1. Who We Are

GaragePlanner is a mobile application and web platform that connects car owners with garages for booking service appointments and requesting quotes. The data controller is:

GaragePlanner
Website: https://garageplanner.nl
Contact: privacy@garageplanner.nl

2. What Data We Collect and Why

Account data (customers): When you register as a customer, we collect your name, email address, and phone number. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Account data (garages): When you register as a garage, we collect the business name, owner name, address, city, postal code, phone number, email address, KvK number, VAT number, GPS coordinates, and optionally a logo and banner image. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Vehicle information: When you add a vehicle to your profile, we collect the license plate, make, model, year of manufacture, and optionally the VIN. Legal basis: performance of a contract.

Appointment and booking data: We store the details of appointments you book, including the selected services, scheduled date and time, status, and any notes. Legal basis: performance of a contract.

Quotes and invoices: We store quote requests, accepted quotes, and invoices linked to your appointments. Legal basis: performance of a contract and legal obligation (Art. 6(1)(c) GDPR).

Messages: When you communicate with a garage through the in-app messaging feature, we store those messages. Legal basis: performance of a contract.

Reviews: When you submit a review of a garage, we store the text and rating linked to your account. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

Push notifications: If you grant notification permission, we store a device push token linked to your account to deliver appointment reminders and status updates. Legal basis: consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time in your device settings.

Usage data: We do not use third-party analytics or advertising trackers.

3. How Long We Keep Your Data

We retain your account and transaction data for as long as your account is active, and for up to 7 years after account deletion where required by Dutch accounting law. Push tokens are deleted when you log out or disable notifications. Password reset tokens expire within 1 hour.

4. Who We Share Your Data With

We share data only as necessary to provide the service:

5. International Transfers

Our servers are hosted within the European Economic Area (EEA). If any data is processed outside the EEA (e.g., by Resend), we ensure adequate safeguards are in place (Standard Contractual Clauses or equivalent).

6. Your Rights Under GDPR

If you are located in the European Economic Area, you have the following rights:

To exercise any of these rights, contact us at privacy@garageplanner.nl. We will respond within 30 days. You also have the right to lodge a complaint with the Dutch data protection authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

7. Security

We store passwords in hashed form (bcrypt). All data is transmitted over HTTPS. Access to personal data is restricted to authorised personnel only.

8. Children

GaragePlanner is not directed at children under 16. We do not knowingly collect data from children.

9. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via email or an in-app notification. The "Last updated" date at the top of this page reflects the most recent revision.

10. Contact

For privacy questions or requests: privacy@garageplanner.nl