Privacy policy
Last updated: 30 June 2026
1. Who we are
Automotive data report is a subscription analytics platform operated by AutoBrief (“AutoBrief”, “we”, “us”, “our”). AutoBrief is the controller of the personal data described in this policy.
For any privacy question, or to exercise your rights, contact us at info@autobrief.io.
2. Scope of this policy
This policy explains what personal data we process when you visit the website, create an account, subscribe and use the report, and what your rights are. It does not cover third-party websites we link to, which have their own policies.
3. Data we process
- Account data you provide: first name, last name, business email address and company name.
- Authentication and security data: a one-way bcrypt hash of your password (we never store the password itself) and a secret used for mandatory two-factor authentication (TOTP).
- Subscription and billing data: your role, chosen plan (monthly or annual), the date your access is valid until, and a Stripe customer identifier. Card numbers are entered directly into Stripe and are never seen or stored by us.
- Session and technical data: an opaque random session token stored in the adria_session cookie, your cookie-consent choice, and standard server logs (IP address, browser/user-agent, requested pages and timestamps).
- Communications: transactional emails we send you (welcome, password reset, admin invitations) and any messages you send us.
4. How we collect data
- Directly from you, when you register, subscribe or contact us.
- Automatically, through strictly necessary cookies and server logs when you use the site.
- From our payment processor (Stripe), which tells us your payment and subscription status through a verified webhook.
5. Why we process data and the legal basis
- To provide the service — create and secure your account, authenticate you and give access to the report (Art. 6(1)(b) GDPR, performance of a contract).
- To take payment and manage your subscription via Stripe (Art. 6(1)(b), performance of a contract).
- To meet legal obligations such as accounting and tax records (Art. 6(1)(c), legal obligation).
- To keep the platform secure, prevent abuse and improve the product (Art. 6(1)(f), legitimate interests).
- To load optional analytics — only where you have given consent (Art. 6(1)(a), consent), which you may withdraw at any time.
6. Payments
Payments are processed by Stripe. Your card details are entered into a secure form served by Stripe and sent directly to Stripe; we never receive or store your full card number. Stripe is PCI-DSS certified and acts as a processor and independent controller for payment data. See Stripe's privacy policy at stripe.com/privacy.
7. Cookies
We use a small set of first-party cookies that are essential to sign-in and to remember your cookie choice, and — only with your consent — optional analytics cookies. When the payment step loads, Stripe also sets its own fraud-prevention cookies. Full details, names and lifetimes are in our cookie policy.
8. Who we share data with
- Stripe — payment processing.
- Our cloud hosting provider (Amazon Web Services, EU region) — running the platform and database.
- Our email delivery (SMTP) provider — sending transactional emails.
- An analytics provider — only if you accept analytics cookies.
- Authorities or professional advisers — where required by law.
- We do not sell your personal data and do not use it for third-party advertising.
9. International transfers
We host data in the European Union wherever possible. Where a processor transfers data outside the EU/EEA (for example Stripe), the transfer is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10. How long we keep data
- Account data: for as long as your account exists.
- Session tokens: expire 30 days after sign-in, or immediately when you sign out.
- Password-reset links: expire within one hour.
- Payment-event records: kept as required for accounting and reconciliation, then pruned.
- After account deletion: we keep a hashed form of your email address to prevent re-registration and to meet legal obligations; all other personal data is deleted or anonymised.
11. How we protect data
Passwords are stored only as salted bcrypt hashes, two-factor authentication (TOTP) is mandatory, and sessions are opaque server-side tokens held in httpOnly, SameSite cookies (marked Secure in production). Traffic is encrypted in transit with TLS, and access to systems is limited to authorised personnel.
12. Your rights
Under the GDPR you have the right to access your data, to rectification, to erasure (“right to be forgotten”), to restriction of processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent at any time without affecting processing carried out beforehand.
To exercise any of these rights, email info@autobrief.io; we respond within one month. You may also lodge a complaint with your national supervisory authority — in Slovenia the Information Commissioner (ip-rs.si), in Croatia the Personal Data Protection Agency (AZOP, azop.hr).
13. Children
Automotive data report is a professional, business-to-business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
14. Changes to this policy
We may update this policy as the service evolves or the law changes. We will post the new version here with an updated date and, for material changes, notify account holders by email.