Skip to content
Shiny-Cars

Privacy Policy

Note: This privacy policy must be reviewed by a lawyer before launch.

1. Data Controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) is:

Shiny-Cars Fahrzeugaufbereitung

[Placeholder for Barisch's full name]

Industriestraße 1E

24558 Henstedt-Ulzburg, Germany

Email: info@shiny-cars.eu

Phone: 04193 / 968 15 66

2. Hosting

Our website is hosted by Vercel Inc. When you visit our website, information (e.g., IP address, time of access, browser used) is automatically transmitted to Vercel's servers and stored in server log files.

Provider: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. An EU Commission adequacy decision (Data Privacy Framework) is in place.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and efficient provision of the website).

3. Firebase Services (Google)

We use various Google Firebase services to provide our website functionality.

Cloud Firestore

We use Cloud Firestore as a database to store website content, services, customer reviews, and contact inquiries.

Firebase Authentication

Firebase Authentication is used exclusively for administrative access (login). No customer data is processed through Firebase Auth.

Firebase Storage

Firebase Storage is used to store and serve images (e.g., before/after photos, gallery).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest) and Art. 6(1)(b) GDPR (contract fulfillment for contact inquiries).

Firebase Privacy Information: https://firebase.google.com/support/privacy

4. Instagram Graph API

We embed content from our Instagram profile on our website via the Instagram Graph API (Meta Platforms).

Instagram posts and media are loaded in the process. It is possible that Meta may collect your IP address and browser data.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in displaying our social media content).

5. Cal.com (Appointment Booking)

We use Cal.com for online appointment booking. When booking, the data you enter (name, email, phone number, desired appointment) is transmitted to Cal.com.

Data processing takes place on servers within the EU or in compliance with the GDPR.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in efficient appointment management).

6. Google Maps

We plan to integrate Google Maps to display our location. Data will be transmitted to Google LLC, including your IP address.

Legal basis: Art. 6(1)(a) GDPR (consent).

[Placeholder – will be updated before launch once Google Maps is integrated.]

7. Google Analytics

We plan to use Google Analytics in the future to analyze user behavior on our website. Google Analytics uses cookies and transmits the generated information to Google servers in the USA.

Legal basis: Art. 6(1)(a) GDPR (consent via cookie banner).

[Placeholder – will be updated before launch once Google Analytics is integrated.]

8. Meta Pixel (Facebook Pixel)

We plan to use Meta Pixel in the future to measure the effectiveness of our advertisements. Meta Pixel sets cookies and transmits data to Meta Platforms.

Legal basis: Art. 6(1)(a) GDPR (consent via cookie banner).

[Placeholder – will be updated before launch once Meta Pixel is integrated.]

9. Contact Form

When you contact us via the contact form, the data you provide is processed and stored to handle your inquiry.

Data collected: name, email address, phone number (optional), message, desired service. The data is stored in Firebase Firestore.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries).

10. Data Subject Rights

You have the following rights under the GDPR regarding your personal data:

  • Right of access (Art. 15 GDPR) – You can request information about your data stored with us.
  • Right to rectification (Art. 16 GDPR) – You can request the correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR) – You can request the deletion of your data, provided no legal retention obligations exist.
  • Right to restriction of processing (Art. 18 GDPR) – You can request the restriction of processing of your data.
  • Right to data portability (Art. 20 GDPR) – You can receive your data in a commonly used format.
  • Right to object (Art. 21 GDPR) – You can object to the processing of your data at any time.
  • Right to withdraw consent – If you have given consent, you can withdraw it at any time.
  • Right to lodge a complaint with a supervisory authority – You have the right to lodge a complaint with a data protection supervisory authority.

11. Cookies

Our website uses cookies. Cookies are small text files stored on your device.

We use technically necessary cookies for the operation of the website (e.g., language selection). Analytics and marketing cookies are only set with your explicit consent.

Legal basis: Art. 6(1)(f) GDPR (technically necessary cookies) and Art. 6(1)(a) GDPR (consent for optional cookies).

12. Changes to this Privacy Policy

We reserve the right to update this privacy policy to adapt it to changed legal situations or changes to our website. The current version always applies.