Back to Carboost

Privacy Policy

Last updated: 2026-03-11

1. Who We Are

Carboost is operated by Krisdevs, a company registered in Belgium (BE 0778.905.149) ("we", "us", or "our").

We are the data controller responsible for your personal data processed through the Carboost platform (carboost.app). For any questions regarding this policy or your personal data, contact us at [email protected].

2. Data We Collect

We collect and process the following categories of personal data:

Account data

  • Name, email address, profile picture (provided directly or via Google OAuth)
  • Optional profile information: bio, username, location, website, social media handles (GitHub, LinkedIn, X/Twitter)
  • Account credentials (password hash for email/password authentication)

Authentication & session data

  • OAuth tokens (access, refresh, ID tokens from Google)
  • Session tokens and expiry timestamps
  • IP address and user agent (browser/device information)

Vehicle data

  • Vehicle details you enter or import: make, model, year, price, mileage, specifications, condition, location, description
  • Vehicle images (uploaded by you or imported from listings)
  • AI-generated content: image classifications, descriptions, voiceover transcripts

Video data

  • Generated video files, voiceover audio, subtitles, scene compositions
  • Template selections, music choices, voice preferences

Payment data

  • Subscription details: plan, status, billing period, amount
  • Payment processor customer ID (Polar). We do not store credit card numbers or payment method details directly.
  • Credit transaction history and usage records

Organization & team data

  • Organization name, logo, contact details
  • Team member roles and invitation records

Outreach data (dealer outreach feature)

  • Dealer contact information: name, email, phone, address, website
  • Communication records: email subject, body, touchpoint history
  • Campaign page visit data (tracked internally, not via third-party pixels or email tracking)

Usage & technical data

  • AI credit consumption: token counts, character counts, render durations
  • Feature usage patterns and error logs
  • Language/locale preference

3. How We Collect Your Data

We collect data through the following means:

  • Directly from you: when you create an account, fill in vehicle details, upload images, configure videos, or contact us
  • From OAuth providers: when you sign in with Google, we receive your name, email, and profile picture as authorized by you
  • Automatically: IP address, user agent, and session data are collected when you use the platform
  • From third-party sources: vehicle listing data when you import from car marketplace URLs
  • Generated by our systems: AI-generated descriptions, transcripts, image classifications, and rendered videos

5. How We Use Your Data

We use your personal data to:

  • Provide and operate the Carboost platform, including account management, vehicle listings, video generation, and outreach features
  • Process your payments, manage subscriptions, and allocate credits
  • Generate AI-powered content: voiceover scripts, image descriptions, vehicle analysis
  • Render and deliver video advertisements
  • Send transactional communications (organization invitations, outreach emails on your behalf)
  • Maintain platform security and prevent fraud
  • Comply with legal obligations (tax records, regulatory requirements)
  • Improve our services based on usage patterns

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

6. Third-Party Processors

We share your personal data with the following third-party service providers (sub-processors) who process data on our behalf:

ProviderPurposeData sharedLocation
CloudflareFile storage (R2), video rendering (Containers)Images, videos, audio filesGlobal / United States
Google (Gemini AI)Transcript generation, vehicle analysisVehicle data, images, listing textUnited States
ElevenLabsText-to-speech voice generationVoiceover scriptsUnited States
PolarPayment processingEmail, name, subscription dataUnited States
ResendEmail deliveryEmail addresses, email contentUnited States
Google OAuthAuthenticationEmail, name, profile pictureUnited States

Each sub-processor is bound by a Data Processing Agreement (DPA) and is required to process your data only for the specified purposes with appropriate security measures in place.

We maintain an up-to-date list of sub-processors. If we add new sub-processors, we will update this policy accordingly.

7. International Data Transfers

Your personal data is transferred to and processed in the United States by our sub-processors. These transfers are protected by the following safeguards:

  • EU-U.S. Data Privacy Framework (DPF): Cloudflare, Google, and Polar are certified under the EU-U.S. Data Privacy Framework, which the European Commission recognized as providing adequate protection (adequacy decision of July 2023).
  • Standard Contractual Clauses (SCCs): Where a provider is not DPF-certified or as an additional safeguard, we rely on the European Commission's Standard Contractual Clauses incorporated into our Data Processing Agreements.
  • Supplementary measures: All data is encrypted in transit (TLS) and at rest. Access is limited to authorized personnel only.

You may request a copy of the relevant transfer safeguards by contacting us at [email protected].

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

Data categoryRetention period
Account dataDuration of your account, plus 30 days after deletion
Session data & tokens30 days (auto-expiry)
Generated videos7 days after generation (automatically deleted)
Vehicle data & imagesDuration of your account or until you delete them
Payment & billing records7 years (Belgian tax law requirement)
Security logs (IP, user agent)12 months
Outreach email recordsDuration of your account or until you delete them
AI usage logs12 months

When data is no longer needed, it is securely deleted or anonymized. Backup systems may retain data for up to an additional 30 days before purging.

9. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights:

  • Right of access (Art. 15): Request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Right to restriction (Art. 18): Request that we limit the processing of your data in certain circumstances.
  • Right to data portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format (JSON or CSV).
  • Right to object (Art. 21): Object to processing based on legitimate interests. For direct marketing, this right is absolute.
  • Right to withdraw consent (Art. 7(3)): Withdraw consent at any time where processing is consent-based, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at [email protected]. We will respond within one month. In complex cases, this may be extended by two additional months, and we will inform you of any extension.

If you are unsatisfied with our response, you have the right to lodge a complaint with the Belgian Data Protection Authority (APD/GBA):

10. Cookies

We use a minimal number of cookies, all of which are strictly necessary for the operation of our platform:

CookiePurposeDurationType
Session cookieMaintains your authenticated session30 daysStrictly necessary
Locale cookieRemembers your language preference (en/fr/nl)1 yearStrictly necessary

We do not use analytics cookies, marketing cookies, tracking pixels, or any third-party tracking scripts. Since we only use strictly necessary cookies, no cookie consent banner is required under the ePrivacy Directive.

If we introduce non-essential cookies in the future, we will implement a cookie consent mechanism and update this policy before doing so.

11. Children's Privacy

Carboost is a business service not directed at children. We do not knowingly collect personal data from anyone under the age of 16. Under Belgian law, the digital age of consent is 13 years.

If you believe we have inadvertently collected data from a child, please contact us at [email protected] and we will promptly delete such data.

12. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption in transit (TLS/HTTPS) for all data transmissions
  • Encryption at rest for stored data via our infrastructure providers
  • OAuth token encryption in the database
  • Access controls and role-based permissions
  • Webhook signature verification for third-party integrations
  • Regular security reviews of our codebase and infrastructure

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Belgian Data Protection Authority within 72 hours and inform affected individuals without undue delay where the risk is high.

13. Changes to This Policy

We may update this privacy policy from time to time. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, by sending a notification via email or through the platform.

We encourage you to review this policy periodically to stay informed about how we protect your data.

14. Contact Us

For any questions about this privacy policy, to exercise your data protection rights, or to raise a concern, contact us at:

  • Email: [email protected]
  • Company: Krisdevs
  • Location: Genk, Belgium
  • Company number: BE 0778.905.149