Privacy Policy
Last updated · September 1, 2026
1. Controller and contact details
CarCare is operated by Salvatore Marco Marra, Einzelunternehmen, Stralsunder Ring 48, 38444 Wolfsburg, Germany. For the personal data described in this policy, Salvatore Marco Marra is the controller within the meaning of the EU General Data Protection Regulation (GDPR), unless a provider acts as a separate controller for its own processing.
Privacy requests may be sent to support@carcarelog.de. General legal and business enquiries may be sent to info@carcarelog.de. You can also contact us by telephone at +49 1520 1071555.
2. Scope of this policy
This policy explains how CarCare processes personal data when you visit www.carcarelog.de, create or use an account, manage vehicles, upload records, subscribe, contact support, use vehicle-identification features, or exercise legal rights.
It applies primarily to users in Germany and the European Economic Area. Where mandatory privacy law in another country grants additional rights, those rights remain unaffected.
3. Data we process
Account and profile data may include your email address, name, authentication identifiers, language, timezone, distance unit, currency preference, notification settings, and account status.
Vehicle and maintenance data may include vehicle nickname, make, model, model year, trim, VIN, licence plate, fuel or powertrain, transmission, engine information, odometer readings, maintenance schedules, reminders, workshop/provider details, parts, costs, warranty information, purchase information, notes, and service-history entries.
Files you choose to upload may include receipts, invoices, images, PDFs, or other maintenance documents. AI document scans may contain workshop and line-item details, dates, amounts, odometer readings, VINs, licence plates, and any personal information printed in the document. You are responsible for avoiding unnecessary personal or sensitive information in uploaded files.
Subscription and billing metadata may include Stripe customer and subscription identifiers, plan, status, billing interval, payment status, invoice or checkout references, consent records, and timestamps. We do not store full payment-card details; those are handled by Stripe.
Technical and security data may include IP address, request metadata, browser/device information, authentication events, rate-limit data, error information, and security logs that are necessary to operate and protect the service.
Product analytics data may include the page path, referrer, signup event, a stable internal account identifier, IP address, user-agent, timestamps, and other technical request metadata. The stable account identifier is transmitted to Vaya for pseudonymisation; according to Vaya, only a salted hash of that identifier is retained. We do not intentionally send Vaya your name, email address, vehicle information, maintenance records, uploaded files, or payment details.
Support and legal-request data may include your messages, the information needed to identify your account or contract, and records relating to privacy, cancellation, or withdrawal requests.
If you choose to submit a customer review, we process your rating, public review text, optional private feedback, publication consent, moderation status, and a verified link to one vehicle in your account. Public attribution is limited to your first name and that vehicle’s make and model; CarCare does not publish the selected vehicle ID, nickname, VIN, licence plate, or private feedback.
4. Purposes and legal bases
We process account, vehicle, maintenance, uploaded-file, reminder, and subscription data where necessary to create and perform your contract with us, provide the service, maintain your account, generate schedules, deliver reminders, process exports, and manage billing. The principal legal basis for EEA users is Article 6(1)(b) GDPR.
We process data required for bookkeeping, tax, consumer-protection, withdrawal, fraud-prevention, and other legal duties where processing is necessary to comply with a legal obligation. The principal legal basis is Article 6(1)(c) GDPR.
We process limited technical, security, abuse-prevention, service-integrity, and support data where necessary for our legitimate interests in operating a secure and reliable service, preventing misuse, defending legal claims, and improving operational reliability, provided those interests are not overridden by your rights. The principal legal basis is Article 6(1)(f) GDPR.
We process limited page-view and product-event data through Vaya to understand how the service is used, measure completed registrations and feature adoption, identify technical or usability problems, and improve the service. We rely on our legitimate interests under Article 6(1)(f) GDPR, provided that those interests are not overridden by your rights and freedoms. Vaya analytics data is not used by CarCare for advertising, cross-site tracking, automated decision-making, or the creation of marketing profiles.
Where we introduce optional processing that legally requires consent, we will ask for consent separately. You may withdraw consent at any time for future processing without affecting processing that was lawful before withdrawal.
Publishing your first name, rating, review text, and vehicle make and model is based on your explicit consent under Article 6(1)(a) GDPR. Withdrawing that consent in account settings removes the review from public display immediately. Review verification and proportionate moderation are also used to protect users and the integrity of the service.
5. Vehicle lookup and NHTSA/vPIC
If you use vehicle lookup or VIN-identification features, the relevant vehicle query data may be sent to the U.S. National Highway Traffic Safety Administration (NHTSA) Vehicle Product Information Catalog (vPIC) service. This may include a VIN or vehicle make/model information, depending on the feature you use.
A VIN can be personal data when it is linked or linkable to an identifiable person. We use vehicle lookup only to provide the feature you request. NHTSA/vPIC data is informational and may be incomplete or inaccurate; you should verify safety-critical and manufacturer-specific information against official vehicle documentation.
6. AI document scans and Mistral AI
When you choose Add from document, CarCare sends the selected PDF or image over an encrypted connection to the Mistral AI API for OCR and structured extraction. Mistral AI is a French company incorporated in Paris under number 952 418 325, with registered office at 15 rue des Halles, 75001 Paris, France. The integration uses Mistral's EU API endpoint. Mistral AI processes the document to return an editable draft; CarCare validates the result and never adds it to vehicle history without your explicit confirmation.
CarCare does not store the original scan as a receipt or temporary storage object. It retains a cryptographic file fingerprint and limited lifecycle metadata for quota enforcement and same-file retry protection. Access to the normalized review draft, confidence information, warnings, and compact page/source coordinates expires after 24 hours if you do not confirm them. A scheduled daily cleanup then clears that protected database payload, so it may remain until the next cleanup run, but normally no later than approximately 48 hours after extraction. Confirmation clears the payload immediately. If you separately attach an original document as a receipt, the normal receipt retention and deletion rules apply instead.
Mistral states that data is hosted in the European Union by default, while some features may involve temporary processing by subprocessors in other locations subject to applicable safeguards. Zero data retention is not enabled for CarCare's Mistral organization. Under Mistral's current public Privacy Policy, API inputs and outputs may be retained for the time needed to generate the output and then for up to 30 rolling days for abuse monitoring when zero data retention is not activated. CarCare has disabled Mistral's API Data usage for improving our services setting for its organization, so new CarCare API inputs and outputs are not used for model training. This training control is separate from zero data retention and does not remove the abuse-monitoring retention period. The operator must keep the applicable Data Processing Addendum, subprocessor list, data-location settings, applicable model-training controls, and regional-processing safeguards under review.
7. Payments and Stripe
Payments and subscription billing are processed through Stripe. We send Stripe the information necessary to create and manage your customer, checkout, subscription, and billing records, such as account email, name where available, plan, and internal account identifiers.
Stripe processes payment credentials and may process billing, fraud-prevention, regulatory, and transaction data under its own privacy terms where it acts as an independent controller, and on our behalf where it acts as a processor or service provider. We do not receive or store your complete payment-card number or card security code.
8. Email delivery and Resend
We use Resend to deliver transactional emails such as authentication messages, reminder emails, service notices, and confirmations of legal requests. We provide Resend with the recipient email address and the message content required to deliver the communication.
Transactional emails are part of providing the service or complying with legal obligations. We do not currently use Resend to send behavioural advertising based on tracking profiles.
9. Hosting, database, authentication, and storage
Vercel hosts and delivers the web application and may process request, network, and technical security data needed to serve the site and application.
Supabase provides the application database, authentication, and private file storage. The primary Supabase project region is Frankfurt, Germany (eu-central-1). Data may nevertheless be processed by authorised subprocessors or support systems in other locations where required to provide the service and subject to applicable safeguards.
10. Cookies, local storage, and analytics
We do not use Google Analytics, PostHog, Vercel Analytics, Vercel Speed Insights, advertising pixels, or behavioural advertising trackers.
We use Vaya for limited product analytics. When a page is loaded, Vaya may receive the page path, referrer, IP address, user-agent, timestamp, and related technical request data. When a signed-in account is available, we send a stable internal account identifier so that activity can be associated pseudonymously with the same account. When registration is completed, we send a "signup" event. According to Vaya, the account identifier is retained only as a salted hash.
We use this information to measure registrations, understand aggregate and account-level product usage, detect usability or technical problems, and improve CarCare. We do not intentionally provide Vaya with names, email addresses, vehicle details, maintenance records, uploaded documents, or billing information.
CarCare uses browser storage where necessary for functionality, authentication, security, session management, theme or preference handling, and similar essential purposes. We do not intentionally configure Vaya analytics cookies or advertising identifiers. Stripe may use its own technically necessary cookies or comparable technologies on Stripe-hosted checkout or billing pages.
11. Recipients and service providers
We disclose personal data only where necessary for the purposes described in this policy. Current core providers are Vercel for hosting and delivery, Supabase for database, authentication and storage, Mistral AI for user-requested document extraction, Stripe for payments and subscription billing, Resend for transactional email, Vaya for limited product analytics, and NHTSA/vPIC for requested vehicle lookup data.
We may also disclose data to professional advisers, competent authorities, courts, or law-enforcement bodies where required by law or reasonably necessary to establish, exercise, or defend legal claims. We do not sell personal data and do not share personal data for cross-context behavioural advertising.
CarCare may show a neutral optional link to Trustpilot after an internal review. We do not send the internal rating, review text, vehicle, or account data to Trustpilot through that link. If you choose to visit or review on Trustpilot, Trustpilot processes your visit and submission under its own terms and privacy information.
12. International transfers
Some providers or their subprocessors may process data outside Germany or the European Economic Area, including in the United States. Where GDPR transfer rules apply, we use or rely on legally recognised transfer mechanisms as applicable, such as adequacy decisions, the EU Standard Contractual Clauses, and supplementary safeguards.
Vaya publishes a contact address in Austin, Texas, United States. Analytics requests sent to Vaya may therefore involve processing in the United States. The applicable transfer safeguards depend on Vaya's processing arrangements and are reviewed as part of our provider assessment.
Mistral AI is configured through its EU API endpoint and states that data is hosted in the European Union by default, but it also states that temporary transfers outside the EU may occur for some features through listed subprocessors. The operator must verify the actual OCR 4.1 processing locations and applicable contractual safeguards before production use.
You may contact us at the privacy address above for further information about safeguards relevant to your data.
13. Retention
We keep account and service data for as long as your account is active and as needed to provide the service. When you delete your account, we remove or anonymise data from active systems where it is no longer needed, subject to technical backup cycles and legal retention duties.
Payment, invoice, tax, consumer-rights, and accounting records may be retained for the statutory periods required by German commercial and tax law. Security and abuse-prevention records are kept only for as long as reasonably necessary for the relevant security purpose.
Vaya analytics records are retained only for as long as necessary to measure registration and product use, investigate technical or usability issues, and improve the service, after which they are deleted or irreversibly anonymised. We periodically review whether the records remain necessary. According to Vaya, the stable account identifier is not retained in its original form and only a salted hash is stored.
Support, withdrawal, cancellation, and legal-request records may be retained for as long as necessary to handle the request, demonstrate compliance, and resolve or defend legal claims, generally no longer than the applicable limitation or statutory retention period.
Customer reviews and private feedback are kept with the account while it is active. A withdrawn review is removed from public display immediately and is deleted when the account is deleted, subject only to backup cycles or a legal obligation that requires limited retention.
For AI document scans, access to an unconfirmed normalized review draft expires after 24 hours. The scheduled daily cleanup normally clears that draft no later than approximately 48 hours after extraction, while a confirmed draft is cleared immediately. The quota and idempotency ledger—including a cryptographic file fingerprint, vehicle link, provider/model, file type and size, page count, status, sanitized failure code, and timestamps—is kept with the account so lifetime or monthly usage and duplicate retries remain enforceable. Account deletion removes that ledger through the account's normal deletion cascade. CarCare's cleanup does not control any retention that Mistral AI performs under the operator's separate account and contract.
14. Your GDPR rights
Subject to the applicable conditions, you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, and data portability. You may object to processing based on legitimate interests and may withdraw consent where processing is based on consent.
To exercise a privacy right, contact support@carcarelog.de with “Privacy request” in the subject. We may request reasonable information to verify your identity before disclosing or changing account data.
You also have the right to lodge a complaint with a competent data-protection authority. The supervisory authority responsible for our establishment is the Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany. You may also contact the authority competent for your habitual residence or place of work where applicable.
15. Automated decision-making
CarCare may calculate dates, mileage-based deadlines, status labels, generic maintenance suggestions, and confidence or mismatch warnings using rules and information in your account. AI document extraction prepares an editable draft only and cannot create service history without your explicit confirmation. These functions are organisational tools and do not produce legal or similarly significant decisions about you within the meaning of Article 22 GDPR.
16. Children
CarCare is intended for people who can lawfully enter into the relevant contract. We do not knowingly market paid subscriptions to children. If you believe a child has provided personal data without the required authorisation, contact us so that we can review and, where appropriate, delete it.
17. Security
We use technical and organisational measures appropriate to the nature of the service, including authenticated access, private storage for uploaded files, transport encryption provided by our hosting infrastructure, access controls, request validation, and abuse-prevention measures. No internet service can guarantee absolute security.
Do not send passwords, full card details, private API keys, or other authentication secrets by email or support message.
18. Changes to this policy
We may update this policy when the service, providers, or legal requirements change. The current version and update date are published on this page. If a change materially affects how we process existing personal data, we will provide additional notice where required by law.