Privacy policy
Last updated
Version 2026.08.15.1
Effective from: 15 August 2026
How Carvoh processes personal data relating to the platform.
Data controller and contact
The data controller is AF TRADE & INVESTMENT, operated by Antonio Fascetta, Rue de la Station 8, bus A, 6040 Charleroi, Belgium.
For any question or request relating to your personal data, write to contact@carvoh.com. Carvoh may request the information necessary to verify your identity before responding.
Data processed
- Account and authentication data: name, email address, username, protected password, sessions, security elements and, when you enable them, information relating to enhanced authentication.
- Profile data: contact details, photo, biography, business information and organisation data according to your account type.
- Listing data: vehicle characteristics, price, availability, location, photos and other media, as well as information such as VIN or Car-Pass that the advertiser chooses to provide.
- Interaction data: messages, offers, rental requests, favourites, saved searches, reports and exchanges with support.
- Technical and security data: logs, IP address in hashed form when recorded, user agent, referrer and events necessary for operation, security or internal usage measurement.
- Choice data: privacy preferences, cookie choices and evidence of acceptance of the Terms.
Purposes and legal bases
Providing the platform
We process the data necessary to create and manage the account, publish and display listings, messages, offers and rental requests. This processing is necessary for performance of the Terms or performance of measures taken at your request before that relationship.
Security, moderation and defence of rights
We process data to prevent fraud and abuse, ensure security, moderate content, manage reports and defend our rights. The basis is our legitimate interest in maintaining a safe and compliant platform, or compliance with a legal obligation where applicable.
Preferences and internal measurement
We use preferences and technical events to operate, diagnose and improve the service. Where consent is required for a tracker or access to an optional service, we request it before activation. You may withdraw your optional choices at any time.
Communications
We use your contact details for service, security and account-related communications. Any marketing communication subject to consent is based on that consent; no marketing category is active on the effective date of this policy.
Recipients and services
Access to data is limited to persons authorised by Carvoh and providers necessary to operate the service. The application, PostgreSQL and media are hosted by OVH in Frankfurt, Germany.
Transactional emails are routed through Resend. Maps and geocoding activated by the user may involve Mapbox.
When a mapping feature is activated, a geocoding request may contain the entered address text or coordinates. Mapbox states that it acts primarily as a processor for its customers' data. Its documentation states that its source data are stored and served from a primary AWS region in the United States, with worldwide caching; processing therefore cannot be limited to the EEA.
Transfers outside the EEA
Processing carried out on the OVH infrastructure described above remains in Germany. This location does not extend to third-party providers.
For Mapbox, a transfer outside the EEA, in particular to the United States, is possible. Mapbox publishes a DPA including the European Commission's 2021 standard contractual clauses where required and states that it participates in the EU–US Data Privacy Framework. The terms actually applicable to Carvoh depend on its Mapbox contract and configuration.
Retention periods
- Active account: while the account is in use. The Marketplace does not yet implement automatic deletion based on inactivity; closure or an erasure request is handled on a case-by-case basis in accordance with the arrangements below.
- Active listing: while it is published. Deletion or expiry of a listing, its media, its VIN or its Car-Pass is not yet subject to an automated time-based purge; these data are therefore not subject to a fixed retention commitment.
- Messages, contacts, offers, rental requests, reports and moderation cases: the Marketplace does not yet implement an automated time-based purge based on their closure or last exchange. An erasure request is reviewed individually in accordance with the GDPR.
- Logs and security data: target retention period of twelve months. Individual analytics events: maximum target of thirteen months. These targets are applied by the operational retention task described in Marketplace operations; data that have actually been anonymised may be retained for longer.
- The CMP choice stored in your browser expires no later than six months. GDPR consent evidence stored server-side is kept for the time necessary to demonstrate the validity of consent and comply with applicable obligations.
- Evidence of contractual acceptance of the Terms is retained for the duration of the contractual relationship, then for the time necessary to establish, exercise or defend rights and comply with applicable legal obligations.
- Requests concerning GDPR rights: three years after closure. Backups are purged according to their technical cycle, ranging from thirty to ninety days.
Your rights
Subject to the conditions and limits provided for by the GDPR, you may request access to your data, their rectification, erasure, restriction of processing, object to certain processing and request portability of the data you provided where that right applies.
You may withdraw optional consent at any time without affecting the lawfulness of processing already carried out. A request may be sent to contact@carvoh.com. We respond within the time limits provided for by the GDPR and inform you of any justified extension.
You may lodge a complaint with the Belgian Data Protection Authority.
Automated decisions, security and updates
Carvoh does not make decisions producing a legal effect concerning you solely on the basis of automated processing within the framework described here.
We apply technical and organisational measures appropriate to the risk to protect data. Since no system is completely secure, we also invite you to protect your credentials.
This policy may change when our processing or applicable rules change. Significant changes will be presented by appropriate means.