+pitster
Find a workshopCustomer account
For service providers⌄
Service organisation login/register
Log inRegister
Workshop loginInvitation-only accountLog in

Personal data

Privacy policy

This policy explains what Pitster processes, why it is needed, who can access it, and how to exercise your rights.Effective 14 August 2026

On this page

01Controller and contact02Data we process03Purposes and legal bases04Access, sharing, and service providers05Retention and account closure06Your data-protection rights07Security and updates

Controller and contact

The Pitster platform operator determines how platform account and marketplace data is processed. Privacy and data-rights requests can be submitted through the Contact page or to support@pitster.app. The contracting entity shown in a provider agreement or invoice remains responsible for its own processing activities.

Data we process

Depending on your role and use of the platform, data may include identity and contact details, authentication identifiers, vehicles and optional VIN or mileage, garage records, appointment requests, repair lifecycle information, estimates, invoices, service history, warranties, workshop and organisation details, staff assignments, billing records, support tickets, and technical security logs.

  • Customer information entered directly by the customer.
  • Service information entered by a workshop professional who has an authorised relationship with the customer or vehicle.
  • Organisation, workshop, billing, and access information supplied by service providers.
  • Technical information generated for authentication, security, communications, and platform reliability.

Purposes and legal bases

Pitster processes data to create and secure accounts, provide appointment and repair functions, maintain portable service history, send requested service communications, administer subscriptions, prevent misuse, resolve support tickets, and comply with legal duties.

The applicable basis may be performance of a contract, steps requested before a contract, compliance with a legal obligation, legitimate interests in operating and protecting the platform, or consent where the law specifically requires it. A privacy acknowledgement is not consent to optional advertising or analytics.

Access, sharing, and service providers

Access is role- and location-restricted. Platform administrators and Service Organisation managers do not have routine access to customer garage content. Workshop professionals may access or add service data only through an authorised customer, booking, vehicle, or location relationship. Customers can view their information and manage available sharing permissions.

Technical processors may include Supabase, Vercel, MXroute, Stripe, SMS providers, Meta WhatsApp Business Platform, and Google Maps. They receive only the information needed for their function and operate under their own terms and applicable data-protection arrangements. WhatsApp is used only after operational-message opt-in and can be disabled per booking or by sending STOP. Google may receive technical device, connection, and request information when a map loads.

Retention and account closure

Operational account and service data is kept while it is needed to provide the platform and maintain legitimate service records. A verified closure request begins with account blocking or deactivation. An administrator then schedules a deletion review after either 30 or 60 days, records the due date, and follows up through the admin ticket queue.

Erasure is not absolute. Invoices, payment evidence, security logs, dispute records, warranty evidence, or other records may be retained where law or overriding legitimate grounds require it. Backups may expire on separate controlled cycles. Data is deleted or anonymised when the applicable purpose and retention period end.

Your data-protection rights

Subject to the GDPR and applicable law, you may request access, correction, erasure, restriction, portability, or objection, and may withdraw consent where processing depends on consent. Pitster may ask for proportionate identity verification and will explain if a request cannot be fulfilled in full.

You may complain to the Romanian data-protection authority, ANSPDCP, or another competent supervisory authority. Exercising a right does not affect mandatory records belonging to another party or the rights and freedoms of others.

Security and updates

Pitster uses access controls, row-level database policies, role separation, secure authentication, audit records, and protected administrative operations. No online system can be guaranteed risk-free. Report suspected misuse through the problem-report form.

This policy may be updated as services or legal requirements change. Material changes will be identified by a revised effective date and, where appropriate, an in-platform notice.

Request account closure

Send a written account-closure request through the secure form. An administrator verifies the request, blocks or deactivates the account first, and records a 30- or 60-day deletion follow-up. Data that must be retained for legal, billing, fraud-prevention, or dispute purposes is handled separately.

Start an account-closure request

Privacy references

EU General Data Protection RegulationRomanian data-protection authority (ANSPDCP)Google Privacy Policy
© Cozumel SRL, All rights reserved.
TermsPrivacyCookies