Privacy Policy

Last updated: July 2026 · Version 1.1

1. Introduction

This Privacy Policy explains how Revorra (“we”, “us”, “our”) collects, uses, stores, shares, and protects your personal data when you use the Revorra platform (website, APIs, and associated services).

Legal Framework

This policy is drafted in compliance with:

  • Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR);
  • Romanian Law No. 190/2018 implementing GDPR;
  • Directive 2002/58/EC — ePrivacy Directive as transposed in Romania;
  • Regulation (EU) 2022/2065 — Digital Services Act where applicable;
  • Romanian Law No. 506/2004 on personal data processing in electronic communications.

Supervisory Authority

The competent supervisory authority is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania — www.dataprotection.ro

2. Data We Collect

2.1 Account Data (Provided by You)

DataPurposeLawful Basis
First name, last nameAccount identification, displayContract (Art. 6(1)(b))
Email addressAuthentication, communication, verificationContract (Art. 6(1)(b))
UsernamePublic identity on PlatformContract (Art. 6(1)(b))
Password (BCrypt hashed)AuthenticationContract (Art. 6(1)(b))
Bio, avatar imageProfile personalisationConsent (Art. 6(1)(a))
Location (city, general)Localisation, content relevanceConsent (Art. 6(1)(a))
Social media linksProfile enrichment (optional)Consent (Art. 6(1)(a))
OAuth2 provider dataSimplified registrationConsent (Art. 6(1)(a))

2.2 Garage / Vehicle Data

DataPurposeLawful Basis
Make, model, year, colourGarage displayContract
Engine specs (HP, torque, transmission)Community featuresContract
Mileage, body typeVehicle descriptorsContract
VIN (optional)Vehicle identificationConsent
Vehicle images, modificationsDisplay & communityContract

VINs may constitute personal data if linkable to an identified owner. Provision is voluntary — do not share publicly if you wish to maintain privacy.

2.3 Social Interaction Data

Posts, comments, likes, follows, group membership and roles, group join requests, post views, and reports — processed under Contract or Legitimate Interest (Art. 6(1)(f)).

2.4 Event Data

Event creation data (title, description, location, date/time, type, visibility), participation status, and invitations — processed under Contract.

2.5 Business Account Data

Business name, slug, description, logo, cover image, contact details, address, category, verification status, member roles, and invitations — processed under Contract.

2.6 Technical and Security Data

DataPurposeLawful Basis
IP addressSecurity, abuse prevention, rate limitingLegitimate interest
User agentSecurity, session trackingLegitimate interest
Session data (login/logout)Session management, securityLegitimate interest
Rate limiting dataAbuse preventionLegitimate interest
Honeypot interaction dataBot detectionLegitimate interest
Account reputation scorePlatform integrityLegitimate interest

2.7 Image Metadata

SHA-256 hash (deduplication), image category, upload source, user ID, and timestamps. Images are processed into three variants (thumbnail 300px, medium 800px, full 1200px) in WebP format. Originals are not retained after processing.

2.8 Analytics and Observability Data

Analytics events (pseudonymised), abuse logs, application performance metrics, structured logs, and distributed traces — processed under Legitimate Interest or Consent for non-essential analytics.

Where third-party analytics tools are used, data is anonymised or pseudonymised before transmission. See Section 5 for details.

3. How We Use Your Data

PurposeLegal Basis
Provide and maintain the PlatformContract
Authentication and securityContract + Legitimate interest
Email verification and password resetContract
Social features, garage, events, business directoryContract
Communication (notifications, email)Contract + Consent
Content moderation and abuse preventionLegitimate interest
Platform improvement and analyticsLegitimate interest (balancing test applied)
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interest we have conducted a balancing test and concluded processing is proportionate and does not override your fundamental rights. You may object at any time (see Section 7).

3.1 Public Content & Search Engine Visibility

Revorra is a community platform: some of your content is publicly visible, including to visitors without an account, and may be indexed by search engines (e.g. Google) so it can appear in search results:

  • your profile (name, username, avatar, bio, city and country — never your email address or exact GPS coordinates);
  • your garage / builds (cars, photos, modifications, descriptions);
  • public events you create and business pages & reviews;
  • public posts and comments shown on those pages.

What is never public:

  • your email address, precise location and account settings;
  • private events — invitation-only, never listed publicly and never in sitemaps;
  • private group content — members-only.

Interacting (posting, commenting, liking, joining) always requires an account. When you delete content or your account, the public pages are removed; search engines may keep cached copies for a short period until they re-crawl.

4. Data Retention

CategoryRetention
Account dataDuration of account + 30-day grace period
Posts, comments, likesDuration of account (deletable by user)
Business account dataDuration + 6 months
Event data12 months after event (then anonymised)
Session / login records6 months
Secure tokensUntil used or max 24 hours
Email task / audit logs12 months
IP addresses (rate limiting)24 hours (in memory)
Abuse event logs24 months
Analytics events24 months (then aggregated/anonymised)
Observability (logs / traces / metrics)30 days / 7 days / 15 days
Reports24 months after resolution

Deletion Process

  1. Account enters a 30-day grace period (reactivatable);
  2. After 30 days, personal data is permanently deleted or anonymised;
  3. Content shared/reposted by others may persist in anonymised form;
  4. Backup copies are purged within 90 days;
  5. Data subject to legal hold is retained until the obligation expires.

5. Third-Party Data Sharing

5.1 Data Processors

ProcessorPurposeData SharedSafeguard
AWSCloud hosting, SES emailAll Platform dataDPA, SCCs, EU region
PostHogProduct analyticsPseudonymised eventsDPA, EU cloud
OAuth2 ProvidersAuthenticationEmail, nameProvider DPA, consent
OpenStreetMapMap tilesIP addressPseudonymised

5.2 International Transfers

Where data is transferred outside the EU/EEA we rely on adequacy decisions, Standard Contractual Clauses (EU 2021/914), and supplementary measures (encryption, pseudonymisation, access controls) following EDPB recommendations.

5.3 We Do Not

  • Sell your personal data to third parties;
  • Share data for third-party direct marketing without explicit consent;
  • Use automated decision-making with legal effects without notification and the right to object.

6. Data Security

Technical Measures

MeasureImplementation
Encryption in transitTLS 1.2+ for all connections
Password securityBCrypt hashing
Token securityJWT with expiration; SHA-256 hashed secure tokens
Rate limitingPer-action, per-IP, per-email, global limits
Bot detectionHoneypot fields
Access controlRole-based (platform + business roles)
MonitoringPrometheus, Grafana, structured logging, tracing
Abuse detectionReputation scoring, abuse event logging

Organisational Measures

  • Access restricted to authorised personnel on a need-to-know basis;
  • Confidentiality obligations for all personnel;
  • Regular security reviews and vulnerability assessments;
  • Documented incident response procedures;
  • Employee training on data protection.

7. Your Rights

Under GDPR you have the following rights:

7.1 Right of Access (Art. 15)

Request confirmation of whether we process your data and obtain a copy in electronic format. Timeline: within 30 days.

7.2 Right to Rectification (Art. 16)

Correct inaccurate or incomplete data — most data can be corrected directly through Account settings.

7.3 Right to Erasure (Art. 17)

Request deletion where data is no longer necessary, you withdraw consent, you object and no overriding grounds exist, or data was unlawfully processed. Exceptions apply for legal compliance and defence of claims.

7.4 Right to Restriction (Art. 18)

Request restricted processing while accuracy is verified, when processing is unlawful, or while we verify legitimate grounds after your objection.

7.5 Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format (JSON) and transmit it to another controller. Scope includes account data, garage data, posts, events, and group memberships.

7.6 Right to Object (Art. 21)

Object to processing based on legitimate interest at any time. For direct marketing — we stop immediately.

7.7 Automated Decision-Making (Art. 22)

We do not make decisions based solely on automated processing that produce legal effects. Automated systems (e.g. abuse detection) include human review.

7.8 Withdraw Consent

Where processing is based on consent you may withdraw at any time via Account settings, notification preferences, or cookie settings.

How to Exercise Your Rights

  • Self-service: Account settings (profile editing, notification preferences, data download, account deletion);
  • Email: [email protected];
  • Mail: Revorra, Attn: Data Protection Officer.

We verify your identity before processing. Requests are handled within 30 calendar days, extendable by up to 60 days for complex requests (with notification).

8. Data Breach Procedure

  • Supervisory authority: Notified within 72 hours unless the breach is unlikely to result in risk (Art. 33 GDPR);
  • Data subjects: Notified without undue delay when high risk exists (Art. 34 GDPR) via email and in-app notification;
  • Documentation: All breaches are recorded in our internal register.

9. Children’s Data

The Platform is not directed at children under 16. We do not knowingly collect data from children under 16. In Romania the age of digital consent under GDPR is 16 (Law No. 190/2018, Art. 8). Users aged 16–18 may use the Platform but cannot engage in Marketplace transactions.

10. Changes to This Policy

Material changes are communicated via email, in-app notice, and an update to the “Last Updated” date. We encourage you to review this policy periodically.

11. Contact Us

Data Protection Officer[email protected]
General inquiries[email protected]
Supervisory AuthorityANSPDCP, B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest

This Privacy Policy is available in Romanian upon request. The Romanian version shall prevail for Users domiciled in Romania in case of discrepancy.

Related Policies