Privacy Policy
Effective: May 27, 2026.
This privacy policy describes how localcars.me (“We,” “our,” or “the site”) collects, uses, and protects your personal data in accordance with the Montenegro Personal Data Protection Act and the EU General Data Protection Regulation (GDPR).
1. Data Controller
localcars.me, based in Montenegro.
Email for privacy questions: podrska@localcars.me
2. What We Collect
• Company registration: company name, contact person, email, phone, address, tax ID.
• Booking data: customer name, email, phone, pickup dates and location.
• Technical data: IP address, device type, browser, anonymized analytics traffic.
• Cookies: see our Cookie Policy.
3. Purposes of Processing
• Processing bookings and communicating with companies.
• Sending transactional emails (booking confirmation, cancellation, reminders).
• Improving the site and preventing abuse (rate limiting, audit log).
• Legal obligations (accounting, invoicing).
4. Legal Basis
• Contract performance (booking, company subscription).
• Legitimate interest (site security, analytics).
• Consent (marketing emails — optional, you can withdraw).
• Legal obligation (record retention).
5. Who We Share With
• The company whose vehicle you booked — necessary for service delivery.
• Email provider (Mailgun) for transactional emails.
• Hosting and CDN providers (Apache server in Montenegro, Cloudflare for static assets).
We never sell personal data to third parties.
6. Retention Period
• Booking data: 5 years (tax and legal obligations).
• Technical logs: 90 days.
• Marketing consent: until withdrawn.
7. Your Rights (GDPR)
• Right to access your data.
• Right to rectification of inaccurate data.
• Right to erasure (“right to be forgotten”).
• Right to restriction of processing.
• Right to data portability.
• Right to object.
• Right to lodge a complaint with the Montenegro Personal Data Protection Agency.
To exercise rights, write to: podrska@localcars.me — we respond within 30 days.
8. Security
We use HTTPS (TLS 1.3), httpOnly secure cookies, JWT authentication, rate limiting, and regular backups. Containers are isolated on a secured server in Montenegro.
9. Minors
The site is not intended for persons under 18. We do not knowingly collect data from minors.
10. Policy Changes
We may update this policy. The current version is always available on this page. Material changes will be announced via email to registered users.