1. Overview & scope
This Technical Abuse Policy ("Policy") describes activities that are prohibited on the RentMy platform and how Renterval LLC (operating as RentMy, "RentMy", "we") investigates and enforces against them. This Policy supplements — and forms part of — our Terms & Conditions. Capitalized terms used here have the meanings given in those Terms.
This Policy applies to:
- Account holders and their invited team members.
- Renters and visitors interacting with RentMy-hosted storefronts.
- Anyone making API calls or programmatic requests against the Service.
2. Prohibited activities
You will not, and will not authorize or assist any third party to, use the Service to:
- Violate any applicable law, regulation, or third-party right.
- Engage in fraud, money laundering, or sanctions evasion.
- Distribute or facilitate distribution of malware, viruses, ransomware, or any malicious code.
- Send unsolicited bulk email, SMS, or other communications ("spam"), or use the Service in violation of CAN-SPAM, the TCPA, GDPR e-privacy rules, or equivalent.
- Phish for credentials, payment data, or other sensitive information.
- Impersonate another person or entity, or misrepresent your affiliation.
- Upload, host, or transmit content that is unlawful, defamatory, harassing, hateful, or constitutes child sexual abuse material or non-consensual intimate imagery.
- Attempt to gain unauthorized access to any account, system, or data.
- Probe, scan, or test the security or vulnerability of the Service except under §5 below.
- Interfere with, degrade, or disrupt the Service, including via denial-of-service attacks, resource flooding, or signal-amplification attacks.
- Reverse engineer, decompile, or disassemble any part of the Service.
- Use the Service to mine cryptocurrency, host distributed compute workloads unrelated to rental operations, or otherwise consume disproportionate resources (see §8).
- Bypass usage limits, rate limits, throttling, paywalls, or other technical protection measures.
- Use the Service to rent items that are illegal in the jurisdiction where the Renter is located, or that are designed primarily for unlawful purposes.
3. System & network abuse
You will not engage in activities that compromise or attempt to compromise the security or operation of the Service or the systems of other RentMy users. This includes — but is not limited to:
- Unauthorized port scanning, vulnerability scanning, or fuzzing of RentMy infrastructure or any storefront hosted on it.
- Sending packets with forged, spoofed, or otherwise misleading headers.
- Attempting to bypass authentication, authorization, or audit controls.
- Using vulnerabilities in the Service for purposes other than coordinated disclosure (§5).
- Operating, hosting, or facilitating command-and-control infrastructure for botnets or malware.
- Conducting man-in-the-middle attacks against any RentMy user or RentMy infrastructure.
4. Resource & rate limits
The Service enforces rate and resource limits to keep performance fair across all users. Documented limits are published in our API and product documentation and may be adjusted over time. You agree to:
- Respect documented rate limits and avoid request patterns that constitute abuse, even if not specifically rate-limited.
- Implement back-off behavior on receiving HTTP 429 or 5xx responses, with exponential delay and jitter.
- Cache and batch where reasonable instead of polling at sub-minute intervals.
- Avoid generating excessive write traffic via bulk operations during peak hours; use the bulk endpoints when available.
- Not deploy infrastructure intended to circumvent fair-use limits (e.g. distributing requests across multiple accounts to defeat per-account caps).
Workloads that materially affect Service stability or other users' experience may be throttled, throttled down, or blocked at our discretion, with notice where practicable.
5. Security & responsible disclosure
If you believe you've found a security vulnerability in the Service, we want to hear about it. Please report it privately and give us a reasonable opportunity to fix it before disclosing publicly.
- How to report: email [email protected] with the subject line "Security disclosure" and as much detail as you can — affected URL or endpoint, reproduction steps, screenshots or PoC code, and your contact details.
- Safe-harbor. RentMy will not pursue legal action against good-faith security research that is reported to us privately, that does not access or modify other users' data without consent, that does not interrupt or degrade the Service for others, and that gives us a reasonable time to fix the issue before public disclosure.
- Out of scope: denial-of-service testing, social engineering of RentMy employees, physical attacks against RentMy offices, and attacks against third-party services (payment processors, infrastructure providers) — please report those to the appropriate vendor.
6. Malware, spam & phishing
You may not use the Service to host, send, or distribute:
- Malware, ransomware, spyware, or any code intended to harm or gain unauthorized access to a system.
- Phishing pages, credential-harvesting forms, or content designed to deceive recipients into revealing sensitive information.
- Bulk email, SMS, or push notifications that are not solicited or that violate applicable law (CAN-SPAM, TCPA, GDPR e-privacy directives, CASL, etc.).
- Email messages that omit valid sender identification, omit a working unsubscribe mechanism, or use deceptive subject lines.
RentMy uses automated and human review to detect spam and abuse. Confirmed violations result in account suspension. We reserve the right to publicly blacklist sending domains used to send abusive messages from our infrastructure.
7. Bots, crawlers & automation
You may automate interactions with the Service via the documented API and webhook surface. You may not:
- Use unofficial scrapers, headless browsers, or automated tools that simulate human user activity to circumvent the API or rate limits.
- Programmatically create accounts, complete checkouts, or generate fake bookings.
- Crawl any non-public surface of the Service or harvest user data, contact lists, or pricing without authorization.
Bot traffic that mimics human behavior or evades detection may be blocked, fingerprinted, or challenged with CAPTCHA at any time.
8. Cryptomining & excessive compute
The Service is built for rental management, not general-purpose compute. You may not use the Service or its serverless functions, background workers, or storage to:
- Mine cryptocurrency, run proof-of-work, or run distributed-ledger validation workloads.
- Host or distribute media files (audio, video, large binaries) unrelated to your rental catalogue.
- Use the platform as a general-purpose CDN or proxy for content unrelated to your business.
RentMy reserves the right to throttle, suspend, or terminate accounts whose usage patterns are inconsistent with rental operations.
9. Reporting abuse
To report abuse, fraud, or any violation of this Policy by a RentMy account or storefront:
- Email: [email protected] — subject line: "Abuse report"
- Phone: + (408) 728-8556 (business hours)
To help us act quickly, include: the URL or account in question, the specific behavior you observed, headers or screenshots if you have them, and your contact details so we can follow up.
10. Investigation & response
RentMy investigates reports promptly. We may, without prior notice, take any action we believe in good faith is reasonable to protect the Service or other users, including:
- Blocking IPs, rate-limiting, or throttling specific traffic patterns.
- Disabling specific features (e.g. email sending) on an account pending review.
- Removing or quarantining content that violates this Policy.
- Requesting additional information from the account owner.
- Suspending or terminating the account.
Where lawful and practicable, we will notify the account owner and give them an opportunity to respond before taking permanent action. Where the Service or other users are at risk, we may act first and notify after.
11. Account suspension & termination
Violations of this Policy may result in any of the following, at RentMy's discretion:
- Warning and request for remediation.
- Temporary feature suspension (e.g. outbound email throttled to a daily cap).
- Account suspension pending investigation.
- Permanent account termination, with or without refund, in accordance with the Terms & Conditions.
- Civil or criminal referral where unlawful activity is suspected.
Accounts terminated for serious or repeated abuse are not eligible to be re-created. We may share signals about abusive accounts (hashed identifiers, IP ranges) with other service providers and anti-abuse networks to prevent the same actor from reaching other platforms.
12. Cooperation with law enforcement
RentMy cooperates with valid law-enforcement requests in accordance with applicable law and our Privacy Policy. We require a subpoena, court order, search warrant, or equivalent legal process before disclosing non-public account or content data, except in emergencies involving an imminent threat of death or serious physical injury.
Law-enforcement requests should be sent to [email protected] with the subject line "Law-enforcement request" and must include the requesting agency, the legal basis, and the specific data sought.
13. Changes to this policy
We may update this Policy from time to time as new abuse vectors emerge. The latest version will always be available at this URL, with the "Last updated" date at the top reflecting the effective date. Material changes will be announced by email or in-app notice.
14. Contact us
- Email: [email protected]
- Phone: + (408) 728-8556
- Mailing address: Renterval LLC, Privacy Office, San Jose, California, USA
A safe, fast, reliable platform takes effort from all of us. Thanks for keeping RentMy clean.