Privacy information

Privacy policy

Updated: 29 August 2026Legally binding version: German

This English version is provided for information. The German Datenschutzerklärung is the legally binding version.

1. Controller

MG AutoTech, owner Melih Gökkaya
Böckinger Str. 32, 70437 Stuttgart, Germany
E-mail: info@mgautotech.de
Telephone: +49 151 51561670

2. Data processed and purposes

We process master data, contact details, customer and account identifiers, vehicle and control-unit data, order and service data, messages, payment status, uploaded original files, delivered file versions, and technical security and access logs.

Processing is carried out to provide the customer account, perform File Service orders, handle billing and communication, secure the portal, diagnose errors, and meet legal record-keeping obligations.

3. Legal bases

The legal bases include Article 6(1)(b) GDPR for contracts and pre-contractual steps, Article 6(1)(c) GDPR for legal obligations, Article 6(1)(f) GDPR for IT security, abuse prevention and reliable service operation, and Article 6(1)(a) GDPR where consent is requested.

4. Hosting, database and file storage

The public website and File Service application run on a virtual private server (VPS) provided by Hostinger. Supabase provides customer accounts and authentication, database functions, and file storage.

Access to the website and application passes through Cloudflare as a CDN, reverse proxy and security service; Caddy forwards requests to the application on the VPS. For these purposes, Cloudflare may process technical connection and security data such as IP address, time, requested resource, browser and device information, and security signals.

These services process the data required for their respective technical functions. This may include the account, order and file data described above, as well as technical connection data such as IP address, time, requested resource, browser information and security events.

5. E-mail and support

Transactional and notification e-mails are sent through Resend. This involves processing the recipient address, message content, delivery status and technical delivery information. Direct support enquiries are stored to handle and document the request.

6. Payments

Depending on the selected method, card payments are handled by Stripe, or bank transfers are assigned manually. Stripe processes payment and transaction data under its own data-protection responsibility. MG AutoTech generally receives only the payment status and reference information needed for assignment, confirmation, accounting and fraud prevention. Bank transfers are assigned using the transmitted bank and payment-reference data.

7. Sign-in and Google login

Technically required authentication information and session cookies are used for sign-in. If you voluntarily choose “Continue with Google”, you are directed to Google, which processes the data needed for sign-in. MG AutoTech receives the basic profile data released by Google, such as e-mail address and name.

We use Cloudflare Turnstile for protected authentication flows. Cloudflare processes technical connection, browser, device and security signals to detect automated or abusive access. The resulting verification token is sent to Supabase with the relevant authentication operation and is verified there on the server side.

8. Cookies, browser storage and optional measurement

We use technically necessary cookies and browser storage for sign-in, session management, language selection, security functions and saving your privacy choice. Analytics and advertising measurement are disabled by default and are enabled only after your active choice.

If you consent to analytics, Google Analytics is used on approved public content pages to measure page use and the secure request funnel. If you additionally consent to advertising measurement, Google Ads is used to understand whether an advertisement leads to a verified registration, request or payment. Personalized advertising remains disabled.

Only information intended for measurement is sent to Google. This may include the sanitized public page path without query parameters or fragments, browser and device information, consent state, and available campaign or ad-click identifiers. For verified outcomes, the event type, a pseudonymous deduplication identifier and, for a verified payment, amount and currency may also be sent. File names, vehicle data, e-mail addresses, account data and order numbers are not sent to Google as measurement events.

With analytics consent, MG AutoTech also uses a random visitor identifier and processes the public landing path, source and medium, an allow-listed campaign name, referrer domain only, an available country code and browser language for internal campaign attribution. After successful sign-in, this identifier can be linked internally to verified account events so registrations, requests and payments can be attributed to their source. Search terms and complete referrer URLs are not stored for this purpose; the visitor identifier is processed on the server as a one-way value.

You can change or withdraw your choice at any time through the privacy settings available on the website. Withdrawal applies to future processing.

9. Vehicle Selector Widget

When an embedded widget is loaded, technical access data is processed to deliver it, verify the domain, diagnose errors, enforce usage limits and prevent abuse. This may include the time, path, approved and requesting domain, language, browser identifier, access status and a non-reversible hash of the IP address. The raw IP address is not stored in the widget access log.

When a vehicle is selected, only the vehicle data required for that specific selection is sent to the previously approved website. Operators of embedding websites remain responsible for their own privacy information, contact forms and further processing.

10. Storage duration

We retain data only for as long as needed for the account, order, support, security and billing purposes. Contract, payment and booking data is retained in line with legal retention obligations. Files and technical logs are deleted or anonymised when their purpose no longer applies and no contractual, security-related or legal reason requires continued retention.

11. Your rights

Subject to the GDPR, data subjects have rights of access, rectification, erasure, restriction of processing, data portability and objection. Consent can be withdrawn at any time with effect for the future.

Please send requests to info@mgautotech.de. You also have the right to complain to a data-protection supervisory authority, particularly the authority responsible for Baden-Württemberg.

12. Data security and updates

We use appropriate technical and organisational measures, including encrypted transmission, role-based access, private file storage, time-limited download links, server-side permission checks and logging of security-relevant operations.

This privacy information will be updated when the services used or processing workflows materially change.