detailmasters

detailmasters

Privacy Policy

July 25, 2026

This policy is published in English only. It applies to every country we serve; where local law grants you stronger rights, those rights apply in addition to what is described here.

1. Controller and scope

The controller of your personal data is Telmo Eduardo Antunes Alfarrobeira, IČO 21781478, Kaprova 14, 11000 Prague, Czech Republic ("we"). Privacy questions and requests: info@detailmasters.pro. This policy explains what personal data we process on the platform at detailmasters.pro, why we process it, and what rights you have.

It covers everyone who uses the platform — customers who book services, the detailing businesses (and their staff accounts) that list on it, and agents who refer businesses to us.

2. Where we operate and which law applies

We offer the platform in the following countries: Portugal, Czech Republic, Spain, France, Germany, Italy, Austria, United Kingdom, Switzerland, Poland, Hungary, Slovakia, Sweden.

Depending on where you are, one of the following applies to the processing described here:

  • European Union / EEA — the General Data Protection Regulation (Regulation (EU) 2016/679, "EU GDPR"), together with the national data-protection and electronic-communications rules of your country.
  • United Kingdom — the UK GDPR and the Data Protection Act 2018, together with the Privacy and Electronic Communications Regulations (PECR).
  • Switzerland — the Federal Act on Data Protection (FADP/revFADP).

Where this policy refers to a GDPR article, read it as the equivalent provision of the UK GDPR for users in the United Kingdom, and of the FADP for users in Switzerland. Because we are established in the Czech Republic, the EU GDPR is our baseline and we apply its standard of protection to everyone.

3. Data we process

  • Account data — name, e-mail, phone, country, preferred language, password (stored as a salted hash), optional avatar and bio, marketing consent.
  • Billing data — optional billing address and tax identifiers you provide for invoices.
  • Booking data — services booked, dates and times, prices (range, confirmed price, per-extra prices, payments recorded by the business), notes you add, service address for mobile services.
  • Vehicle data — vehicles you save (make, model, year, colour, licence plate) and vehicle details entered with a booking.
  • Photos — before/after photos of your vehicle uploaded by the business to document the work.
  • Payment data — processed by Stripe; we receive only payment references (amounts, status, intent identifiers), never your card number.
  • Content — reviews, review responses, appeals, messages sent through service updates.
  • Loyalty, coupon and package data — points, redemptions, issued coupons and their usage, purchased packages and used sessions.
  • Notification data — in-app notifications and, if you opt in, push subscription endpoints for this device.
  • Technical data — IP address, request logs, cookie identifiers described below.

4. Where the data comes from

Mostly directly from you. Some data is created by businesses you interact with: a business may record a walk-in booking with your name and contact details, keep customer notes about the services performed, upload photos of your vehicle, and record payments. Businesses are independent controllers of their own customer records; we process this data as part of providing the platform.

5. Purposes and legal bases

  • Providing the service (accounts, bookings, payments, packages, loyalty, notifications) — performance of a contract (Art. 6(1)(b) GDPR).
  • Invoicing and tax record-keeping — legal obligation (Art. 6(1)(c)).
  • Booking reminders and essential service e-mails — performance of a contract.
  • Marketing e-mails, promotional coupons, review invitations — your consent (Art. 6(1)(a)), withdrawable at any time in account settings.
  • Push notifications — your consent, given per device and withdrawable in account settings or your browser.
  • Advertising and conversion measurement (Google Ads, Google Analytics) — your consent (Art. 6(1)(a) GDPR), given or refused in the cookie banner and withdrawable at any time.
  • Platform security, fraud prevention, dispute records — legitimate interest (Art. 6(1)(f)).
  • Anonymous, aggregated statistics (e.g. specialists, cities, bookings counters) — legitimate interest.

In Switzerland, processing is carried out on the basis of the FADP; consent-based processing (marketing, push, advertising cookies) works the same way and is withdrawable at any time.

6. Cookies and local storage

We use a minimal set of first-party storage:

  • dp_session (cookie) — marks an active session so protected pages can redirect correctly; expires after 7 days.
  • NEXT_LOCALE (cookie) — remembers your language choice; 1 year.
  • detailpro_token (localStorage) — your login token on this device.
  • dismissed_promo_* (localStorage) — remembers promotional banners you closed.

Analytics and advertising cookies are optional, off by default, and load only with your consent:

  • Google Analytics 4 — audience and traffic measurement (e.g. _ga, _ga_* identifiers).
  • Google Ads — measuring sign-up conversions from our advertising campaigns. We use enhanced conversions, which send a hashed (irreversible) version of your e-mail address to Google to match a conversion to an ad click; Google may set conversion cookies such as _gcl_*.

We use Google Consent Mode v2: until you choose, advertising and analytics storage stay denied and these services receive only limited, cookieless signals. The cookie banner lets you "Accept all" or "Reject optional"; the strictly necessary storage above remains active either way. You can change your choice at any time by clearing this site's cookies and local storage, which makes the banner reappear.

Consent for non-essential storage is required under the EU ePrivacy rules as implemented in each country, under PECR in the United Kingdom, and under the FADP together with the Swiss Telecommunications Act in Switzerland.

7. Recipients and processors

We share personal data only as needed to run the platform:

  • Businesses you book with — receive your booking details, contact data, vehicle details and service address (for mobile services).
  • Stripe Payments Europe — payment processing.
  • MongoDB Atlas — database hosting.
  • Vercel — web hosting and content delivery.
  • Resend — transactional and consented marketing e-mail delivery.
  • Cloudinary — image hosting (business logos, galleries, vehicle photos).
  • Push delivery services of your browser vendor (Apple, Google, Mozilla) — only if you enable push notifications.
  • Google (Google Analytics 4 and Google Ads) — audience measurement and advertising conversion tracking, only if enabled and consented to; enhanced conversions share a hashed, irreversible version of your e-mail address.
  • Agents — see business-level data of the businesses they referred; they do not receive customer personal data.

We also disclose data where we are legally required to do so, or to establish, exercise or defend legal claims.

8. International transfers

Our infrastructure is operated primarily in Europe, but some processors listed above may process data outside the EEA, the United Kingdom or Switzerland — in particular in the United States.

Where that happens, the transfer is covered by an appropriate safeguard:

  • an adequacy decision — including the EU–US Data Privacy Framework and its UK Extension, and the Swiss–US Data Privacy Framework, where the recipient is certified;
  • the European Commission's Standard Contractual Clauses for transfers out of the EEA;
  • the UK International Data Transfer Agreement, or the UK Addendum to the Standard Contractual Clauses, for transfers out of the United Kingdom;
  • the Standard Contractual Clauses as recognised by the Swiss Federal Data Protection and Information Commissioner for transfers out of Switzerland.

You can request a copy of the relevant safeguard by writing to us.

9. Retention

Account data is kept for as long as your account exists. Booking, review and loyalty records are kept while the account is active to provide your history. Payment references are retained as required for accounting and dispute resolution.

Invoicing and accounting records are retained for the statutory period that applies to us as a Czech company (up to 10 years). Where the law of your own country requires a business to keep records of a transaction for longer, the business you booked with is responsible for that retention in its own systems.

When you delete your account, personal data is deleted or anonymised, except where retention is legally required.

10. Your rights

You have the right of access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interest, and the right to withdraw consent at any time without affecting processing carried out before the withdrawal. These rights exist under the EU GDPR, the UK GDPR and the FADP alike.

Self-service: you can export your data (account settings → "Your data"), update your details, manage marketing consent and push notifications, and delete your account — all in the app. For anything else, write to us; we respond within one month.

We do not use your personal data for automated decision-making that produces legal effects concerning you.

11. Complaints and supervisory authorities

If you believe we have handled your data incorrectly, please contact us first — most issues are resolved quickly. You also have the right to lodge a complaint with the supervisory authority of your country of residence, your place of work, or the place of the alleged infringement:

  • Portugal — Comissão Nacional de Proteção de Dados (CNPD), cnpd.pt
  • Czech Republic — Úřad pro ochranu osobních údajů (ÚOOÚ), uoou.gov.cz
  • Spain — Agencia Española de Protección de Datos (AEPD), aepd.es
  • France — Commission Nationale de l'Informatique et des Libertés (CNIL), cnil.fr
  • Germany — the data protection authority of your federal state; overview at bfdi.bund.de
  • Italy — Garante per la protezione dei dati personali, garanteprivacy.it
  • Austria — Datenschutzbehörde (DSB), dsb.gv.at
  • Poland — Urząd Ochrony Danych Osobowych (UODO), uodo.gov.pl
  • Hungary — Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), naih.hu
  • Slovakia — Úrad na ochranu osobných údajov SR, dataprotection.gov.sk
  • Sweden — Integritetsskyddsmyndigheten (IMY), imy.se
  • United Kingdom — Information Commissioner's Office (ICO), ico.org.uk
  • Switzerland — Federal Data Protection and Information Commissioner (FDPIC/EDÖB), edoeb.admin.ch

As we are established in the Czech Republic, ÚOOÚ acts as our lead supervisory authority within the EU — but you may always complain to your own national authority.

12. Security

Data is encrypted in transit (TLS). Passwords are stored as salted hashes. Access to production systems is restricted and authenticated; staff accounts within a business operate under granular per-section permissions; payment card data never touches our servers. Invoice documents are served only through authenticated or unguessable capability links.

13. Children

The platform is not directed at children. You must be at least 18 years old to create an account. We do not knowingly process children's data; if you believe a child has provided us personal data, contact us and we will delete it.

14. Changes and contact

We may update this policy as the platform evolves; material changes will be announced in the app or by e-mail. This policy is maintained in English only, so that a single authoritative text applies across every market we serve. Contact: info@detailmasters.pro.