Privacy Policy
Last updated: 2026-07-29
This is a working draft written to cover the data WrapViz actually collects and where it goes — it is not legal advice, and hasn't had a lawyer's review. Same honesty bar as the rest of this compliance work: real launch needs sign-off, this just means the app isn't shipping with a blank page where a policy should be. See also the Legal Notice and Terms & Conditions.
What we collect
- The photo of your vehicle you upload, and the renders generated from it.
- Your email address and account identifier, via Clerk (sign-in).
- Payment details are handled entirely by Stripe — we never see or store card numbers.
- For widget visitors: an anonymous session token and a hashed (not raw) IP address, used only to enforce the free-render allowance — never linked to an account.
Personal data that may be in your photo
A photo of your vehicle may incidentally contain personal data beyond the car itself — for example a visible licence plate, or a bystander in the background. Our render pipeline is designed to leave everything outside the vehicle's paintable panels (including plates, people, and the background) untouched, but this is enforced by prompt instructions to the AI model rather than a hard technical guarantee in every case — see the disclaimer shown with each render. Treat any photo you upload as if its full contents, not just the car, will be processed and temporarily stored as described below.
Why, and our legal basis
To generate your render, run your account and credit balance, process payment, and (for wrap shops) deliver leads you've explicitly requested to be contacted about. Under GDPR Art. 6, we rely on:
- Contract (Art. 6(1)(b)) — processing your photo and account details is necessary to provide the render you've asked for and to run your account.
- Consent (Art. 6(1)(a)) — obtained before your photo is uploaded or processed (see the consent step in the upload flow), specifically for sending your photo to the third-party AI providers listed below.
- Legitimate interest (Art. 6(1)(f)) — for basic fraud/abuse prevention (rate limiting, the free-render cap) and for keeping the service secure and operating correctly.
Who we share it with
- Clerk — authentication.
- Stripe — payment processing and billing.
- Cloudflare R2 — where uploaded photos and renders are stored.
- Google (Gemini) or OpenAI — the AI model that generates your render from your photo.
We do not sell your data, and we don't use it for third-party advertising.
Some of these processors (notably Google and OpenAI) are based outside the EU/EEA. Where that applies, transfers rely on the processor's own EU Standard Contractual Clauses or equivalent safeguard. [TODO — confirm each processor's current transfer mechanism before launch; this is stated generally, not verified against each provider's current DPA.]
Every image these providers generate is AI-generated content, which we label as such wherever it's shown or downloaded, in line with the EU AI Act's transparency requirements.
How long we keep it
Uploaded photos and their renders are automatically deleted 30 days after upload. You can delete them yourself at any time before that from the render result screen. Account and billing records are kept longer where we're required to for accounting purposes.
Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten") — you can delete your uploaded photos and renders yourself at any time from the render result screen, or ask us to delete your account and all associated data entirely.
- Restrict or object to processing in certain circumstances.
- Data portability — receive the data you've provided us in a structured, commonly-used format.
- Withdraw consent at any time where processing is based on consent, without affecting processing already carried out.
To exercise any of these rights, contact abdelilah.kajouj@021.be. We'll respond within one month, as required by GDPR Art. 12.
You also have the right to lodge a complaint with a supervisory authority. In Belgium, that's the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), or the supervisory authority in your own EU member state.
Cookies
We use only the cookies necessary for sign-in (Clerk) and, for widget visitors, an anonymous session — no third-party advertising or analytics cookies.