Privacy Policy
How Garag processes personal data.
Contents
Updated: 28 July 2026
1. Data controller
The Garag platform (“Garag”, “the platform”, “we”) and the processing of personal data available on it are provided by the platform operator. For any matter relating to the processing of personal data, exercising your rights or this policy, write to legal@garag140.com.2. What data we collect
Account data (email address, name, username and, where provided, phone number; the password is stored only in encrypted form). Data about the vehicles you add to your garage (make, model, year, VIN, registration number, photos). Booking, order and service-history data. Messages with the workshop and the reviews and ratings you leave. Consent records (including the fact, date and version of the consent). For workshop owners and mechanics — data about the workshop, the team and the services provided. Technical data: IP address, device and browser type, cookies and the anonymous identifier garag_anon_id.3. Purposes of processing
Providing the service: finding workshops, booking online, keeping your garage and service history. Communication between the client and the chosen workshop. User support. Ensuring security and preventing abuse (spam, fraud, rule violations). Meeting legal requirements. With your consent — analytics to improve the service and marketing communications.4. Legal grounds
Performance of a contract — providing the platform's features and handling your bookings (Art. 6(1)(b) GDPR). Consent — analytics and marketing cookies, promotional mailings (Art. 6(1)(a) GDPR); consent can be withdrawn at any time. Legitimate interests — platform security, content moderation and service improvement (Art. 6(1)(f) GDPR). Legal obligation — where processing is required by law (Art. 6(1)(c) GDPR).5. Data recipients
When you create a booking, the necessary data is passed to the workshop you chose and to the mechanics assigned by that workshop — so that they can carry out the booking and contact you. To run the platform we use providers that process data on our instructions and under data-processing agreements (DPAs), each only to the extent its function requires: application hosting, logs and file storage for photos (Vercel); the database (Neon); subscription payment processing (Stripe); transactional email (Resend); error monitoring and crash diagnostics (Sentry); maps and workshop addresses (Google); messenger bot messages (Telegram). We do not sell personal data to third parties.6. Transfers outside your country
Infrastructure providers may store and process data on servers located outside your country or the EEA. In such cases the transfer is made using the safeguards provided for by the GDPR (for example, standard contractual clauses).7. Retention period
We keep data no longer than is necessary for the purposes of processing. Account data and the content linked to it are kept while the account is active; after an account is deleted, the contents of its trash are permanently erased within 30 days. The technical activity log (security log: sign-ins and key actions) is kept for up to 12 months and then deleted automatically. Login sessions are deleted within 30 days after they expire. In-app notifications are deleted 90 days after they are read, and unread ones no later than 12 months after they were created. One-time confirmation links and codes (email verification, password reset) are deleted within a day after they expire. Consent records are kept append-only and are not deleted, so that we can confirm the fact and version of the consent you gave. Orders and service history are retained for the period set by tax and accounting law; a workshop closing does not erase them. Automated clean-up runs as a daily scheduled job.8. Your rights
In relation to your data you have the right to: obtain access and a copy, correct inaccurate data, erase data, restrict processing, object to processing, port your data, and withdraw consent previously given. You can download a copy of your data yourself at /api/me/export (for signed-in users). To exercise the other rights, write to legal@garag140.com. You also have the right to lodge a complaint with a data-protection supervisory authority — in Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa.9. Data security
Passwords are stored only in encrypted (hashed) form. Access to data is restricted by role: a client sees only their own data, a mechanic only the orders assigned to them at their workshop, a workshop owner only their own workshop. A user's personal vehicle history is not available to their employer, even if that user is also a mechanic.10. Changes to this policy
For material changes we publish a new version of the policy and, where required, ask for consent again. The date of the last update is shown at the top of the document.11. Data contacts
Questions about data — legal@garag140.com. See also the Cookie Policy.