Privacy Policy
Last updated: July 2026 · Version 1.1
1. Introduction
This Privacy Policy explains how Revorra (“we”, “us”, “our”) collects, uses, stores, shares, and protects your personal data when you use the Revorra platform (website, APIs, and associated services).
Legal Framework
This policy is drafted in compliance with:
- Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR);
- Romanian Law No. 190/2018 implementing GDPR;
- Directive 2002/58/EC — ePrivacy Directive as transposed in Romania;
- Regulation (EU) 2022/2065 — Digital Services Act where applicable;
- Romanian Law No. 506/2004 on personal data processing in electronic communications.
Supervisory Authority
The competent supervisory authority is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania — www.dataprotection.ro
2. Data We Collect
2.1 Account Data (Provided by You)
| Data | Purpose | Lawful Basis |
|---|---|---|
| First name, last name | Account identification, display | Contract (Art. 6(1)(b)) |
| Email address | Authentication, communication, verification | Contract (Art. 6(1)(b)) |
| Username | Public identity on Platform | Contract (Art. 6(1)(b)) |
| Password (BCrypt hashed) | Authentication | Contract (Art. 6(1)(b)) |
| Bio, avatar image | Profile personalisation | Consent (Art. 6(1)(a)) |
| Location (city, general) | Localisation, content relevance | Consent (Art. 6(1)(a)) |
| Social media links | Profile enrichment (optional) | Consent (Art. 6(1)(a)) |
| OAuth2 provider data | Simplified registration | Consent (Art. 6(1)(a)) |
2.2 Garage / Vehicle Data
| Data | Purpose | Lawful Basis |
|---|---|---|
| Make, model, year, colour | Garage display | Contract |
| Engine specs (HP, torque, transmission) | Community features | Contract |
| Mileage, body type | Vehicle descriptors | Contract |
| VIN (optional) | Vehicle identification | Consent |
| Vehicle images, modifications | Display & community | Contract |
VINs may constitute personal data if linkable to an identified owner. Provision is voluntary — do not share publicly if you wish to maintain privacy.
2.3 Social Interaction Data
Posts, comments, likes, follows, group membership and roles, group join requests, post views, and reports — processed under Contract or Legitimate Interest (Art. 6(1)(f)).
2.4 Event Data
Event creation data (title, description, location, date/time, type, visibility), participation status, and invitations — processed under Contract.
2.5 Business Account Data
Business name, slug, description, logo, cover image, contact details, address, category, verification status, member roles, and invitations — processed under Contract.
2.6 Technical and Security Data
| Data | Purpose | Lawful Basis |
|---|---|---|
| IP address | Security, abuse prevention, rate limiting | Legitimate interest |
| User agent | Security, session tracking | Legitimate interest |
| Session data (login/logout) | Session management, security | Legitimate interest |
| Rate limiting data | Abuse prevention | Legitimate interest |
| Honeypot interaction data | Bot detection | Legitimate interest |
| Account reputation score | Platform integrity | Legitimate interest |
2.7 Image Metadata
SHA-256 hash (deduplication), image category, upload source, user ID, and timestamps. Images are processed into three variants (thumbnail 300px, medium 800px, full 1200px) in WebP format. Originals are not retained after processing.
2.8 Analytics and Observability Data
Analytics events (pseudonymised), abuse logs, application performance metrics, structured logs, and distributed traces — processed under Legitimate Interest or Consent for non-essential analytics.
Where third-party analytics tools are used, data is anonymised or pseudonymised before transmission. See Section 5 for details.
3. How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Provide and maintain the Platform | Contract |
| Authentication and security | Contract + Legitimate interest |
| Email verification and password reset | Contract |
| Social features, garage, events, business directory | Contract |
| Communication (notifications, email) | Contract + Consent |
| Content moderation and abuse prevention | Legitimate interest |
| Platform improvement and analytics | Legitimate interest (balancing test applied) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interest we have conducted a balancing test and concluded processing is proportionate and does not override your fundamental rights. You may object at any time (see Section 7).
3.1 Public Content & Search Engine Visibility
Revorra is a community platform: some of your content is publicly visible, including to visitors without an account, and may be indexed by search engines (e.g. Google) so it can appear in search results:
- your profile (name, username, avatar, bio, city and country — never your email address or exact GPS coordinates);
- your garage / builds (cars, photos, modifications, descriptions);
- public events you create and business pages & reviews;
- public posts and comments shown on those pages.
What is never public:
- your email address, precise location and account settings;
- private events — invitation-only, never listed publicly and never in sitemaps;
- private group content — members-only.
Interacting (posting, commenting, liking, joining) always requires an account. When you delete content or your account, the public pages are removed; search engines may keep cached copies for a short period until they re-crawl.
4. Data Retention
| Category | Retention |
|---|---|
| Account data | Duration of account + 30-day grace period |
| Posts, comments, likes | Duration of account (deletable by user) |
| Business account data | Duration + 6 months |
| Event data | 12 months after event (then anonymised) |
| Session / login records | 6 months |
| Secure tokens | Until used or max 24 hours |
| Email task / audit logs | 12 months |
| IP addresses (rate limiting) | 24 hours (in memory) |
| Abuse event logs | 24 months |
| Analytics events | 24 months (then aggregated/anonymised) |
| Observability (logs / traces / metrics) | 30 days / 7 days / 15 days |
| Reports | 24 months after resolution |
Deletion Process
- Account enters a 30-day grace period (reactivatable);
- After 30 days, personal data is permanently deleted or anonymised;
- Content shared/reposted by others may persist in anonymised form;
- Backup copies are purged within 90 days;
- Data subject to legal hold is retained until the obligation expires.
5. Third-Party Data Sharing
5.1 Data Processors
| Processor | Purpose | Data Shared | Safeguard |
|---|---|---|---|
| AWS | Cloud hosting, SES email | All Platform data | DPA, SCCs, EU region |
| PostHog | Product analytics | Pseudonymised events | DPA, EU cloud |
| OAuth2 Providers | Authentication | Email, name | Provider DPA, consent |
| OpenStreetMap | Map tiles | IP address | Pseudonymised |
5.2 International Transfers
Where data is transferred outside the EU/EEA we rely on adequacy decisions, Standard Contractual Clauses (EU 2021/914), and supplementary measures (encryption, pseudonymisation, access controls) following EDPB recommendations.
5.3 We Do Not
- Sell your personal data to third parties;
- Share data for third-party direct marketing without explicit consent;
- Use automated decision-making with legal effects without notification and the right to object.
6. Data Security
Technical Measures
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all connections |
| Password security | BCrypt hashing |
| Token security | JWT with expiration; SHA-256 hashed secure tokens |
| Rate limiting | Per-action, per-IP, per-email, global limits |
| Bot detection | Honeypot fields |
| Access control | Role-based (platform + business roles) |
| Monitoring | Prometheus, Grafana, structured logging, tracing |
| Abuse detection | Reputation scoring, abuse event logging |
Organisational Measures
- Access restricted to authorised personnel on a need-to-know basis;
- Confidentiality obligations for all personnel;
- Regular security reviews and vulnerability assessments;
- Documented incident response procedures;
- Employee training on data protection.
7. Your Rights
Under GDPR you have the following rights:
7.1 Right of Access (Art. 15)
Request confirmation of whether we process your data and obtain a copy in electronic format. Timeline: within 30 days.
7.2 Right to Rectification (Art. 16)
Correct inaccurate or incomplete data — most data can be corrected directly through Account settings.
7.3 Right to Erasure (Art. 17)
Request deletion where data is no longer necessary, you withdraw consent, you object and no overriding grounds exist, or data was unlawfully processed. Exceptions apply for legal compliance and defence of claims.
7.4 Right to Restriction (Art. 18)
Request restricted processing while accuracy is verified, when processing is unlawful, or while we verify legitimate grounds after your objection.
7.5 Right to Portability (Art. 20)
Receive your data in a structured, machine-readable format (JSON) and transmit it to another controller. Scope includes account data, garage data, posts, events, and group memberships.
7.6 Right to Object (Art. 21)
Object to processing based on legitimate interest at any time. For direct marketing — we stop immediately.
7.7 Automated Decision-Making (Art. 22)
We do not make decisions based solely on automated processing that produce legal effects. Automated systems (e.g. abuse detection) include human review.
7.8 Withdraw Consent
Where processing is based on consent you may withdraw at any time via Account settings, notification preferences, or cookie settings.
How to Exercise Your Rights
- Self-service: Account settings (profile editing, notification preferences, data download, account deletion);
- Email: [email protected];
- Mail: Revorra, Attn: Data Protection Officer.
We verify your identity before processing. Requests are handled within 30 calendar days, extendable by up to 60 days for complex requests (with notification).
8. Data Breach Procedure
- Supervisory authority: Notified within 72 hours unless the breach is unlikely to result in risk (Art. 33 GDPR);
- Data subjects: Notified without undue delay when high risk exists (Art. 34 GDPR) via email and in-app notification;
- Documentation: All breaches are recorded in our internal register.
9. Children’s Data
The Platform is not directed at children under 16. We do not knowingly collect data from children under 16. In Romania the age of digital consent under GDPR is 16 (Law No. 190/2018, Art. 8). Users aged 16–18 may use the Platform but cannot engage in Marketplace transactions.
10. Changes to This Policy
Material changes are communicated via email, in-app notice, and an update to the “Last Updated” date. We encourage you to review this policy periodically.
11. Contact Us
| Data Protection Officer | [email protected] |
| General inquiries | [email protected] |
| Supervisory Authority | ANSPDCP, B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest |
This Privacy Policy is available in Romanian upon request. The Romanian version shall prevail for Users domiciled in Romania in case of discrepancy.



