Rando

Legal & Compliance

Security notice

A plain description of the controls that protect your Rando account and rental records.

Platform practices

Encryption in transit

All traffic to randocars.com is served over HTTPS with modern TLS ciphers.

Access control

Renter records are protected by row-level authorization so accounts can only read their own data.

Document storage

Uploaded driver licenses and IDs are stored in private buckets and served only through short-lived signed links.

Payment handling

Card details are captured and processed by our payment provider. Rando systems store only the card brand and last four digits.

Session security

Authentication uses short-lived tokens with refresh rotation; sessions can be revoked from your portal.

Monitoring

Application errors and anomalous authentication activity are logged and reviewed.

Your part

  • Use a unique password for your Rando account and enable a password manager.
  • Rando will never ask for your password, full card number or one-time code by phone or email.
  • Report suspicious messages claiming to be from Rando to security@randocars.com.
  • Sign out of shared devices; you can revoke active sessions from your portal.

Reporting a vulnerability

Send findings to security@randocars.com with reproduction steps and impact. We acknowledge reports within two business days. Please do not access data belonging to other renters, run denial-of-service tests, or publicly disclose an issue before we have responded.