Privacy Policy — Carnama
Carnama (“we”, “us”, the “Service Provider”) operates this service. Contact: support@carnama.app.
This policy describes how we collect, use, share, and store information when you use Carnama: the Android app (package com.carnama.app), the iOS app (bundle com.carnama.app), the web app at https://app.carnama.app, the website at https://carnama.app, and related APIs.
We do not sell your personal data. We do not show ads. We do not use your data for cross-context behavioural advertising.
Who the app is for
Carnama is an app for vehicle owners and workshops in Pakistan (cars and bikes). Keep a garage, log service, and let workshops verify work. It is not directed at children under 18. Accounts require an email and password. You must verify your email before you can use the app.
Information we collect
You provide
- Vehicle owner account: name, email, password (stored hashed on our servers). The app may also ask for an optional phone number.
- Workshop account: contact name, email, password (hashed), phone, business name, country, city, optional address, and services offered.
- Vehicles: vehicle type (car or bike), plate, country, chassis number, catalog details (make, model, variant, year, colour), mileage, and vehicle photos.
- Service history: types of work, date, mileage, cost, notes, optional workshop tag, status (for example user-logged, pending, verified), receipt photos uploaded by workshops, and invoices created by workshops (invoice number, line items, currency, totals).
- Transfers: recipient Carnama email (the recipient must already have an owner account), plate-retention choice, and related plate/chassis details. Offers are delivered in the app and by push notification, not as a marketing email.
- Retained plates: plates you keep after a transfer, until you assign or release them.
- Feedback you send in the app (message, optional rating and category), and emails you send to support.
Automatically / from the device (with permission where required)
- Sign-in tokens stored on your device or in the browser so you stay logged in, and your IP address used for security and rate limiting.
- Push notification token and platform (Android/iOS) if you allow notifications.
- Crash logs, performance diagnostics, and app-usage analytics (including an app account identifier and whether the account is owner or workshop).
- Device or app identifiers used by Firebase (analytics, crash reporting, performance, push, remote config).
- Location permission: the mobile app may request location so we can show nearby workshops on a map. That map is optional and can be turned off. We do not require location to use Carnama, and we do not store your GPS coordinates on our servers today. You can refuse location in system settings.
We do not collect payment card numbers, contacts, SMS, health data, or advertising IDs for this app today. Invoice amounts you or a workshop enter are service costs, not card payments.
How we use information
- Create and secure your account (including email verification and password-reset emails from noreply@carnama.app).
- Provide the garage, service history, workshop lookup, invoices, transfers, retained plates, and notifications.
- Store vehicle photos and workshop receipt images so they can be shown in the app.
- Improve reliability and understand feature usage (crashes, performance, analytics, remote configuration).
- Prevent abuse (rate limits, blocked accounts) and comply with law and store rules.
How we share information
We share data only as needed to run Carnama:
- Workshops: can look up a plate and see vehicle and service information needed to log or verify work. On pending owner-logged work they may see a shortened customer name (first name and last initial), not your email.
- Vehicle owners: when signed in, can see a workshop directory (business name, country, city, address) in order to tag service. Service history, invoices, and receipt photos stay with the vehicle/plate, including after a transfer.
- Transfer counterparties: the other owner sees names, emails, plate, and vehicle details needed to send, accept, decline, or cancel an offer.
- Service providers that process data on our behalf:
- Railway (API hosting) and MongoDB (database)
- Cloudflare (DNS / reverse proxy) and Vercel (websites)
- Google Firebase (analytics, crash reporting, performance monitoring, push notifications, remote config) and Google Play (distribution)
- Cloudinary (photo storage)
- Resend (email delivery)
- Legal: if required by law, a lawful request, or to protect rights, safety, or the service.
These providers have their own privacy policies, including Google Play Services, Firebase, Cloudinary, and Resend.
We do not sell personal information.
Cookies and similar technologies
The web app stores a login token in your browser (localStorage) so you stay signed in, and may use session storage during email verification. The mobile app stores session tokens and related preferences on the device. Hosting and security providers (for example Cloudflare or Vercel) may set essential cookies. Firebase SDKs on the mobile app use device identifiers for analytics, crash reporting, performance, push, and remote config. We do not use advertising cookies, pixels, or ad networks. Where required by law, we will obtain consent before using non-essential tracking.
Retention
We keep account data while your account exists. Sign-in tokens stop working after you log out or we delete the account (the server rejects tokens for deleted accounts). Push tokens and in-app notifications are removed on logout (for that device) or on account deletion.
After deletion we remove your login and personal profile. We do not run a separate “keep everything for 12 months” clock. Limited vehicle and shop records may remain so plates, service history, and invoices stay accurate, as described below. Copies in backups, email inboxes (for example verification, password reset, or feedback already sent), and analytics/crash systems may take additional time to age out.
Delete your Carnama account
Vehicle owners and workshops can delete their account in the Carnama mobile app (this is not currently available on the website):
- Open Carnama and sign in
- Go to Profile
- Tap Delete Account
- Enter your password and type DELETE to confirm
This permanently deletes your account. You will not be able to sign in afterwards.
If you delete a vehicle owner account: your login, profile, feedback, uploaded vehicle photos, retained-plate wallet, push tokens, and in-app notifications are deleted. Pending transfer offers are cancelled. Vehicles you own become unclaimed plates so workshops can still find them; service history and invoices stay with the plate, without your login. Historical transfer records may keep internal IDs and the recipient email so the audit trail remains, but names will no longer resolve to an account.
If you delete a workshop account: your login, workshop profile, shop diary, push tokens, and in-app notifications are deleted. Receipt photos you uploaded are removed. Service history and invoices stay on customer plates with a frozen shop name/address snapshot (shown as a former workshop). Pending owner requests waiting on your shop are closed as user-logged. The same email can register a new workshop later; it will not inherit the old invoices or diary.
If you cannot use the app, email support@carnama.app from the address on your account and ask us to delete it. Uninstalling the app or stopping use of the website does not by itself delete data already stored on our servers.
Your choices and rights
- Owners: Profile → Edit Profile to change your name (email cannot be changed in the app today).
- Workshops: Profile → Edit Profile to change contact name, business name, phone, country, city, address, and services (email cannot be changed in the app today).
- Device permissions: location, camera, photos, notifications — you can refuse or turn them off in system settings.
- You may request access to, correction of, or deletion of your personal data, or withdraw consent where processing is based on consent, by using in-app deletion or emailing support@carnama.app.
Your California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information is collected, the right to delete personal information, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising these rights. We do not sell personal information and we do not share it for cross-context behavioural advertising. To exercise these rights, contact support@carnama.app.
Security
We use HTTPS to encrypt data in transit. Passwords are stored hashed. We use rate limits and account blocking to reduce abuse. No method of transmission or storage is 100% secure.
Data breach notification
If a data breach occurs that affects your personal data, we will notify you in accordance with applicable law, including, where required, the nature of the breach and the steps being taken to address it.
International processing
Our providers may process data in countries other than yours (including where Firebase, Cloudinary, email, hosting, or our database operate). If you use Carnama, this processing is needed to provide the service. Where applicable law requires safeguards for international transfers, we rely on appropriate mechanisms used by those providers, such as Standard Contractual Clauses or adequacy decisions.
Children
Carnama is not intended for children under 18, or such higher age as required where you live. We do not knowingly collect personal data from children. If you believe a child has created an account, contact support@carnama.app and we will delete it.
Changes
We may update this policy. The “Last updated” date will change. Where required by law, we will seek consent to material changes before they take effect. Continued use after an update means you accept the new policy to the extent permitted by law.
Contact
Carnama
support@carnama.app