Legal
Privacy Policy
How COEV collects, uses, and protects your personal data.
COEV PRIVACY POLICY (INFORMATIONAL — ENGLISH)
This English summary is provided for convenience. The binding privacy policy is the Polish version at coev.io/polityka-prywatnosci.html.
1. DATA CONTROLLER
The data controller is the entrepreneur operating the COEV platform. Identification details (business name, address, tax ID) are published in the website footer and provided on request pursuant to Polish e-services law. Contact: support@coev.io
2. DATA WE COLLECT
- Account data: name, email, user ID
- Federated login IDs (Google, Facebook) if used
- Payment data processed by Stripe (e.g. card last digits, Stripe customer ID)
- Booking data: times, location, vehicle, status, amounts
- Provider tax reporting data (DAC7): tax ID, address, date of birth, bank account
- Technical data: IP address, session logs, language preference (localStorage)
- Geolocation — only with your browser consent
3. PURPOSES AND LEGAL BASES (GDPR)
- Account and booking services — contract (Art. 6(1)(b))
- Payment processing via Stripe — contract (Art. 6(1)(b))
- Legal obligations (DAC7, accounting, tax) — legal obligation (Art. 6(1)(c))
- Claims and defence — legitimate interest (Art. 6(1)(f))
- Email notifications — contract (Art. 6(1)(b))
- Geolocation — consent (Art. 6(1)(a))
4. RECIPIENTS
Stripe Technology Europe Ltd., hosting providers, Google/Meta (if social login used), and public authorities when required by law. Data may be transferred outside the EEA based on EU Standard Contractual Clauses or equivalent safeguards.
5. RETENTION
- Account data: for the life of the account plus 6 years
- Booking and billing records: at least 5 years (tax/accounting)
- Technical logs: up to 12 months
6. YOUR RIGHTS
You have the right to access, rectify, erase, restrict, port, and object to processing, and to lodge a complaint with the Polish Data Protection Authority (UODO). Requests: support@coev.io (within 30 days).
7. COOKIES AND LOCAL STORAGE
The marketing site may use essential cookies. The web app stores language preference and authentication token in browser localStorage.
8. SECURITY
We use HTTPS, access controls, and password hashing appropriate to the risk.
9. CHANGES
We will notify users of material changes via the platform or email.