Car SpotCar Spot
  • How It Works
  • Features
  • FAQ
Download

Privacy Policy for Car Spot: Car Identifier

Effective date: 27th June, 2026

Developer: AppTek

Contact: legal@carspot.dev

Car Spot respects Your privacy and is committed to protecting Your Personal Data. This Privacy Policy explains how We collect, use, store, and protect Your information when You use Our Application on iOS and Android. It also explains Your rights under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and how Our data practices align with Apple's App Privacy and Google Play's Data Safety requirements.

By using the Application, You agree to the terms of this Privacy Policy.

Interpretation and Definitions

For the purposes of this Privacy Policy, capitalized terms have the meanings defined below, whether they appear in singular or plural form.

  • Account means a user account created to access features of the Service.
  • Application refers specifically to Car Spot: Car Identifier, the mobile software application provided by the Company for iOS and Android devices.
  • Company ("we", "us", "our", or AppTek) refers to AppTek, the developer and operator of the Service.
  • Device means any device capable of running the Application and accessing the Service, such as a smartphone or tablet.
  • Guest Mode means using limited features of the Application without creating an Account.
  • Personal Data means any information relating to an identified or identifiable individual.
  • Service refers to the broader car identification and tracking service operated by the Company, which is delivered primarily through the Application and may include related backend systems, infrastructure, and supporting features.
  • Service Provider means any third party that processes data on behalf of the Company (such as infrastructure, hosting, analytics, or AI providers).
  • User Content means photos, images, and other content uploaded, submitted, or created by You within the Application.
  • You means the individual accessing or using the Application or Service, or the legal entity on whose behalf such individual is accessing or using the Application or Service, as applicable.

1. Information We Collect and How It Is Used

When You use the Application, We collect information that is necessary to provide, operate, and improve the Service. Where You have an Account, this information is linked to it. The information falls into the following categories:

1.1 Account and Identity Information

Information used to create, identify, and manage Your Account, such as account identifiers, email address, sign-in method (email/password, Google, or Apple), and account-related timestamps. If You sign in via Google or Apple, We receive Your name, email address (which Apple may relay through a private address), and profile picture from the provider.

Purpose: To authenticate You, manage Your Account, and associate Your data with Your use of the Service.

1.2 Profile Information

Information You choose to provide to personalize Your Account and experience within the Application, including display name, username, bio, avatar image, and progress indicators (XP, level, rank).

Purpose: To personalize the Service, display relevant information within the Application, and track Your progress.

1.3 User-Generated Content

Content You create, upload, or submit while using the Application, including images, associated metadata, and other content generated through Your use of the Service. This includes spotted cars and their associated details, car identification corrections You submit, collections You create, and shareable links You generate.

Purpose: To provide the core functionality of the Service and allow You to view, manage, and retrieve Your content.

1.4 Location Information

Precise location data (GPS latitude and longitude) collected only while the Application is in use and with Your explicit permission. We also derive an approximate location name (city, region, country) from Your coordinates.

Purpose: To associate content or activity with a geographic location as part of the Service's functionality. Location data is never collected in the background. You may disable location tagging at any time in the Application's settings.

1.5 Usage and Activity Information

Information about how You interact with the Application, such as actions taken (e.g., scans performed, collections created), frequency of use, activity dates, and engagement over time.

Purpose: To support Application features (such as activity history and streaks), monitor usage patterns, enforce rate limits, and improve functionality and user experience.

1.6 Organizational and Preference Data

Information related to how You organize, group, or manage Your content and preferences within the Application, including settings such as theme, currency, distance units, and region.

Purpose: To enable content organization and customization features.

1.7 Support and Communications Data

Information You provide when contacting Us for support or assistance, including messages, support requests, optional screenshots, and technical information associated with Your Device (such as device model, operating system name and version, and app version).

Purpose: To respond to inquiries, troubleshoot issues, and improve the Service.

1.8 Purchase and Subscription Information

Information related to in-app purchases and subscriptions processed through Apple's App Store, Google Play, or RevenueCat (our subscription management provider). RevenueCat receives Your anonymous user identifier and purchase events; it does not receive Your email address or other profile information. We do not collect or store payment card details or billing information.

Purpose: To manage access to paid features and track subscription status.

1.9 Analytics, Diagnostics, and Error Reporting

Technical and diagnostic data, such as device information, operating system version, application version, crash reports, and error logs. We use Sentry for error monitoring, which may capture sampled session replays (short screen recordings) to help diagnose errors. Session replays do not capture text input fields, passwords, or sensitive data. Personally identifiable information is not sent to Sentry in production builds.

Purpose: To maintain performance, identify and fix errors, and improve reliability and user experience.

1.10 Guest Mode Data

If You use the Application in Guest Mode (without an Account), We process Your photos for AI identification but do not store them or any Personal Data on Our servers. A hashed (pseudonymized) representation of Your IP address is temporarily stored for up to 48 hours for rate limiting and abuse prevention purposes, after which it is automatically deleted. No other Personal Data is persisted for Guest Mode users. Scan results are stored only on Your Device until You create an Account.

Purpose: To provide limited Service functionality and prevent abuse.

1.11 Creator and Referral Program Data

If You participate in the creator or referral program, We track referral relationships (who referred whom), associated subscription events, and revenue amounts attributable to referrals, for the purpose of calculating referral attribution and commission payouts. Creator participants' contact information (name, email) is stored for program administration.

Purpose: To operate the referral program and attribute referrals correctly.

1.12 Sharing and Social Data

When You create shareable links, Your display name, avatar, and the content You choose to share (car spot details, collections) may be visible to anyone who accesses the link. Share links expire after 3 days. Social features such as follows, likes, and public profiles may make certain information visible to other users.

Purpose: To enable sharing and social features within the Service.

2. Legal Basis for Processing (GDPR)

We process Your Personal Data under the following legal bases, in accordance with GDPR:

  • Performance of a contract: To provide the core functionality of the Application and Service, including Account access, content creation, progress tracking, and data storage.
  • Consent: For accessing Device features such as location, camera, and photo library. You can withdraw consent at any time through Your Device's settings.
  • Legitimate interest: To maintain and improve Application reliability, security, and functionality, and to prevent abuse (e.g., rate limiting, fraud detection).

Automated decision-making (GDPR Article 22): The Service uses AI-based systems (including Google Gemini) for car identification. These systems analyze photos You submit and generate automated results including car make, model, year, generation, and specifications. These automated results do not produce legal or similarly significant effects on You, and are provided for informational and entertainment purposes only. You may submit corrections to any AI-generated identification. You have the right to request human review of any automated result by contacting Us at legal@carspot.dev.

3. Third-Party Service Providers

We use the following categories of Service Providers to operate the Service. These providers process data on Our behalf and are contractually required to protect Your data:

  • Supabase (cloud infrastructure) — stores all user data, images, and authentication information. Supabase's servers are in the United States.
  • Google Gemini AI (artificial intelligence) — processes photos You submit for car identification. The photo content is sent to Google's servers for analysis and is subject to Google's API Terms of Service. Google does not use data sent through the Gemini API to train its models.
  • RevenueCat (subscription management) — manages in-app subscriptions and purchases. RevenueCat receives Your anonymous user identifier, purchase events, and device platform information.
  • Sentry (error monitoring) — collects crash reports, error logs, and sampled session replays for debugging purposes. Sentry's servers are in the United States.
  • Brevo (email delivery) — if You joined Our waitlist, Brevo processes Your email address to deliver marketing communications such as launch notifications. Brevo does not handle transactional emails (such as password resets), which are delivered by Our infrastructure provider (Supabase).
  • Google Sign-In / Apple Sign-In (authentication) — if You choose to sign in with Google or Apple, these providers share Your identity information with Us as described in their respective privacy policies.

We do not sell Your Personal Data and do not share it with third parties for their own marketing purposes.

4. International Data Transfers

Some of Our Service Providers are based in or process data in the United States and other countries outside the European Union. Where Personal Data is transferred outside the EU/EEA, We ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • The EU-US Data Privacy Framework, where applicable
  • Contractual obligations requiring Service Providers to protect Your data

You may contact Us for more information about the specific safeguards applied to any particular transfer.

5. Data Storage and Security

Remote Storage

All user data, including Account information, Location Data, User Content, activity data, and progress-related data is securely stored using Supabase.

Local Storage

The Application stores certain data locally on Your Device to enable offline functionality and improve performance. This includes cached content, preferences, and authentication tokens. Authentication tokens are stored using encrypted storage (Keychain on iOS, encrypted SharedPreferences on Android). Other cached data is stored in standard device storage.

Security Measures

We apply reasonable technical and organizational safeguards to protect Your data, including:

  • Secure server infrastructure with row-level security policies
  • Encrypted data transmission (TLS/HTTPS)
  • Encrypted local storage for authentication credentials
  • Access controls designed to prevent unauthorized access
  • Rate limiting to prevent abuse

While no system can guarantee absolute security, We continuously work to protect Your information. In the event of a data breach that poses a risk to Your rights and freedoms, We will notify affected users and the relevant supervisory authority within 72 hours as required by GDPR.

6. Your Rights Under GDPR (EU/EEA Users)

If You are located in the European Union or European Economic Area, You have the following rights under GDPR:

  • Right to access: View the Personal Data associated with Your Account
  • Right to data portability: Download a copy of Your Personal Data in a structured, machine-readable format (JSON)
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten"): Delete Your data and Your Account
  • Right to restriction or objection: Request limits on how Your data is processed
  • Right to withdraw consent: Where processing is based on consent, You may withdraw it at any time without affecting the lawfulness of prior processing
  • Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority in Your country of residence if You believe Your data is being processed unlawfully

How to Exercise These Rights

  • Download Your data: Available directly within the Application (Settings > Download My Data)
  • Reset Your data: Clear stored spotted cars, collections, shared links, correction submissions, Location Data, User Activity Data, XP, level, rank, and scan usage counters from within the Application
  • Delete Your Account: Available directly in the Application (Settings > Delete Account) and permanently removes Your data from Our servers

You may also contact Us at legal@carspot.dev if You need assistance exercising any of these rights. We will respond to requests within 30 days.

7. Your Rights Under CCPA (California Residents)

If You are a California resident, You have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know: You may request that We disclose the categories and specific pieces of Personal Data We have collected about You, the sources of collection, the business purposes for collection, and the categories of third parties with whom We share Your data.
  • Right to delete: You may request that We delete the Personal Data We have collected from You, subject to certain exceptions.
  • Right to opt-out of sale or sharing: We do not sell Your Personal Data. We do not share Your Personal Data for cross-context behavioral advertising.
  • Right to non-discrimination: We will not discriminate against You for exercising any of Your CCPA rights.

To exercise these rights, You may use the in-app controls described in Section 6, or contact Us at legal@carspot.dev.

Categories of Personal Data collected (per CCPA categories):

  • Identifiers (email address, username, user ID)
  • Geolocation data (precise GPS coordinates, when permitted)
  • Internet or electronic network activity (usage patterns, activity logs)
  • Audio, electronic, or visual information (photos of cars)
  • Commercial information (subscription status)

We do not knowingly collect or sell the Personal Data of consumers under 16 years of age.

Right to correct: You may request that We correct inaccurate Personal Data that We maintain about You. You can update most information directly within the Application, or contact Us at legal@carspot.dev.

Right to limit use of sensitive personal information: We collect precise geolocation data, which is classified as sensitive personal information under the CCPA. You may direct Us to limit the use of this sensitive personal information to purposes necessary to provide the Service. You can disable location collection at any time in the Application's settings. To submit a request to limit, contact Us at legal@carspot.dev.

Authorized agents: You may designate an authorized agent to submit a request on Your behalf. We may require verification that the agent has been properly authorized.

Response timing: We will acknowledge Your request within 10 business days and respond substantively within 45 calendar days, with the possibility of a 45-day extension if necessary and communicated to You.

8. Data Retention and Deletion

We retain Personal Data for the following periods:

  • Account and profile data: Until Account deletion
  • Car spots, collections, and related content: Until deleted by You or Account deletion
  • Activity log data: Until Account deletion or data reset
  • Support tickets: 2 years after ticket resolution, then automatically deleted
  • Share links: 3 days after creation (auto-expire)
  • Rate limiting data (hashed IPs): 48 hours (auto-cleaned)
  • Waitlist email addresses: Until You request removal
  • Unknown car submissions: Indefinitely (for reference database improvement); link to Your Account is removed upon Account deletion
  • Creator and referral program data: Until Account deletion or program termination
  • Quest and progress data: Until Account deletion or data reset

When You reset data, the selected information is permanently removed from Our servers. When You delete Your Account, all associated Personal Data is permanently deleted from Our servers. We do not retain user data after Account deletion beyond short-term technical backup requirements (up to 30 days).

Third-party data retention: Data previously sent to third-party Service Providers (such as Sentry crash reports, RevenueCat purchase records, or photos processed by Google Gemini AI) is subject to those providers' own data retention policies and cannot be deleted by Us. Google's Gemini API may retain submitted data for up to 30 days for abuse monitoring purposes.

9. Disclosure of Personal Data

Legal Requirements

We may disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (such as a court or government agency).

Business Transfers

If the Company is involved in a merger, acquisition, or asset sale, Your Personal Data may be transferred. We will notify You before Your data becomes subject to a different privacy policy.

10. Age Requirements and Children's Privacy

The Service is intended for users of all ages. However, if You are under the age of 13 (or the minimum age required by applicable law to enter into a legally binding agreement), You may only use the Service with the consent of a parent or legal guardian.

We do not knowingly collect Personal Data from children where such collection would violate applicable child data protection laws, including the U.S. Children's Online Privacy Protection Act (COPPA) and Article 8 of GDPR. If We become aware that Personal Data has been collected without the required parental or legal guardian consent, We will take reasonable steps to delete such data as soon as practicable.

If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data without Your consent, please contact Us at legal@carspot.dev.

11. Device Permissions

The Application may request access to the following Device features. All permissions are optional and can be granted or revoked at any time through Your Device's settings:

  • Camera: To capture photos of cars for identification
  • Photo Library: To select existing photos for identification and to save spotted car photos
  • Location: To tag where cars were spotted (foreground only, never in the background)

The Application does not access Your microphone, contacts, calendar, or other sensitive Device features.

12. Links to Other Websites

The Application may contain links to third-party websites or services that are not operated by the Company. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. We strongly advise You to review their privacy policies.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. For material changes, We will provide notice through the Application or by updating the effective date on this page. Changes will be posted with a revised effective date. Continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy.

14. Contact Us

If You have questions, concerns, or requests regarding this Privacy Policy or Your Personal Data, please contact Us at:

Email: legal@carspot.dev

We aim to respond to all legitimate requests within 30 days. If Your request is particularly complex, We may notify You and extend the response period by up to 60 additional days.

By using the Application, You confirm that You are legally permitted to enter into this Privacy Policy, or that You have obtained the consent of a parent or legal guardian where required by law, that You are over the age required to hold an Account under applicable law, and that You have read, understood, and agree to this Privacy Policy.

Car SpotCar Spot

© 2026 AppTek. All rights reserved.

Privacy PolicyTerms of ServiceSubscription TermsContact