Privacy policy
Last updated 2026-09-16
The short version
RigLog stores what you put into it — your vehicles, the work you log, your photos and documents — plus the email address you signed up with. There is no advertising, no tracking, and no analytics script of any kind. Nothing is sold, and nothing is shared except with the services listed below that are needed to run the app.
You can download everything we hold, or delete all of it, from Profile & settings. Neither needs you to ask anyone.
Who is responsible
The operator of this RigLog installation is the data controller for the information described here.
For anything in this policy, open a ticket on the feedback board. You do not need to wait for a reply to exercise the rights below — the export and deletion buttons in your settings do both immediately.
What we collect, and why
Your account. Email address, display name, and a public username generated from that name. Optionally a location and an avatar. We need the email to log you in and to send password resets. Passwords are stored only as a bcrypt hash — nobody, including us, can read them back.
What you log. Vehicles, tasks, costs, photos, receipts, documents and their expiry dates, wishlist items, and GPS tracks if you use the trail log. This is the app’s purpose; it is stored because you asked it to be.
What you post publicly. Feedback tickets, votes and comments, parts-wanted posts, and any project you switch to public. These are visible to anyone, including people without an account, and public projects are indexed by search engines. That is the point of them — but it is worth being deliberate about it.
Server logs and abuse counters. Ordinary web-server logs, and short-lived counters used to stop brute-force login attempts and spam. Details are in the retention table below.
We do not ask for, and have no use for, anything in the “special category” sense — health, politics, beliefs, biometrics. Please don’t put it in a task note.
Why we are allowed to (legal basis)
- Performance of a contract — your account and everything you log. You asked for an app that remembers your build; it cannot do that without storing it.
- Legitimate interests — keeping the service secure and working: rate limiting, abuse prevention, server logs.
- Consent — optional email and push notifications about projects you follow. You turn them on, and you can turn them off in settings at any time.
- Legal obligation — keeping records of payments.
Who else sees it
Only the services needed to run the app. Each one gets the minimum that its job requires, and none of them is an advertising network.
Vercel
Hosting, and Blob storage for uploaded photos, receipts and documents.
What they receive: Everything the app stores, plus the usual server-log data (IP address, browser user agent, requested URL).
The database host
The Postgres database itself.
What they receive: Everything the app stores.
Stripe
Payments for RigLog Pro and for donations.
What they receive: Your email address and the payment details you enter on Stripe’s own checkout page. Card numbers never reach RigLog — we store only Stripe’s customer and subscription identifiers.
Only if you buy Pro or donate.
Brevo, or Resend
Sending transactional email — password resets and the notifications you opted into.
What they receive: Your email address and the contents of that message.
Whichever is configured for this deployment.
Sign in with Google.
What they receive: Google tells us your email address and name. We do not receive your Google password.
Only if you use that sign-in option.
OpenStreetMap
Map tiles on the trail log.
What they receive: Your browser requests map images directly from openstreetmap.org, so it sees your IP address and which part of the map you are looking at.
Only on trail log pages, which are off-road projects only.
unpkg
Serves the map’s marker icons.
What they receive: Your IP address, as with any image loaded from another site.
Only on pages showing a map.
NHTSA vPIC (US Department of Transportation)
Decoding a VIN when the built-in table does not recognise it.
What they receive: The VIN you asked to decode. Nothing identifying you is sent with it.
Only when you use the VIN decoder.
Your browser’s push service (Google, Mozilla, Apple, …)
Delivering web push notifications.
What they receive: The notification’s contents, sent to the endpoint your browser gave us. Which service that is depends on your browser.
Only if you turn push notifications on.
Some of these are based outside the EU. Where that is the case, the transfer relies on the European Commission’s standard contractual clauses or an adequacy decision, through the provider’s own data processing terms.
We would also hand over data if legally compelled to — a court order, for example. That is not a loophole we go looking for.
Collaborators
If you invite a mechanic or specialist to a vehicle, they can see that vehicle and its tasks, and add work of their own. They cannot see your other vehicles, your account settings, or anything else. You can hide cost totals from them with a setting on the vehicle, and you can revoke an invitation at any time. Revoking removes their access immediately.
How long it is kept
Your account, vehicles, tasks, photos, documents, wishlist, trail logs and collaborator invitations
Until you delete them, or until you delete your account — at which point they are removed immediately, including the uploaded files themselves.
Feedback tickets, votes, comments, and parts-wanted posts
Deleted with your account. They disappear from the public board too.
Donation records
Kept after account deletion, with your account detached from them. A payment that happened is an accounting record; what is removed is the link to you.
Password reset tokens
One hour, then they stop working. Deleted with your account.
Rate-limiting counters, which stop brute-force and spam
At most an hour, after which they are swept away. Depending on what is being limited, the counter’s key contains an email address or an IP address alongside the count.
Your rights
Under the GDPR you can:
- Get a copy of everything we hold — the Download my data button in settings produces it immediately, as JSON.
- Correct anything wrong — edit it in the app.
- Delete everything — the Delete account button in settings removes your account, every project, and the uploaded files themselves. It is immediate and cannot be undone.
- Take it elsewhere — the same export is structured JSON, meant to be read by something other than us.
- Object, or ask us to restrict processing, and withdraw consent for notifications at any time.
- Complain to a supervisory authority. In Romania that is ANSPDCP; elsewhere in the EU, your own country’s authority.
The first two and the middle two are buttons rather than requests on purpose. You should not have to ask permission to leave.
Cookies
RigLog sets only the cookies needed to keep you logged in and to protect the sign-in form. There are no tracking or advertising cookies, which is why you are not asked to consent to any. The full list is here.
Children
RigLog is not aimed at children and we do not knowingly hold data about anyone under 16. If you believe we do, tell us and it will be removed.
Changes
If this policy changes in substance, the date at the top changes with it. Material changes will be announced on the feedback board rather than made quietly.