Privacy Policy

Our privacy policy and how we use your data

Article 1 — Scope, Applicability, and Definitions

This Privacy Policy ("Policy") describes how Gearz ("Gearz," "we," "us," or "our") collects, uses, discloses, and protects information when you access or use our website, web and mobile applications, and all related services (collectively, the "Service"). The Service includes, without limitation, the Gearz social platform, vehicle garage features, club management tools, event discovery, ticketing, and gamification features such as the Gearhead Score.

This Policy applies to all individuals who access or use the Service, whether as registered members, event attendees, club organizers, or casual visitors. It does not govern information you share directly with other users, club organizers, or third-party services linked from the Service.

Throughout this Policy, the following definitions apply:

  • "Personal Data" means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked — directly or indirectly — to an identified or identifiable natural person.
  • "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
  • "Controller" means the entity that determines the purposes and means of Processing Personal Data. For the purposes of this Policy, Gearz is the Controller.
  • "Service" means all Gearz websites, applications, features, and related services, including subscription tiers (Enthusiast, Tuner, Gearhead, and Crew Chief).

Article 2 — Data Controller and Contact

Gearz is the Controller of Personal Data processed through the Service. We are responsible for deciding how and why your Personal Data is processed, and for ensuring that such Processing complies with applicable data-protection laws.

If you have questions, concerns, or requests regarding this Policy or the Processing of your Personal Data, you may contact us at:

We aim to respond to all legitimate requests within thirty (30) calendar days. In certain circumstances, it may take longer if your request is particularly complex or you have made multiple requests, in which case we will notify you and keep you informed of our progress.

Article 3 — Categories of Personal Data Collected

Depending on how you interact with the Service, we may collect the following categories of Personal Data:

  • Identity Data: First name, last name, username, display name, profile photograph, and date of birth.
  • Contact Data: Email address, telephone number, and postal address (where provided).
  • Vehicle Data: Make, model, year, trim, modifications, vehicle photographs, nicknames, and other garage details you choose to share.
  • Technical Data: Internet Protocol (IP) address, browser type and version, operating system, device identifiers, time-zone setting, language preferences, and other technologies present on the devices you use to access the Service.
  • Profile Data: Username, password (stored in hashed form), club memberships, event attendance history, social connections, Gearhead Score and its component metrics, interests, preferences, feedback, and survey responses.
  • Usage Data: Information about how you use the Service, including pages viewed, features accessed, search queries, click paths, session duration, and interactions with clubs, events, and the activity feed.
  • Transaction and Payment Data: Subscription tier (Enthusiast, Tuner, Gearhead, or Crew Chief), billing address, transaction history, and ticket purchases. Payment-card details are processed by our third-party payment processor, Stripe, and are not stored on our servers.
  • Location Data: Approximate geolocation derived from your IP address or, with your explicit consent, precise geolocation from your device, used to display nearby events and clubs.
  • Communications Data: Preferences regarding marketing communications, notification settings, and records of correspondence between you and Gearz.

Article 4 — How We Collect Personal Data

4.1 Information You Provide Directly

We collect Personal Data that you voluntarily submit when you create an account, complete your profile, add vehicles to your garage, join or create a club, RSVP to or purchase tickets for an event, post to the activity feed, subscribe to a paid tier, or contact us for support.

4.2 Information Collected Automatically

When you access the Service, we automatically collect Technical Data and Usage Data through server logs, cookies, pixel tags, and similar technologies. This information helps us operate, maintain, and improve the Service.

4.3 Information From Third Parties

We may receive Personal Data about you from third-party sources, including:

  • Authentication providers: If you sign in using a social login (e.g., Google or Apple), we receive your name, email address, and profile image from that provider.
  • Payment processors: Stripe may provide us with transaction-confirmation data and limited billing information necessary to maintain your subscription and ticket records.
  • Public sources: We may supplement your profile with publicly available information where relevant and lawful.

Article 5 — Purposes and Legal Bases for Processing

We process Personal Data only where we have a valid legal basis to do so. The table below sets out the primary purposes for which we process your Personal Data and the corresponding legal basis under applicable data-protection law.

PurposeLegal Basis
Create and manage your account, profile, and subscriptionPerformance of a contract
Process ticket purchases and subscription payments via StripePerformance of a contract
Operate club management, event discovery, garage features, and the activity feedPerformance of a contract
Calculate and display your Gearhead Score and gamification metricsLegitimate interest
Send transactional communications (e.g., receipts, event reminders, account alerts)Performance of a contract
Send promotional or marketing communications about Gearz features and eventsConsent (or legitimate interest where permitted)
Display nearby events and clubs based on your locationConsent (precise) / Legitimate interest (approximate)
Improve, personalize, and secure the Service, including fraud detection and abuse preventionLegitimate interest
Conduct analytics and research to understand usage patternsLegitimate interest
Comply with legal obligations, respond to lawful requests, and protect our rightsLegal obligation / Legitimate interest

Where Processing is based on consent, you may withdraw that consent at any time by contacting us at privacy@gearz.io or by adjusting your account settings. Withdrawal of consent does not affect the lawfulness of Processing carried out before withdrawal.

Article 6 — Disclosures to Third Parties

We do not sell your Personal Data. We may share your Personal Data with the following categories of recipients, only to the extent necessary for the purposes described in this Policy:

6.1 Service Providers

We engage third-party vendors who process Personal Data on our behalf to provide infrastructure, payment processing, analytics, communication, and support services. Key providers include:

  • Supabase — authentication, database hosting, and file storage
  • Vercel — application hosting and edge delivery
  • Stripe — payment processing for subscriptions and event tickets

Each service provider is contractually obligated to process Personal Data only in accordance with our instructions and applicable data-protection law.

6.2 Club Organizers

When you join a club or RSVP to a club event, certain Profile Data and Vehicle Data may be shared with the club's organizer(s) to facilitate membership management and event coordination. Organizers receive only the data necessary for these purposes.

6.3 Legal and Regulatory Authorities

We may disclose Personal Data to law enforcement, regulatory bodies, or other public authorities where we are legally required to do so, or where disclosure is reasonably necessary to protect our rights, safety, or property, or those of our users or the public.

6.4 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your Personal Data may be transferred to the acquiring entity. We will notify you via email and/or a prominent notice on the Service before your Personal Data is transferred and becomes subject to a different privacy policy.

6.5 With Your Consent

We may share your Personal Data with other third parties when you have given us your explicit consent to do so, or when you direct us to share it (for example, sharing your garage publicly or posting on the activity feed).

Article 7 — Cookies and Tracking Technologies

We use cookies, pixel tags, local storage, and similar technologies to operate the Service, remember your preferences, understand usage patterns, and improve your experience. These technologies may collect Technical Data and Usage Data as described in Article 3.

We classify cookies into the following categories:

  • Strictly Necessary: Required for the Service to function (e.g., authentication tokens, session identifiers). These cookies cannot be disabled.
  • Functional: Enable enhanced functionality and personalization (e.g., language preferences, theme settings).
  • Analytics: Help us understand how the Service is used so we can measure performance and improve features.

Where required by law — including in the European Economic Area (EEA), the United Kingdom (UK), and under the ePrivacy Directive — we obtain your consent before placing non-essential cookies on your device. You may manage your cookie preferences at any time through the cookie-consent banner or your browser settings.

For complete details on the cookies we use, their purposes, and how to manage them, please refer to our Cookie Policy.

Article 8 — International Data Transfers

Gearz is operated from the United States. If you access the Service from outside the United States — including from the EEA, UK, or Switzerland — your Personal Data may be transferred to, stored in, and processed in the United States or other countries that may not provide the same level of data-protection as your jurisdiction of residence.

Whenever we transfer Personal Data outside the EEA, UK, or Switzerland, we implement appropriate safeguards designed to ensure that your data receives a level of protection substantially equivalent to that provided under European data-protection law. These safeguards include:

  • Transferring to countries that the European Commission has recognized as providing an adequate level of data protection.
  • Using Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision (EU) 2021/914), and, for UK transfers, the UK International Data Transfer Addendum (IDTA).
  • Requiring our service providers to maintain technical and organizational security measures that meet or exceed the requirements of applicable data-protection law.

You may request a copy of the safeguards we have put in place by contacting us at privacy@gearz.io.

Article 9 — Data Security

We implement reasonable administrative, technical, and physical safeguards designed to protect your Personal Data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures include, but are not limited to:

  • Encryption of data in transit (TLS/SSL) and at rest where applicable.
  • Row-level security (RLS) policies enforced at the database layer to ensure users may access only data they are authorized to view.
  • Authentication managed by Supabase Auth, with support for multi-factor authentication (MFA).
  • Access controls that limit employee and contractor access to Personal Data on a need-to-know basis.
  • Regular monitoring of our systems for vulnerabilities and potential incidents.

No method of electronic transmission or storage is completely secure. While we strive to use commercially reasonable means to protect your Personal Data, we cannot guarantee absolute security. If you have reason to believe your interaction with the Service is no longer secure, please contact us immediately at privacy@gearz.io.

Article 10 — Data Retention

We retain your Personal Data only for as long as reasonably necessary to fulfill the purposes for which it was collected, including to satisfy legal, regulatory, tax, accounting, or reporting obligations. The specific retention period depends on the nature of the data and the purpose of Processing.

The following are illustrative retention periods:

  • Account Data: Retained for the lifetime of your account. If you delete your account, we will erase or anonymize your Personal Data within ninety (90) days, unless retention is required by law.
  • Transaction Records: Retained for up to seven (7) years following the transaction date to comply with tax and financial-reporting obligations.
  • Usage and Analytics Data: Retained in identifiable form for up to twenty-four (24) months, after which it is aggregated or anonymized.
  • Communications Preferences: Retained for as long as necessary to honor your opt-out or unsubscribe requests.
  • Security Logs: Retained for up to twelve (12) months for incident-investigation and fraud-prevention purposes.

When we no longer have a legitimate business need to process your Personal Data, we will either delete it or anonymize it in accordance with applicable law. If deletion is not immediately possible (for example, because data resides in backup archives), we will securely isolate it from further Processing until deletion is feasible.

Article 11 — Your Rights Under the GDPR

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and equivalent local laws afford you certain rights with respect to your Personal Data. Subject to applicable exceptions, you have the right to:

  • Access — Request confirmation of whether we process your Personal Data and, if so, obtain a copy of such data.
  • Rectification — Request correction of inaccurate or incomplete Personal Data we hold about you.
  • Erasure — Request deletion of your Personal Data where there is no compelling reason for its continued Processing (commonly referred to as the "right to be forgotten").
  • Restriction of Processing — Request that we restrict the Processing of your Personal Data in certain circumstances (e.g., while we verify the accuracy of your data following a challenge).
  • Data Portability — Request a copy of the Personal Data you provided to us in a structured, commonly used, machine-readable format, and request that we transmit it to another controller where technically feasible.
  • Objection — Object to Processing of your Personal Data where we rely on legitimate interest as the legal basis, including for profiling or direct marketing.
  • Withdraw Consent — Where Processing is based on your consent, withdraw that consent at any time without affecting the lawfulness of Processing carried out before withdrawal.
  • Lodge a Complaint — Lodge a complaint with your local data-protection supervisory authority. A list of EEA supervisory authorities is available on the European Data Protection Board website.

To exercise any of these rights, please contact us at privacy@gearz.io with the subject line "GDPR Rights Request." We may ask you to verify your identity before fulfilling your request. We will respond within thirty (30) days, or within the extended period permitted by applicable law if necessary.

Article 12 — Your Rights Under the CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your Personal Data:

  • Right to Know — You have the right to request that we disclose the categories and specific pieces of Personal Data we have collected about you, the categories of sources from which it was collected, the business or commercial purposes for collection, and the categories of third parties with whom it was shared.
  • Right to Delete — You have the right to request that we delete the Personal Data we have collected about you, subject to certain legal exceptions.
  • Right to Correct — You have the right to request that we correct inaccurate Personal Data.
  • Right to Opt-Out of Sale or Sharing — We do not sell your Personal Data for monetary consideration. To the extent that any data sharing for targeted advertising may be considered a "sale" or "sharing" under the CCPA, you have the right to opt out. You may exercise this right by contacting us at privacy@gearz.io.
  • Right to Non-Discrimination — We will not discriminate against you for exercising any of your CCPA rights. You will not receive a different level of service or pricing as a result of exercising your rights.

To submit a request, email us at privacy@gearz.io with the subject line "CCPA Rights Request." We will verify your identity by matching information you provide against our records. We will respond within forty-five (45) days, or within the extended period permitted by the CCPA if necessary.

Article 13 — Children's Privacy

The Service is not directed at individuals under the age of sixteen (16). We do not knowingly collect Personal Data from children under 16. If you are under 16, please do not register for the Service or submit any Personal Data to us.

If we become aware that we have collected Personal Data from a child under 16 without verifiable parental consent, we will take reasonable steps to delete such data promptly. If you believe a child under 16 has provided Personal Data to us, please contact us at privacy@gearz.io so that we may investigate and take appropriate action.

For users in the United States, this commitment is consistent with the requirements of the Children's Online Privacy Protection Act (COPPA).

Article 14 — Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will revise the "Last updated" date at the top of this Policy.

For material changes — such as a new category of Personal Data being collected, a change in the purposes of Processing, or a reduction in your rights — we will provide you with at least thirty (30) days' advance notice by posting a prominent notice on the Service and, where you have provided us with an email address, sending you an email notification.

Your continued use of the Service after the effective date of a revised Policy constitutes your acceptance of the changes. If you do not agree with any modification, you should discontinue use of the Service and, if applicable, delete your account.

Article 15 — Contact Information

If you have any questions, concerns, or requests regarding this Policy or our privacy practices — or if you wish to exercise any of your rights described herein — please contact us:

If you are located in the EEA, UK, or Switzerland and are not satisfied with our response, you have the right to lodge a complaint with your local data-protection supervisory authority. We nonetheless encourage you to contact us first so that we may attempt to resolve your concern directly.