This policy applies to the AutoMeu mobile app (Android and iOS) and the web service available at app.automeu.ro. Please read it carefully before using the app.

1. Who we are

AutoMeu is an app developed and operated independently, based in Romania. For any question regarding privacy, you can contact us at contact@automeu.ro.

2. What data we collect

2.1 Account data

When you create an account, we collect:

  • First and last name — to personalize the app
  • Email address — for authentication and important notifications
  • Phone number (optional) — for contact regarding appointments

If you sign in via Google Sign-In, we receive from Google: your name, email address, and a unique Google identifier. We do not receive your Google password.

If you sign in via Sign in with Apple (available on iOS), we receive from Apple: your name, email address (which may be a "private relay" address provided by Apple, if you choose to hide your real email) and a unique Apple identifier. We do not receive your Apple ID password.

2.2 Vehicle data

  • License plate number, make, model, year of manufacture
  • Usage log: fuel fill-ups (liters, price, mileage), repairs, services, expenses
  • ITP (technical inspection), Rovinieta (road tax vignette) and RCA (mandatory motor liability insurance) check results (retrieved from public sources)

2.3 Notification data

If you grant permission for push notifications, we store an FCM token (Firebase Cloud Messaging) associated with your device. This is used exclusively to send the expiry alerts (ITP, Rovinieta, RCA, and the other available types) that you have configured.

2.4 Location data

The app may request access to your location exclusively to display nearby ITP inspection stations on the map. Your location is not stored on our servers and is not transmitted to any third party.

2.5 Technical data

For the service to function, we automatically log: the IP address at login, the device type (mobile/web), and the app version. This data is used exclusively for security and diagnostics.

2.6 Donation data

If you choose to support the app through a voluntary contribution via Google Play, the transaction is processed entirely by Google. We do not collect, store, or have access to your card or payment account details. We only receive confirmation that a contribution was made.

3. How we use the data

PurposeData usedLegal basis (GDPR)
Authentication and account securityEmail, password (hash), IPPerformance of a contract
App functionalityVehicle data, logPerformance of a contract
Sending expiry alertsFCM token, vehicle dataConsent (granted in the app)
ITP/Rovinieta/RCA verificationLicense plate number, VINPerformance of a contract
Security and auditIP, user ID, critical actionsLegitimate interest

We do not use your data for advertising, commercial profiling, or sale to third parties.

4. Who we share data with

We do not sell or transfer your personal data. We use the following technical service providers:

  • Google LLC — authentication (Google Sign-In), push notifications (Firebase Cloud Messaging), payment processing (Google Play Billing) on Android. Google's policy: policies.google.com/privacy
  • Apple Inc. — authentication (Sign in with Apple), distribution and payment processing (App Store) on iOS. Apple's policy: apple.com/legal/privacy
  • RAR (Romanian Auto Register) — public lookup of vehicle technical data
  • CNAIR / erovinieta.ro — road tax vignette (Rovinieta) validity check
  • AIDA — RCA insurance policy check

Queries to RAR, CNAIR and AIDA are performed using the license plate number or VIN provided by you and represent access to public data.

5. How long we keep the data

  • Account and vehicle data — for the lifetime of the account
  • Security logs — 90 days
  • FCM token — until logout or uninstallation of the app
  • Account data after deletion — maximum 30 days (backup), after which it is permanently deleted

6. Data security

Data is transmitted exclusively over HTTPS/TLS connections. Passwords are stored exclusively in hashed form (bcrypt). Access to the database is restricted and monitored. We apply security practices in line with OWASP standards.

7. Your rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access — request a copy of the data we hold about you
  • Rectification — correct inaccurate data directly in the app or by email
  • Erasure — request the deletion of your account and all associated data
  • Portability — receive your data in a structured format (JSON)
  • Objection — object to processing based on legitimate interest
  • Withdrawal of consent — disable push notifications at any time from the app settings

To exercise these rights, contact us at contact@automeu.ro. We respond within 30 days. You also have the right to lodge a complaint with ANSPDCP (the Romanian National Supervisory Authority for Personal Data Processing) — dataprotection.ro.

8. Children

The AutoMeu app is not intended for individuals under 13 years of age, and we do not knowingly collect data from children. If you become aware that a child under 13 has provided data without parental consent, please contact us.

9. Changes to this policy

We may update this policy periodically. Significant changes will be notified in the app or by email. The date of the last update is indicated in the header of this page.

10. Contact

For any question regarding data privacy: