Privacy Policy
Effective date: 2026-09-08
Last updated: 2026-09-08
Version: 3.2
Controller: Carsu B.V., Harderwijkerweg 145, 3852 AB Ermelo, The Netherlands (KvK 92122167).
Group company: Carsu Italia S.r.l., Via Fabro 8, 10122 Torino, Italy (REA TO-1365449, P.IVA / C.F. 13468500015), a wholly owned subsidiary of Carsu B.V. (see §1a).
Privacy contact: privacy@carsu.com
1. Who this applies to
Carsu B.V. ("Carsu", "we") operates a SaaS platform for the automotive aftermarket. This policy explains how we process personal data, in compliance with the GDPR, UK GDPR, the ePrivacy Directive, and applicable national data-protection law. It applies to:
- Platform users (workshop owners and their staff), whether they use the web platform or the Carsu mobile app;
- End customers of those workshops whose data is processed via our platform, including when they request an appointment through a booking widget that a workshop has placed on its own website;
- Business contacts whose details we hold for our own marketing, whether they signed up on our website, gave us their details at an event or in a business relationship, or are on a list we obtained lawfully from another source;
- Website visitors at www.carsu.com and app.carsu.com.
1a. Carsu Italia S.r.l.
Carsu B.V. has one operating subsidiary, Carsu Italia S.r.l. (Turin, Italy), which employs and engages part of our development, support and customer-facing team. Carsu Italia processes personal data in two capacities:
- On behalf of Carsu B.V. Carsu Italia's staff and contractors develop, operate and support the platform and may access personal data held by Carsu B.V. for that purpose. In this capacity Carsu Italia acts as a processor for Carsu B.V. under an intra-group data processing agreement (Art. 28 GDPR), with the same security and confidentiality obligations as any other sub-processor (§7.1). No transfer outside the EEA is involved.
- As your contracting party. Where your order form, subscription confirmation or invoice names Carsu Italia S.r.l. as the contracting entity (typically for workshops in Italy), Carsu Italia is the Controller of your account, billing and payment data in place of Carsu B.V., and the Processor of your end-customers' data under the Data Processing Agreement in the Terms and Conditions. This policy applies unchanged, with "Carsu" meaning Carsu Italia S.r.l. for that data. The competent supervisory authority for Carsu Italia is the Italian Garante per la protezione dei dati personali (§17).
Carsu B.V. and Carsu Italia S.r.l. share the same platform, the same sub-processors and the same privacy contact (privacy@carsu.com). Data is not "transferred" between them in any way that changes where it is stored or who can see it; both operate on the same EEA infrastructure under the same access controls. Any other subsidiary, affiliate or group company of Carsu B.V. that processes personal data in connection with our services adheres to this policy.
2. Our role
| Activity | Carsu's role | Legal basis |
|---|---|---|
| Platform account, billing, payments | Controller | Contract (Art. 6(1)(b)) |
| End-consumer data processed via the platform, including the booking widget and stored customer property (tyre hotel) | Processor (workshop is Controller) | Workshop's basis |
| Messages sent to end-consumers (WhatsApp, SMS, Viber) | Processor | Workshop's basis |
| Invoices and fiscal reports transmitted to tax authorities on the workshop's behalf | Processor | Workshop's legal obligation |
| Google Calendar data synced via OAuth at your election | Controller | Consent (Art. 6(1)(a)) and contract (Art. 6(1)(b)) |
| Mobile app usage, push notifications and analytics | Controller | Contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) |
| Our own marketing to platform users | Controller | Consent given at sign-up (Art. 6(1)(a)) |
| Our own marketing to business contacts | Controller | Consent or legitimate interest (see §6) |
| Website analytics and cookies | Controller | Consent / legitimate interest |
Where Carsu acts as Processor, the workshop remains responsible for the lawfulness of its processing, including obtaining any required consents.
3. Data we process
From you or the workshop: name, email, phone, business name, VAT, billing address, licence plate, vehicle details, service history, appointments, messages, photographs of vehicles and work performed, records of customer property held in storage (for example seasonal tyres), payment identifiers (card details go directly to Stripe, we don't store them).
From Google APIs, with your OAuth consent (optional calendar sync): calendar events you choose to import from your Google Calendar, including event title, start and end time, location, description, attendee email addresses, and recurrence patterns. We access this data only through Google's API using the calendar.events.readonly scope. We never receive your Google password and we never write events back to your Google Calendar. You may disconnect the integration at any time (see §8 and §11).
From public registers and verification services: where a workshop issues an invoice to a business customer in another EU country, we check the customer's VAT number against the EU VIES service and keep the response as audit evidence. Where a national scheme requires it, we may look up vehicle details by registration number in an official vehicle register.
From business contacts: name, email, company, country, language, the source of the contact, and the consent basis and evidence on which we hold it (see §6).
Collected automatically: IP address, device and browser data, pages visited, feature usage, session duration, cookies (see §10). In the mobile app: app version, operating system version, and a device push-notification token (see §5b). In newsletters: whether a link in the email was clicked.
4. Legal bases
We rely on contract (Art. 6(1)(b)) to deliver the service, legitimate interest (Art. 6(1)(f)) for security, fraud prevention, product improvement, service communications, and marketing to business contacts as described in §6, consent (Art. 6(1)(a)) for marketing to platform users, non-essential cookies, and optional third-party integrations such as Google Calendar sync, and legal obligation (Art. 6(1)(c)) for tax, accounting, fiscal reporting, and law-enforcement requests.
5. How we use data
To run and improve the platform; to process payments; to send messages on behalf of workshops; to issue invoices and, where a workshop is subject to a national e-invoicing or fiscal-reporting scheme, to transmit invoice data to the competent tax authority on the workshop's behalf; to synchronise and display your Google Calendar events on the Carsu calendar page (where you have authorised this); to provide support (including AI-assisted translation via Intercom, which does not use your data to train its models); to generate anonymised aggregated insights (§7.4); to ensure security and prevent fraud; to meet legal obligations; and, on the bases described in §6, for our own marketing.
AI use. Our AI features (Intercom translation; Anthropic for de-identified operational use) do not produce legal or similarly significant effects on you, and do not amount to automated decision-making under Art. 22 GDPR. We classify our AI use as minimal risk under the EU AI Act. You can opt out of AI-assisted translation by emailing support@carsu.com. Data obtained from Google APIs is excluded from all AI and machine-learning processing (see §5a).
5a. Google API Services User Data Policy: Limited Use
Carsu's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google Calendar data only to provide and improve the calendar-sync feature visible to you in the Carsu platform. We do not:
- Transfer Google user data to third parties except as necessary to provide or improve user-facing features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with your prior notice;
- Use Google user data for serving advertisements, including retargeting, personalised, or interest-based advertising;
- Sell Google user data to third parties, data brokers, or information resellers;
- Use Google user data to develop, improve, or train generalised or non-personalised artificial-intelligence or machine-learning models.
Human access to Google user data is restricted to (a) cases where we have obtained your specific consent to view specific messages, files, or events; (b) where required for security investigations, abuse prevention, or to comply with applicable law; (c) where the data has been aggregated and anonymised for internal operations in line with this Policy; or (d) where required to provide customer support with your explicit request.
5b. The Carsu mobile app
Carsu offers an Android and iOS app for workshop staff. It signs you in with the same Carsu account as the web platform and shows the same data your workshop already holds: jobs, vehicles, customers and messages. In addition to what is described elsewhere in this Policy, the app can:
- Use the camera, only when you choose to photograph a vehicle or scan a number plate. Photographs you take are attached to the job or vehicle you chose and are stored with the rest of your workshop's data. Plate scanning runs on the device; the camera image is not sent anywhere.
- Read a photo you pick from your photo library, only when you choose to attach one to a job. The app does not browse or upload your library.
- Send push notifications to your device, for example when a job is assigned to you or a job you are working on needs your attention. To do this the app registers a device token with Apple (APNs) or Google (FCM) and we store that token against your account. Notifications never contain a number plate, a customer's name or a phone number. You can turn notifications off in your device settings at any time, and the token is deregistered when you sign out.
- Send product-analytics events (which screens are used, how long actions take) to our own servers and on to Mixpanel in the EU, linked to your Carsu user ID. They never include number plates, names, phone numbers or customer details. You can turn this off at any time in Settings → Privacy → Share usage data.
The app does not access your location, contacts, calendar or microphone, does not use advertising identifiers, and stores nothing on the device beyond a sign-in token, your settings, and a temporary cache of your workshop's data that is cleared when you sign out. Photos are re-encoded before upload so that camera metadata, including location, is removed.
Sign-in to the app uses the same identity provider as the web platform (Clerk, see §7.1). Signing in with Apple or Google is available as a convenience and gives us only the name and email address that you allow the provider to share.
6. Communications
Service messages. Service-related messages (security alerts, billing, terms changes, and notifications about activity in your workshop account) are sent on the basis of contract or legitimate interest and cannot be opted out of, except that push notifications in the mobile app can be disabled in your device settings.
Marketing to platform users. When you create a Carsu account we ask whether you want to receive product news, tips and offers about Carsu's own services. We send them only if you said yes (consent, Art. 6(1)(a)), and we keep a record of when and how you agreed. Every such email contains an unsubscribe link, unsubscribing takes effect immediately, and you can change your choice at any time in your account settings or by emailing privacy@carsu.com.
Marketing to business contacts. We also send our newsletter to business contacts in the automotive aftermarket who are not yet Carsu users. We hold each contact on one of the following bases, recorded per contact together with its source and date: (a) your consent, for example when you subscribed on our website or at an event; (b) an existing business relationship with Carsu B.V.; or (c) our legitimate interest in contacting a business in the automotive aftermarket about a service relevant to that business, where we have balanced that interest against your rights and the message is clearly related to your professional role. Where we hold a contact on basis (c), we do not send anything until a compliance review has confirmed the basis, and where we cannot confirm a basis we either ask you for permission first or do not contact you at all.
Your choices. Every marketing email contains an unsubscribe link. You can also object to any marketing by emailing privacy@carsu.com. An unsubscribe or objection is recorded on a suppression list and cannot be overridden by a later list import or re-subscription on our side; only you can re-subscribe. We do not send marketing over WhatsApp or SMS to platform users or business contacts unless you have separately opted in to that channel.
Measurement. We record whether a marketing email was delivered, bounced or generated a complaint, and whether a link in it was clicked (we do not use open-tracking pixels), so that we can stop sending to addresses that do not work and understand which content is useful. We do not use this information to build individual profiles.
7. Data sharing
7.1 Sub-processors
We use the following sub-processors under GDPR Art. 28 Data Processing Agreements:
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud infrastructure, file and photo storage | EU (West Europe / North Europe) |
| Carsu Italia S.r.l. (group company) | Software development, platform operations, support and customer management on behalf of Carsu B.V. | EU (Italy) |
| Clerk | Identity provider: sign-in, sessions, multi-factor authentication for the web platform and mobile app | US (SCC) |
| Stripe | Payments | EU / US (SCC) |
| WhatsApp Business API (Meta) | Messaging | EU / US (SCC) |
| Viber (Rakuten) | Messaging | EU / International (SCC) |
| Twilio | SMS gateway | EU / US (SCC) |
| Resend | Transactional and marketing email delivery | EU |
| Apple Inc. | Push notification delivery to iOS devices (APNs); Sign in with Apple | US (SCC) |
| Google LLC | Push notification delivery to Android devices (FCM) | EU / US (SCC) |
| Intercom | Support & AI translation | US (SCC) |
| Anthropic | AI services (de-identified data) | US (SCC) |
| Mixpanel | In-app and mobile product analytics | EU (EU data residency) |
| Cloudflare | CDN, bot mitigation | EU / Global edge (SCC) |
| Google Ireland Ltd. | Website analytics (GA4, GTM) | EU / US (SCC) |
| Microsoft Ireland Operations Ltd. | Website UX analytics (Clarity) | EU / US (SCC) |
| Meta Platforms Ireland Ltd. | Advertising measurement (Meta Pixel) | EU / US (SCC) |
| LinkedIn Ireland Unlimited Company | Advertising measurement (LinkedIn Insight Tag) | EU / US (SCC) |
Google LLC is also an upstream data source (not a sub-processor) when you authorise the optional Google Calendar integration. Data flows from Google to Carsu under your OAuth consent and is governed by §3, §5, and §5a of this Policy. Calendar data is not transferred to any of the sub-processors listed above, and the push-notification role of Google LLC above involves only device tokens and notification content, never calendar data.
7.2 Sub-processor changes
We notify platform users at least 30 days before engaging or replacing a sub-processor. Objection rights are set out in the DPA in our Terms and Conditions (Annex A, §A5).
7.3 Other recipients
We may share personal data with professional advisors under confidentiality obligations, with law enforcement where legally required, and in connection with a merger or acquisition (with prior notice).
Tax authorities and fiscal intermediaries. Where a workshop is subject to a national e-invoicing or fiscal-reporting obligation (currently Spain's Verifactu, Italy's Sistema di Interscambio, Greece's myDATA and Digital Client List, and Poland's KSeF as each is enabled), we transmit the invoice or report data the law requires, which may include the name, tax identifier and address of the workshop's customer and the vehicle registration number, to the competent authority on the workshop's behalf, directly or through a certified e-invoicing intermediary established in the EU; the intermediaries we currently use per country are listed on request at privacy@carsu.com. The workshop remains the issuer of the invoice and the Controller of that data. VAT numbers of business customers are checked against the EU VIES service, which returns the registered name and address held by the member state.
7.4 Anonymised insights
We may share irreversibly anonymised, aggregated insights with industry partners. Recipients are contractually prohibited from attempting re-identification. Because such data is outside the scope of GDPR (Recital 26), it is not a transfer of personal data. Data obtained from Google APIs is excluded from anonymised insights under our Limited Use commitment (§5a).
We do not sell personal data.
8. Your rights
You have the rights to access, rectification, erasure, restriction, portability, objection, and to withdraw consent at any time, without affecting the lawfulness of prior processing. Email privacy@carsu.com to exercise them. We will verify your identity and respond within 30 days (extendable by two months for complex requests).
Deleting your account. You can delete your Carsu account yourself from Settings → My Account on the web platform, or Settings → Delete account in the mobile app. Your account is deactivated immediately, you are signed out everywhere, and you no longer appear anywhere in your workshop. If you sign in again within 12 months, your account is restored; after 12 months your identity data is permanently deleted. Records your workshop must keep by law, such as invoices, payments and audit entries, are retained; your name is removed from them once the 12-month window has ended. Workshop owners and administrators must first hand their role to another member, because deleting them would leave nobody able to manage the workshop's billing, members or subscription.
If a workshop processes your data through our platform, your primary contact is the workshop (as Controller). We will assist them in handling your request. Where a workshop still holds property of yours in storage (for example seasonal tyres) at the time you ask for erasure, the workshop may need to keep the minimum record that links the stored items to you until they are returned or lawfully disposed of; we support the workshop in anonymising everything else.
Business contacts. If we hold your details for marketing, you can ask us at any time which basis we rely on and where we obtained them, and you can object; we will stop and add you to our suppression list.
Google Calendar integration: revocation and deletion. You can revoke Carsu's access to your Google account at any time by either (a) disconnecting the integration from within your Carsu account settings, or (b) removing the Carsu app from your Google account at myaccount.google.com/permissions. Revocation immediately stops further synchronisation. Calendar event data already cached on our servers is deleted within 30 days of disconnection (see §11). To request immediate deletion, email privacy@carsu.com.
9. International transfers
Our primary infrastructure is in the EEA. Where data is transferred outside the EEA or UK, we rely on the Standard Contractual Clauses (Decision 2021/914) or the UK IDTA/Addendum, supplemented by encryption (TLS 1.2+ in transit, AES-256 at rest) and transfer impact assessments. EU–UK transfers rely on the UK adequacy decision (renewed July 2025). You can request a copy of the applicable SCCs from privacy@carsu.com.
10. Cookies and analytics
Website. Cookies on www.carsu.com are described in our Cookie Policy. The booking widget that a workshop may embed on its own website sets only a strictly necessary session cookie and no analytics or marketing cookies.
In-app. When signed into the Carsu platform we use a session cookie, a CSRF protection cookie, and a language preference (all strictly necessary). We use Mixpanel for product analytics on the web platform and in the mobile app on the basis of legitimate interest (Art. 6(1)(f)). You can turn analytics off in the mobile app at any time under Settings → Privacy → Share usage data; on the web platform, or to have past events deleted, email privacy@carsu.com and we will stop collection and delete associated records within 30 days.
11. Retention
| Data | Retention | Reason |
|---|---|---|
| Account and profile data | Subscription + 12 months | Service provision and export window |
| Deactivated user identity (name, email, phone at our identity provider) | 12 months after deletion request | Reactivation window; then permanently deleted |
| Billing and invoices | 7 years (10 years where Italian law requires) | Dutch / Italian tax law |
| Fiscal transmissions and clearance receipts | Same as the invoice they relate to | Statutory evidence of transmission |
| Vehicle and service data | Subscription + 12 months | Service provision |
| Photographs attached to jobs and vehicles | Same as the job or vehicle record they are attached to | Service provision, evidence of work performed |
| Stored customer property records (tyre hotel) | Until the items are returned, transferred or disposed of, + 12 months | Custody evidence, disputes |
| Communication logs | 24 months | Service delivery, disputes |
| Support tickets | 36 months | Quality assurance |
| Synced Google Calendar events | Duration of active sync + 30 days after disconnection or account deletion | Service provision; Limited Use compliance |
| Google OAuth tokens | Until you disconnect the integration or revoke access at myaccount.google.com | Required to maintain the sync you authorised |
| Mobile push-notification tokens | Until you sign out, uninstall the app, or the token is reported invalid | Notification delivery |
| Mobile and web analytics events | 24 months | Product improvement |
| Newsletter delivery and click records | 24 months | List hygiene, measurement |
| Analytics cookies | Up to 13 months | Website improvement |
| Marketing cookies | Up to 12 months | Advertising measurement |
| Marketing consent records and suppression list | Consent + 3 years; suppression entries indefinitely | Proof of consent; honouring your objection |
After retention we delete or irreversibly anonymise the data. Google API data is deleted, not anonymised, in line with our Limited Use commitment.
12. Security
We apply technical and organisational measures under GDPR Art. 32, including encryption in transit and at rest, role-based access control with least privilege, MFA for all admin and platform access, regular vulnerability assessments, access logging, and documented incident response. We are working toward SOC 2 Type II and ISO 27001. Responsible vulnerability disclosure: security.txt or security@carsu.com.
OAuth tokens for Google API access are stored encrypted at rest and are accessible only to the platform components that perform the calendar sync. Photographs and documents are stored in private storage and served only through short-lived signed links to signed-in users of the workshop they belong to.
13. Data breaches
Where a breach is likely to result in a risk to your rights, we notify the supervisory authority within 72 hours (Art. 33) and, where the risk is high, you directly without undue delay (Art. 34). Where Carsu acts as Processor, we notify the Controller (workshop) without undue delay.
14. UK residents
UK residents have the same rights as described in §8. Transfers between the EU and UK rely on the EU adequacy decision for the UK (renewed July 2025, valid until 2031). Where UK data protection law conflicts with this policy for UK residents, UK law prevails.
15. Children
Our services are B2B and are not directed at children. We do not knowingly collect data from individuals under 16 (or under 14 in Italy, per D.Lgs. 101/2018). If we discover such data, we delete it promptly.
16. Changes
We update this policy when our practices, technology, or legal obligations change. Material changes are notified by email or in-platform at least 30 days in advance.
17. Complaints
You can complain to the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), the lead supervisory authority for Carsu B.V. under the GDPR one-stop-shop, to the Italian Garante per la protezione dei dati personali (garanteprivacy.it) where Carsu Italia S.r.l. is your contracting party, or to the data protection authority in your EU country of residence. We'd prefer you contact us first at privacy@carsu.com so we can try to resolve your concern directly.
18. Related documents
This policy should be read alongside our Terms and Conditions (including the Data Processing Agreement in Annex A) and our Cookie Policy.
19. Contact
Privacy: privacy@carsu.com
Legal: legal@carsu.com
Security: security@carsu.com
General: hello@carsu.com
Post: Carsu B.V., Harderwijkerweg 145, 3852 AB Ermelo, The Netherlands
Italy: Carsu Italia S.r.l., Via Fabro 8, 10122 Torino, Italy; PEC carsu.italia@pec.it