Privacy Policy
Effective date: 29 July 2026
Last updated: 29 July 2026
Version: 2026-07-29
Tuners Cafe (“we”, “us”, “our”) operates the Cruise platform, available at tunerscafe.com and through the Cruise mobile web application (“the App”). This policy explains what personal data we collect, why we collect it, who we share it with, and your rights under UK data protection law.
During account setup you’ll be asked to confirm you’ve read this policy before you can use the App. See also our Cookie Policy for details on the third-party network requests the App makes.
If you have questions, contact us at cruise@tuners.cafe.
1. Who is the Data Controller?
Tuners Cafe
United Kingdom
Contact: cruise@tuners.cafe
2. What Data We Collect and Why
2.1 Account and Identity
When you register or sign in, we collect:
| Data | Source | Purpose |
|---|---|---|
| Display name | You / Google or Facebook sign-in | Identify you within the App |
| Email address | You / Google or Facebook sign-in | Account authentication and communications |
| Phone number | You (optional) | Alternative authentication method |
| Email / phone verification status | Authentication system | Confirm account ownership |
| Date of birth | You | Confirm you meet our minimum age requirement (Section 8) |
Legal basis: Performance of contract (account creation and management); legal obligation (age verification).
2.2 Vehicle Data
When you add a vehicle to your garage, we collect:
| Data | Source | Purpose |
|---|---|---|
| UK registration mark (number plate) | You | Identify the vehicle |
| Make, model, variant | You / DVLA | Populate your garage with accurate vehicle details |
| Tax status and due date | DVLA | Informational display |
| MOT status and expiry date | DVLA | Informational display |
| Year of manufacture | DVLA | Display and categorisation |
| Engine capacity and fuel type | DVLA | Display and categorisation |
| CO₂ emissions and Euro status | DVLA | Display and categorisation |
| Colour | You / DVLA | Display and discrepancy flags |
| Date of last V5C issue | DVLA | Display |
We use your registration mark to query the DVLA Vehicle Enquiry Service (a UK government API). The full set of data returned by that query is stored against your vehicle record.
We also store your ownership status (current owner, previous owner, aspiring owner, or future owner) so you can accurately represent your relationship with each vehicle.
Legal basis: Performance of contract (garage feature); legitimate interests (providing accurate vehicle information).
2.3 Location Data (Cruising Activity)
When you start a cruising session, the App records:
| Data | Source | Purpose |
|---|---|---|
| GPS latitude and longitude | Your device | Log your cruising activity against a vehicle |
| Vehicle being driven | You | Link activity to the correct garage entry |
| Timestamp | System | Record when the activity occurred |
Location data is stored permanently in your activity history. You can delete your account to request removal.
Legal basis: Legitimate interests (providing the cruising activity feature); consent (you explicitly start a session).
2.4 Events
When you propose or attend an event, we collect:
| Data | Source | Purpose |
|---|---|---|
| Your profile ID | Account | Associate you with the event as organiser or attendee |
| Event name, location, dates | You | Create and display the event |
| Event details URL | You | Research and populate event information automatically |
| Attendee list | App interactions | Show who is attending |
When you provide an event URL, we fetch the page content from that URL to extract event details automatically (see Section 5 — OpenAI).
Legal basis: Performance of contract (event feature); legitimate interests (automating event data entry).
2.5 Chats and Chat Messages
When you join a chat and send messages, we collect:
| Data | Source | Purpose |
|---|---|---|
| Your profile ID and display name | Account | Identify message author |
| Message content | You | Display messages to chat members |
| Censored version of message content | Automated | Store a safe version where profanity has been masked |
| Profanity score | Automated | Enforce community standards |
| Profanity violation tally | Automated | Track repeat violations; trigger moderation actions |
Messages are analysed automatically for profanity. If a message contains profanity, both the original and a censored version are stored. Your violation count is tracked on your profile; repeated violations may trigger automatic suspension from chat.
Legal basis: Performance of contract (messaging feature); legitimate interests (maintaining community safety).
2.6 Subscription and Billing
If you subscribe to a paid plan:
| Data | Source | Purpose |
|---|---|---|
| Email address | Account | Stripe customer creation |
| Stripe customer ID | Stripe | Link your account to billing |
| Stripe subscription ID | Stripe | Manage your subscription |
| Subscription plan, status, and billing cycle | Stripe | Display your current plan |
| Billing period start and end dates | Stripe | Show when your plan renews |
We do not store your payment card details. All payment processing is handled directly by Stripe, which acts as a data processor under its own compliance frameworks.
Legal basis: Performance of contract (subscription management).
2.7 Friend Invitations and Connections
When you invite someone to connect:
| Data | Source | Purpose |
|---|---|---|
| Invitee email address or phone number | You | Deliver the invitation |
| Invitation token and expiry | System | Validate the invitation |
| Connection record | App interaction | Track accepted connections |
Legal basis: Legitimate interests (social connectivity feature).
2.8 Kudos (Reputation System)
We maintain a reputation score for your account. Each Kudos transaction records:
| Data | Source | Purpose |
|---|---|---|
| Points awarded or revoked | System / admin | Your reputation history |
| Reason for award | System | Explain why Kudos were given |
| Timestamp | System | Audit trail |
Legal basis: Legitimate interests (community reputation and engagement).
2.9 Notifications
We store in-app notifications triggered by platform activity (e.g., someone accepted your invitation, you received Kudos). These are tied to your profile and retained until dismissed or your account is deleted.
Legal basis: Performance of contract (in-app notification delivery).
2.10 Local Storage (Your Device)
The App stores the following data locally on your device:
| Key | Data | Purpose |
|---|---|---|
emailForSignIn |
Your email address | Temporarily held during email sign-in flow; cleared after sign-in |
cruise:defaultVehicleId |
Your last-selected vehicle ID | Restore your garage context between sessions |
| Upgrade banner dismissed | A flag (true/false) | Remember that you dismissed the upgrade prompt |
This data lives only on your device and is not transmitted to our servers independently.
3. Data We Do Not Collect
- Payment card details — handled exclusively by Stripe
- IP addresses — not logged or stored by our application
- Device identifiers or fingerprints — not collected
- Browser or device model — not collected
- Advertising identifiers — not collected
- Third-party tracking or analytics — we do not run any analytics tools (no Google Analytics, Mixpanel, Hotjar, etc.)
4. Data Processors
We use the following third parties to operate the App. Each acts as a data processor under a data processing agreement or applicable terms.
| Processor | Role | Data Shared | Location |
|---|---|---|---|
| Google Firebase | Cloud infrastructure (Authentication, database, storage, functions) | All platform data | UK / EU (europe-west2 region) |
| DVLA (Driver and Vehicle Licensing Agency) | UK vehicle registration lookup | Vehicle registration mark | United Kingdom |
| Google Places API | Address autocomplete for event locations | Address search queries | Google infrastructure |
| OpenAI | AI vehicle image generation; event URL content analysis | Vehicle make/model prompts; scraped event page content | United States |
| Stripe | Payment processing and subscription management | Email address, subscription metadata | United States (EU Standard Contractual Clauses apply) |
| Google (Sign-In) | Google account authentication | Name, email address, profile photo | Google infrastructure |
| Meta (Facebook Login) | Facebook account authentication | Name, email address | Meta infrastructure |
| Google Fonts | Loads the App’s typeface | Your device’s IP address (via the font request) | Google infrastructure |
| Google reCAPTCHA | Bot protection for phone number sign-in | Device/browser signals used for bot scoring | Google infrastructure |
Notes on international transfers
Where data is transferred outside the UK (to OpenAI and Stripe in the United States), we rely on UK International Data Transfer Agreements or Standard Contractual Clauses, as applicable under UK GDPR.
5. How Long We Keep Your Data
| Data type | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Vehicle and ownership records | Until you delete your account |
| Activity (location) history | Until you delete your account |
| Chat messages | Until deleted by you or a moderator, or your account is deleted |
| Event records | Until you delete the event or your account |
| Subscription records | 7 years (legal/tax compliance) |
| Invitation records | 90 days after expiry or acceptance |
6. Your Rights
Under UK GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate data
- Erasure — request deletion of your data (“right to be forgotten”)
- Restriction — ask us to limit how we use your data while a dispute is resolved
- Data portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — where processing relies on consent, withdraw it at any time (e.g., location tracking)
Erasure can be requested directly in the App (Profile → Delete my account), which queues your account for deletion — we aim to complete it within 30 days. For Access, Rectification, Restriction, Portability, or Object requests, contact cruise@tuners.cafe; we aim to respond within one month, as required by UK GDPR.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
7. Cookies
The App does not set advertising or analytics cookies, and we don’t run any analytics tools. It does load two third-party Google resources as part of normal operation, which is covered in full in our Cookie Policy:
- Google Fonts, to load the App’s typeface
- Google reCAPTCHA, to protect phone number sign-in from automated abuse — this can set a cookie in your browser
We use browser localStorage (described in Section 2.10) solely for functional purposes to improve your experience.
8. Children
Cruise requires users to be at least 13 years old, and we ask for your date of birth when you set up your account to enforce this. If you are 13–17, we also require confirmation that a parent or legal guardian has given permission for you to use Cruise, in line with our Terms and Conditions.
We do not knowingly collect personal data from anyone under 13. If you believe we have inadvertently collected data from a child under 13, or that a user aged 13–17 is using Cruise without appropriate permission, please contact us at cruise@tuners.cafe so we can review the account.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will update the “Last updated” date and version number at the top of this page. For material changes, we will ask you to re-confirm your agreement in the App before you can continue using it.
10. Related Documents
11. Contact Us
Tuners Cafe
cruise@tuners.cafe