App privacy
CarCrew App Privacy Policy
This Privacy Policy applies to the CarCrew mobile application for iOS. It explains which personal data we process, the purposes for which we process it and the legal bases on which that processing takes place.
1. Controller
The controller responsible for processing personal data in the CarCrew app is:
Tim SessinghausSunderweg 26
58300 Wetter (Ruhr)
Germany
Email: tim@schneider-sessinghaus.de
Phone: +49 152 29450820
Email for privacy, support, the app and the website: info@carcrew.app
Instagram: official_carcrew.app
2. Scope
This Privacy Policy applies to the CarCrew mobile application (iOS). It describes which personal data we process, the purposes for which we process it and the legal bases on which that processing takes place.
3. What data does the app generally process?
CarCrew is an app for recording and managing vehicle data, costs, receipts and, optionally, trips. Depending on how the app is used and the subscription plan selected, the following data in particular may be processed:
- Account data: name or display name, email address if provided, and internal user ID
- Vehicle data: vehicle name, make, model, model year, registration number if entered, Bluetooth name if entered, odometer readings, and cost and parameter data such as consumption, insurance and vehicle tax
- Trip data: start and end times, route or distance, cost per trip, and the driver's name in shared fleets
- Location data: location during a trip for trip recording and, where cloud or sharing features are enabled, optionally the vehicle's last location or “last stop”; depending on the privacy setting, this may be approximate only
- Receipt data: receipt scans and text recognised using OCR for the purpose of creating expenses or entries
- Communication data: content that you send to us by email
- Technical data: device and app information such as a push token and, where applicable, diagnostic and usage data as described under Firebase below
4. Local storage on your device
A large amount of data, including vehicles, expenses and trips, is stored locally on your device so that the app can function and be used offline.
Legal basis: Art. 6(1)(b) GDPR for the performance of a contract or steps taken prior to entering into a contract, and/or Art. 6(1)(f) GDPR based on our legitimate interest in providing a functional app.
5. Account, sign-in and user management
If you use cloud features or sign in, authentication may be provided through one of the following methods:
- Anonymous sign-in using a technical user ID
- Email address and password
- Sign in with Apple
This involves processing a user ID and, where you provide them, an email address and name.
Purpose: providing cloud synchronisation, sharing and fleet features, and associating your data with your account.
Legal basis: Art. 6(1)(b) GDPR.
6. Cloud features and fleet sharing
Depending on the subscription plan, including ProLite, Pro or ProPlus, the app may provide cloud features. In that case, data is processed in a cloud database, including in particular:
- User profile data such as email address, display name and subscription tier
- Fleet and member management data such as members, roles, permissions and invitations
- Vehicle data as described above
- Trip, cost and expense data, including summaries, values displayed in the app and, where applicable, driver assignments
- Fleet events and status information, for example when a member leaves vehicle sharing
Purpose: synchronisation between devices, shared use and displaying data to authorised fleet members.
Legal basis: Art. 6(1)(b) GDPR.
7. Location data
7.1 Trip recording
When you record trips, the app processes location data to measure routes and document trips. You can change the app's location permission in iOS at any time.
Purpose: measuring trips, calculating routes and costs, and displaying the start, destination and trip history to the extent these functions are used by the app.
Legal basis: Art. 6(1)(b) GDPR.
7.2 “Last stop” for cloud and sharing features (optional)
When you use cloud or sharing features, the vehicle's last location or “last stop” may be processed for authorised fleet views. The location data is end-to-end encrypted. Privacy modes may be available in the app settings, including:
- Location sharing OFF: no last location is stored, or existing location data is deleted
- Approximate: coordinates are placed on a grid or otherwise made less precise
- Precise: used only when you actively allow precise sharing
Purpose: convenience features for shared fleets, such as displaying status information or the last location.
Legal basis: Art. 6(1)(b) GDPR and, for optional privacy features, additionally Art. 6(1)(a) GDPR based on consent or a user-controlled choice in the app settings.
8. Bluetooth, CarPlay and automatic trip detection
The app may use Bluetooth and car audio connections to start or stop trips automatically or associate a trip with a vehicle, for example by using a stored Bluetooth name or an active car audio connection.
No content of your communications is accessed. Only the technical detection of a connection or route is used to provide the app feature.
Legal basis: Art. 6(1)(b) GDPR.
9. Camera and receipt scanning (OCR)
When you scan receipts, the app uses the camera. Text recognition using OCR takes place on the device to transfer text from the receipt.
Purpose: convenient recording of expenses and receipts.
Legal basis: Art. 6(1)(b) GDPR.
10. Push notifications
If you enable push notifications, a device token is processed so that notifications can be delivered to your device, including fleet-related notifications.
Legal basis: Art. 6(1)(b) GDPR and/or Art. 6(1)(f) GDPR based on our legitimate interest in operating the app and, where applicable, consent given through the iOS system prompt.
11. In-app purchases and subscriptions
Subscriptions are processed through the Apple App Store. Payment data is processed by Apple. As a rule, we receive only the information required to provide the subscription status in the app, such as the product, status, term and entitlement.
Purpose: processing the subscription and enabling the relevant features.
Legal basis: Art. 6(1)(b) GDPR.
12. Service providers used
We use Firebase, a Google service, for cloud features and certain technical services.
Depending on the service, data may be processed in data centres within and outside the European Union and European Economic Area. Appropriate safeguards, such as Standard Contractual Clauses, are used for transfers to third countries.
Recipients or categories of recipients:
- Google and Firebase for hosting, databases, authentication and push notifications
- Apple for the App Store, in-app purchases, StoreKit and, where applicable, system services
- Email providers for support enquiries sent by email
Firebase services
- Firebase Authentication
Purpose: account sign-in, anonymous sign-in and associating cloud data with a user account.
Data processed: user ID, optional email address, optional display name and authentication tokens.
- Cloud Firestore
Purpose: cloud synchronisation, fleet sharing, roles and permissions, invitations, vehicles, trips, costs and fleet events.
Data processed: the content you enter in the app as described in Section 3.
- Firebase Cloud Messaging
Purpose: technical delivery of push notifications.
Data processed: device tokens and technical delivery metadata.
- Firebase App Check and Firebase Installations
Purpose: preventing misuse, verifying the integrity of app requests and providing an app instance identifier for technical processes.
Data processed: app attestation tokens, app instance identifiers, and technical security and integrity signals.
- Firebase Analytics
Purpose: analysing app usage to improve and optimise the product and its features.
Data processed: app usage event data, device and app information, and technical identifiers.
- Firebase Crashlytics
Purpose: diagnosing errors and improving stability.
Data processed: crash reports, device and app information, diagnostic data, and technical identifiers.
- Firebase Performance Monitoring
Purpose: performance analysis and identifying bottlenecks.
Data processed: performance metrics, technical device and app information, and network metadata.
- Firebase Remote Config
Purpose: controlling configuration and the availability of features.
Data processed: technical identifiers, configuration requests and configuration states.
- Firebase In-App Messaging
Purpose: providing notices and communications within the app.
Data processed: technical identifiers and data relating to delivery and interaction with in-app messages.
- Firebase Cloud Functions, Firebase Storage and Firebase Realtime Database
Purpose: server-side logic, file storage and technical data storage where enabled for specific functions in the relevant version of the app.
Data processed: depending on the function, typically the content described in Section 3 and technical metadata.
Apple services
- Apple Push Notification service
Purpose: technical delivery of push notifications.
Data processed: device tokens and delivery metadata.
- Apple Maps and geocoding services
Purpose: displaying maps and routes and converting coordinates into addresses where these functions are used.
Data processed: the location or coordinates required to display maps and addresses, together with technical usage data relating to Apple services.
13. Retention periods
We retain personal data only for as long as necessary for the respective purposes:
- Account and cloud data: for as long as you use the cloud feature or until deletion is requested
- Trip, vehicle and cost data: for as long as you store it in the app or until it is deleted by you or upon request
- Support enquiries: until the enquiry has been fully resolved, followed by deletion unless statutory retention obligations apply
14. Your rights
Under the GDPR, you have the following rights in particular:
- Right of access under Art. 15 GDPR
- Right to rectification under Art. 16 GDPR
- Right to erasure under Art. 17 GDPR
- Right to restriction of processing under Art. 18 GDPR
- Right to data portability under Art. 20 GDPR
- Right to object under Art. 21 GDPR
- Right to withdraw consent under Art. 7(3) GDPR where processing is based on consent
To exercise your rights, email info@carcrew.app.
15. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. In particular, the competent authority is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)Kavalleriestr. 2–4
40213 Düsseldorf
Germany
16. Changes to this Privacy Policy
We may update this Privacy Policy where necessary, for example if features change or new legal requirements apply. The current version is available at https://carcrew.app/datenschutz-app/.
Last updated: 29 January 2026