Privacy Policy

September 13, 2026 · v2026-09-13

What data we collect, where it lives, and how you can exercise your rights.

Data controller

Cristiano Manzoni — owner and developer of the Pitlog application. For any privacy request: gdpr@manzoni.cloud.

How we use data

The app is local-first: all maintenance data (vehicles, tasks, logs, attachments, notes) stays on the device by default. No account is required to use the app, and local data is not sent to any server until you explicitly enable cloud sync.

Cloud sync is optional and free, like every other feature. When enabled, the app sends data to our servers in Italy/Germany (Hetzner) to let you use the same account across multiple devices.

Data we collect

Account: email and password (hashed with argon2). The password is never readable, not even by us.

Profile: name, preferred language, notification preferences.

Maintenance data: vehicles, tasks, services, photos and document attachments (only with sync enabled).

Session tokens: refresh tokens bound to the device (stable deviceId, deviceName), visible and revocable from the Sessions page.

Push notification tokens: if you enable push reminders on a mobile device, we register its Expo/FCM/APNs token to deliver them.

Telegram chat_id: only if you enable Telegram notifications.

Application logs and crash reports: via Sentry, with email and chat_id filtered out before upload.

Consents and tracking

At registration we record privacy and terms acceptance with date, version and IP address, as required by GDPR (art. 7). Optional consents (analytics, marketing) are recorded separately and can be withdrawn at any time from Settings.

Advertising: Pitlog shows you no advertising. Neither the web app nor the mobile app displays or requests ads, and no personalised advertising takes place. The web app contains no advertising code at all. For completeness: the mobile app still bundles the Google AdMob SDK, so that advertising could be reintroduced without a rewrite. It is switched off — the app never initialises it, and the build explicitly instructs the SDK to hold off any app measurement until it is initialised, which does not happen while advertising is off. If it ever were, it would be AdMob banners and frequency-capped full-screen ads limited to a "PG" rating; this policy would be updated first, and in the EEA, the UK and Switzerland a Google-certified consent form (UMP) would ask for your choice before any personalised advertising ran.

Refusing advertising consent would never restrict any app feature: every feature of Pitlog is free and available to every account.

Attachments (photos and documents)

Photos and documents you attach to logs, modifications or vehicles — images and PDFs, plus other document formats (office documents, OpenDocument files, plain text) when an administrator allows them — are uploaded through the application server, which checks their type and size and stores them on MinIO (self-hosted S3-compatible storage) in the same datacenter as the application server, together with their metadata (file name, type and size). Files other than images and PDFs are always delivered as downloads. Download URLs expire after a short time (15 minutes by default).

Retention

We keep your data while your account is active. When you request deletion, the account is disabled immediately and data is permanently erased after a 30-day grace period (you can cancel during this window). Anonymized application logs may remain up to 90 days for security purposes.

Your rights (GDPR)

You have the right to access, rectify, export ("Export my data" in Privacy settings), restrict, object and delete. Use the in-app actions or write to gdpr@manzoni.cloud. You can also lodge a complaint with the Italian DPA (www.garanteprivacy.it).

International transfers

Data is hosted on servers in Germany (EU). Push-notification services route through Apple (USA) and Google (USA): in those cases we only send the opaque token and the reminder text, no profile data.

Changes

We update this policy as features evolve. The last-updated date and version are at the bottom of the page; substantive changes will require re-acceptance at next sign-in.

Email: gdpr@manzoni.cloud