Short retention, clear choices
1. Who controls your data
Controller: ILO APPLICATIONS SL, NIF B93663862, EU VAT ID ESB93663862, Málaga, Spain. The registered street address and public privacy mailbox are deployment values that must be verified before paid launch. Company details shows their current status.
2. Data we process
- Source photos, finished images, extraction masks, technical image checks and the choices needed to process the order.
- Email address, locale, consent records, secure-link identifiers and order status.
- Payment status, amount, currency, tax and receipt references received from Stripe; we do not receive your full card number.
- Security and operations data such as IP-derived request information, timestamps, device/browser data, rate-limit events, audit logs and error diagnostics. Image-free diagnostic metadata is retained for six calendar months.
- Optional share-page title, selected finished images, download setting, publication/renewal dates and abuse reports.
- Messages you send for a privacy, legal, refund or support request.
3. Why and on what legal basis
- Contract: pre-payment checks you request, checkout, processing, delivery, refinements, recovery and owner controls.
- Consent: an optional public share page and any optional non-essential browser storage or marketing use. You may withdraw consent prospectively.
- Legal obligation: tax, accounting, consumer, fraud-prevention and data-rights records where required.
- Legitimate interests: keeping the service secure, preventing abuse, measuring operational reliability without customer-media analytics, and establishing or defending legal claims, balanced against your rights.
4. AI-edited images
The active service creates an AI-edited listing image with your original vehicle in a new background. It is designed to retain visible vehicle details and condition. Review the finished image against the original before publishing.
See the AI & photo processing disclosure for the processing explanation.
5. Recipients and international transfers
We use service providers by category: EU hosting and object storage, payment and tax processing (Stripe), transactional email, security/monitoring, and approved image-processing providers. They receive only the data needed for their task and act under contracts or as independent controllers where their service requires it.
Some providers may process data outside the EEA. Before activation we document the transfer mechanism and safeguards, such as an adequacy decision or Standard Contractual Clauses, plus relevant supplementary measures. The live provider register and configurations must be approved before paid launch; we do not claim that every optional provider is active.
6. Retention and deletion
- Unpaid uploads: no longer than 24 hours, unless you delete sooner.
- Private consumer order photos and results: normally seven days after delivery, unless needed briefly to resolve an active defect, refund or legal claim. A business account's owner-managed retention setting applies to that account instead.
- Optional share-page copies: up to 12 months from publication or renewal; unpublishing hides the page immediately and deletion removes its active assets.
- Image-free order, consent, payment, tax, security and rights-request records: only for the applicable contractual, statutory or claims period; image-free diagnostic metadata is retained for six calendar months.
- Deleting an order immediately removes its access and hides it from the service. Physical cleanup is performed by a retrying background process, subject to legal holds and the verified backup/provider schedule; we do not promise an immediate physical deletion.
- Restricted backup copies are handled separately under the verified backup and restore process and may persist for up to 30 days before deletion. Legal billing records follow their own applicable retention duties.
- Consumer private photos and results are normally retained for seven days after delivery. Business-account retention is managed by that account owner, including after cancellation. Image-free diagnostic metadata is retained for six calendar months. Deletion immediately hides the order and removes access; physical cleanup is retried and is not promised to be immediate. Restricted backup copies may persist for up to 30 days before deletion; legal billing records follow their own applicable retention duties.
7. Public share pages are different
Creating a share page is optional and separate from the seven-day private workspace. Anyone with its opaque URL can view the selected results, so recipients can copy or redistribute them. Share pages are marked noindex and omitted from our sitemap, but no technical setting can guarantee that a third party will not record or disclose the URL.
Source photos, before/after views, EXIF/GPS, filenames, order identifiers, email and payment data are never part of the public page. The owner-management token is separate from the public URL.
8. Your GDPR rights
Subject to applicable limits, you may ask for access, correction, erasure, restriction, portability, or objection; withdraw consent; and complain to the Spanish Data Protection Agency (AEPD) or your local supervisory authority. You may also ask about transfer safeguards.
Self-service export provides an image-free JSON summary and deletion immediately removes active access while physical cleanup is retried. Those tools do not narrow your statutory access rights: photos may themselves be personal data, and we assess a verified rights request under the GDPR. We may retain data that the law requires or that is necessary for a legal claim, and will explain this when applicable.
9. Google Analytics (optional)
When optional Google Analytics 4 is offered and you accept it, it measures only public marketing pages. Google Ireland Limited is the analytics provider. We send only a sanitised canonical page URL, page title, language and referring origin. We never send customer photos, order identifiers, email addresses, search queries or URL fragments. Advertising signals, ads personalisation and enhanced measurement are disabled.
Google may process analytics data outside the EEA where applicable. See Google's Privacy Policy and information about data processing: https://policies.google.com/privacy and https://business.safety.google/adsprocessorterms/.
10. Security, children and changes
We use access tokens separated from public share links, encryption in transit, private storage, input validation, least-privilege administration, audit records and bounded retention. No internet service is risk-free; report a suspected privacy or security issue through the verified contact channel.
The service is not directed to children and a person placing an order must be able to enter the contract. We publish material privacy changes before they apply and retain the notice version accepted with an order where required.