Privacy Policy
Data controller: Ainamotive Oy
Business ID (Y-tunnus): 3648210-1
VAT number: FI36482101
Contact: info@remapify.net
Effective date: 2026-08-25
This Privacy Policy explains how Remapify collects, uses, and protects personal data when you use our platform and services. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Finnish data-protection law.
1. Who we are
Remapify is the data controller responsible for the personal data described in this policy. If you have any questions about this policy or about how we handle your data, contact us at info@remapify.net.
2. What data we collect
We collect and process the following categories of personal data:
Account data: the email address you register with, your password (stored only in hashed form; we never see or store your plaintext password), and two-factor authentication details (we store a secret enabling time-based codes; we do not store your codes).
Billing profile data: whether you are buying as a business or as a private individual, the name to appear on your invoice, your billing address, your VAT number where you provide one, and your phone number. We also record which version of our Terms of Service you accepted, and when.
Payment data: we do not see or store your card details. Payments are processed by Stripe on their own systems. We store what we need to account for the sale: the amount, the currency, the tax treatment, the billing details as they stood at the time of payment, and Stripe's own identifiers for the payment.
Service data: the vehicle and file information you submit as part of a File Request (for example: vehicle make, model, engine code, gearbox type, mileage, VIN or registration number where you choose to provide it, ECU model, read tool, and any notes you add), the files you upload and download, your credit balance and transaction history, and your messages in support chats and tickets.
Technical and security data: information needed to operate the service securely, including login and security events, and limited device information used for the “trusted device” feature (a browser/operating-system label such as “Chrome on Windows”, and, where available from our security provider, the country associated with a login). We do not store your full IP address as part of the trusted-device feature.
Communications: the content of messages, support tickets, and emails you exchange with us.
3. How we use your data, and our legal bases
We process your personal data for the following purposes and on the following legal bases under the GDPR:
- To provide the service (create and manage your account, process File Requests, deliver files, manage credits, provide support), legal basis: performance of a contract.
- To secure the service (authentication, two-factor authentication, trusted-device recognition, fraud and abuse prevention, audit logging), legal basis: legitimate interests in keeping the platform and its users secure, and, where applicable, legal obligation.
- To send you service-related notifications (for example, that a file is ready, that you have a reply, or a security notice), legal basis: performance of a contract and legitimate interests. You can control which email notifications you receive in your account settings.
- To keep business and accounting records (for example, records of transactions), legal basis: legal obligation and legitimate interests.
- To improve and maintain the service, legal basis: legitimate interests.
Where we rely on legitimate interests, we have balanced those interests against your rights and consider the processing proportionate. You may object to such processing (see Section 8).
4. Notifications and marketing
We send service-related (transactional) notifications as part of providing the service. You can manage which email notifications you receive from your account settings at any time. We do not sell your personal data. We do not use your data for third-party advertising.
5. File content
The vehicle files you upload and the files we return are processed to provide the engineering service you request. File content and the vehicle information attached to a File Request are accessible only to you and to authorised Remapify personnel, and are protected by access controls on our platform. We recommend you keep your own backups of both your original reads and the files we supply.
6. Who we share data with (processors)
We do not sell your personal data. We share it only with service providers (“processors”) that help us operate the platform, and only to the extent necessary. These providers process data on our instructions under data-processing agreements. Our principal processors are:
- Supabase: database, authentication, and file storage (storing account data, billing data, service data, and uploaded/processed files).
- Netlify: hosting and delivery of the web application.
- Cloudflare: content-delivery network and security protection for the platform.
- Stripe: payment processing and invoicing. Stripe receives your billing name and address, your email address, your VAT number where you have provided a verified one, and the details of the purchase. Your card details go to Stripe directly and never reach us.
- Resend: email delivery (sending account, verification, and notification emails).
- Cloudmersive: antivirus scanning. Files you upload are scanned for malware before they are made available. This means the content of an uploaded file is transmitted to the scanning service for the purpose of that check.
- Anthropic: an assistance feature available only to our own staff, used to review entries in our vehicle reference database. It receives records from that catalogue. It does not receive your account data, your billing data, your messages, or any file you upload.
We also use the EU Commission's VIES service to check a VAT number you enter. That is a verification lookup against an official EU system rather than a processor acting on our instructions.
We may also disclose personal data where required by law, regulation, or valid legal process.
6a. Transfers outside the EEA
Several of the providers listed above are established in the United States or process data there, including Netlify, Cloudflare, Stripe, Resend, Cloudmersive, and Anthropic. Where personal data is transferred outside the European Economic Area, we rely on the safeguards permitted under Chapter V of the GDPR, which are the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. You can ask us for details of the safeguard relied on for a particular provider at info@remapify.net.
7. How long we keep data
We keep personal data only for as long as necessary for the purposes described in this policy. The periods below are the longest we keep each category. We review stored data regularly and delete it once its period has passed, and you can ask us to delete your data sooner (see Section 8).
- Account and billing profile data: for as long as your account exists, and for 12 months after you close it, so that we can deal with anything arising from your last orders.
- Uploaded and processed files, and the job records attached to them: 24 months after delivery. That is the period in which support questions and revision requests actually arrive. Please keep your own backups of both your original read and the file we supply.
- Support messages and tickets: 24 months after the conversation ends.
- Accounting records (invoices, payments, and the credit transactions behind them): 6 years from the end of the financial year, as Finnish bookkeeping law requires. We cannot delete these on request.
- Security and audit records (login and security events, the audit log of significant actions): 24 months.
- Trusted-device records: 30 days from when the device was trusted, or immediately when you revoke it.
Where a legal obligation, an unresolved dispute, or the establishment or defence of a legal claim requires us to keep something longer, we keep it for as long as that requires and no longer. When data is no longer needed, we delete or anonymise it.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure of your data in certain circumstances;
- request restriction of processing in certain circumstances;
- object to processing based on our legitimate interests;
- request portability of certain data you provided to us; and
- withdraw consent where we rely on consent (this does not affect processing carried out before withdrawal).
To exercise any of these rights, contact us at info@remapify.net. We will respond within the time limits set by the GDPR.
You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), the supervisory authority for data protection in Finland, if you believe your data has been handled unlawfully.
9. Security
We take appropriate technical and organisational measures to protect your personal data, including encryption of data in transit, hashed password storage, mandatory two-factor authentication, row-level access controls that isolate each customer's data, and audit logging of significant actions. No system can be guaranteed perfectly secure, but we work to protect your data and to respond appropriately to any security incident.
10. Cookies and similar technologies
We use only the cookies necessary to operate the service, for example, to keep you signed in and to support the trusted-device feature. We do not use third-party advertising or tracking cookies.
11. Changes to this policy
We may update this Privacy Policy from time to time. Updated versions take effect when published on the platform. We will take reasonable steps to notify you of material changes.
12. Contact
For any question about this policy or your personal data, contact us at info@remapify.net.