Rentalcars (and not as an independent controller), will validate the submitted documents and report the verification results back to Planet Rentalcars. This report will include automated extraction of specific data from your documents, such as full name, address, date of birth, place of birth, nationality, document numbers (ID card and driver's license), issue and expiry dates, issuing country and authority, and driver's license categories.
Planet Rentalcars will store this data to document and verify that valid documents have been submitted for online check-in and checked by an identity verification provider. This data storage is usually followed by a selective transfer of the data to the relevant rental provider to facilitate the online check-in process.
Legal basis: The verification of the authenticity of the driver’s license and ID card, the automated extraction of personal data from these documents, and the storage of this data for documentation purposes is based on Article 6(1)(b) GDPR.
Permanent storage of online check-in data
Planet Rentalcars offers customers who have already used the online check-in service the optional possibility to store their data permanently, meaning that it will be retained until actively revoked or requested for deletion.
To use this service, you must be the holder of a customer account. If you opt for this service, you can benefit from a simplified online check-in process for future rentals. You will not need to undergo identity verification again but must confirm that the documents remain valid and that you still hold a valid driver’s license at the time of vehicle pickup.
Legal basis: The permanent storage of this data until revoked is based on Article 6(1)(b) GDPR.
Transfer of online check-in data to the rental provider
If you voluntarily use the online check-in service for your rental, Planet Rentalcars will require you to provide an initial identification or re-identify yourself if your documents have expired. If you have opted for permanent data storage, you must confirm that your documents are still valid.
Once identification or confirmation is complete, Planet Rentalcars will transfer the necessary data to the relevant rental provider. The exact data required for online check-in is determined solely by the rental provider, not by Planet Rentalcars.
It is expected that at a minimum, the following personal data will be transmitted: full name, address, date of birth, phone number, email, nationality, document numbers (ID card and driver’s license), issue and expiry dates, issuing country and authority, and credit card information.
In some cases, it may also be necessary for Planet Rentalcars to provide the rental provider with a copy of your ID and/or driver’s license (photo version), which you previously uploaded to our system.
Legal basis: The transfer of this data to the rental provider as part of the online check-in process is based on Article 6(1)(b) GDPR.
Storage duration
- Log file data is stored for a maximum of 3 months before being deleted or anonymized.
- If extended storage is required, IP addresses and customer account IDs are partially anonymized to ensure that identification is no longer possible.
- In some cases, we may not be able to delete your data immediately, even if you request it. This includes:
- When we are legally required to retain certain data (e.g., financial, tax, or anti-fraud records).
- When data is needed to resolve legal disputes or enforce agreements.
- If data is stored in backups, deletion may take longer, but we will remove it from active systems.
2.12 Other data processing & storage
We process the following data in connection with the sending of a car hire offer:
- E-mail address
- Details of the offer
- Static link reflecting the preferences of the comparison result
The legal basis for the processing is Art. 6 para. 1 lit. b GDPR.
We process the following data in connection with the last searches:
- Driver age
- Pick-up and return location
- Pick-up and return date
- Pick-up and return time
- Static link reflecting the preferences of the comparison result
The legal basis for the processing is Art. 6 para. 1 lit. b GDPR, provided that you have used the service at all. No further processing of the data takes place.
We process the following data in connection with the reminder emails:
- Driver age
- Pick-up and return location
- Pick-up and return date
- Pick-up and return time
- Details of the offer
- Static link reflecting the preferences of the comparison result
The legal basis for the processing is Art. 6 para. 1 lit. b GDPR if you have used the service. No further processing of the data takes place.
We process the following data in connection with the use of our chatbot:
- Input from you that you voluntarily provide to us while using the chatbot
- Optional telephone number, only if the user wishes to be called back
- Optional e-mail address, only if, for example, the sending of an offer is desired
In order to be able to present you with automated and therefore targeted answers to your questions, we must process and analyze your input. The legal basis for processing is Art. 6 para. 1 lit. f) GDPR, provided that you make use of this service.
However, if a callback is also initiated with the help of the chat, the content of the chat history and the telephone number will be transmitted to us in order to contact you as requested. After a successful callback, this data is automatically and irrevocably deleted. The legal basis for the processing is Art. 6 para. 1 lit. f) GDPR.
However, if you have specific questions about an existing contract that you have concluded with us in the past and either actively log in to your customer account while using the chatbot or are already logged in, we will add this chat history to the relevant contract as contract-related communication and thus store it permanently. The legal basis for the processing is Art. 6 para. 1 lit. b) GDPR.
Notwithstanding this, we will use both your entries, if they have not already been anonymised, and the automatic responses of the chatbot in anonymised form both to check the correctness of the responses and to optimise the responses by our system in anonymised form. The legal basis for both processing operations is Art. 6 para. 1 lit. f) GDPR.
3. Cookies
To view our Cookie policy, click here.
As part of our ongoing efforts to improve our services for users, we may use additional tracking technologies provided by third parties and ourselves, which employ both anonymized and temporary "session cookies" as well as "persistent cookies." Cookies are usually small text files that a web server transfers to your device when you visit a website.
Session cookies (temporary cookies) are not stored permanently on the device you use to access our website and disappear when you close your browser. These cookies may contain information about your browser type, screen resolution, operating system, or other device-specific data. They help facilitate navigation on our website and ensure proper display of web content.
Persistent cookies (also called permanent cookies), on the other hand, store anonymous information on your device and remain available even after you close your browser. Each of these cookies has a specific expiration date, after which it is automatically deleted. The purpose of these cookies is, among other things, to generate anonymous statistics on the use of our online presence. Such statistics help us identify areas where we can optimize our website to make it easier for you to use.
Both types of cookies are anonymous. No individual user profiles are created based on your browsing behavior.
Of course, you can use our website without cookies by disabling them in your browser settings. Please refer to your browser’s help section for instructions on how to deactivate cookies. However, be aware that disabling cookies may cause display and navigation issues when using our website.
Important for you:
The data collected by us through cookies is not shared with third parties and is not linked to your personal data without your consent. Additionally, third-party providers cannot and are not intended to identify you personally based on the data stored in these cookies.
4. Tracking Technologies
4.1 DoubleClick
DoubleClick is a service of Google Inc, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google”). DoubleClick uses cookies (so-called ‘floodlights’) to present you with better and more relevant adverts. The cookies are often used to display adverts that are relevant to you, to improve campaign performance reports or to prevent you from seeing the same advert more than once.
Planet Rentalcars may use Google’s DFP ad management system to support online advertising. Google uses so-called "session cookies" and/or "persistent cookies" for this purpose. The information collected using cookies or Spotlight technology is anonymous and not personally identifiable. They do not contain your name, address, telephone number, or email address.For further information and Google's applicable privacy policy, please visit:https://policies.google.com/privacy?hl=en-GBThis technology is also known as "Online Behavioural Advertising" (OBA). You can read more about it here:https://www.youronlinechoices.com/uk/about-behavioural-advertisingTo disable this technology provided by Google, please visit:https://www.youronlinechoices.com/uk/your-ad-choicesGoogle has committed to complying with these processes as part of its self-regulatory obligations and privacy policy.
4.2 Google Analytics
This website uses Google Analytics, a web analytics service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Google Analytics uses cookies to enable an analysis of your website usage. The information generated by these cookies is generally transmitted to a Google server in the United States and stored there.
Due to the activation of IP anonymization, your IP address is truncated within the European Union (EU), the European Economic Area (EEA), or the United Kingdom (UK) before transmission. In exceptional cases, the full IP address may be transmitted to a Google server in the USA and shortened there.
On behalf of this website’s operator, Google will use this data to evaluate your website usage, compile website activity reports, and provide other services related to website usage and internet activity. The IP address transmitted by your browser within Google Analytics is not merged with other Google data.You can prevent the storage of cookies by adjusting your browser settings, but this may affect the website’s functionality.Additionally, you can prevent Google Analytics from collecting and processing your data by installing the opt-out browser plugin available here:https://tools.google.com/dlpage/gaoptout?hl=en-GBFor further information, visit Google’s privacy policy:https://support.google.com/analytics/topic/2919631?hl=en&ref_topic=1008008&sjid=7400741658809403025-EU
4.3 Google Tag Manager
This website uses Google Tag Manager, a tag management service provided by Google Inc. Google Tag Manager helps manage website tracking without using cookies.Tags are small code snippets used to:- Measure traffic and visitor behavior
- Analyze the impact of online advertising and social channels
- Implement remarketing and audience targeting
- Test and optimize the website
Google Tag Manager does not collect personal data but triggers other tracking tags. If you have already disabled tracking at the cookie or domain level, this will still apply to tracking tags managed via Google Tag Manager.For more information:https://support.google.com/tagmanager/answer/9323295?hl=en
4.4 Google Ads conversion tracking
This website uses Google Ads Conversion Tracking, an analytics service provided by Google Inc.If you visit our website via a Google ad, a "conversion cookie" is automatically set by Google Ads. This cookie expires after 30 days and does not allow personal identification.Each Google Ads client receives a unique cookie, preventing cross-client tracking. This cookie helps Google and us determine:
- Whether someone clicked on an ad
- If they were redirected to a conversion-tracked page
- How many times they clicked the ad within 30 days
Google only provides aggregate data on ad performance. We cannot identify individual users.If you do not want to participate in tracking, you can disable cookies in your browser settings or block cookies from www.googleadservices.com.Alternatively, you can opt out of Google Ads tracking here:https://adssettings.google.com/authenticatedFor more information:https://policies.google.com/technologies/ads?hl=en-GB
4.5 Microsoft Bing Ads – Universal Event Tracking (UET)
This website uses Microsoft Bing Ads Universal Event Tracking (UET), a conversion tracking service provided by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA ("Microsoft").If you arrive at our website via a Bing ad, a cookie is set on your device. Microsoft and we can then determine:
- The total number of users who clicked an ad
- If users reached a predefined goal page
Microsoft stores this data for 180 days. No personally identifiable information is collected.If you do not want to participate in Bing tracking, you can disable cookies in your browser or opt out via this link:https://account.microsoft.com/privacy/ad-settings/signedout?ru=https%3A%2F%2Faccount.microsoft.com%2Fprivacy%2Fad-settingsFor further details, visit:https://www.microsoft.com/en-GB/privacy/privacystatement/
4.6 General Tracking
Planet Rentalcars uses its own tracking tool, GeneralTracking, to collect anonymized event data.If you wish to opt out of GeneralTracking, click here.
4.7 Crietor remarketing
We use the online marketing services of Criteo GmbH, Gewürzmühlstr. 11, 80538 Munich, based on legitimate interests (i.e., interest in analyzing, optimizing, and economically operating our online offering in accordance with Article 6(1)(f) GDPR).
Criteo’s services allow us to display advertisements on and for our website in a more targeted manner, ensuring that users only see ads that are relevant to their potential interests. If a user, for example, is shown advertisements for products they previously viewed on other websites, this is known as "remarketing".
For this purpose, when users visit our website and other websites where Criteo is active, Criteo executes a code and embeds so-called (re)marketing tags (invisible graphics or code, also referred to as "web beacons") into the website. These tags help store an individual cookie on the user’s device (or use similar technologies). This cookie records information about which websites the user has visited, which content they are interested in, and which offers they have clicked on. Additionally, it logs technical details about the browser and operating system, referring websites, visit duration, and other data regarding the use of the online offering. This information may also be combined with data from other sources by Criteo. If the user subsequently visits other websites, advertisements tailored to their interests may be displayed.
The processing of user data is pseudonymous, meaning that no clear personal data (such as names) are processed, and users' IP addresses are shortened. Processing is based solely on an online identifier, a technical ID. Any IDs (e.g., order numbers) or email addresses shared with Criteo are hashed and stored as a series of characters that do not allow identification.
For more information and options to opt out of data collection by Criteo, please refer to Criteo’s privacy policy: https://www.criteo.com/de/privacy. You can also deactivate Criteo remarketing by adjusting the corresponding settings on the linked page: Cookie Usage Information.
5. Data retention period
We retain your personal data for as long as necessary for:
- Contract fulfilment and legal obligations
- Compliance with record-keeping laws (e.g., tax and accounting regulations)
- Handling customer service and complaints
The standard retention periods are:
- 2–10 years for tax and financial records
- Up to 4 years for complaints and disputes under EU travel law
- Up to 30 years for legal claims under statute of limitations laws
6. Right to Withdraw Consent and Right of Access
As a customer you have the following rigts according to the UK GDPR:
- Right to access (Art. 15 UK GDPR)
- Right to rectification (Art. 16 UK GDPR)
- Right to erasure ("Right to be forgotten", Art. 17 UK GDPR)
- Right to restrict processing (Art. 18 UK GDPR)
- Right to data portability (Art. 20 UK GDPR)
- Right to object (Art. 21 UK GDPR)
6.1 Product reviews and recommendations via email
As a customer of Planet Rentalcars, we may use your email address to send you product review requests or other feedback requests related exclusively to your purchase, contract completion, or similar transactions. In this context, we may also use your email and/or postal address to send you product recommendations for similar products or services that we offer.
These review requests and product recommendations are sent regardless of whether you have subscribed to a newsletter.
You can withdraw your consent to receive such requests at any time by sending a letter to: AurumCars GmbH, Erika-Mann-Str. 62-66, 80636 Munich, Germany datenschutz@aurumcars.deNo additional costs apply beyond the standard transmission fees according to your basic tariff.
6.2 Right to Withdraw Consent
You have the right to withdraw any consent you have previously given for data processing, either selectively or completely, with effect for the future.To do so, please send a written request to: AurumCars GmbH, Erika-Mann-Str. 62-66, 80636 Munich, Germany datenschutz@aurumcars.deNo additional costs apply beyond the standard transmission fees according to your basic tariff.To ensure that we can clearly identify you, please include your full name, postal address, date of birth, and reference to a transaction, offer, or contract in your request.
6.3 Right of Access
Upon written request, our Data Protection Officer will provide information about the personal data we have stored about you. Additionally, they will process your request for deletion under Article 17 GDPR or your request to restrict processing under Article 18 GDPR and initiate the necessary steps accordingly.Please send your request in writing to:AurumCars GmbH Joachim Heer, Data Protection OfficerErika-Mann-Str. 62-66, 80636 Munich, Germanydatenschutz@aurumcars.de
To ensure data security, a response can only be provided if you include the following details in your request: Full first and last name Current and, if applicable, previous postal address Date of birth Email addressThese details serve as a security measure to prevent unauthorized access to your personal data.
6.4 Right to Erasure ("Right to be Forgotten")
If you wish to have your data deleted or blocked, you can contact our Data Protection Officer directly.
Please send your deletion request in writing to:AurumCars GmbH Joachim Heer, Data Protection Officer Erika-Mann-Str. 62-66, 80636 Munich, Germany datenschutz@aurumcars.de
To process your request in compliance with Article 17 GDPR (Right to Erasure) and Article 18 GDPR (Restriction of Processing), we require the following details: - Full first and last name - Current and, if applicable, previous postal address - Date of birth - Email address(es)Providing offer, transaction, or contract numbers (if available) can help speed up the process but is not mandatory.These details ensure that we can identify and remove all relevant data associated with you. Without this information, we cannot guarantee that your request for data deletion or blocking will be fully processed.
7. Customer account
The customer account is operated by Auth0, Inc., a subsidiary of Okta, Inc (20 Farringdon Rd, London, EC1M 3HE, United Kingdom) at the Okta address and is subject to separate terms of use, which require user consent and can be accessed here.
The customer account allows you to view and manage all your activities in a central location. Additionally, we use this data to improve your customer experience and personalize the services. However, this only occurs when you are logged in at the time of performing an activity.
As long as you have a customer account, the activities associated with it are not deleted by us unless you specifically request it, either directly or through your customer account. In such cases, the associated activities will be handled as if they had not been linked to your customer account at that time. This means that the standard deletion periods, as outlined in section 5, will automatically apply.
8. Linking policy
If external links (hyperlinks) refer to third-party websites that are outside Planet Rentalcars’ control, we are only liable if we are aware of the content and if it would be technically possible and reasonable for us to prevent their use in the event of illegal content.
For any further content and, in particular, for damages resulting from the use or non-use of such information, only the provider of the respective website is responsible, not the party that merely refers to the publication via a link.
Planet Rentalcars explicitly disclaims any responsibility for third-party content of any kind.
9. Additional notes
9.1. Obligation to provide data
If you enter into a business relationship with us, you must provide the necessary data for contract initiation and execution. Without this information, we cannot process your requests or provide services.
9.2. Automated Decision-Making & Profiling
- No fully automated decision-making takes place.
- We may use profiling for:
- Personalized product recommendations
- Fraud prevention and risk assessment
You have the right to object to profiling used for direct marketing at any time.
10. Consent declarations
I consent to the fact that, when making an online rental car booking, my computer’s IP address, along with the corresponding date and time, is transmitted to Planet Rentalcars and stored for security reasons in order to protect both myself and Planet Rentalcars from data misuse.
All consent declarations can be revoked at any time with future effect, either:
- By sending a letter to: AurumCars GmbH, Erika-Mann-Str. 62-66, 80636 Munich, Germany
- Or via email to: datenschutz@aurumcars.de
Cookie Preference
If you would like to change your cookie preferences, you can adjust your settings here.The respective privacy policies of third-party providers can be found directly on their respective websites.