Privacy Policy
Last updated: 2026-07-24Effective: Draft until legal approvalVersion: 2026-07-24
How Miorly Auto handles account, profile, garage, vehicle, photo, post, message, report, device, security, and consent data.
This policy reflects the current repository and production architecture: Miorly ID authentication, Supabase database/auth/storage, Vercel hosting, Miorly Auto social and garage data, and no third-party analytics SDK currently integrated. Controller/operator details remain pending: LEGAL ENTITY DETAILS REQUIRED BEFORE PUBLIC LAUNCH.
Draft for product development. Must be reviewed by qualified legal counsel before a public production launch.
1.
Introduction
- 1.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
2.
Scope
- 2.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
3.
Controller or operator information
- 3.1LEGAL ENTITY DETAILS REQUIRED BEFORE PUBLIC LAUNCH. This placeholder must be replaced before public launch with the legally responsible entity, address, and contact details required by applicable law.
4.
Information users provide
- 4.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
5.
Miorly ID account information
- 5.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
6.
Profile information
- 6.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
7.
Garage information
- 7.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
8.
Vehicle information
- 8.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
9.
Vehicle photographs
- 9.1Vehicle photos may reveal location, license plates, people, or property. Upload flows must validate MIME/size, use owner-scoped storage paths, and avoid publishing sensitive identifiers by default.
10.
Posts and comments
- 10.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
11.
Communities
- 11.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
12.
Messages
- 12.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
13.
Reports
- 13.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
14.
Support communications
- 14.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
15.
Device and browser information
- 15.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
16.
Security logs
- 16.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
17.
Cookies
- 17.1Essential cookies are used for Supabase authentication and preferences such as theme. No marketing cookies are present in the repository audit for this phase.
18.
Analytics
- 18.1No third-party analytics SDK is currently integrated. If analytics is added later, the provider, purpose, category, and consent behavior must be documented before deployment.
19.
Approximate location
- 19.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
20.
Precise location if ever enabled
- 20.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
21.
Why information is processed
- 21.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
22.
Legal bases where applicable
- 22.1Candidate legal bases are documented for review; final legal basis selection is LEGAL REVIEW REQUIRED and must not be treated as final legal advice.
23.
Contract
- 23.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
24.
Legitimate interests
- 24.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
25.
Consent
- 25.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
26.
Legal obligations
- 26.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
27.
Fraud and security
- 27.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
28.
Moderation
- 28.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
29.
Recommendations
- 29.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
30.
Who receives information
- 30.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
31.
Service providers
- 31.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
32.
Supabase
- 32.1Supabase is used for authentication/session handling and PostgreSQL data storage. Row-level security and owner-scoped policies are the primary access-control layer.
33.
Vercel
- 33.1Vercel hosts the Next.js application and processes request/runtime logs needed to deliver and secure the service.
34.
Analytics providers actually used
- 34.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
35.
International transfers
- 35.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
36.
Retention
- 36.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
37.
Account deletion
- 37.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
38.
Data export
- 38.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
39.
Correction
- 39.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
40.
Objection and restriction
- 40.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
41.
Portability
- 41.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
42.
Marketing preferences
- 42.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
43.
Cookie preferences
- 43.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
44.
Children
- 44.1Miorly Auto is not child-directed. The age architecture should use the minimum sufficient signal, such as age band or birth year, before collecting full date of birth.
45.
Security
- 45.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
46.
Cross-border processing
- 46.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
47.
Regional rights
- 47.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
48.
Changes
- 48.1Miorly Auto processes this category only where needed to operate the service, secure accounts, support user controls, moderate abuse, or comply with applicable obligations. Final regional wording requires legal review.
49.
Contact
- 49.1Privacy contact: LEGAL CONTACT REQUIRED BEFORE PUBLIC LAUNCH.
50.
Data processing matrix
LEGAL REVIEW REQUIRED for final legal bases and regional deadlines.
- 50.1Miorly ID account data — account/session operation — stored in Supabase Auth/identity — controlled through Miorly ID — candidate basis: contract/security.
- 50.2Profile data — identity in Auto social surfaces — stored in identity/auto profile tables — editable by user — candidate basis: contract.
- 50.3Garage and vehicle specs — garage, recommendations, vehicle-linked posts — stored in auto vehicle tables — user controls visibility — candidate basis: contract.
- 50.4VIN/plate/private vehicle identifiers — private garage operation only — private table/view restrictions — deleted/anonymized on account closure unless hold applies — candidate basis: contract/security.
- 50.5Reports and moderation records — safety, abuse prevention, DSA-style notices — stored in social moderation tables — appeal/status controls — candidate basis: legitimate interests/legal obligations where applicable.
- 50.6Security/runtime logs — reliability and fraud/security — retained for limited periods — not user-editable but subject to lawful request where applicable — candidate basis: legitimate interests/security.
Official sources reviewed
- European Commission — Data protection in the EU
- European Commission — GDPR individual rights
- EDPB — Process personal data lawfully
- FTC — Privacy and Security business guidance
- California Privacy Protection Agency — CCPA regulations
- ICO — UK GDPR right to be informed
- Japan Personal Information Protection Commission
- OPC Canada — PIPEDA fair information principles
- OAIC — Australian Privacy Principles
- Korea PIPC — PIPA guidance for foreign operators
- Brazil Planalto — LGPD Law No. 13.709/2018
