Privacy Policy — CarRoster

Last updated: 11 September 2026.

This English version is provided for convenience. In the event of any discrepancy, the Slovenian version is authoritative for Slovenian customers and data subjects.


1. Controller and contact details

The controller for personal data processed via the carroster.net website and CarRoster user accounts is:

Nik Šimenc
Globočnikova ulica 9, 1000 Ljubljana, Slovenija
Email: niksimenc@gmail.com

(referred to below as “CarRoster”, “we” or “the controller”)

CarRoster is operated by a natural person, not a registered company. For all day-to-day matters — including requests to exercise your rights under Section 13 — please write to info@carroster.net, which reaches the same person and is monitored as the service’s contact address.


2. Who this policy covers

This privacy policy applies to:

  • visitors to the carroster.net website;
  • anyone who contacts us at info@carroster.net or otherwise reaches out to us;
  • holders of CarRoster user accounts (owners, admins, drivers and viewers within a customer organisation using CarRoster).

This policy does not apply to a customer’s employees who appear in the system as vehicle holders, drivers on a trip, or in damage descriptions, but who do not hold their own user account. For those individuals, the controller is the customer organisation itself, which is responsible for informing them under Article 14 GDPR through its own employee privacy notice. The relationship between CarRoster and the customer regarding this data is governed by a separate Data Processing Agreement (DPA), not this document.


3. Our role: controller or processor

CarRoster acts in two distinct roles, depending on the type of data:

As a processor, we handle all of a customer’s fleet data: vehicle holder names, trips, reservations, damage reports, photographs, expenses and service records. We process this data solely on the customer’s instructions; the customer is its controller and decides who is entered into the system, for what purpose, and for how long. The details of this processing (security measures, sub-processors, retention periods, and each party’s rights and obligations) are set out in the DPA we sign with every customer.

As a controller, we handle a narrower set of our own data:

  • account and login data for user account holders (email address, password, role, two-factor authentication);
  • website visitor data;
  • data from people who contact us at info@carroster.net.

The rest of this document describes our role as controller. For our role as processor, see the DPA.


4. What personal data we process

4.1 Account and login data

When a user account is created (by invitation from your organisation), we process:

  • name, email address, department and role (owner, admin, driver or viewer), as set by your organisation at the time of invitation;
  • password — stored only as a cryptographic hash (bcrypt), never in readable form, and never visible to us either;
  • sign-in metadata: last sign-in time, email confirmation status;
  • for owners and admins specifically: an enrolled two-factor authentication (TOTP) factor — the underlying secret is held by our authentication provider, not visible to us;
  • basic authentication-provider log entries, which may include an IP address at sign-in or password change — this is the only place IP addresses are retained, and it is done by our infrastructure provider, not by us directly.

New public sign-up is not available — access to CarRoster is by invitation from an existing customer only.

4.2 Vehicle and trip data

As part of the service (acting as processor for the customer), the system records: who checked out a vehicle, their department, checkout/check-in dates and odometer readings, fuel level, and any free-text notes. This section is informational — the legal basis and responsibility for this data rests with the customer, see Section 3.

4.3 Damage reports and photographs

When a vehicle damage report is filed, the system records the date, the location of the damage on a vehicle diagram, the type and a free-text description, and optionally a photograph. Photographs are stored in a private, access-restricted location and are not publicly accessible.

4.4 Expenses and service records

Expense type, amount, date, free-text notes and the associated vehicle and department are recorded.

4.5 Activity / audit log

For certain sensitive actions (e.g. changing a user’s role, revoking access, deleting a department), the system automatically keeps a log of who performed the action, what was done, and when. Entries cannot be edited or deleted through the application by anyone, including the organisation’s owner — the log exists solely for accountability and traceability.

There is one exception, and it is the only one: if you delete your account, your name is removed from the entries you yourself made and replaced by a neutral placeholder. The entries are not deleted and are not otherwise altered — what was done, and when, remains recorded. See “Deleting your account” in Section 10.

4.6 Technical data and error reports

If the application encounters an error, a technical report is automatically sent (the type of error and where it occurred). These reports are sent by two separately-configured integrations — one for the web application and one for the mobile application — which report to two separate projects at the same provider (see Section 8).

Both are deliberately configured to exclude your IP address and your identity, and to redact anything that looks like an email address before the report leaves your device or browser. The redaction covers slightly different parts of the report in each of the two: in the web application it is applied both to the error message and to the accompanying exception text, in the mobile application to the error message. What is excluded is the same in substance in both.


For data where we act as controller (see Section 3), we process personal data on the following legal bases:

  • performance of a contract (Art. 6(1)(b) GDPR) — to create and manage your user account and provide the service;
  • legitimate interest (Art. 6(1)(f) GDPR) — to keep the system secure, prevent misuse, and respond to enquiries sent to info@carroster.net.

For fleet data (trips, reservations, damage reports), where we act as processor, the legal basis and purpose are determined by the customer as controller of that data, consistent with their own employee notice. The usual basis for this kind of processing is the customer’s legitimate interest in administering its vehicle fleet (e.g. tracking who has which vehicle, recording damage) — without location tracking or surveillance, see Section 6.

We do not rely on consent as a legal basis for processing data about a customer’s employees, since consent given within an employment relationship is generally not freely given and is therefore not an appropriate basis.


6. What CarRoster does not do

We call this out deliberately, because for many readers it is the most important part of this policy:

  • We do not use GPS tracking. There is no GPS functionality, no in-vehicle tracking device, and neither app requests location permission.
  • We do not carry out covert driver surveillance. Checkout and check-in are recorded by the driver themselves — the tool is designed for coordination, not monitoring.
  • We do not profile users and do not carry out automated decision-making with legal or similarly significant effects on individuals (Art. 22 GDPR).
  • We do not show advertising, and we do not sell or share personal data with third parties for their own marketing purposes.
  • We do not use analytics or advertising cookies — see Section 12.

7. Who has access to data

Access within an organisation is restricted by user role (owner, admin, driver, viewer), and these restrictions are enforced directly at the database level, not only in the user interface — so a user cannot see or edit more than their role allows, even if they attempted to bypass the application itself.

Data belonging to one customer organisation is technically fully isolated from every other organisation using CarRoster — cross-organisation access is not possible.

CarRoster staff do not have routine access to your data; we may access it exceptionally, in the context of support, at your request, or where necessary to resolve a technical issue.

To be precise about what that leaves behind: interventions that change something are recorded in the activity log described in Section 4.5, together with who performed them and when. Reading data without changing it is not separately recorded in that log, so we do not claim that every act of viewing is traceable after the fact.


8. Sub-processors and international transfers

We use the following sub-processors to provide the service:

Provider Role Where data is located
Supabase, Inc. (US) Database, authentication, file storage EU — Frankfurt, Germany (confirmed)
Vercel, Inc. (US) Website and app hosting Global edge network — no fleet data passes through Vercel (see note below)
Cloudflare, Inc. (US) DNS and encrypted backup storage Eastern Europe (Cloudflare R2 “EEUR” region)
Functional Software, Inc. (Sentry) (US) Technical error monitoring EU (Germany)
GitHub, Inc. / Microsoft (US) Runs the automated nightly backup job EU/global; data passes through the runner only in encrypted form
Resend (smtp.resend.com) Sign-up, confirmation and password-reset email EU — Ireland (eu-west-1)

Note on Vercel. Vercel delivers only the application’s static files (HTML, JavaScript, CSS). The application then communicates directly from your browser with Supabase in Frankfurt, so no fleet data passes through Vercel at any point. As a content delivery network, Vercel answers each request from whichever of its points of presence is closest to the visitor, so there is no single storage location to state — and the regional setting Vercel offers applies to server-side code, of which this deployment runs none. What Vercel does necessarily process is the connection metadata inherent in serving any web request: IP address and browser identification, for delivery and abuse prevention.

All listed providers are US-headquartered; data is processed and stored in the locations stated above. Two of those entries need qualifying rather than reading as EU guarantees: Vercel has no single location, for the reason given in the note; and Cloudflare’s Eastern Europe region is a placement preference, not a contractual commitment that data remains within the EU. For transfers of personal data to third countries or to providers based outside the EU, we rely on Standard Contractual Clauses (SCCs) as provided for under GDPR, and we maintain a data processing agreement with each provider.

This list may change over time; we will notify you of any material change to our sub-processors.


9. Where data is stored

Our primary database and file storage are located in a data centre in Frankfurt, Germany (EU). Backups are stored encrypted, separately from the primary database, in Cloudflare’s Eastern Europe (“EEUR”) region.


10. Retention periods

The retention periods in the table below are provisional: they are not yet finalised, we are settling them with legal and accounting advice, and this policy will be updated when they are. What follows the table — how account deletion works, and the limitation noted at the end — is not provisional: it describes what the application does today.

Data Proposed retention
Trips and active checkouts 12–24 months after the trip ends
Reservations Short-term — deleted on conversion to a trip or on expiry
Damage reports and photographs For the vehicle’s service life in the fleet, plus a defined period after disposal
Service records For the vehicle’s service life, plus a defined period
Expenses Per statutory Slovenian accounting retention rules
Activity log 12 months
Account data Until the account is deleted — by you, from within the application, or by us at your request
Backups 14 days (automatic)

Deleting your account

If you hold your own user account, you can delete it yourself at any time, from within the application: Settings → Delete my account. There is no waiting period, and you do not need to contact us. Deletion requires you to be signed in and to re-confirm your password; if you are an admin or an owner, it also requires your second factor — so that only the person actually using the account can remove it.

When you do, the following happens:

  • Removed immediately: your sign-in credentials, your profile record, every signed-in session on every device, and any two-factor enrolment.
  • Anonymised: the entries you made in your organisation’s activity log stop naming you — your name is replaced by a neutral placeholder, while what was done and when it happened remains recorded.
  • Retained: trips, reservations, damage reports, expenses and service records. These record a driver’s or holder’s name as free text rather than as a link to your account, and they belong to your organisation as controller, not to you — see Section 2.

The one case in which deletion is refused: you are the only owner of an organisation that still has other members. An organisation cannot be left without an owner, so the deletion does not proceed and you are asked to appoint another owner first. If you are the organisation’s only remaining member, deletion does proceed; the organisation itself is left standing but without members, because its records belong to the organisation and removing them is not a decision this function makes on anyone’s behalf.

Revocation is not deletion. When an organisation’s owner revokes a member’s access, that member immediately loses access to the organisation’s data, but their account record itself continues to exist until they delete it themselves or ask us to delete it.

An important limitation we disclose honestly: deletion of an account, as described above, is fully automated. Deletion of individual records on request — a particular damage report or photograph, for example — is not, and requires manual action on our part. Similarly, the separate photo backup copy currently has no automatic expiry. We will address both before making any broader promise of on-request record deletion as described in Section 13.


11. Security measures

We apply the following measures, all of which have actually been verified:

  • all traffic is encrypted in transit (HTTPS), with additional security headers that block a range of common web attacks;
  • each organisation’s data is technically isolated from every other organisation’s data at the database level;
  • access is restricted by user role, enforced at the database level, not only in the user interface;
  • two-factor authentication is mandatory for organisation owners and admins, and is re-checked during an active session, not only at sign-in;
  • the most sensitive actions (role changes, revoking access, deleting a department) additionally require a completed two-factor authentication challenge — a stolen access token alone is not sufficient;
  • the sensitive-action activity log can only be written by the system itself; no user, including an organisation’s owner, can edit or delete it;
  • photographs are stored in a private location, accessible only via short-lived, purpose-generated links, and are restricted to appropriate image formats and file sizes;
  • passwords are hashed (bcrypt) and never accessible in readable form, even to us;
  • backups are encrypted before leaving the execution environment and stored separately from the primary database, so that a failure or deletion of the main system does not also compromise the backup.

12. Cookies and local storage

The carroster.net website uses no cookies and loads nothing from third parties (fonts are self-hosted on our own infrastructure).

The app.carroster.net application stores only the following in your browser:

  • whether you selected “remember me”;
  • your sign-in session (required for login to function);

the mobile app stores locally on your device only your own preferences (language, theme, currency, whether you’ve read notifications) and your “remember me” choice.

None of this is used for analytics or advertising, so under applicable e-privacy rules (the Slovenian ZEKom-2) this storage does not require your consent — it is either strictly necessary for the service to function, or a preference you chose yourself.


13. Your rights

Regarding data for which we act as controller (see Section 3), you have the right to:

  • access your personal data (Art. 15 GDPR);
  • rectification of inaccurate data (Art. 16);
  • erasure of your data, where this does not conflict with other obligations (Art. 17). If you hold your own user account, you can delete it yourself at any time, immediately and without contacting us — see “Deleting your account” in Section 10, which also sets out what is removed, what is anonymised and what your organisation keeps. Erasure of individual fleet records is a separate matter and is still handled manually; see the limitation noted at the end of Section 10;
  • restriction of processing in certain cases (Art. 18);
  • data portability in a structured format (Art. 20);
  • object to processing based on legitimate interest (Art. 21);
  • to be informed that we do not carry out automated decision-making with legal effects (Art. 22).

If you are an employee of a CarRoster customer and do not hold your own user account, please contact your employer (the customer) directly to exercise your rights, as they are the controller of your trip data — see Section 2.


14. How to exercise your rights, and our response time

Send your request to info@carroster.net. We will respond within one month at the latest; where a request is complex or we receive a high volume of requests, this may be extended by up to two further months, and we will inform you of this — with reasons — within the first month (Art. 12(3) GDPR).


15. Data breaches

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within the statutory deadline (generally 72 hours of becoming aware of it), and will notify you directly where the risk is high.


16. Children

CarRoster is a business service intended for companies and their employees. It is not directed at children, and we do not knowingly collect data about anyone under 18.


17. Changes to this policy

We may update this policy from time to time, for example due to changes in the service or in applicable law. The date of the last change is shown at the top of this document. We will notify you of material changes by email or via a notice within the application.


18. Complaint to the Slovenian Information Commissioner

If you believe that the processing of your personal data violates data protection law, you have the right to lodge a complaint with:

Informacijski pooblaščenec Republike Slovenije (Information Commissioner of the Republic of Slovenia) Dunajska cesta 22, 1000 Ljubljana, Slovenia Phone: +386 1 230 97 30 Email: gp.ip@ip-rs.si Website: www.ip-rs.si

Before lodging a complaint, we would appreciate the opportunity to resolve the matter directly — please write to us at info@carroster.net.