Skip to content

Legal

Privacy

Our commitment to protecting your data and how Carendar works with a privacy-first approach.

Last updated: 2026-01-14

Your privacy is important to us. This Privacy Policy explains our commitment to protecting your data and why Carendar operates with a privacy-first approach.

Privacy-first approach

No ads and no third‑party tracking. We do not sell your personal data. The website only uses an essential first‑party cookie to remember your cookie choices.

Who we are

For privacy questions, contact: gabriel@ultron.ro

Operator (legal entity)

This website is operated by Croitoru Gabriel PFA (Romania), registered with the Trade Register under number F40/1475/2022.

Tax ID (CUI)
45933816
IBAN
LT283250068329465998
Bank
Revolut Payments UAB

Data we collect

No personal data collection by default

Carendar is designed to work without requiring you to provide personally identifiable information (PII) such as your name or address. No account registration is required to browse this website.

Support and contact

If you contact us, we process the information you provide (such as your email address and message) to respond.

Website logs

Our web servers may process technical data (such as IP address and user-agent) for security, abuse prevention, and debugging.

Cookies on this website

We use an essential cookie to store your cookie consent choices. We do not currently use analytics or marketing cookies on the website. See Cookie policy.

Vehicle data and maintenance logs

Carendar stores your vehicle information (such as make, model, year) and maintenance history to provide tracking, reminders, and insights.

Supabase migration notice

We are migrating synchronization towards Supabase (Postgres) to support a shared, cross-platform database. During this transition, your sync data may be stored in iCloud (CloudKit) and/or Supabase depending on the app version and features you use.

Security features

Carendar implements security measures to protect your data and help keep your information private.

Auto-Lock protection

The app can lock when backgrounded for enhanced privacy.

Biometric authentication

Face ID / Touch ID can protect sensitive areas. Biometric data stays on-device.

Secure storage

Sensitive documents can be stored locally with OS-level protection.

Encrypted transport

When data is synced, it is transmitted using encrypted connections (TLS).

Document storage

Sensitive documents (such as IDs) can be stored locally on your device and protected with OS-level encryption and biometric authentication. They are not required for using the service.

Subscription and payment information

Subscription transactions are processed through Apple’s App Store. We do not store or have access to your payment information.

Third-party services

Carendar uses third-party service providers to deliver features. Carendar remains your primary contact for privacy requests. Our providers act as processors/sub-processors under our instructions.

  • Supabase (Postgres): used to power account-based sync and the web portal. Supabase processes data on our behalf as a processor.
  • Apple services: StoreKit for subscriptions, and (where applicable) CloudKit for sync.
  • Crash reporting (optional): if enabled in the app, a crash-reporting provider may receive technical diagnostics to help improve stability.
  • Mapbox: used for mapping features (e.g., journey/location features), when enabled in the app.

Account deletion (Supabase)

You can close your account from the web portal (/admin). This deletes your Supabase Auth account and triggers deletion of associated data stored in Supabase where applicable. Some records may remain in backups for a limited time.

Legal bases (where applicable)

  • Consent: for any non-essential cookies (if introduced).
  • Contract/performance: to provide app features you request (such as sync).
  • Legitimate interests: to secure the website, prevent abuse, and maintain reliability.

Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law.

  • Support inquiries: retained for up to 3 years after the inquiry is resolved, unless longer retention is required for legal or regulatory purposes.
  • Server security logs: retained for up to 90 days for security and debugging purposes.
  • Account data (Supabase): retained until account deletion is requested. After deletion, data may remain in backups for up to 30 days before permanent deletion.

Your data rights

If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with similar data protection laws, you have the following rights regarding your personal data:

  • Right of access: you can request a copy of the personal data we hold about you.
  • Right to rectification: you can request correction of inaccurate or incomplete data.
  • Right to erasure: you can request deletion of your personal data, subject to certain legal exceptions.
  • Right to restrict processing: you can request that we limit how we use your data in certain circumstances.
  • Right to data portability: you can request a copy of your data in a structured, machine-readable format.
  • Right to object: you can object to processing based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent: where processing is based on consent, you can withdraw it at any time.

To exercise these rights, please contact us at the email address provided below. We will respond to your request within one month, though this period may be extended by two additional months if necessary, taking into account the complexity and number of requests.

Children's privacy

Carendar is intended for users 18 years and older. We do not knowingly collect personal information from children.

Data breach notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, and in any event within 72 hours of becoming aware of the breach, where feasible. We will provide clear information about the nature of the breach and the measures we are taking to address it.

International data transfers

If you use sync features, your data may be processed in the regions where our providers (such as Apple iCloud and Supabase) operate. We use encryption in transit and access controls to protect data.

When transferring data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or adequacy decisions where applicable.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here and update the “Last updated” date.

Supervisory authority

If you are located in the EEA or UK and believe that we have not addressed your concerns satisfactorily, you have the right to lodge a complaint with your local data protection supervisory authority. For Romania, this is the National Supervisory Authority for Personal Data Processing (ANSPDCP).

Contact us

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at: gabriel@ultron.ro