Privacy Policy
Last updated: June 2026
This policy explains how check4me processes personal data under the GDPR. Controller: check4me GmbH, Försterstraße 110, 90441 Nürnberg, Germany. The German version is authoritative.
1. Controller
check4me GmbH Försterstraße 110, 90441 Nürnberg, Germany Managing director: Irfan Amidou Email: info@check-4me.com
2. Overview
We process data of buyers, checkers, and visitors to operate the vehicle inspection marketplace. We do not sell personal data for advertising.
3. Data categories
Account data, booking data, chat, reports, payment references (Stripe), verification data (Stripe Identity / uploads), technical logs, consent timestamps.
4. Legal bases
Contract (Art. 6(1)(b)), consent (Art. 6(1)(a)), legitimate interests — security (Art. 6(1)(f)), legal obligations (Art. 6(1)(c)).
5. Registration
Email or Google OAuth. After first login we record cookie and privacy consent in account metadata.
6. Bookings, reports, chat
Processed to deliver the service. Chat visible to buyer, assigned checker, and staff for disputes.
7. Stripe payments
Payments and Connect payouts via Stripe. We store status and Stripe IDs, not full card numbers.
8. Checker verification
Identity and driving licence via Stripe Identity. Meisterbrief via private upload with explicit consent. Retention: max 90 days upload; 30 days after approval for files.
9. Cookies
We use strictly necessary cookies (e.g. auth session, language/theme, stored cookie consent choice). Marketing/analytics cookies (Meta/Facebook Pixel) are only set after explicit consent via our cookie banner. You can accept all, necessary only, or choose categories and change your selection anytime via the cookie button or legal pages. After login we also record necessary-cookie and privacy consent in account metadata.
10. Notifications
In-app notifications; optional email via Resend.
11. Retention
Account data until deletion; billing data per statutory periods; verification files per section 8.
12. Processors
Supabase, Stripe, Vercel, Resend (optional), Google (OAuth). DPAs under Art. 28 GDPR.
13. International transfers
Some providers are in the US; transfers use SCCs and applicable safeguards.
14. Mandatory data
Some data is required to use the service.
15. Automated decisions
No Art. 22 GDPR profiling. Rule-based SLAs (48h accept/auto-accept) only.
16. Your rights
Access, rectification, erasure, restriction, portability, objection, withdrawal of consent — info@check-4me.com
17. Supervisory authority
BayLDA, Promenade 18, 91522 Ansbach, Germany — https://www.lda.bayern.de
18. Minors
Service for adults 18+.
19. Changes
Current version at /legal/privacy.