Published 2026-08-25 · LuckyMDM Blog
In short: a phone rental platform inevitably touches a lot of user information, but what it can collect has clear boundaries. The core principles: minimal collection, notice and consent, no overreach, and deletability. Risk control needs “device state”, not “user privacy” — the two must stay separate.
Several rental platforms have recently been flagged for illegal collection of personal information. That is a warning for the whole industry: running risk control is fine, but collecting and using user data has hard limits. This page maps those limits.
A rental platform naturally handles identity, contact and device information — and sometimes location. Collected or used improperly, that data leads to regulatory action, penalties, and a direct hit to user trust.
One premise must be clear from the start: doing risk control does not mean you can collect whatever you want. Risk control needs to know whether a device is normal and whether there is overdue risk — not what the user is doing.
| Category | Example | Can you collect it? |
|---|---|---|
| Identity verification | Name, ID document (for real-name) | ✅ Yes, necessary for business |
| Fulfilment contact | Phone number, emergency contact | ✅ Yes, necessary for contract/collection |
| Device state | Online status, OS version, Activation Lock state | ✅ Yes, necessary for risk control |
| Sensitive privacy | Contacts, gallery, chat history, precise location trail | ❌ No — not tied to risk control |
| Over-collection | Extra information beyond the business purpose | ❌ No — violates minimal collection |
One sentence: device state that supports risk control is fine; user privacy that has nothing to do with risk control is off-limits.
This is the most important distinction in rental risk control. Device data (is this machine online, what OS, is Activation Lock on) and personal data (what the user reads, who they contact, where they go) are two different things.
LuckyMDM’s risk-control logic works on device state, not user surveillance. A compliant supervision lock locks the device, not the user; it reads device state, not personal content.
A compliant remote lock acts at the device level only and does not read personal content — provided it is contract-authorised and used only on overdue.
Not recommended. Location for risk control should be limited to contract-defined scenarios like overdue collection, not continuous daily tracking.
Delete user data as agreed and wipe the device before resale or re-rental.
Learn more: E-contract for phone rental · Is phone rental a scam? · LuckyMDM product