GaragePilotGaragePilot
    Home>Legal>Privacy Policy

    Privacy Policy — GaragePilot

    Version 1.1 — Effective: February 18, 2026

    Document Information

    Scope of this version: Global (with provisions for US, Canada, EU/EEA, UK, Australia, East Asia, and Latin America)

    Official URL for this Policy: GaragePilot.io/legal

    1. Data Controller and Contact

    Data Controller: Gadsden Tecnologia LTDA. (CNPJ 48.706.913/0001-54)

    Headquarters: São José/SC, Brazil

    Data Protection Officer (DPO): Ian Storni

    Contact (privacy/data/support): suport@gadsden.cc

    2. What Data We Collect

    2.1. Data You Provide

    • Account registration: name, email, phone (if provided), account type (End User/Service Provider).
    • Vehicles and context: license plate, VIN (if provided), make/model/year, mileage, history, notes, maintenance records.
    • Attached files: photos, PDFs, receipts, documents related to the vehicle/service.
    • Communications: messages sent to support.

    2.2. Data Collected Automatically (Web and Apps)

    • Technical records: date/time, IP address, session identifiers, usage events, crash logs, and performance metrics.
    • Device data (apps): device model, operating system, app version, language/region, technical identifiers, and network information necessary for operation and security.

    2.3. Payment Data

    • Web (Stripe): transaction data, status, billing history, and identifiers (card details are typically retained by the payment processor).
    • App Store/Google Play: payment data is primarily handled by Apple/Google; Gadsden receives technical confirmations (e.g., subscription/entitlement status).

    3. How We Use Your Data (Purposes)

    • Provide the service: account, authentication, report generation, history, and features.
    • Security: fraud prevention, abuse detection, auditing, and integrity.
    • Support: responding to requests and resolving incidents.
    • Product improvement: usage analytics and metrics, preferably with anonymized/aggregated data.
    • Legal compliance: fulfilling legal and judicial obligations and orders.

    4. Legal Bases for Processing

    We process data under applicable legal bases, including:

    • Performance of a contract (delivering what you signed up for);
    • Legal/regulatory obligation;
    • Legitimate interest (e.g., security, fraud prevention, careful improvement);
    • Consent, where required (e.g., promotional communications and non-essential technologies, if adopted).

    For EU/EEA/UK users: processing is based on GDPR Article 6 grounds. For US users: we comply with applicable state privacy laws including the CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), and similar statutes. For Canadian users: processing follows PIPEDA principles. For Australian users: the Australian Privacy Principles (APPs) apply.

    5. Cookies and Similar Technologies (Bubble and Session)

    5.1. Web: The Platform uses essential cookies (and/or equivalent mechanisms) for authentication and session integrity, as part of Bubble's operation.

    5.2. Without these essential cookies, features such as login and staying logged in may not function properly.

    5.3. If analytics/marketing cookies are used, the Platform will present a consent mechanism and category details.

    6. With Whom We Share Data

    We share data only when necessary, with:

    • Infrastructure and hosting: Bubble and associated infrastructure (including AWS).
    • Payments and subscriptions: Stripe (web), Apple/Google (app stores), RevenueCat and/or equivalent entitlement/billing services, Google Pay/Apple Pay where applicable.
    • Content and media: image/asset delivery and optimization providers (e.g., imgix) and hosting services (e.g., Vercel).
    • DevOps and code: repositories and development tools (e.g., GitHub).
    • AI and processing: model providers and platforms (e.g., OpenAI, Anthropic, Google AI Studio/Google Cloud) for Output generation and related features.
    • Vehicle data and validations: BigDataCorp, NHTSA, NMVTIS, DataOne Software, VinAudit, MarketCheck, CarMD, and other lookup/decoding/validation providers, where applicable.
    • Authorities: pursuant to legal obligation, court order, or to protect rights and prevent fraud.

    7. Vendor List (Operational Reference)

    Vendors currently used and/or planned (examples): Bubble, AWS, NHTSA, NMVTIS, Stripe, RevenueCat, Google Pay, Apple Pay, Vercel, imgix, GitHub, OpenAI, Anthropic, Google Cloud, Google Play Store/Google, Google AI Studio, BigDataCorp, Apple App Store/Apple, DataOne Software, VinAudit, MarketCheck, CarMD.

    Extended non-exhaustive list to minimize update frequency:

    • Public databases and government services: SERPRO, SENATRAN (Brazil), FIPE (Brazil), state DMV agencies (US), DVLA (UK), and equivalent bodies internationally;
    • Observability and security: error/crash monitoring, logs, anti-fraud, abuse detection, and transactional email services;
    • Analytics: product metrics and event platforms;
    • CDN/storage: CDN providers, managed storage, and databases, as the architecture evolves.

    8. International Data Transfers

    Depending on infrastructure and providers, data may be stored or processed outside your country of residence. In such cases, we adopt reasonable protection measures and contractual safeguards.

    For EU/EEA/UK users: transfers outside the EEA rely on adequacy decisions or Standard Contractual Clauses (SCCs) where applicable. For Australian users: we take reasonable steps to ensure overseas recipients handle data in accordance with the APPs.

    9. Security

    We implement technical and organizational measures to protect data against unauthorized access, loss, and breach. However, no system is infallible.

    10. Retention and Deletion

    • We retain data for as long as necessary to provide the service, comply with legal obligations, auditing, security, and the regular exercise of rights.
    • You may request deletion where applicable, subject to mandatory retention periods and legal requirements.

    11. Your Rights (Data Subject Rights)

    Depending on your jurisdiction, you may request: confirmation of processing, access, correction, anonymization/blocking/deletion, portability, information about data sharing, and withdrawal of consent, where applicable.

    EU/EEA/UK (GDPR): You have the right to access, rectification, erasure, restriction, portability, and to object to processing. You may also lodge a complaint with your local supervisory authority.

    US (CCPA/CPRA and state laws): California residents may request disclosure, deletion, and opt out of the sale/sharing of personal information. Similar rights exist under Virginia, Colorado, Connecticut, and other state privacy laws.

    Canada (PIPEDA): You have the right to access and correct your personal information.

    Australia (Privacy Act): You may access and correct your personal information under the Australian Privacy Principles.

    Channel: suport@gadsden.cc (we may request identity verification).

    12. Third-Party Data Entered by Service Providers

    If you are a Service Provider and enter client data, you represent that you have the necessary legal basis and authorizations. You are responsible for informing your clients and handling data requests under your management, where applicable.

    13. Children and Minors

    The Platform is not intended for minors without a legal guardian. The minimum age is 13 (or 16 in certain EU/EEA jurisdictions). If we identify unauthorized minor use, we may suspend the account and request regulation.

    14. Updates to This Policy

    We may update this Policy. Material changes will be communicated via the app/website, with a new effective date.

    15. International Expansion

    In case of expansion to other countries, local addenda may apply (language, equivalent rights, legal bases, and support workflows).

    Generate Pre-Purchase Report

    Discover the true cost of ownership, pending maintenance, and red flags before closing the deal.

    Start using GaragePilot

    Track maintenance, fuel, and expenses for your vehicle in one place, with full security and privacy.

    GaragePilotGaragePilot

    Your digital vehicle logbook. Maintenance, fuel, and expenses — tracked.

    © 2026 GaragePilot. All rights reserved.

    Product

    • Pre-purchase Report
    Terms & Policies
    • Terms of Service
    • Privacy
    • Cookies

    Contact

    • suporte@garagepilot.io

    GaragePilot is owned by Gadsden Tecnologia LTD. Santa Catarina, Brazil