Privacy Policy
Last updated: 16 June 2026
1. Introduction
This Privacy Policy explains how Carpture (“we”, “us”, “our”) collects, uses, stores, and protects your personal data when you use the Carpture mobile application (the “App”). It also explains your rights under applicable data protection law.
The App is available worldwide. Where you are located in the United Kingdom or European Economic Area, this policy reflects our obligations under the UK GDPR, the Data Protection Act 2018, and — where applicable — the EU GDPR. Users in other jurisdictions may have additional rights under local law; we aim to meet a high standard globally.
2. Data Controller
The data controller for your personal data is:
Carpture
United Kingdom
Email: support@carpture.app
If you have any questions about this policy or how we handle your data, please contact us at the address above.
3. Data We Collect
3.1 Account Data
When you register, we collect:
- Email address
- Password (stored as a hashed credential; we never store plaintext passwords)
Authentication is handled via Supabase, which processes your credentials securely on our behalf.
3.2 Profile Data
When creating your account, you are required to provide a username. After registration, you may optionally add:
- Profile image
3.3 User-Generated Content
When you use the App's core features, we collect and store:
- Spot posts: location (the city or area name is displayed on the spot card), predefined tags (e.g. sand, industrial), car make tag, and associated images
- Additional images added to existing spots, including a car make tag
- Forum threads: text content and/or up to five images per thread
- Comments on spots and threads
- Likes and saves on spots, threads, and comments
- Follow relationships between users
3.4 Location Data
We collect location data in two ways:
- Manual location tagging: when creating a spot or searching, you may type or select a location using Google Places Autocomplete. The resulting coordinates are stored as part of the spot record.
- Device GPS: if you grant the App permission to access your device's location, you may choose to use your current coordinates to sort spots by proximity or to set your current location when creating a spot. These are optional features you must actively select. We do not continuously track or store your GPS coordinates; they are used only in-session for the purposes described.
Location permission is optional. You may deny or revoke it at any time via your device settings. Doing so will not prevent you from using the App, but proximity-based features will be unavailable.
3.5 Image Data
Images you upload are processed client-side before transmission. Specifically:
- Images are re-encoded to WebP format and resized before upload.
- This re-encoding process does not preserve EXIF metadata (including any GPS coordinates, device identifiers, or timestamps embedded in the original file).
The original filename from your device is retained and stored alongside the image. If your device generates filenames that include personal information (such as a date or location), that information may be stored. We recommend being aware of this. We retain filenames on the basis of legitimate interests, as they assist with technical support and content management. We intend to implement automatic filename sanitisation at upload in a future update.
Processed images are stored securely on our cloud infrastructure.
3.6 Notification Data
We store in-app notification records on our servers. These record events such as likes, saves, comments, and follows directed at your content. Notifications are displayed within the App only. We do not currently send push notifications to your device, and we do not store device push tokens.
3.7 Crash and Diagnostic Data
We use Sentry for crash reporting. When the App crashes or encounters an error, Sentry may collect:
- Device type and operating system version
- App version
- Stack traces and error logs
- A Sentry-assigned device identifier
We configure Sentry to minimise personal data collection. Crash reports do not intentionally include your email address, username, or content. However, error context (e.g. a screen name or action being performed) may be included.
3.8 Advertising Data
We use Google AdMob to serve advertisements within the App. AdMob may collect and process data in accordance with Google's own privacy policy, including:
- Advertising identifiers (IDFA on iOS, GAID on Android)
- IP address
- Device and usage information for ad targeting and measurement
On first launch, we will request your consent before enabling personalised advertising, in accordance with Google's EU User Consent Policy and applicable law. You may withdraw consent or opt out of personalised ads at any time via your device settings (Limit Ad Tracking / Opt out of Ads Personalisation) or through the in-app settings.
Google's privacy policy is available at: https://policies.google.com/privacy
3.9 Usage Data
We do not collect general usage analytics (such as screen views or tap events) beyond what Sentry captures incidentally as part of crash reporting.
4. How We Use Your Data
We use your personal data for the following purposes:
- To create and manage your account
- To enable you to create, view, like, save, and comment on spots and threads
- To display your profile and content to other users
- To enable social features including following, followers, and following counts
- To sort and filter spots by location, proximity, car make, and tags
- To display in-app notifications about activity on your content
- To diagnose technical errors and maintain the stability of the App (via Sentry)
- To serve advertisements within the App (via Google AdMob)
- To comply with legal obligations
5. Legal Basis for Processing (UK/EU GDPR)
We rely on the following legal bases:
- Contract (Article 6(1)(b)): processing necessary to provide you with the App and its features, including account creation, content posting, and social features.
- Consent (Article 6(1)(a)): for access to your device's GPS location; and for personalised advertising via AdMob. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legitimate interests (Article 6(1)(f)): for crash reporting and diagnostic data (including the Sentry-assigned device identifier used to deduplicate crash reports), to maintain a stable and secure App. We have assessed that our interests are not overridden by your rights and freedoms in these cases. You have the right to object to processing carried out on this basis at any time by contacting us at support@carpture.app; we will cease processing unless we can demonstrate compelling legitimate grounds.
- Legal obligation (Article 6(1)(c)): where we are required to process data to comply with applicable law.
We do not carry out solely automated decision-making, including profiling, that produces legal or similarly significant effects on you (Article 22 UK/EU GDPR).
6. Data Sharing and Third-Party Processors
We do not sell your personal data. We share data only with the following categories of third-party processors, each engaged under appropriate contractual terms:
6.1 Infrastructure and Storage
Amazon Web Services (AWS): our cloud infrastructure and hosting provider. AWS infrastructure may be hosted in multiple regions; we rely on AWS's standard contractual clauses for any international transfers.
6.2 Authentication
Supabase: handles user authentication (email/password). Supabase processes your email address and hashed password on our behalf.
6.3 Crash Reporting
Sentry: receives crash and error reports as described in Section 3.7. Data is processed in accordance with Sentry's data processing agreement.
6.4 Advertising
Google AdMob: serves advertisements within the App. Google acts as an independent data controller for data it collects for advertising purposes — not as a processor on our behalf. Please refer to Google's privacy policy for details of their processing.
6.5 Location Search
Google Places API: used to power the location autocomplete search feature. Queries you type into the location search are transmitted to Google's Places API. Google acts as an independent data controller for this processing. Google's privacy policy applies.
6.6 Other Disclosures
We may also disclose personal data where required to do so by law, court order, or regulatory authority; or where necessary to protect the rights, property, or safety of Carpture, our users, or others.
7. International Data Transfers
Some of our third-party processors (including AWS, Sentry, and Google) may process data outside the United Kingdom or European Economic Area. Where this occurs, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office (ICO) or the European Commission
- Adequacy decisions where applicable
You may request further information about the safeguards in place for international transfers by contacting us at support@carpture.app.
8. Data Retention
We retain your personal data only for as long as necessary for the purposes set out in this policy, or as required by law.
- Account data: retained for the duration of your account. Upon account deletion, all data associated with your account is permanently and immediately deleted from our systems.
- Crash reports (Sentry): retained in accordance with Sentry's default retention period (typically 90 days).
- Advertising data (AdMob): retained in accordance with Google's data retention policies.
- Backups: deleted account data may persist in encrypted backups for up to 90 days before being permanently overwritten. We will not use backup data to restore deleted accounts.
9. Your Rights
If you are located in the UK or EEA, you have the following rights under the UK GDPR / EU GDPR:
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): to request deletion of your data in certain circumstances. You may delete your account directly within the App, which will immediately and permanently erase your data.
- Right to restriction: to request that we restrict processing of your data in certain circumstances.
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent (GPS location, personalised ads), you may withdraw it at any time via your device settings or in-app settings.
- Right to lodge a complaint: you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or your local supervisory authority if you are in the EEA. A list of EEA supervisory authorities is available at edpb.europa.eu.
To exercise any of the above rights, please contact us at: support@carpture.app
We will respond to requests within one calendar month. We may need to verify your identity before processing a request.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These measures include:
- Passwords are hashed and never stored in plaintext
- All communication between the App and our servers takes place over HTTPS
- Cloud storage is configured with access controls to prevent unauthorised access
- Authentication tokens are managed by Supabase and subject to their security practices
- Access to production infrastructure is restricted to authorised personnel
No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to maintaining appropriate safeguards.
11. Children
The App is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@carpture.app and we will take steps to delete it promptly.
12. User-Generated Content and Public Visibility
Content you post on Carpture — including spots, images, comments, and threads — is visible to other users of the App. Your username and profile information are associated with your public content. Please be mindful of the information you choose to include in your posts, images, and profile. Once content has been viewed or shared by others, we cannot guarantee its removal from third-party caches, screenshots, or external copies that may have been made.
While we process image files in a way that removes embedded EXIF metadata (including GPS data), the location you manually tag on a spot is stored and displayed publicly as part of that spot.
13. Cookies and Tracking Technologies
The App itself does not use browser cookies. However, third-party SDKs integrated into the App (particularly Google AdMob) may use device-level tracking technologies such as advertising identifiers (IDFA/GAID). You can manage these via your device's privacy settings.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the “Last updated” date at the top of this policy and, where appropriate, by providing notice within the App. Where a material change affects processing that relies on your consent, we will seek fresh consent before that processing begins. Continued use of the App following notification of non-consent-based changes constitutes acknowledgement of the updated policy.
15. Data Protection Officer
We are not currently required to appoint a Data Protection Officer (DPO) under Article 37 of the UK/EU GDPR, as our processing does not meet the thresholds requiring mandatory appointment. Privacy-related queries and data subject requests are handled directly by the controller. Contact details are provided in Section 16 below.
16. Contact
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:
Carpture
support@carpture.app