Privacy policy

Last updated2026-08-16

Data controller

Thomas Vienne — contact@stemmapass.com. Any request about your data can be sent to this address.

What we collect

Account: email address, your name if you provide it, preferred language, units and currency, and a recovery address if you set one.

Vehicles: make, model, year, mileage, track hours, and — if you enter them — the VIN and registration plate.

Servicing: workshop invoices you photograph or type in, parts fitted, amounts.

Track sessions: dates, circuits, durations, distances, and any GPS traces you import.

Payment: StemmaPass never sees or stores card details. Stripe handles them alone and passes us only a customer identifier and the amount paid.

Purposes and legal bases

Running the service — keeping the log, computing wear, producing the passport and the PDF: performance of our contract.

Signing you in and securing access: performance of our contract.

Emailing you about wear and upcoming deadlines: performance of our contract, switchable off in your settings at any time.

Measuring site traffic in aggregate: legitimate interest. The measurement is cookieless and cannot identify you.

Processors and transfers outside the European Union

The service relies on the following providers, acting only on our instructions:

ProviderPurposeOutside EU
Vercelhébergement du site et journaux techniquesYes
Neonbase de données (comptes, véhicules, entretiens)No
OpenAIlecture des factures d’atelier photographiéesYes
Resendenvoi des e-mails (connexion, alertes)No
Stripepaiements et facturationYes
Cloudflaregestion du domaine et réacheminement du courrierYes
Googleconnexion par compte Google, si vous l’utilisezYes

Transfers outside the European Union rely on the European Commission’s standard contractual clauses.

One point deserves your attention: when you photograph a workshop invoice, the image is sent to OpenAI to extract the parts. It may contain your name, your registration plate and amounts. You can avoid this by entering the service by hand — the option sits alongside AI extraction everywhere it is offered.

Retention

Your data is kept for as long as your account exists.

A deleted vehicle goes to the bin and stays recoverable for thirty days, after which it is erased along with its history.

Sign-in links expire after fifteen minutes, sessions after thirty days.

Deleting your account deletes your vehicles, invoices and sessions. Billing records held by Stripe follow their own accounting obligations.

The public passport

The resale passport is published only if you switch it on, and you can switch it off at any time.

While it is on, the public page never shows your name, your email address, the VIN, the registration plate or your invoice amounts. It shows the service history, wear status and track sessions.

The link carries an unguessable identifier: it is not indexed, but anyone you send it to can read it.

Your rights

You have rights of access, rectification, erasure, restriction, objection and portability. Write to contact@stemmapass.com; we answer within one month.

You may also lodge a complaint with the French data protection authority, the CNIL — www.cnil.fr.

Cookies

StemmaPass sets a single session cookie, strictly necessary to keep you signed in. It is neither advertising nor analytics, and therefore requires no prior consent.

Traffic measurement is cookieless and uses no persistent identifier. No third-party tracker is loaded.