Privacy Policy
This Privacy Policy explains how ColossAuto ("we", "us", "the app") collects, uses, and protects your personal data when you use our mobile application. ColossAuto is operated by Valerii Raikovskyi, a private individual residing in Vilnius, Lithuania (the "data controller").
We comply with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and applicable Lithuanian data protection law.
1. Data we collect
1.1. Information you provide
- Account data: email address, password (stored as a salted hash by Firebase Authentication, never in plaintext), display name, and email verification status (whether you have confirmed your address).
- Service listings (if you are a service owner): business name, address, phone number, working hours, service categories, photos, description.
- User-generated content: chat messages with other users, reviews you leave on services, replies from service owners.
- Photos you submit — taken with your device camera (we request the camera permission) or selected from your photo library (we request the photo library permission). Photos are used only for service listings you choose to publish.
1.2. Information collected automatically
- Approximate or precise location (only when you grant permission) — used to show nearby auto services on the map and to enable distance-based search.
- Push notification token issued by Firebase Cloud Messaging — required to deliver chat and announcement notifications.
- Crash reports and diagnostics via Firebase Crashlytics — anonymized stack traces, device model, OS version, ColossAuto version.
- Photos you choose to upload for service listings — stored in Firebase Storage.
We do not collect advertising identifiers (we explicitly opt out of Android's AD_ID permission). We do not track you across third-party apps or websites.
2. How we use your data
- Authentication and account management — to let you sign in, recover your password, verify your email.
- Core functionality — to show services on the map, deliver chat messages, publish your reviews, allow service owners to manage their listings.
- Push notifications — to alert you about new chat messages, replies to your reviews, moderation results, or platform announcements.
- Service improvement — to fix bugs (via Crashlytics) and understand which features are used.
- Safety and moderation — to review service listings before they go public and to handle reports of inappropriate content.
3. Legal basis for processing (GDPR Article 6)
- Contract (Art. 6(1)(b)) — account data, service listings, chat messages: needed to provide the service you signed up for.
- Consent (Art. 6(1)(a)) — precise location, photos: only used when you grant permission. You can revoke at any time in system settings.
- Legitimate interest (Art. 6(1)(f)) — crash reporting, diagnostics, anti-abuse moderation: needed to keep the app stable and safe.
4. Who we share data with
We do not sell your personal data. We share data only with the following processors strictly for service operation:
- Google / Firebase (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Messaging, Crashlytics, Cloud Functions) — backend infrastructure. Data is processed in Google's EU data centers (Firebase project region: europe-west1, Belgium).
- Google Maps Platform (Google Maps SDK, Places API) — used to render the map and to look up service addresses. When you view the map, your approximate location is sent to Google to display map tiles and to compute distance-based search. Operates under Google's own privacy policy.
- Apple — for Sign in with Apple (if you choose this method) and Apple Push Notification service (for iOS push delivery).
- Google Sign-In — if you choose to sign in with your Google account.
These processors operate under their own privacy policies and are bound by data processing agreements that meet GDPR requirements.
Other ColossAuto users see only what you choose to publish — your display name in chat and reviews, public service listings (if you are an owner).
5. International data transfers
Your data is primarily stored in the European Union (Google's europe-west1 region, Belgium). Some operational data (e.g. crash reports) may be transferred to the United States by Google and Apple under Standard Contractual Clauses and the EU-US Data Privacy Framework.
6. How long we keep your data
- Account data: until you delete your account.
- Service listings: until you delete them or delete your account.
- Chat messages: you can remove a conversation from your chat list at any time; messages are permanently deleted when your account or your conversation partner's account is deleted.
- Reviews: remain published until you delete them individually. If you delete your account, your reviews stay but are anonymized — your name is replaced with "Deleted user" — to keep service ratings fair for other users.
- Crash reports: retained by Firebase Crashlytics for 90 days (default).
- Push notification token: regenerated whenever you reinstall the app; cleared from our database and topic subscriptions when you sign out or delete your account.
- Audit logs of moderation actions: retained for legal compliance up to 3 years.
7. Your rights under GDPR
As a data subject, you have the right to:
- Access your data — request a copy of what we store about you.
- Rectify incorrect data — edit your profile and listings directly in the app, or write to us.
- Erase your data ("right to be forgotten") — delete your account in the app (Account → Delete account) or via our web deletion request page. You can also delete some of your data without closing your account — remove individual reviews, favourites or inbox items, or delete a whole conversation, all in the app — or email us for anything else.
- Restrict processing — ask us to pause certain uses of your data.
- Data portability — request your data in machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent at any time for processing based on consent.
- Lodge a complaint with the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt).
To exercise any of these rights, email collosadmin@gmail.com. We respond within 30 days as required by GDPR.
8. Security
We protect your data through:
- HTTPS / TLS encryption for all data in transit.
- Encryption at rest in Firebase storage and Firestore.
- Firebase App Check — Play Integrity (Android) and App Attest (iOS) to prevent abuse by unauthorized clients.
- Server-side authorization rules (Firestore Security Rules) — every read and write is checked against your authentication state.
- Password hashing — passwords are never stored in plaintext; Firebase Authentication uses industry-standard hashing.
9. Children
ColossAuto is not directed at anyone under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy occasionally. Material changes will be announced in the app and via push notification at least 14 days before taking effect. The "Last updated" date at the top reflects the current version.
11. Contact
Data controller: Valerii Raikovskyi, Vilnius, Lithuania.
Email: collosadmin@gmail.com