Privacy policy
Last updated: 8 September 2026
1. Controller
Thomas Gewinner
Bachstraße 23
55569 Monzingen
Germany
Phone: 0151-27081898
Email: gewinner.thomas@gmail.com
2. Purpose and basic principle of the service
CarNotify allows registered vehicle owners to create a QR code for a vehicle. People who scan this QR code can send a message to the owner. The public scan page does not display the owner's name, address, phone number, email address, license plate or other stored vehicle data.
3. Web hosting
This website is hosted by:
Einzelunternehmen Tom Gewiese
Tom Gewiese
Obernaglbach 2
94259 Kirchberg im Wald
Germany
Email (no support): vertrieb@skrime.eu
Abuse email (no support): mail@threatoff.eu
Phone (no support): +49 160 92595136
Technically required data is processed during hosting in order to deliver the website and to ensure stability and security. Where the hosting provider processes personal data on our behalf, this processing must be arranged in accordance with the GDPR requirements for processors.
4. Server log files
When the website is accessed, server log files may process information such as IP address, date and time, requested resource, transferred data volume, referrer, browser/operating-system information and HTTP status code. This processing serves the secure and stable operation of the website and the detection and prevention of technical attacks. The legal basis is Art. 6(1)(f) GDPR. The specific retention period of hosting logs depends on the hosting provider's server configuration.
5. Registration and user account
Registration currently requires name, street and house number, postal code, city, country, phone number, email address and password, as well as the data of the first vehicle. These details are required to provide the user account, vehicle assignment and service functions. The legal basis is Art. 6(1)(b) GDPR. Passwords are stored only as password hashes and cannot be read in plain text.
6. Vehicle data
Stored vehicle data includes license plate, make, model and color. These details are processed in the protected user and administration areas and are not shown on the public QR scan page. Personal and vehicle details are additionally encrypted in the database by the application.
7. Email verification
A temporary random verification token is created to verify an email address. Only a hash of this token is stored in the database. After successful verification the token is discarded.
8. QR codes and public scan pages
The QR code contains only a URL with a randomly generated public token. Personal owner or vehicle data is not written into the QR code. The QR code can be disabled or renewed in the user area; renewing it invalidates the previous token.
9. Contacting a vehicle owner
A person scanning the code may choose a notification reason and optionally enter a short message and voluntary reply contact. These details are used to create the email to the vehicle owner. To limit abuse, the application also processes a keyed hash derived from the IP address. The plain IP address is not stored in the application's contact-attempt table. Rate-limit data is removed from the application after no more than 30 days.
10. Email delivery
Transactional emails, especially verification, password reset, QR code delivery and owner notifications, are sent via the configured SMTP service at gewinner-cloud.de. Recipient address, sender information and the relevant message content are processed for this purpose. Where the email is required to provide the account or a requested function, the legal basis is Art. 6(1)(b) GDPR.
11. Google reCAPTCHA
Google reCAPTCHA may be used for functions that are particularly vulnerable to abuse, currently including registration, resending a verification email, password reset and notifying a vehicle owner. reCAPTCHA is used solely for security, fraud prevention and abuse prevention.
reCAPTCHA is loaded only after explicit consent. Before consent, no reCAPTCHA script is embedded. When enabled, data such as IP address, browser, device and interaction information and the _GRECAPTCHA cookie may be processed. The legal basis for consent-based processing is Art. 6(1)(a) GDPR; where information is stored on or read from the user's device, this is based on consent under § 25(1) TDDDG.
According to Google's current reCAPTCHA information, Google has classified itself as a processor for reCAPTCHA customer data since 2 April 2026. Responsibility for providing information and integrating the service lawfully remains with the website operator.
12. Cookies, language preference and “stay signed in”
CarNotify uses a technically necessary session cookie so that login, session management and CSRF protection work. A consent cookie stores whether only necessary functions or additionally reCAPTCHA have been allowed. A language preference cookie stores the selected German/English language so that it does not have to be chosen again on every visit.
If the user chooses “Stay signed in”, a persistent authentication cookie valid for up to 30 days is set. The browser stores a random token; the database stores only a cryptographic hash of the secret token part. The token is rotated when it is used and is deleted on logout. This function is only activated when requested by the user.
reCAPTCHA is loaded only after consent. The selection can be changed at any time via “Cookie settings” in the footer. Withdrawal of consent applies to future processing.
13. Local QR code generation
The QR matrix is generated in the logged-in user's browser using a JavaScript library hosted locally on this web server. The QR content is not sent to an external QR generator or external CDN. The generated QR image is then stored on the own web server so it can be displayed again, printed and sent as an email attachment.
14. Legal bases at a glance
- Art. 6(1)(b) GDPR: registration, account management, vehicle management, QR code functionality and necessary transactional emails.
- Art. 6(1)(f) GDPR: secure provision of the website, server logs and necessary technical abuse protection where consent is not required.
- Art. 6(1)(a) GDPR and § 25(1) TDDDG: consent to activate Google reCAPTCHA and related processing or storage/access on the device.
15. Recipients of data
Recipients of personal data may include the hosting provider, the SMTP/email service and Google as reCAPTCHA provider, in each case only where required for the relevant function. The application does not provide for disclosure for advertising purposes.
16. Transfers to third countries
When external service providers are used, processing outside the European Union or European Economic Area cannot always be ruled out. Where a third-country transfer takes place, the requirements of Chapter V GDPR must be observed, in particular an adequacy decision or appropriate safeguards.
17. Retention periods
- Account data: generally until account deletion or for as long as required for the service.
- Vehicle data and QR images: generally until deletion of the vehicle or account.
- Email verification token: normally no more than 24 hours.
- Password reset token: normally no more than 60 minutes.
- Application rate-limit/abuse-protection data: no more than 30 days.
- Session cookie: normally until the browser session ends.
- Language preference cookie: up to 12 months.
- Persistent “stay signed in” token: up to 30 days; removed earlier on logout.
- Consent cookie: up to 180 days or until the selection is changed.
Statutory retention obligations and technically necessary backup cycles remain unaffected where applicable.
18. Data security
The application uses prepared SQL statements, password hashing, CSRF protection, protected sessions, random QR tokens, access controls, rate limits, encrypted sensitive data and hashed persistent-login tokens. Production operation must use HTTPS only. Server, PHP, database and libraries must be kept up to date.
19. Data subject rights
Subject to the statutory requirements, data subjects have rights including access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Consent may be withdrawn at any time for the future under Art. 7(3) GDPR.
20. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. For the controller's place of establishment, the following authority may in particular be relevant:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Hintere Bleiche 34
55116 Mainz
Phone: +49 (0) 6131 8920-0
Email: poststelle@datenschutz.rlp.de
21. Account deletion
Registered users can delete their account in the user area. The account, related vehicle records and stored QR images are removed from the production system and the related QR codes stop working. Statutory retention duties and technically necessary backups remain unaffected where applicable.
22. Changes to this privacy policy
This privacy policy will be updated when functions, service providers, technical processes or the legal situation change.