Last updated 25 August 2026
RVmigo is a marketplace, never a party to the rentals arranged on it — so most of what we hold exists to introduce a host to a renter and to keep a record of what the two of them agreed. This page sets out what that is, section by section, in the plainest terms we can manage.
RVmigo is a marketplace where people rent RVs directly from the owners. Hosts and renters deal with each other — they agree the trip, sign the rental agreement between themselves, and settle up directly, and RVmigo never handles the money. This page sets out what we collect while you use the site, who can see it, how long it stays, and what you can ask us to do about it.
Signing up stores your name, your email address and your password, which is hashed rather than kept as you typed it. Two things are optional until they aren't: a profile photo, and a phone number, which we ask for before you can send a booking request because a host needs a way to reach you about the trip. Your first name and photo appear on reviews you write; if you host, your full name and photo appear on your own host page, which search engines can index.
A session records the IP address and the browser it was created from. Signing out clears it; one you simply abandon stops working at its expiry, but the record of it stays, because that record is not deleted on a schedule. Attempts to sign in are rate-limited by the address they come from, which means we hold that address briefly whether or not the attempt was yours. This is ordinary sign-in machinery rather than anything we analyse, but it is your information, so it is listed here.
Publishing a listing means telling us where the RV is and what it is. The street address, the precise coordinates behind the map, the ZIP code, the VIN and licence plate, and registration and inspection dates are held back by default — our database layer drops those columns from every read that does not ask for them by name. The reads that do ask are your own pages, an administrator's, and the two surfaces built for a booking that is already under way: the trip page, and the printed trip pack. Insurance and roadside cover work differently on purpose: on public pages a renter sees only that cover is on file and the date it runs to, because that is what they are deciding on. Your policy and membership numbers appear in one place, the printed trip pack, which only the two people on a booking can open.
The street address you enter is never shown to renters. Where the RV sits is public, but not to the same precision everywhere: the listing's own page shows an approximate area centred on a point we offset from the real one, while search results and a host's own page show its true position. Once a host accepts, the renter sees the exact pickup point. A delivery address goes the other way and goes sooner — the host sees it as soon as the request arrives, because how far they would have to drive is part of deciding whether to say yes.
Hosts complete an identity check before they can publish, and renters before they can book. What we keep is the result: whether it passed and when, and — where the check records them — the type of document, its expiry date, the region that issued it, and a reference the provider can use to find their own record. Each attempt is kept, so a check that failed and was retried leaves both rows. Images of your document, the number printed on it, and anything derived from your face are not stored by RVmigo — our systems read the result and discard the rest. Other people see a badge saying documentation is on file; they never see the document.
How we handle biometric dataA booking request records, among other things, what the host needs in order to say yes:
Email addresses and phone numbers stay hidden from both sides while a request is still pending, and a message you send in a conversation is refused rather than quietly edited if it contains one — so nothing is hidden after the fact, and what you send is what the other person reads. Once a host accepts, each party can see the other's details, because at that point they have a trip to arrange between them. They stay visible afterwards: questions about a trip, and about who paid whom, outlive the trip itself.
Some of what you type is about somebody else. The names of additional drivers, a delivery address, and the email address a host enters to send someone a quote all describe a person who may have no account here and who never dealt with us directly. We ask for names alone — the form rejects anything shaped like a licence or document number — and we use these details for nothing beyond the booking they belong to. A quote recipient's address is used to send them the quote, to check against when someone types it to claim that quote, and to send the code that proves they can read it; nothing here creates an account for them, and if they want one they make it themselves. Additional drivers' names are written into the rental agreement, which is fixed at the moment it is generated and is not edited afterwards.
Messages between a host and a renter are stored so that either side can refer back to them, and so that we can look into a report. We may review and remove messages, listings or reviews. Reviews are held back until both sides have written one or the review window closes, and a published review is never deleted or rewritten — one that breaks the rules is hidden from view and the original stays on file.
The rental agreement is built from the terms of that one booking, fixed at that moment, and each party signs it by typing their name. Alongside the name and the time, we record the IP address and the browser the acceptance arrived from. That exists for one purpose: if either party later disputes having agreed, it is what shows the acceptance happened, and every e-signature service records the same thing for the same reason. Neither party sees the other's — those two values are visible only to RVmigo administrators.
The documents a host uploads, the condition photos either party takes at pickup and return, and a receipt a renter attaches when they mark a reservation deposit sent are kept outside the public part of the site. Condition photos and deposit receipts are served only to the two people on that booking and to administrators. A host's documents are served to administrators, and — for the types we mark renter-visible, which is their cover paperwork plus anything they filed as "other" — to any renter who has booked with that host, including on a booking that was later cancelled. Every photo you upload is re-encoded when it reaches us — listing photos, your profile photo, the condition photos at pickup and return, a deposit receipt, and any photo you file as a document — which strips its metadata, including any GPS coordinates the camera wrote. A document you upload as a PDF is the one exception: there is nothing to re-encode a PDF to, so it is stored exactly as you sent it and whatever your scanner recorded in it stays there.
Signing in sets a cookie identifying your session, plus a short-lived signed one holding your session details so that most pages need not re-read the database. Your light or dark theme preference is kept by your browser rather than in a cookie. Using the control below stores one more, either way you set it, holding nothing but that answer, so your choice survives your next visit. We also use Google Analytics, which sets its own cookies so that Google can recognise your browser across visits and tell one visit from several. We have switched off the setting that would let Google match you to a signed-in Google account, switched off sharing the data with Google for its own products, and not connected the account to Google Ads at all, and every time the tag loads it is told in so many words that advertising uses of your data are refused. There are no advertising cookies and nothing that follows you to other sites. We do not sell personal information, and we do not share it for advertising. If your browser tells the page it has Global Privacy Control switched on, we take that on its own as switching analytics off; the control below does the same thing explicitly. Before anything is sent we strip quote and calendar links out of the page address, because those links are themselves the credential. One event is reported by our own servers rather than by your browser — sending a booking request — so that we can tell the requests that began with a search here from the ones that began with a host's quote. It carries the identifiers Google's own cookies already hold — the one for your browser, and the one for the visit when your browser has it — and nothing further about you beyond the booking details listed below. It is not sent at all if you have switched analytics off with the control below, and if your browser attaches the Global Privacy Control signal to its requests we take that on its own as switching it off too, that being the form of the signal our servers can see. What Google receives is:
Analytics is allowed on this browser.
Switching this reloads the page, because a tag that has already loaded cannot be unloaded again. Turned off, we do not load Google's script at all and the cookies it set are deleted.
This covers the analytics described above. It does not switch off the error and performance monitoring in the next section, which reports on every page load and not only when something breaks.
Separately from the analytics above, every page load reports how long it took, and anything that breaks reports the error and the page it happened on, to an error-monitoring service. We do not deliberately send form contents or account details, though anything the server writes to its own log goes to the same place. That service may also record a replay of a session in which an error occurred — all text on the page is masked and images are blocked, so it captures the shape of what happened rather than what you were reading. We strip quote and calendar links out of the errors and page reports we send, and we switch replay off on any page opened directly from one; a link followed from elsewhere in the site can still reach a replay. When you send us feedback we attach the page, your browser, your screen size, whether you were in light or dark mode, a reference to the error if there was one, and a one-way keyed hash of your IP address rather than the address itself.
If you report a problem, or something on your account needs looking into, an administrator can open it and see the pages the way you see them. That view cannot act: it cannot send a message, sign anything, record a payment or change what you have saved, and the contents of your messages stay hidden from it. It closes itself after half an hour. Every time one is opened, the account, the administrator who opened it and the time are written to a record we keep.
RVmigo runs on services other companies provide — hosting, the database, file storage for photos and documents, delivery of the emails we send you, the error monitoring above, the analytics above, and a mapping service that turns an address into map coordinates. They handle information on our behalf and for those purposes only. Two of them are named rather than described, because who holds what is something you should be able to look up and act on: Google Analytics, named in the section above, and the company that carries out the identity check, named on our biometric policy page.
We do not delete anything on a schedule, with one exception: the analytics data described above, which Google deletes 14 months after your last visit. Your account and what hangs off it stay while the account does. A booking record, the rental agreement generated from it and the acceptance record described above stay as long as that booking record, because together they are the account of what two people agreed — and an agreement that could be quietly edited afterwards would be worth nothing. The names of additional drivers stay with their booking for the same reason. Ask us to remove something and we will delete what we can without destroying the record of a trip that actually happened.
You can change your profile photo, edit or unpublish a listing, and remove photos and documents you uploaded. You can switch off the analytics described above with the control in that section, on a phone as readily as on a desktop; the add-on linked beside it stops your browser sending to Google across every site you visit, but Google publishes it for desktop browsers only, and it cannot reach the one event our own servers send — for that, use the control here. For anything else — a copy of what we hold, a correction, or closing your account — send us a note and we will do it by hand; there is no self-serve button for it yet. Requests about the biometric data behind an identity check are handled separately, and the biometric policy page explains how.
If this policy changes, the date at the top of this page changes with it. If a change materially alters what we do with information we already hold, we will say so rather than leave you to spot the difference.
Questions about this policy, or about what we hold for you, go through the same form as everything else: Feedback