Legal
Privacy Policy
Last updated: 5 August 2026
This Privacy Policy explains what personal data CarCare Digital processes when you use carcaredigital.com and our applications, why we process it, who we share it with, and the rights you can exercise.
We aim to keep this document readable. Where we make a legal statement, we also try to explain what it means in practice.
1. Who is responsible
CarCare Digital operates the carcaredigital.com platform and acts as the data controller for personal data processed through it. For any privacy matter, including requests to exercise your rights, contact [email protected] with “Privacy” in the subject line. When a workshop, dealer, or fleet uses the platform to manage its own customers, that business is the controller of its customer records and we act as a processor on its behalf under our business terms.
2. Data we collect
Account data — email address, password hash, name, interface language, country, phone number when you provide one, notification preferences, and plan status. Vehicle and maintenance data — vehicles, mileage, VIN when you enter it, service records, parts, workshops, expenses, fuel entries, reminders, fault codes, and uploaded documents and photos. AI assistant data — the questions you submit and the answers returned, together with the vehicle context used to generate them, so the assistant can keep conversation history and enforce plan quotas. Billing data — plan, billing period, subscription status, and payment identifiers received from our payment processor. We do not store full card numbers; card data is handled by the processor. Marketplace data — listings you publish, photos, vehicle score inputs, and messages exchanged with buyers or sellers. Technical and security data — IP address, device and browser information, timestamps, authentication and administrative events, rate-limit counters, and error diagnostics. Analytics data — aggregated, privacy-friendly usage statistics collected through our self-hosted analytics instance. We do not use third-party advertising trackers or cross-site profiling.
3. Why we process it, and on what legal basis
Performance of a contract — creating and maintaining your account, storing your vehicle records, generating passports and reports, sending the reminders you configured, providing the assistant, and operating paid plans. Legitimate interests — keeping the service secure and available, preventing abuse and fraud, rate-limiting, diagnosing faults, and improving the product using aggregated usage data. Consent — optional notification channels such as WhatsApp or Viber, optional marketing messages, and any processing where we explicitly ask for permission. You can withdraw consent at any time. Legal obligation — accounting and tax records, and responding to lawful requests from competent authorities.
4. Public passport sharing
A vehicle passport is private by default. Publishing one creates a link that anyone holding it can open without an account, showing only the categories of information you enabled. You can unpublish a passport at any time, which invalidates the public link. Treat a published link as public information: anyone you share it with can pass it on.
5. Service providers we use
We share data with a limited number of processors, only to the extent needed to run the service, and under contractual confidentiality and security obligations: • Hosting and infrastructure — servers, database, and object storage for your account and files. • Payment processing — Lemon Squeezy, for subscriptions, invoices, and card handling. • Transactional email — our email provider, for account, reminder, and billing messages. • Messaging channels — WhatsApp Business and Viber Business, only when you enable those reminder channels. • AI processing — the configured assistant provider, which receives the question and the vehicle context needed to answer it. • Error monitoring and analytics — for reliability diagnostics and aggregated usage statistics. We do not sell personal data, and we do not share it for third-party advertising.
6. International transfers
Our production infrastructure is operated in Europe. Some processors may process data outside the European Economic Area. Where that happens, we rely on an adequacy decision or on Standard Contractual Clauses together with appropriate safeguards. You can ask us which processors are involved in a specific feature and what transfer mechanism applies.
7. How long we keep data
Account and vehicle data — for as long as your account exists. Deleting a vehicle, document, or record removes it from the product, and backups age out on our normal retention cycle. Account deletion — on request, we delete or irreversibly anonymise your personal data, except where retention is legally required. Billing records — retained for the statutory accounting period, typically several years, even after account closure. Security logs — retained for a limited period proportionate to abuse detection and incident investigation.
8. Security
We apply technical and organisational measures appropriate to the risk, including encrypted transport (HTTPS), hashed passwords, session cookies restricted to the site, optional two-factor authentication for administrators, role-based access to administrative functions, authenticated access to private documents rather than public file URLs, upload validation, rate limiting on sensitive endpoints, and audit logging of administrative actions. No system is absolutely secure. If a breach affects your rights, we will notify you and the competent supervisory authority as required by law.
9. Your rights
Subject to applicable law, and in particular under the GDPR, you may request: • access to your personal data • correction of inaccurate data • deletion of your data • restriction of processing • portability of data you provided • objection to processing based on legitimate interests • withdrawal of consent, without affecting processing already carried out Write to [email protected] with “Privacy” in the subject line. We respond within one month and may ask you to confirm your identity before acting on a request. If you believe we have not handled your request properly, you may lodge a complaint with the data protection authority in your country of residence.
11. Children
The service is intended for adults who can enter into a binding contract. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the product and legal requirements evolve. The date at the top always reflects the current version. For material changes affecting how we use your data, we will notify you in the product or by email before the change takes effect.
13. Contact
Privacy and data protection requests: [email protected]