Last updated: August 15, 2026
Privacy Policy
We care about your privacy. This document explains what personal data we collect, why we process it, and what rights you have under the GDPR.
§1. Personal Data Controller
The controller of your personal data is Dawid Szmigiel, operating a sole proprietorship under the business name “Dawid Szmigiel IT Solutions”, with its registered office at: ul. Listopadowa 17, 46-320 Praszka, Poland, NIP (Tax ID): 5761599645, REGON: 542171897. For matters concerning the processing of personal data, you can contact us at: kontakt@automotiveplace.pl.
The Operator has not appointed a Data Protection Officer (DPO). Please direct all data protection inquiries to the e-mail address above.
This Privacy Policy describes how we collect, use, and protect your personal data when you use the Automotive Place platform, including the mobile application and related services. The Platform is directed at users located in Poland and in other EU/EEA countries.
§2. What Data We Collect
When you use the Platform, we collect and process the following categories of personal data:
- –Registration data – e-mail address, username (nickname), password in encrypted form, or data from an external identity provider (e.g. Google).
- –Google account data – if you sign in with Google, we receive from Google: your account identifier, e-mail address, first name, and profile picture (data obtained from Google, solely for signing in and creating your profile).
- –Profile data – first name, profile picture, description, location (if provided voluntarily).
- –Project data – vehicle information: make, model, year of manufacture, technical specifications, VIN number (if provided – you control its public visibility yourself), photos, modification and service history.
- –Location data – the location you assign to projects, spots, trips, and places, and – only after you grant consent in your browser or device – your current location (GPS), used to find nearby content and display it on the map.
- –Activity data – posts, comments, likes, participation in spots and trips, group memberships, company reviews, date of last activity.
- –Chat communication data – message content (up to 2000 characters), uploaded photos, polls and votes cast in them, and the author's display name; visible to the participants of the given spot, trip, or group.
- –Preference data – content country and scope, preferred vehicle makes and types – used to personalise the content shown to you.
- –Device and notification data – in the mobile app, after system-level consent: push notification token, operating system platform, and device language – for delivering notifications.
- –Technical data – IP address, device type, operating system, browser, activity logs, error diagnostics data, cookies.
- –Communication data – the content of support requests, feedback, and bug reports submitted via the in-app form.
- –Content report data – if you report content via the “Report” feature: the report category and description, together with your username and e-mail address (recorded in order to process the report).
- –Billing data – when you purchase the Premium plan: your customer identifier with the payment operator (Stripe), subscription and payment history, and data required by tax and accounting regulations. You provide full payment card details solely to the payment operator – we have no access to them.
§3. Purposes and Legal Bases of Processing
We process your data for the following purposes and on the following legal bases (Art. 6 GDPR):
- –Provision of services (Art. 6(1)(b)) – account registration and maintenance, operation of the Platform's features (including chat, groups, and notifications about activity related to your account), personalisation of content based on the preferences you choose, and handling of the Premium subscription.
- –Legitimate interest of the Operator (Art. 6(1)(f)) – system security and protection against bots and attacks, abuse prevention, error diagnostics and service stability, establishing and defending legal claims, and service improvement.
- –Consent (Art. 6(1)(a), and for electronic communications also Art. 398–399 of the Polish Electronic Communications Law) – analytics cookies, access to your current location (GPS), and sending e-mails about selected content categories (events, nearby spots, trips, new projects) and activity reminders; we use the date of your last activity to time reminder e-mails. You manage consent categories in Settings → Notifications, and every message also contains an unsubscribe link.
- –Legal obligation (Art. 6(1)(c)) – fulfilment of obligations arising from applicable law, in particular tax and accounting regulations.
We do not make decisions about you based solely on automated processing that would produce legal effects or similarly significantly affect you. Automatic content filters (text filter, photo analysis) can only prevent publication – decisions to remove published content are made by a human.
§4. Sharing Data with Third Parties
We do not sell your personal data. We share it only with entities supporting the provision of our services – mostly under data processing agreements (Art. 28 GDPR):
- –Infrastructure providers – Vercel, Inc. (application hosting) and Google (Google Cloud / Firebase: authentication, databases, photo storage, notification delivery).
- –Analytics provider – Google (Firebase / Google Analytics), only after you give consent in the cookie banner; data in pseudonymised form (a random identifier, without your name or e-mail address).
- –Payment operator – Stripe (Stripe Payments Europe, Ltd., Ireland) – handling payments for the Premium plan; with respect to transaction data, Stripe acts as an independent controller (stripe.com/privacy).
- –E-mail service provider – Resend, Inc. (USA) – technical delivery of e-mail messages (e-mail address, first name, language preferences).
- –Error monitoring – Functional Software, Inc. (Sentry, USA) – technical data about application errors (IP address, browser type, error trace), based on legitimate interest (service stability and security).
- –Technical logs – Axiom, Inc. (USA) – server-side application event logs.
- –Bot and attack protection – Arcjet, Inc. (USA) – IP address and request headers, analysed to block attacks and abuse.
- –Push notification providers – Expo (650 Industries, Inc., USA) and Google Firebase Cloud Messaging and Apple Push Notification service – device tokens and the content of delivered notifications (mobile app).
- –Map providers – map tiles in the web version are fetched from Geoapify via our own server (your IP address is not passed to Geoapify); the mobile app uses system maps (Google Maps on Android, Apple Maps on iOS).
- –External identity providers – e.g. Google, if you signed in via OAuth (solely for authorisation purposes).
- –Public authorities – to the extent required by law, at the request of authorised authorities.
§5. Data Retention and Account Deletion
We store your data for the time necessary to fulfil the purposes for which it was collected:
- –Account data – for as long as you hold an active account. After account deletion, data is deleted or anonymised within 30 days, except for data that must be retained by law.
- –Chat messages – stored until the related spot, trip, or group ends or is deleted (the chat is then deleted in its entirety). After your account is deleted, your messages are anonymised (we remove the link to your account and your display name), and the photos you uploaded are deleted.
- –Push notification tokens – until the device is deregistered or the account is deleted.
- –Content reports – for the time necessary to process the report, no longer than 3 years; reports you have submitted are deleted together with your account.
- –Technical logs – for a maximum of 12 months.
- –Support requests and feedback – for 3 years from submission.
- –Billing data and data for tax and accounting purposes – for the period required by law (as a rule, 5 years from the end of the tax year).
Account deletion: you can delete your account yourself in the app or on the website – Settings → Delete account (automotiveplace.app/app/settings/delete). If you no longer have access to your account, send a deletion request to kontakt@automotiveplace.pl. The scope of deleted and anonymised data is described above and in §4 of the Terms of Service.
§6. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding the processing of your personal data:
- –Right of access – you may request information about what data we process.
- –Right to rectification – you may request the correction of inaccurate data.
- –Right to erasure ("right to be forgotten") – you may request the deletion of your data if there are no grounds for its further processing.
- –Right to restriction of processing – you may request that processing be restricted in certain cases.
- –Right to data portability – you may receive your data in a machine-readable format.
- –Right to object – you may object to the processing of your data based on legitimate interest.
- –Right to withdraw consent – where processing is based on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out before it.
To exercise any of the above rights, contact us at: kontakt@automotiveplace.pl. Exercising your rights is free of charge. We will respond without undue delay, and no later than within one month of receiving your request; in particularly complex cases this period may be extended by a further two months, of which we will inform you together with the reasons.
You also have the right to lodge a complaint with a data protection supervisory authority – in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO, uodo.gov.pl).
§8. Data Security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, or destruction, including:
- –Encryption of data in transit (HTTPS/TLS).
- –Storage of passwords in securely hashed form by the authentication provider (Firebase Authentication, scrypt algorithm) – the Operator has no access to passwords in plain text.
- –The option to enable two-factor authentication (2FA) and to review active login sessions in your account settings.
- –Access control for personal data (principle of least privilege).
- –Automated protection against bots and attacks, and regular security reviews and system updates.
Despite the safeguards in place, no system is fully immune to threats. In the event of a personal data breach, we will inform you in accordance with GDPR requirements.
§9. Data Transfers Outside the EEA
Some of our providers process data on servers located outside the European Economic Area, primarily in the USA. This applies in particular to: Google, Vercel, Stripe, Resend, Sentry (Functional Software), Axiom, Arcjet, and Expo. In each case, we ensure appropriate safeguards: standard contractual clauses approved by the European Commission (SCCs) and, for providers holding a current certification, the EU–U.S. Data Privacy Framework (an adequacy decision of the European Commission); DPF-certified providers include Google LLC, Vercel Inc., and Functional Software, Inc. (Sentry).
You can obtain a copy of the safeguards applied by contacting us at kontakt@automotiveplace.pl.
§10. Children's Privacy
The Platform is not directed at children under the age of 16. Registration requires a declaration of being at least 16 years old (and, for persons under 18, of having the consent of a parent or legal guardian). We do not knowingly collect personal data from children. If you believe that a child under 16 has provided us with their data, please contact us and we will promptly delete such data.
§11. Changes to This Privacy Policy
This Privacy Policy may be updated, e.g. in connection with changes to the Platform's features, providers, or applicable law. We will inform you of significant changes in advance via an in-app notification or e-mail. Last updated: August 15, 2026.
§12. Contact
For matters relating to personal data protection, exercising your rights under the GDPR, or other privacy-related issues, please contact us at: kontakt@automotiveplace.pl.
This Privacy Policy has been drawn up in Polish and English. The English version is a translation provided for convenience; in the event of any discrepancies, the Polish version prevails.
Questions about privacy? Get in touch with us.
kontakt@automotiveplace.pl