Effective date: April 9, 2026
This Privacy Policy describes how A group of entrepreneurs (“we,” “us”) collects, uses, discloses, and protects personal data in connection with the CarGest websites and services (the “Services”).
1. Who this applies to
We may process data about visitors to our marketing site, trial and paying account administrators and staff (“Workspace Users”), and—when you use CarGest to run your business—data about your end-customers that you or your users enter into the product (“End-Customer Data”). For End-Customer Data, you are typically the controller and we act as a processor per our DPA where required.
2. Data we collect
2.1 You provide to us
- Account and profile: name, email, organization name, credentials, role, billing-related data.
- Content you submit: vehicle records, reservations, customer profiles, documents, messages, support tickets.
- Payment data: processed by payment providers; we generally receive limited metadata, not full card numbers.
2.2 Automatic / technical
- Logs & device: IP address, approximate location, browser type, timestamps, pages or API routes used.
- Cookies & similar technologies: see our Cookie Policy.
3. How we use personal data
- Provide the Services: hosting, authentication, features, support, security, abuse prevention.
- Billing & administration: invoices, renewals, tax and accounting compliance.
- Communications: transactional messages (e.g. reset password, receipts) and, where permitted, product updates; you can opt out of non-essential marketing where applicable.
- Improvement & analytics: aggregated or de-identified metrics, diagnostics.
- Legal: comply with law, enforce our Terms, protect rights and safety.
4. Legal bases (EEA/UK/Switzerland)
Where GDPR-style rules apply, we rely on:
- Contract (necessary to provide the Services you request);
- Legitimate interests (security, fraud prevention, improving the product), balanced against your rights;
- Legal obligation;
- Consent where required (e.g. certain cookies or marketing)—withdrawable at any time without affecting prior lawful processing.
5. Sharing & subprocessors
We share data with:
- Service providers that help us host, email, bill, analyze, or support the Services, under contracts requiring protection of personal data.
- Authorities or third parties when required by law or to protect rights, or with your instruction.
- Business transfers in a merger, acquisition, or asset sale, subject to appropriate notices and safeguards.
A current list of categories of subprocessors may be provided upon request or published on our site as we formalize vendor disclosures.
6. International transfers
We may process data in the United States and other countries. Where we transfer personal data from the EEA/UK/Switzerland, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, unless an exception applies.
7. Retention
We retain personal data as long as needed to provide the Services, comply with law, resolve disputes, and enforce agreements. Backup copies may persist for a limited time. You may request deletion subject to legal exceptions.
8. Security
We implement technical and organizational measures appropriate to the risk (encryption in transit, access controls, logging). No method of transmission or storage is 100% secure.
9. Your rights
Depending on your region, you may have rights to access, rectify, delete, restrict, port, or object to certain processing, and to lodge a complaint with a supervisory authority. To exercise rights, contact us via our contact page. We may need to verify your request.
10. Children
The Services are not directed to children under 16 (or the age required locally). Do not provide their data.
11. Changes
We may update this Policy. We will post the new version and, where appropriate, notify you. Continued use after the effective date may constitute acceptance.
12. Contact
A group of entrepreneurs
Privacy inquiries: Contact us