01Introduction
This Privacy Policy describes how GarageBooks (also referred to as “we”, “GarageBooks”, or the “Platform”) processes the personal data of users who access the website garagebooks.ai and its related services (the “Service”).
This document complies with Regulation (EU) 2016/679 (the “GDPR”) and with Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.
By using the Service you confirm that you have read and understood this Policy. If you do not agree with one or more of its provisions, please do not use the Service.
02Data Controller
The Data Controller is:
- [Ragione Sociale GarageBooks S.r.l.]
- Registered office: [Sede legale – Via, n., CAP, Città, Italia]
- VAT / Tax ID: [P.IVA / C.F. – da inserire]
- Email: privacy@garagebooks.ai
For any request relating to the processing of your personal data (rights, clarifications, complaints), please write to the email address above.
03Categories of personal data processed
Depending on how you use the Service, we may process the following categories of personal data:
- Registration and account data: email address, password (stored encrypted), display name, username, preferred language.
- Profile data: profile picture (avatar), biography, location, favorite car brands, privacy and notification preferences.
- Third-party authentication data: if you sign in with Google OAuth, we receive your email address, full name, and profile picture from Google (scopes:
openid,profile,email). - User-generated content: books added to your collection, uploaded photographs, descriptions, sale listings, messages exchanged with other users, reviews, saved searches, wishlist.
- Transaction data: for subscriptions and AI credit purchases, Stripe Inc. collects payment information (card number, cardholder, billing address). GarageBooks does not store your card data: we receive from Stripe only the customer identifier, subscription status, and receipts.
- P2P marketplace data: for transactions between users via Stripe Connect, Stripe collects the seller’s KYC data (ID document, IBAN, residential/business address). These data are processed by Stripe as an independent controller for anti-money-laundering obligations.
- Navigation and technical data: IP address, user agent, pages visited, action timestamps, session cookies, application and error logs.
- Communication data: content of messages sent to support, emails sent or received through the Service.
04Purposes and legal bases of processing
We process your personal data for the following purposes and on the following legal bases under Article 6 GDPR:
- Provision of the Service (account creation and management, collection management, marketplace, messaging, orders). Legal basis: performance of the contract between you and GarageBooks (Art. 6(1)(b) GDPR).
- Payment and invoicing. Legal basis: contract performance and legal obligations (Art. 6(1)(b) and 6(1)(c) GDPR).
- AI features (cover recognition, price estimation, price research). Images and book metadata are sent to third-party providers (Anthropic, OpenAI) for analysis. Legal basis: performance of the contract at your request (Art. 6(1)(b) GDPR).
- Transactional email notifications (offers received, messages, orders, reviews). Legal basis: contract performance (Art. 6(1)(b) GDPR). You can disable individual categories from your profile settings.
- Service communications (maintenance, changes to Terms or Privacy, security). Legal basis: legitimate interest and legal obligations (Art. 6(1)(f) and 6(1)(c) GDPR).
- Marketing communications (newsletter, product news). Legal basis: your explicit consent, which can be withdrawn at any time (Art. 6(1)(a) GDPR).
- Security, fraud prevention, debugging. Legal basis: legitimate interest of the Controller to protect the Service and its users (Art. 6(1)(f) GDPR).
- Aggregate statistical analysis on user behavior, in anonymous or pseudonymous form. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Compliance with legal obligations (e.g., requests from judicial authorities, retention of tax records). Legal basis: Art. 6(1)(c) GDPR.
05How we process
Data is processed using IT tools, with measures suitable to ensure security, confidentiality, integrity, and availability. Passwords are stored only in hashed form; communications use HTTPS/TLS; system access is limited to authorized personnel.
We do not use your data for automated decision-making with legal effects under Article 22 GDPR. The AI features of the Service (cover recognition, price estimation) are operational aids: the final decision always rests with the user.
06Third-party services and sub-processors
To deliver the Service we rely on the following providers (sub-processors under Article 28 GDPR, with whom a Data Processing Agreement is in place):
- Supabase Inc. (database, authentication, storage, server-side functions). Location: USA / Singapore. Data: account, profile, content, application logs.
- Vercel Inc. (frontend hosting and edge functions). Location: USA. Data: access logs, IP, user agent.
- Stripe Inc. (payments, subscriptions, credit management, Stripe Connect for P2P marketplace, Stripe Tax). Location: USA / Ireland. Data: payment data, seller KYC data.
- Resend Inc. (transactional email delivery). Location: USA. Data: email address, notification content.
- Anthropic PBC (AI models for cover recognition and price research). Location: USA. Data: cover images, book metadata (title, ISBN, brand).
- OpenAI Inc. (legacy fallback AI models). Location: USA. Data: same as above, only for fallback cases.
- Google LLC (Google Books API for metadata enrichment; Google OAuth for optional sign-in). Location: USA. Data: ISBN lookups; for OAuth, basic Google profile.
- Sentry / PostHog (error and product observability, where enabled). Data: error logs, pseudonymized product events.
- Cloudflare / Upstash (rate-limiting, CDN, where enabled). Data: IP, request metadata.
The list is kept up to date. For the current list and the related DPAs, please write to privacy@garagebooks.ai.
07International data transfers
Some of our providers are located in the United States or in other non-EU countries. In such cases the transfer takes place under one of the following safeguards provided by the GDPR:
- Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical and organizational measures.
- EU–U.S. Data Privacy Framework, where the provider has joined it (e.g., Google, Stripe).
We periodically verify our providers’ compliance and update our measures as regulations evolve (e.g., further rulings of the Court of Justice of the European Union).
08Retention periods
We retain personal data only for the time strictly necessary for the purposes for which it was collected, based on the following criteria:
- Account and profile data: for the entire duration of your account. When you delete your account, data is removed within 30 days, except for data subject to mandatory legal retention.
- Public content (listings, reviews issued, public profile): removed when the account is deleted. Reviews issued to other users may be retained in anonymized form so as not to alter the recipient’s reputation.
- Messages: for the entire duration of the account; deleted or anonymized upon account deletion, subject to legal evidence-retention obligations.
- Transaction data and invoices: 10 years as required by Italian tax law (Art. 2220 of the Italian Civil Code).
- Technical access and security logs: maximum 12 months, except where investigations into incidents require longer retention.
- Marketing data: until you withdraw consent or delete your account.
09Your rights
At any time you can exercise the rights granted by Articles 15–22 GDPR:
- Access: obtain confirmation of processing and a copy of your data.
- Rectification: correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”): obtain the deletion of your data, except where retention is mandatory.
- Restriction: request a restriction of processing in specific circumstances.
- Portability: receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Objection: object to processing based on legitimate interest or for direct marketing purposes.
- Withdrawal of consent: withdraw at any time the consents you have granted, without affecting the lawfulness of the processing already carried out.
To exercise these rights you can: (a) use the self-service features available in your profile (data export, account deletion, email preferences management); (b) write to privacy@garagebooks.ai. We will respond within one month of receipt, with a possible extension of two months for particularly complex requests.
You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or with the supervisory authority of the EU Member State in which you habitually reside.
11Data security
We adopt appropriate technical and organizational measures to protect personal data from unauthorized access, loss, alteration, or disclosure. Key measures include:
- In-transit encryption via HTTPS/TLS 1.2+ across all traffic.
- At-rest encryption of databases and storage.
- Secure password hashing (bcrypt or equivalent algorithm).
- System access limited to authorized personnel, with multi-factor authentication.
- Daily encrypted backups.
- Access logging and active monitoring for anomaly detection.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 GDPR, and we will inform the Italian Data Protection Authority within 72 hours of discovery.
12Minors
The Service is intended for users aged 16 or older. We do not knowingly collect personal data from minors under 16. If you become aware that a minor has provided us with personal data without parental consent, please contact us: we will promptly delete the data.
13Changes to this Policy
We may update this Policy at any time to reflect changes to the Service, to applicable law, or to our practices. The current version is always available at garagebooks.ai/en/privacy.
In the event of substantial changes, we will inform you by email or in-app notification before they take effect. The last-updated date is shown at the top of the page.
14Contact
For any questions about this Policy or about the processing of your personal data, you can write to:
- Privacy email: privacy@garagebooks.ai
- General support email: support@garagebooks.ai
- [Ragione Sociale GarageBooks S.r.l.] · [Sede legale – Via, n., CAP, Città, Italia]