RMAbaseStart free

Privacy Policy

Last updated 12 July 2026

RMA Base provides after-sales case management software for hardware suppliers. This policy explains what personal data we handle when you use rmabase.com and the RMA Base application, why we handle it, and the rights you have over it. If anything here is unclear, email hello@rmabase.com and a person will answer.

The two roles we play

For the data that runs your account, such as your name, email address and sign-in activity, we decide how and why it is processed, so we act as the data controller.

For the data inside your workspace, such as your customers, their contacts, assets, serial numbers, cases and uploaded files, you are in charge and we act only on your instructions as a data processor. We process that data solely to provide the service to you, never for our own purposes.

What we collect

  • Account details: your name, email address and a securely hashed password.
  • Workspace content: whatever you and your team put into RMA Base, including customer records, assets, serials, warranties, cases, messages and evidence files.
  • Technical logs: IP addresses, browser type and timestamps, kept briefly to keep the service secure and to diagnose problems.

What we never do

  • We do not sell personal data, to anyone, for anything.
  • We do not run advertising or share data with advertisers.
  • We do not use third-party analytics or tracking cookies. The only cookies RMA Base sets are essential ones: keeping you signed in and remembering preferences like your theme.

Why we process data

  • To provide the service you signed up for, which is our contract with you.
  • To keep the service secure and running, which is our legitimate interest: security logging, abuse prevention and fault diagnosis.
  • To send service emails you would expect, such as case notifications your workspace has switched on, invitations and account messages. We do not send marketing email unless you ask for it.

Who helps us run the service

RMA Base runs on a small number of infrastructure providers who process data on our behalf under contracts that require them to protect it: Render (application hosting), Neon (database), Cloudflare (file storage) and Resend (email delivery). Where a provider processes data outside the UK, the transfer is protected by recognised safeguards such as standard contractual clauses. We do not hand data to anyone else unless the law requires it.

How long we keep it

Workspace data is kept for as long as your account is active, because it is the record the service exists to hold. If you close your account, we delete your data from live systems promptly and it ages out of backups on their normal cycle. Technical logs are kept only briefly. You can also ask us to delete specific data at any time.

How we protect it

Every tenant’s rows are isolated at the database layer, every action is written to an audit trail, access is role-based, and data is encrypted in transit and at rest. The security section on our homepage describes this in more detail.

Your rights

  • Ask for a copy of the personal data we hold about you.
  • Have inaccurate data corrected.
  • Have your data deleted.
  • Receive your data in a portable format.
  • Object to or restrict certain processing.

To exercise any of these, email hello@rmabase.com. If you are in the UK you can also complain to the Information Commissioner’s Office (ico.org.uk), though we would appreciate the chance to sort it out first. If your data is in a customer’s RMA Base workspace, the fastest route is usually the company you bought from; we will help them respond.

Changes to this policy

If we change this policy in a way that matters, we will update this page and the date at the top, and tell account holders about significant changes before they take effect.