Privacy Policy
How we collect, use and protect your personal data
Version 1.0 — Effective 12 May 2026
1. About this policy
CarStats is a paid subscription service that helps users discover and track collector-car price trends. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have.
We collect the data necessary to operate and improve the Service. We never sell or rent your personal data. We do not share it for advertising, profiling or marketing. We use a small set of sub-processors strictly to operate the Service (see Section 4). You have full rights to access, correct and delete your data at any time.
We process your personal data in accordance with the Swiss Federal Act on Data Protection (revFADP) and, where applicable, the EU General Data Protection Regulation (GDPR). This Privacy Policy applies to all personal data we collect when you visit our website at www.carstats.ch or otherwise interact with our Service. It does not cover third-party websites or services we link to.
2. Data we collect
2.1 When you create an account
- Email address (required)
- First and last name (optional)
- A securely hashed password (we never store your plaintext password)
- Invite code, if used to register
- Account creation date
2.2 When you visit our website
- Device and browser information (browser type, operating system, device type, screen size)
- IP address and approximate location derived from it (country and region only)
- Date, time, referrer URL and marketing parameters (e.g. UTM tags)
- A randomly generated session identifier
This data is collected through our self-hosted analytics tool and server logs to understand how the website is used. It is not linked to an identified individual unless you subsequently create an account or log in.
2.3 When you use the Service
- Pages viewed, features used, search queries and filters you apply
- Watchlist entries (the car models and configurations you choose to track)
- Device and browser information (browser type, operating system, device type, screen size)
- IP address and approximate location derived from it (country and region only)
- Date, time and duration of access; referrer URL and marketing parameters
- Login history (date, time and IP of recent logins)
2.4 When you pay for a subscription
- Payment method type (e.g., Visa, Mastercard, TWINT) and the last four digits of your card
- Subscription identifiers and transaction history
- Billing name (first and last name), address and country — required to process your subscription and collected by our payment processor (we do not store full card numbers or billing details locally)
- Invoice records (retained for 10 years per Swiss tax law — see Section 7)
- Transaction confirmations, dispute details and fraud-prevention signals received from our payment processor
2.5 When you contact us
- Your email address and the content of your message
- Any attachments you choose to send us
3. Purposes
We process your personal data only for specific purposes. The table below summarises what we process and why.
| Purpose | Data used |
|---|---|
| Create and operate your account; deliver the Service | Account data, watchlist, usage data |
| Process payments and manage subscriptions | Payment-method metadata, subscription identifiers |
| Issue invoices and keep accounting records | Transaction history, invoice records |
| Send transactional emails (verification, password reset, OTP codes, watchlist alerts, billing receipts, service notifications) | Email address, name, relevant transactional data |
| Detect and prevent fraud, abuse, scraping and security incidents | IP address, login history, anti-scraping signals, device data |
| Maintain audit logs of security-relevant events (e.g., two-factor changes) | User ID, IP, action type, timestamp |
| Record and analyse usage data to operate, maintain and improve the Service | Page views, search queries, device/browser, session metadata |
| Respond to your support requests | Email content, account data |
| Comply with legal requests and obligations (e.g., court orders, regulatory enquiries) | Whatever data is legally required to be disclosed |
4. Recipients & sub-processors
We never sell or rent your personal data. We do not share your personal data with third parties for advertising, profiling or marketing purposes. We share your personal data only with a small set of service providers who process data strictly on our documented instructions to operate the Service. Each sub-processor is bound by a data processing agreement that governs the scope, purpose and security of the processing. These include:
- Hosting and infrastructure provider — application hosting, database and analytics infrastructure, operated in the EU;
- Payment processor — payment processing and subscription management;
- Email delivery service — transactional emails such as verification, password reset, watchlist alerts and billing notifications.
We may also disclose personal data:
- to professional advisers (lawyers, auditors, accountants) where strictly necessary, under confidentiality obligations;
- to authorities and courts where required or permitted by law, including in response to court orders, regulatory enquiries, or to report suspected fraud or abuse;
- to a successor entity in connection with a merger, acquisition, reorganisation or sale of assets, with prior notice to affected users.
5. International transfers
Most of your data is processed and stored within Switzerland or the EU/EEA. Where our service providers process data in the United States, we ensure an adequate level of protection through recognised safeguards, including the Swiss-US and EU-US Data Privacy Frameworks and Standard Contractual Clauses. Details of the specific safeguards in place are available on request.
6. Cookies & similar technologies
We use cookies and similar technologies to operate the Service. We distinguish two categories:
- Strictly necessary cookies — required for authentication, session management and security (e.g., the
refreshTokenHTTP-only cookie). These cannot be disabled without breaking the Service. They are set on the basis of contract performance. - Analytics — we use a self-hosted, privacy-respecting analytics tool running on our own infrastructure to understand how features are used. It does not set persistent identifying cookies and does not perform cross-site tracking. In addition, our servers record usage data (such as pages viewed and features used) when you are logged in; this server-side tracking is functionally necessary to operate and improve the Service and cannot be disabled separately.
Our use of cookies and similar technologies is limited to what is described above.
7. Retention periods
We retain your personal data for as long as your account is active. When you delete your account, we permanently delete or anonymise your data as follows:
- Account data, watchlist, login history, security logs — deleted immediately. Where an abuse investigation is ongoing or unresolved at the time of deletion, we may retain the specific records relating to that investigation until it is concluded.
- Analytics data — dissociated from your identity (anonymised). Aggregated, non-identifying analytics may be retained indefinitely for statistical purposes.
- Billing and tax records — invoice, transaction and subscription-change records required for Swiss accounting purposes are retained in pseudonymised form for up to 10 years (OR Art. 958f).
- Subscription history — plan-change and billing-transition records containing only pseudonymous identifiers are retained for accounting and audit purposes.
- Support correspondence — up to 24 months after closure of the request.
If your account has been inactive for an extended period (e.g. no login within three years), we may send you a reminder by email. If you do not respond or log in again, we may close and delete your account and the associated personal data, subject to any legal retention obligations described above.
8. Security monitoring
We log your IP address and basic technical metadata (user-agent, timestamp) when you log in, when security-relevant events occur, and when our systems monitor activity for signs of abuse.
In particular, we operate automated anti-scraping and fraud-detection measures that analyse request patterns, frequency and technical signals to protect the Service against unauthorised automated access and account abuse. Where these measures detect suspicious activity, access to the Service may be temporarily or permanently restricted.
We do this on the basis of our legitimate interest in:
- protecting the Service against fraud and abuse;
- preventing automated scraping and account takeover;
- investigating security incidents.
Login and security-log IPs are kept while your account is active and are deleted with your account, unless retained under Section 7 for an ongoing abuse investigation. Anti-scraping detection signals are kept only while they are security-relevant. You have the right to object to this processing under revFADP and GDPR; however, where the interest is overriding (for example, an ongoing investigation), we may retain the data despite an objection.
9. Marketing communications
All service-related emails (verification, password reset, watchlist alerts, billing notices, important service announcements) are transactional and cannot be unsubscribed from while you have an active account.
For marketing and promotional communications, we will either rely on your prior opt-in consent or, for existing paying subscribers, send communications about similar products or services with an easy opt-out, as permitted by Swiss UWG Art. 3(1)(o) and applicable EU ePrivacy rules. Every marketing email will contain a one-click unsubscribe link.
10. Automated decisions & profiling
We do not make decisions about you based solely on automated processing that produce legal effects on you, or similarly significantly affect you (GDPR Art. 22 / revFADP Art. 21). Our analytics classify vehicles — not users — into trend categories such as “Rising”, “Stable” or “Depreciating”. We do not profile you commercially, do not produce a consumer credit score, and do not make automated subscription decisions about you.
11. Children
The Service is not directed at anyone under the age of 18 and is not appropriate for children. As stated in our Terms of Service, you must have the legal capacity to enter into a binding contract. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us (see Section 18) and we will delete it without undue delay.
12. Your rights
Under the revFADP and the GDPR you have the following rights regarding your personal data:
- Right of access — obtain confirmation of whether we process your data and a copy of it.
- Right to rectification — have inaccurate or incomplete data corrected.
- Right to erasure — have your data deleted, subject to legal retention obligations.
- Right to data portability (revFADP Art. 28 / GDPR Art. 20) — receive the personal data you provided to us in a structured, commonly-used and machine-readable format. To request a data export, contact us (see Section 18).
- Right to object to processing based on legitimate interest.
- Right to restrict processing (GDPR) in defined circumstances.
- Right to withdraw consent at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Right to lodge a complaint with a supervisory authority — see Section 14.
These rights are not unconditional. They may be limited or excluded where required by law, necessary to protect overriding interests, or where we need to verify your identity. We will inform you if we cannot fully comply with a request and explain the reasons.
13. How to exercise your rights
To exercise any of the rights above, contact us (see Section 18) from the email address registered to your account. We will respond within one month of receipt. If a request is complex or we receive a high volume, we may extend this period by up to two further months and will notify you of the extension and the reasons within the initial period. We may ask you to verify your identity if there is any doubt that the request originates from you.
You can directly manage some data yourself in your account settings:
- edit your name and email address;
- change your password;
- manage your watchlist and notification preferences;
- delete your account.
Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse the request, as permitted by law).
14. Right to complain
If you believe we have processed your personal data unlawfully, we encourage you to contact us first (see Section 18) so we can address the issue. You also have the right to lodge a complaint with a supervisory authority:
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern — www.edoeb.admin.ch.
- EU / EEA: Your local national data-protection authority. A list is available on the European Data Protection Board website (edpb.europa.eu).
15. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These include:
- TLS encryption in transit for all connections;
- industry-standard password hashing (we never store plaintext passwords);
- two-factor authentication available to all users via email one-time codes (codes are stored only in cryptographically hashed form);
- strict access controls and audit logging for administrative actions;
- regular security reviews and patching of dependencies;
- infrastructure operated in the EU (Frankfurt) with industry-standard physical and network controls.
No system is perfectly secure. While we take security seriously, we cannot guarantee absolute security of data transmitted over the internet or stored on any system.
16. EU users
Our Service is directed at users in Switzerland and is not marketed to or specifically targeted at users in the European Union. Where an EU-based user nevertheless accesses the Service, we process their data in accordance with applicable law, including the GDPR where required. EU users may exercise their rights and lodge complaints as described in Sections 12–14.
17. Changes to this policy
We may update this Privacy Policy from time to time, for example to reflect changes in the Service, our sub-processors, or applicable law. We will notify you by email of material changes at least 30 days before they take effect. The current version is always available at www.carstats.ch/privacy. The “Last updated” date at the top of this page shows when it was most recently revised.
18. Data controller
The data controller responsible for processing your personal data is:
Rare Drive GmbH (operating as CarStats)
Bahnweg 18
8700 Küsnacht ZH
Switzerland
Contact: info@carstats.ch
Full company details are set out in our Impressum.
19. Version & effective date
Version: 1.0
Effective from: 12 May 2026