Privacy Policy
Privacy Policy
Version 2026-09-04
1. Controller
The data controller is Josep Vilchez Garcia, a self-employed professional (Spanish tax ID 47860816R) with registered address at Carrer de València 13, Roquetes (Catalonia, Spain), operating under the v13studio brand.
Contact for any privacy matter: cybergarage@v13studio.com.
2. What data we process
- Account: email, name, phone (optional), avatar, language, timezone and sign-in provider (email, Google or Apple).
- Sessions and security: IP address, country, device name and platform, install identifier, push notification token, and a log of security events (sign-ins, email changes, account deletion).
- Your vehicles: plate, VIN, make, model and year, together with the maintenances, expenses, reminders and mileage readings you record.
- Files you upload: vehicle photos, your avatar and expense or maintenance receipts (image or PDF). We do not interpret their content: they are stored as-is for you to consult.
- Notification history: title, body and read state of the notifications we send you, kept for 90 days. The notice is stored even if you have muted the push, so you can check it in the app inbox; rejected commercial communications are not stored.
- Consents: which version of these documents you accepted, when, and from which IP and device. This is the evidence the GDPR requires (art. 7.1).
We do not process third-party data: everything you store belongs to you and only your account can see it.
3. Purposes and legal basis
- Providing the service — creating your account, storing your vehicles and their history, sending the reminders you configure (performance of contract, art. 6.1.b GDPR).
- Security — access auditing, suspicious sign-in alerts, session revocation (legitimate interest, art. 6.1.f).
- Usage analytics — only if you turn it on (consent, art. 6.1.a). See section 4.
- Commercial communications — only if you expressly accept them (consent). We currently send none.
4. Analytics and error reporting
- PostHog (EU servers): usage metrics, only with your consent, which you can give or withdraw in Settings at any time. Events are anonymous: neither your identity nor the content of your data is sent.
- Sentry (EU servers): technical error reports used to fix bugs. They include your internal user identifier and technical device data; authentication headers, email and IP are stripped before anything leaves the device or the server.
The app uses no cookies. The integrated SDKs are Supabase (authentication), Expo (notifications), Sentry and PostHog; only the latter requires your consent and stays off until you give it.
5. Processors
| Provider | Purpose | Where |
|---|---|---|
| Supabase, Inc. (US) | Identity, database and file storage | Data hosted in the EU (eu-central-1) |
| Railway Corp. (US) | Server hosting | Data hosted in the EU |
| Functional Software, Inc. — Sentry (US) | Error reporting | Data hosted in the EU |
| PostHog, Inc. (US) | Usage analytics (opt-in) | Data hosted in the EU |
| Expo — 650 Industries, Inc. (US) | Push notification delivery (receives the device token) | US |
| Microsoft | Transactional email delivery | EU / US depending on the service |
Providers established in the US process data under the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. We do not sell your data or share it with anyone else.
6. Retention
- For as long as your account exists.
- IP and user-agent in security logs are anonymised after 30 days.
- Notification history is deleted after 90 days.
- The data export file expires 24 hours after being generated.
- Deleting your account removes everything permanently, including the consent evidence. We keep no anonymised copies.
7. Your rights
You have the rights of access, rectification, erasure, portability, objection and restriction. The two most common ones are built into the app:
- Export your data (art. 20): Settings → Export my data. You will receive a file with everything we store about you.
- Delete your account (art. 17): Settings → Delete account. It is a two-step process with email confirmation, and it is irreversible.
For anything else, write to cybergarage@v13studio.com. If you believe we have not handled a request properly, you can complain to the Spanish Data Protection Agency (aepd.es) or your local supervisory authority.
8. Security
All communication is encrypted (TLS). Your session credentials are stored encrypted in your device's secure storage. You can enable two-factor authentication (TOTP) and biometric app lock in Settings, and we email you about sign-ins we do not recognise.
9. Minimum age
CyberGarage is for people aged 18 or over. We do not knowingly create accounts for minors; if we detect one, we will delete it.
10. Changes to this policy
Every version is dated. If a change affects your rights or what we process, the app will ask you to accept the new version before you continue using it.