Skip to content
CarTrace

Privacy Policy

Last updated: 4 October 2026

This statement explains, in plain language, what personal data CarTrace processes, why, on what legal basis, how long we keep it, who we share it with, and the rights you have under the GDPR. It applies to our websites (cartrace.nl and our other country domains), the CarTrace apps for Android and iOS, and the services offered through them.

The apps are the same service on a smaller screen and are covered by every section below. What is specific to them — the permissions they ask for, what stays on your phone, and how they identify themselves when you have no account — is in section 9.

1. Who we are (data controller)

The company named below operates CarTrace — its websites and apps — and is the controller responsible for the personal data described here. For any privacy question, or to exercise a right, contact us at info@cartrace.nl.

You also have the right to lodge a complaint with your national data protection authority. In the Netherlands this is the Autoriteit Persoonsgegevens.

Operator
CarTrace
Email
info@cartrace.nl
Our registration details (registered legal name, address, Chamber of Commerce and VAT numbers) will be published here as soon as the company's registration is complete.

2. Data we collect

Some vehicle data shown on CarTrace does not come from you but from external data sources, including official vehicle registries. This is factual vehicle data, not information about you.

The assistant's seller check can look up published ratings of a dealer or seller named in an advert you ask about. For a private seller, that is information published about them online. The seller check does not score people.

  • Account information: name, email, phone (optional), country, city.
  • Vehicle information: make, model, year, colour, licence plate, VIN, photos, theft details.
  • Stolen-vehicle reports: theft date/location, police report number, reward amount.
  • Sightings and suspicious-vehicle reports you submit (a suspicious-vehicle report can be sent anonymously — you don't need an account).
  • Licence plates and VINs you look up with CarCheck, and reports you purchase (a purchased report is kept in your account for 60 days).
  • Usage data: search history, IP address (hashed for rate-limiting and security), device info, pages visited.
  • Optional data: precise location (only if you enable it), spotter payout details (once spotter rewards launch — they are not yet available), alert subscriptions (email + area).
  • Payment data: processed by our payment provider (Stripe) — we do not store card details.
  • AI assistant: the messages you send to our assistant, the preferences it remembers between conversations (for example your budget or the kind of car you are looking for), cars you shortlist, and the feedback you give on its answers.
  • In the app: an anonymous key that identifies your installation when you are not signed in, and — only for the features that need them, and only when you allow it — your approximate location, a voice recording while you hold the microphone button, and photos you choose to attach. Section 9 explains each of these.

3. How we use your data (purposes & legal basis)

PurposeLegal basis
Create and manage your accountContract — Art. 6(1)(b)
List and search stolen vehiclesLegitimate interest — Art. 6(1)(f): recovery & fraud prevention
Send theft alerts and notificationsConsent — Art. 6(1)(a)
Process payments and keep purchased reports availableContract — Art. 6(1)(b)
CarCheck vehicle reportsLegitimate interest — public safety
Review suspicious-vehicle reportsLegitimate interest — Art. 6(1)(f): crime prevention
Marketing emailsConsent — Art. 6(1)(a), opt-in only
Invite you to review a purchase on TrustpilotLegitimate interest — Art. 6(1)(f) for the invitation sent with your invoice (you can object); consent — Art. 6(1)(a) for the invitation script on the website
Analytics and improvementConsent for non-essential; legitimate interest for essential
Fraud preventionLegitimate interest — Art. 6(1)(f)
Answer your questions with the AI assistant and remember your preferences between conversationsContract — Art. 6(1)(b)

4. Sharing your data & sub-processors

We never sell your personal data. We share it only where necessary to run the service, always under GDPR-compliant data-processing agreements, with the providers below:

Our AI assistant runs on Microsoft Azure OpenAI in the EU. Your conversations are sent there to produce an answer and are stored so the assistant can remember context between sessions. Under Microsoft's terms, data sent to Azure OpenAI is not used to train OpenAI's models. Deleting your account erases your conversations and everything the assistant remembers, and you can ask us to erase them on their own at any time using the contact address below.

Each answer from the assistant is stored with a fingerprint: a SHA-256 hash of its text, so that an answer someone shows us can be matched to the conversation it came from. The fingerprint is kept with the conversation and deleted with it, under the conversation retention period in section 6.

When you use voice, your speech is turned into text by Microsoft Azure AI Speech. Spoken replies are produced by Microsoft Azure AI Speech or, when it is switched on, by ElevenLabs. Only the text of the reply is sent to ElevenLabs, never your voice.

After a purchase — a report, a compare pass, a listing or stickers, or the first payment of a new subscription (not its renewals) — we send a copy of your invoice email to Trustpilot A/S in Denmark, which then emails you an invitation to review CarTrace. Trustpilot receives your name, your email address, the invoice number and the invoice email, including the invoice PDF. We do this on the basis of our legitimate interest in asking customers about their purchase; writing a review is up to you, and you can object at any time at info@cartrace.nl. If you have allowed Marketing cookies, the page you return to after paying also asks Trustpilot to invite you, using your account email, your name and the payment reference; Trustpilot invites you only once per order.

Some of these providers also process data for their own purposes, as independent controllers under their own privacy policies: Google for reCAPTCHA and YouTube, Meta for the Pixel, Apple for push delivery, and Trustpilot for the reviews published on its platform.

  • Law enforcement: stolen-vehicle reports may be shared with police when you request it, or where we are legally required to.
  • Public listings: vehicle details you list are publicly searchable, but NOT your name, exact address or contact details unless you choose to share them.
  • Anonymised statistics: we publish aggregated, anonymised theft data that contains no personal data.
ProviderPurposeLocation / safeguard
Microsoft AzureHosting, database, photo storageEU (West Europe)
Microsoft Azure OpenAIAI assistant; the other AI-written text on CarTrace, such as comparisons, summaries, translations and advert draftsEU (West Europe)
Microsoft Azure AI SpeechVoice input and spoken replies, only when you use voiceEU
ElevenLabsSpoken replies from the assistant, only when you use voice and this voice is switched onUS — Standard Contractual Clauses
StripePayment processingEU/US — Standard Contractual Clauses
ResendTransactional & alert emailsUS — Standard Contractual Clauses
Google (Sign-in, Tag Manager, Analytics, Firebase)Optional login; consent-gated analytics on the website and in the appUS — Standard Contractual Clauses
MetaConsent-gated ad measurement (Pixel)US — Standard Contractual Clauses
Microsoft ClarityConsent-gated session recordings and heatmaps of how the website is usedUS — EU-US Data Privacy Framework / Standard Contractual Clauses
TrustpilotReview invitations after a purchase: a copy of your invoice email (name, email address, invoice number and invoice PDF), and — only with Marketing consent — the invitation script on the page you return to after payingEU (Denmark)
OpenStreetMap / NominatimTurning addresses into map coordinatesEU
Google reCAPTCHABot protection on the sign-up, sign-in, report and alert forms, only on those forms (legitimate interest: preventing abuse). Google sees your IP address and browser signals and sets the _GRECAPTCHA cookieUS — EU-US Data Privacy Framework / Standard Contractual Clauses
CARTOMap background tiles; your IP address reaches CARTO when a map loadsUS/EU — global delivery network; Standard Contractual Clauses
YouTube (Google)Embedded video player in privacy-enhanced mode (youtube-nocookie.com), loaded only when you press playUS — EU-US Data Privacy Framework / Standard Contractual Clauses
WindyWebcam images and players on the camera pages, loaded from Windy when you view or open themEU
Firebase Cloud Messaging (Google)Delivering push notifications to the Android and iOS apps, only if you allow notificationsUS — EU-US Data Privacy Framework / Standard Contractual Clauses
Apple (Sign in with Apple, Push Notification service)Optional sign-in with your Apple ID in the iOS app; delivering push notifications to iPhones, only if you allow notificationsUS — EU-US Data Privacy Framework
Microsoft Entra IDOptional sign-in with a Microsoft accountEU/US — EU-US Data Privacy Framework
Tavily / Brave SearchWeb search for the assistant, for example the seller check; only the search query is sent, never your account detailsUS — Standard Contractual Clauses

5. Data transfers

Your data is stored within the EU (Azure West Europe region). Where a provider processes data outside the EEA (for example Stripe, Resend, Google, Meta, Apple or Microsoft), the transfer is protected by an adequacy decision — for US providers certified under it, the EU-US Data Privacy Framework — or by the European Commission's Standard Contractual Clauses.

6. Data retention

Data typeRetention period
Account dataUntil you delete, or 24 months after last login
Active vehicle listingsUntil recovered, expired, or you delete
Photos of a listing removed by our team30 days after the removal (so an appeal can still be reviewed), then the files are deleted
Uploaded photos never added to a report7 days after upload, then deleted
Stolen-vehicle reportsKept while the case is open. Once resolved, the case is reviewed by hand and deleted when it is no longer needed; deleted straight away if you delete the report or your account
Reports about a listing12 months after our decision, then automatically deleted
Purchased CarCheck reports60 days after purchase, then automatically deleted
Suspicious-vehicle reportsUp to 12 months for review, then deleted
Registry sightings3 years from the sighting, then automatically deleted
Payment records and invoices7 years (legal/tax requirement, art. 52 AWR)
Sticker delivery addressesCleared 90 days after dispatch (the order record itself is kept)
Access logs12 months (security)
Withdrawal-right waivers7 years, with the invoice of the purchase
Notification history12 months, then deleted
Support email24 months after the last message, then deleted
Case messages24 months after the last message, then deleted
CarCheck search logs6 months
Assistant conversations24 months after the last message, then deleted
Assistant memory and preferences24 months after last use, then deleted
Assistant quality traces (redacted)12 months, then deleted
Unconfirmed theft-alert signups30 days if the confirmation link is never clicked, then deleted
Theft alerts and CarCheck follow-ups after unsubscribing12 months after you unsubscribe, then deleted
Free CarCheck report emails12 months after the request, then deleted
Disconnected phones (app notifications)90 days after a phone stops accepting notifications, then deleted
Marketing email list / alertsUntil you unsubscribe

7. Your rights

To exercise these rights, use your account settings or email info@cartrace.nl. We respond within one month. We may ask you to confirm your identity first; if you share very little data with us, that can limit our ability to act on a request.

No decision about you is made solely by automated means. Approving, rejecting and removing listings, suspending accounts, and prices are decided by people or by fixed rules, not by an AI system. There is no solely automated decision-making within the meaning of Article 22 GDPR, and no profiling that has legal or similarly significant effects on you. The assistant's memory holds your car preferences, which you can see, edit and delete.

  • Access — request a copy of your data (you can export it from your account settings).
  • Rectification — correct inaccurate data in account settings.
  • Erasure — delete your account and data.
  • Restriction — limit how we process your data.
  • Portability — receive your data in a machine-readable format.
  • Object — object to processing based on legitimate interest, such as the Trustpilot review invitation after a purchase.
  • Withdraw consent — for marketing, analytics and other optional features, at any time.
  • Complain — lodge a complaint with your national Data Protection Authority.

8. Cookies & tracking

We use essential cookies for sign-in and security — including Google reCAPTCHA on our forms, which protects them from bots — and, only with your consent for each category, analytics tags (Google Tag Manager, Google Analytics and Microsoft Clarity) and marketing tags (the Meta Pixel, and Trustpilot's review invitation on the page you return to after paying). Neither category loads before you allow it. See our Cookie Policy for the full list, and use “Cookie settings” in the footer to change your choice at any time.

9. The CarTrace app

The CarTrace apps for Android and iOS are the same service as the website and everything above applies to them. This section covers what is different about a phone: the permissions the app asks for, what never leaves your device, and how the app identifies itself when you have no account.

The app asks for a permission at the moment you first use the feature that needs it, never on the screen where you arrive, and explains why before the system prompt appears. Refusing one costs you that feature and nothing else. You can change any of them later in your phone’s settings for the app.

Reports you have opened and the plates you have looked up recently are held in memory only, for as long as the app is running. They are not written to the phone and are gone when you close it.

  • Camera — for the plate scanner only. The camera image is read on your phone by an on-device text recogniser: the video never leaves the handset, is never recorded, and is never uploaded. Only the plate the scanner reads is sent to us, exactly as if you had typed it.
  • Microphone — for talking to the assistant. Normally the app records only while you hold the microphone button. If you switch on hands-free mode yourself, the microphone reopens after each answer so you can reply without touching the phone, and closes on its own after a pause so a handset put down mid-conversation does not keep listening. Either way the recording is sent to Microsoft Azure AI Speech to be turned into text and is discarded once that is done; we do not keep the audio. The transcribed text is treated like any other message you send the assistant. The first spoken reply of a voice conversation says aloud that Leo is an AI assistant.
  • Approximate location — for the “what was stolen near me” search on the theft map, and nothing else. The app deliberately does not ask for precise location: the map draws a circle of at least a kilometre and published theft coordinates are rounded to roughly a 500-metre grid, so a precise fix would add nothing. Your position is used to run that one search and then discarded. It is not stored on the phone, attached to a report, or sent anywhere else.
  • Photos — the app has no permission to read your photo library. When you attach a photo, your phone’s own photo picker shows you your gallery and hands us only the images you selected. Before a photo is stored we remove the metadata a camera writes into the file, including the coordinates of where it was taken.
What the app stores on your phoneWhyCleared when
Your sign-in tokenSo you are not asked to sign in again every time you open the appYou sign out, or uninstall the app
An anonymous keyIdentifies your installation to the assistant when you have no account, so it can hold a conversation and count a fair allowance. It is issued and signed by our server, is not an advertising identifier, and is not shared with anyoneYou clear the app’s storage, or uninstall the app
Your language, theme and app settingsSo the app opens the way you left it — including the city you last looked at on the map and your voice preferencesYou clear the app’s storage, or uninstall the app

10. Analytics and tracking in the app

The app includes Google Firebase Analytics and it is switched off. Collection is disabled in the app itself, so it gathers nothing on installation, nothing on first launch, and nothing while you use it. Should we ever turn analytics on, it will be behind a choice you make first — the same standard as the cookie banner on the website — and this statement will say so before it happens.

The app contains no advertising SDK, no advertising identifier, and no cross-app or cross-site tracking. We do not sell personal data and we do not share it with data brokers.

Signing out of the app clears your session, the browser storage of any CarTrace page opened inside the app, and the reports it was holding in memory.

11. Your content & public listings

Some things you submit are, by design, shown to others: a stolen-vehicle listing and its photos are publicly searchable so the community can help recover the vehicle. Do not include personal data you don't want to be public in free-text fields or photos.

When you delete your account, your stolen-vehicle listings are deleted with it, together with their photos and the sightings and messages attached to them, and they stop being shown anywhere on CarTrace. The photo files themselves are deleted from our storage shortly afterwards. Published statistics are aggregated and never contained your personal data, so they are not affected. We keep only what the law requires us to keep (for example payment records and invoices), with the link to your account removed.

12. Security & breach notification

We protect your data with TLS encryption in transit, encrypted storage, hashed passwords, access controls and regular security testing.

If a personal-data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority without undue delay and, where the risk is high, inform you directly.

13. Children

CarTrace is intended for users aged 18 and over. We do not knowingly collect data from minors.

14. Changes & contact

We may update this statement and will notify you of material changes. For any privacy matter, contact info@cartrace.nl.