Last updated: August 19, 2026
Privacy Policy
We care about your privacy. This document explains what personal data we collect, why we process it, and what rights you have under the GDPR.
§1. Personal Data Controller
The controller of your personal data is Dawid Szmigiel, operating a sole proprietorship under the business name “Dawid Szmigiel IT Solutions”, with its registered office at: ul. Listopadowa 17, 46-320 Praszka, Poland, NIP (Tax ID): 5761599645, REGON: 542171897. For matters concerning the processing of personal data, you can contact us at: kontakt@automotiveplace.pl.
The Operator has not appointed a Data Protection Officer (DPO). Please direct all data protection inquiries to the e-mail address above.
This Privacy Policy describes how we collect, use, and protect your personal data when you use the Automotive Place platform, including the mobile application and related services. The Platform is directed at users located in Poland and in other EU/EEA countries.
§2. What Data We Collect
When you use the Platform, we collect and process the following categories of personal data:
- –Registration data – e-mail address, username (nickname), password in encrypted form, or data from an external identity provider (e.g. Google).
- –Google account data – if you sign in with Google, we receive from Google: your account identifier, e-mail address, first name, and profile picture (data obtained from Google, solely for signing in and creating your profile).
- –Profile data – first name, profile picture, description, location (if provided voluntarily).
- –Project data – vehicle information: make, model, year of manufacture, technical specifications, VIN number (if provided – you control its public visibility yourself), photos, modification and service history, service reminders, and notes (your list of plans and tasks for the vehicle; you can mark any note as public, in which case anyone viewing the project can see it – all other notes remain visible only to you).
- –Vehicle diagnostic data (OBD) – if you use diagnostics in the mobile app: parameters read from the on-board computer (e.g. engine speed, vehicle speed, temperatures), fault codes (DTC), the VIN read from the vehicle, the OBD adapter's name, and drive recordings (values of selected parameters over time) together with the link to your project – stored on your account when you choose to record them. Recordings and analyses are not visible to other users; you can delete a recording in the app at any time. The live parameter view (AMP Panel) is transmitted via Firebase (Google) infrastructure. Exporting a recording to a file happens locally on your device.
- –Performance measurement data – during a measurement (e.g. acceleration, braking, power) the mobile app reads only speed, altitude, accuracy, and heading from GPS; geographic coordinates (your position) are not read, and the route of the drive is not recorded. The measurement history is stored solely on your device. Only the results you yourself save to a project stage are sent to the server (values, measurement date, and the speed-over-time trace) – they are visible to the people who can see your project.
- –Diagnostic analysis data – if you run an analysis of a recording or of fault codes: summaries of the readings (minimum/maximum/average per parameter – not the raw trace), fault codes, the vehicle description from your project (make, model, technical specifications, modifications, mileage), the symptoms you reported, and recording metadata (duration, date, adapter name). A snapshot of this data and the analysis result are stored together with the analysis. The rules for sharing data with the AI model provider are described in §4.
- –Fault report data (Problems) – published fault reports: title, description, category, photos, and fault codes, as well as suggested solutions (also published on behalf of a company), comments under suggestions, votes cast, and the list of followed problems.
- –Location data – the location you assign to projects, spots, trips, and places, and – only after you grant consent in your browser or device – your current location (GPS), used to find nearby content and display it on the map.
- –Activity data – posts, comments (including comments under other users' projects), likes, votes cast in polls under posts, post co-authorship (a post's author may tag you as a co-author), participation in spots and trips, group memberships, company reviews, date of last activity.
- –Project view data – if you open the details of someone else's project while signed in, we record that fact together with the date. The project's author sees the number of people who have viewed it and the list of those people (username, profile picture, date opened). One view per user – further visits do not create new entries. Signed-out visitors are not counted this way, and the list is not available to anyone other than the project's author. In Settings → Privacy you can enable browsing without being listed – your visits then only increase the counter, and your name does not appear on the author's list (including for earlier visits); this implements the right to object described in §6.
- –Chat communication data – message content (up to 2000 characters), uploaded photos, polls and votes cast in them, and the author's display name; visible to the participants of the given spot, trip, or group.
- –Direct message data – message content and uploaded photos in a conversation held directly with another user, together with the author's display name; visible only to the two people taking part in the conversation. The Operator does not read the content of these conversations for moderation purposes.
- –Preference data – content country and scope, preferred vehicle makes and types – used to personalise the content shown to you.
- –Device and notification data – in the mobile app, after system-level consent: push notification token, operating system platform, and device language – for delivering notifications.
- –Technical data – IP address, device type, operating system, browser, activity logs, error diagnostics data, cookies.
- –Communication data – the content of support requests, feedback, and bug reports submitted via the in-app form.
- –Content report data – if you report content via the “Report” feature: the report category and description, together with your username and e-mail address (recorded in order to process the report).
- –Moderation and violation data – if your content or account has been the subject of a report or of a measure provided for in the Terms of Service: the content of the report, the measure applied together with its statement of reasons, and the appeal correspondence.
- –Billing data – when you purchase the Premium plan: your customer identifier with the payment operator (Stripe), subscription and payment history, and data required by tax and accounting regulations. You provide full payment card details solely to the payment operator – we have no access to them.
§3. Purposes and Legal Bases of Processing
We process your data for the following purposes and on the following legal bases (Art. 6 GDPR):
- –Provision of services (Art. 6(1)(b)) – account registration and maintenance, operation of the Platform's features (including chat, groups, notifications about activity related to your account, OBD diagnostics, performance measurements, fault reports, and diagnostic analyses generated at your request), personalisation of content based on the preferences you choose, and handling of the Premium subscription.
- –Legitimate interest of the Operator (Art. 6(1)(f)) – system security and protection against bots and attacks, abuse prevention, enforcement of the Terms of Service (content moderation and measures in response to violations), error diagnostics and service stability, verification of the e-mail address provided at registration, providing the project's author with view statistics and the list of people who opened their project, establishing and defending legal claims, and service improvement.
- –Consent (Art. 6(1)(a), and for electronic communications also Art. 398–399 of the Polish Electronic Communications Law) – analytics cookies, access to your current location (GPS), and sending e-mails about selected content categories (events, nearby spots, trips, new projects) and activity reminders; we use the date of your last activity to time reminder e-mails. You manage consent categories in Settings → Notifications, and every message also contains an unsubscribe link.
- –Legal obligation (Art. 6(1)(c)) – fulfilment of obligations arising from applicable law, in particular tax and accounting regulations.
We do not make decisions about you based solely on automated processing that would produce legal effects or similarly significantly affect you. Automatic content filters (text filter, photo analysis) can only prevent publication – decisions to remove published content are made by a human. Diagnostic analyses generated at your request (by an AI model or deterministic rules) are for information purposes only, are clearly labelled as automatically generated, and produce no legal or similarly significant effects concerning you.
§4. Sharing Data with Third Parties
We do not sell your personal data. We share it only with entities supporting the provision of our services – mostly under data processing agreements (Art. 28 GDPR):
- –Infrastructure providers – Vercel, Inc. (application hosting), Google (Google Cloud / Firebase: authentication, databases, photo storage, notification delivery, transmission of the live OBD parameter view), and Neon, Inc. (hosting of the Platform's main database; servers in the AWS eu-central-1 region in Frankfurt, within the EEA).
- –Analytics provider – Google (Firebase / Google Analytics), only after you give consent in the cookie banner; data in pseudonymised form (a random identifier, without your name or e-mail address).
- –Payment operator – Stripe (Stripe Payments Europe, Ltd., Ireland) – handling payments for the Premium plan; with respect to transaction data, Stripe acts as an independent controller (stripe.com/privacy).
- –E-mail service provider – Resend, Inc. (USA) – technical delivery of e-mail messages (e-mail address, first name, language preferences).
- –Error monitoring – Functional Software, Inc. (Sentry, USA) – technical data about application errors (IP address, browser type, error trace), based on legitimate interest (service stability and security).
- –Technical logs – Axiom, Inc. (USA) – server-side application event logs.
- –Bot and attack protection – Arcjet, Inc. (USA) – IP address and request headers, analysed to block attacks and abuse.
- –Push notification providers – Expo (650 Industries, Inc., USA) and Google Firebase Cloud Messaging and Apple Push Notification service – device tokens and the content of delivered notifications (mobile app).
- –AI model provider – Anthropic (for EEA customers, contracts are concluded with Anthropic Ireland, Limited, based in Dublin) – generation of OBD diagnostic analyses at your request. We share only summaries of the readings, fault codes, the vehicle description, the reported symptoms, and public fault reports from the Platform matching the fault codes – without the VIN, your name, e-mail address, account identifier, or location. Under Anthropic's commercial terms, this data is not used to train models and is deleted by default within 30 days; transfers outside the EEA are based on standard contractual clauses (§9). Some analyses are generated by deterministic rules without any external provider – in that case the data does not leave our infrastructure.
- –Map and geocoding providers – map tiles (in the web version and in the mobile app) are fetched from Geoapify via our own server – your IP address is not passed to Geoapify; the mobile app also uses system maps (Google Maps on Android, Apple Maps on iOS). Place search and reverse geocoding use the Nominatim service run by the OpenStreetMap Foundation (United Kingdom) – it receives your IP address and the search phrase or coordinates (including your current location, if you use it). Trip routes are calculated in the Geoapify service via our own server – your IP address is not passed to Geoapify, and only the coordinates of the route's stops are transmitted to calculate the route.
- –External identity providers – e.g. Google, if you signed in via OAuth (solely for authorisation purposes).
- –Public authorities – to the extent required by law, at the request of authorised authorities.
§5. Data Retention and Account Deletion
We store your data for the time necessary to fulfil the purposes for which it was collected:
- –Account data – for as long as you hold an active account. After account deletion, data is deleted or anonymised within 30 days, except for data that must be retained by law.
- –Accounts with an unconfirmed e-mail address – an account whose e-mail address has never been confirmed may be deleted together with the data provided at registration. We only delete accounts older than 7 days on which no content was ever created and which nobody used during that time. Confirming the address at any point settles the matter – the account is no longer subject to this clean-up.
- –Project view data – until the project or your account is deleted, whichever comes first.
- –Chat messages – stored until the related spot, trip, or group ends or is deleted (the chat is then deleted in its entirety). After your account is deleted, your messages are anonymised (we remove the link to your account and your display name), and the photos you uploaded are deleted.
- –Direct messages – stored for 7 days from sending, after which they are deleted automatically along with any attached photos. Once no messages remain in a conversation, we delete the conversation itself as well.
- –OBD recordings and diagnostic analyses – you can delete a recording in the app at any time. Independently of that, recordings have an availability period that depends on your plan – once it expires, the recording is no longer available in the app and is subsequently deleted. Deleting a project does not delete the recordings – they only lose their link to the project. Analyses linked to a recording are deleted together with it, and all recordings and analyses are deleted together with the account.
- –Measurement results saved to a project – until the stage is edited (values overwritten), or the project or account is deleted. The measurement history stored on your device remains under your control – you can clear it in the app.
- –Push notification tokens – until the device is deregistered or the account is deleted.
- –Content reports – for the time necessary to process the report, no longer than 3 years; reports you have submitted are deleted together with your account.
- –Moderation and violation data – for the duration of the measure applied and of the appeal proceedings, and afterwards to the extent necessary to defend legal claims, no longer than 3 years.
- –Technical logs – for a maximum of 12 months.
- –Support requests and feedback – for 3 years from submission.
- –Billing data and data for tax and accounting purposes – for the period required by law (as a rule, 5 years from the end of the tax year).
Account deletion: you can delete your account yourself in the app or on the website – Settings → Delete account (automotiveplace.pl/app/settings/delete). If you no longer have access to your account, send a deletion request to kontakt@automotiveplace.pl. The scope of deleted and anonymised data is described above and in §4 of the Terms of Service.
§6. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding the processing of your personal data:
- –Right of access – you may request information about what data we process.
- –Right to rectification – you may request the correction of inaccurate data.
- –Right to erasure ("right to be forgotten") – you may request the deletion of your data if there are no grounds for its further processing.
- –Right to restriction of processing – you may request that processing be restricted in certain cases.
- –Right to data portability – you may receive your data in a machine-readable format.
- –Right to object – you may object to the processing of your data based on legitimate interest.
- –Right to withdraw consent – where processing is based on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out before it.
To exercise any of the above rights, contact us at: kontakt@automotiveplace.pl. Exercising your rights is free of charge. We will respond without undue delay, and no later than within one month of receiving your request; in particularly complex cases this period may be extended by a further two months, of which we will inform you together with the reasons.
You also have the right to lodge a complaint with a data protection supervisory authority – in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO, uodo.gov.pl).
§8. Data Security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, or destruction, including:
- –Encryption of data in transit (HTTPS/TLS).
- –Storage of passwords in securely hashed form by the authentication provider (Firebase Authentication, scrypt algorithm) – the Operator has no access to passwords in plain text.
- –The option to enable two-factor authentication (2FA) and to review active login sessions in your account settings.
- –Access control for personal data (principle of least privilege).
- –Automated protection against bots and attacks, and regular security reviews and system updates.
Despite the safeguards in place, no system is fully immune to threats. In the event of a personal data breach, we will inform you in accordance with GDPR requirements.
§9. Data Transfers Outside the EEA
Some of our providers process data on servers located outside the European Economic Area, primarily in the USA. This applies in particular to: Google, Vercel, Stripe, Resend, Sentry (Functional Software), Axiom, Arcjet, Expo, and Anthropic. Data directed to the OpenStreetMap Foundation's services may be processed in the United Kingdom, which is covered by an adequacy decision of the European Commission. In each case, we ensure appropriate safeguards: standard contractual clauses approved by the European Commission (SCCs) – which are, among others, the basis for transfers to Anthropic – and, for providers holding a current certification, the EU–U.S. Data Privacy Framework (an adequacy decision of the European Commission); DPF-certified providers include Google LLC, Vercel Inc., and Functional Software, Inc. (Sentry).
You can obtain a copy of the safeguards applied by contacting us at kontakt@automotiveplace.pl.
§10. Children's Privacy
The Platform is not directed at children under the age of 16. Registration requires a declaration of being at least 16 years old (and, for persons under 18, of having the consent of a parent or legal guardian). We do not knowingly collect personal data from children. If you believe that a child under 16 has provided us with their data, please contact us and we will promptly delete such data.
§11. Changes to This Privacy Policy
This Privacy Policy may be updated, e.g. in connection with changes to the Platform's features, providers, or applicable law. We will inform you of significant changes in advance via an in-app notification or e-mail. Last updated: August 19, 2026.
§12. Contact
For matters relating to personal data protection, exercising your rights under the GDPR, or other privacy-related issues, please contact us at: kontakt@automotiveplace.pl.
This Privacy Policy has been drawn up in Polish and English. The English version is a translation provided for convenience; in the event of any discrepancies, the Polish version prevails.
Questions about privacy? Get in touch with us.
kontakt@automotiveplace.pl
