Privacy Policy
Working draft · July 30, 2026
Working controller identity: CarCare (working name), [Add the verified company address before launch]. Privacy contact: support@example.com.
Who controls the data
Before launch, replace this section with the verified legal entity, address, privacy contact, and applicable representative details. CarCare is expected to act as controller for account and vehicle data.
Data we expect to process
Account identifiers, preferences, vehicle details, odometer readings, maintenance schedules, service records, private attachments, subscription status, essential security logs, and optional product events. Card data is handled by Stripe and is not stored by CarCare.
Purposes and legal bases
The final reviewed policy must map each purpose—providing the service, billing, security, reminder delivery, support, legal obligations, and optional analytics—to the correct legal basis in each launch market.
Processors and international transfers
The launch review must list Supabase, Vercel, Stripe, Resend, the domain provider, and any enabled monitoring service; link their current DPAs; document regions and cross-border safeguards.
Retention and your choices
Users can export and delete product data from Settings. The final schedule must distinguish operational data from payment or tax records that may need limited legal retention. Marketing leads must not be retained without a valid basis.
Your rights
Add the jurisdiction-specific access, correction, deletion, restriction, portability, objection, withdrawal, complaint, identity-verification, and response-time information after professional review.