Privacy Policy
Effective date: 27 May 2026
In the event of any discrepancy between the Hungarian and English versions of this Privacy Policy, the Hungarian version shall prevail.
1. Introduction
The purpose of this Privacy Policy is to provide clear, detailed and transparent information about the processing of personal data carried out during the use of the website, online store and CarColor Android mobile application operated by CarColor 2000 Kft.
CarColor 2000 Kft. pays particular attention to the protection of personal data and processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation (GDPR), the applicable Hungarian data protection laws, and other relevant consumer protection and electronic commerce regulations.
This Privacy Policy applies to visitors of the website, registered users of the online store, customers, newsletter subscribers, persons contacting customer service, and users of the CarColor Android mobile application.
2. Data Controller details
Data Controller: CarColor 2000 Kft.
Registered office: 1195 Budapest, Vas Gereben utca 4/d., Hungary
Company registration number: 01 09 467424
Tax number: 12125021-2-43
EU VAT number: HU 12125021
Data processing registration number: NAIH-76731/2014.
E-mail: [email protected]
Website: https://www.carcolor.hu/
Online store: https://www.carcolor.hu/shop/
In this Privacy Policy, the Data Controller is hereinafter referred to as the Data Controller, Service Provider or CarColor.
3. Definitions
The terms used in this Privacy Policy have the meanings defined in the GDPR. The most important terms are:
- Personal data: any information relating to an identified or identifiable natural person.
- Data subject: the natural person whose personal data are processed by the Data Controller.
- Processing: any operation performed on personal data, such as collection, recording, storage, modification, retrieval, transmission or deletion.
- Data Controller: the person or organization that determines the purposes and means of processing.
- Processor: the person or organization that processes personal data on behalf of the Data Controller.
- Consent: the freely given, specific, informed and unambiguous indication of the data subject’s wishes.
- Legitimate interest: a lawful interest of the Data Controller or a third party which may serve as a legal basis for processing after a proper balancing test.
4. Principles of data processing
The Data Controller follows the following principles when processing personal data:
- Lawfulness, fairness and transparency: personal data are processed lawfully, fairly and transparently.
- Purpose limitation: personal data are processed only for specified, explicit and legitimate purposes.
- Data minimization: only data necessary for the given purpose are processed.
- Accuracy: the Data Controller strives to keep personal data accurate and up to date.
- Storage limitation: personal data are retained only for as long as necessary.
- Integrity and confidentiality: the Data Controller protects personal data with appropriate technical and organizational measures.
- Accountability: the Data Controller is responsible for compliance with data protection rules.
5. Technical data processed during website and online store visits
| Purpose of processing | Processed data | Legal basis | Retention period |
|---|---|---|---|
| Operation and secure use of the website | IP address, browser type, device data, operating system, time of visit, pages viewed, log data | GDPR Article 6(1)(f) – legitimate interest | Generally up to 6 months; in case of security incident or legal dispute, for the period necessary for enforcement of claims |
| IT security and prevention of abuse | IP address, timestamp, request data, system usage logs, error codes | GDPR Article 6(1)(f) – legitimate interest | Generally up to 6 months, longer where justified |
The legitimate interest of the Data Controller is the secure operation of the website, and the prevention, detection and handling of abuse, attacks, unauthorized access, fraudulent orders and technical errors.
6. Processing related to registration
| Purpose of processing | Processed data | Legal basis | Retention period |
|---|---|---|---|
| Creation and management of user account | Name, e-mail address, password in encrypted form, billing address, delivery address, telephone number, account data | GDPR Article 6(1)(b) – performance of contract | Until deletion of the user account, or until the end of the limitation period for legal claims |
| User identification and login | E-mail address, password in encrypted form, login data | GDPR Article 6(1)(b) – performance of contract | For as long as the account exists |
Passwords are not stored in readable form, but in a technically protected, encrypted or hashed form.
7. Processing related to orders and purchases
| Purpose of processing | Processed data | Legal basis | Retention period |
|---|---|---|---|
| Receiving and fulfilling orders | Name, e-mail address, telephone number, billing address, delivery address, ordered products, order ID, order status, payment and delivery method | GDPR Article 6(1)(b) – performance of contract | Until performance of the contract, then until expiry of the limitation period for legal claims |
| Contacting the Customer for order fulfilment | Name, e-mail address, telephone number, order ID, message content | GDPR Article 6(1)(b) – performance of contract | Until order fulfilment, or until the end of the claim enforcement period |
| Fulfilment of custom products prepared by color code | Name, order data, provided color code, RAL/NCS code, vehicle data, model year, manufacturer, type, VIN where applicable, and other data required for product preparation | GDPR Article 6(1)(b) – performance of contract | Until order fulfilment, then until expiry of the limitation period for legal claims |
The Customer must provide true, accurate and their own data when placing an order. If an order is placed with false, incorrect or another person’s data, the Data Controller may cancel or refuse the order and investigate the abuse.
8. Processing related to invoicing
| Purpose of processing | Processed data | Legal basis | Retention period |
|---|---|---|---|
| Issuing invoices and fulfilling accounting obligations | Billing name, billing address, tax number, order data, payment data, invoice number, date of performance | GDPR Article 6(1)(c) – legal obligation | Retention period required by accounting laws, generally 8 years |
Billing data cannot be deleted during the mandatory accounting retention period, as their processing is based on a legal obligation.
9. Processing related to payment
9.1. Barion online card payment
Online card payment is provided by Barion Payment Zrt. Card data are not transmitted to the Data Controller. Payment is made through Barion’s secure payment interface.
| Purpose of processing | Processed data | Legal basis | Controller / recipient |
|---|---|---|---|
| Processing online payment | Order ID, payable amount, transaction data, payment status, payment data processed by Barion | GDPR Article 6(1)(b) – performance of contract; in certain cases legal obligation | Barion Payment Zrt. as independent controller / payment service provider |
Barion’s own privacy policy is available at: https://www.barion.com/hu/adatvedelmi-tajekoztato/
9.2. Bank transfer
In the case of bank transfer, the Data Controller processes the data necessary to identify the payment, such as the payer’s name, bank account number, payment amount, date and payment reference.
9.3. Cash on delivery and personal payment
In the case of cash on delivery, the delivery partner may also process payment data for delivery and collection of the cash-on-delivery amount. In the case of cash or card payment upon personal pickup, the Data Controller processes the fact of payment and the related documents.
10. Processing related to delivery
| Purpose of processing | Processed data | Legal basis | Recipients |
|---|---|---|---|
| Delivery of ordered products | Name, delivery address, telephone number, e-mail address, parcel ID, cash-on-delivery amount, order data | GDPR Article 6(1)(b) – performance of contract | GLS General Logistics Systems Hungary Kft., Magyar Posta Zrt. / MPL, parcel locker or parcel point service providers |
Delivery partners process the data for delivery, notification, parcel tracking, cash-on-delivery handling and related administration.
11. Processing related to personal pickup
In the case of personal pickup, the Data Controller processes the data necessary to identify and hand over the order and to verify payment.
| Purpose of processing | Processed data | Legal basis | Retention period |
|---|---|---|---|
| Handling personal pickup | Name, order ID, payment data, fact and date of pickup | GDPR Article 6(1)(b) – performance of contract | Same as order data |
12. Customer service and complaint handling
| Purpose of processing | Processed data | Legal basis | Retention period |
|---|---|---|---|
| Handling customer service inquiries | Name, e-mail address, telephone number, order ID, message content, attachments | GDPR Article 6(1)(b) – performance of contract; or GDPR Article 6(1)(f) – legitimate interest | Until the expiry of the claim enforcement period after closure of the matter |
| Handling consumer complaints | Name, contact details, order data, complaint content, response to complaint, documents | GDPR Article 6(1)(c) – legal obligation | For the period required by consumer protection and accounting rules |
Customer service and complaint-related inquiries may be sent to: [email protected]
13. Newsletter, marketing messages and abandoned cart e-mails
| Purpose of processing | Processed data | Legal basis | Retention period |
|---|---|---|---|
| Sending newsletters | Name, e-mail address, time of subscription, consent data, newsletter activity data | GDPR Article 6(1)(a) – consent | Until unsubscribe or withdrawal of consent |
| Personalized marketing communication | E-mail address, purchase history, website usage data, newsletter activity | GDPR Article 6(1)(a) – consent | Until withdrawal of consent |
| Sending abandoned cart e-mails, where such function is active | E-mail address, cart content, time of cart creation | GDPR Article 6(1)(a) – consent, or GDPR Article 6(1)(f) – legitimate interest where supported by a balancing test | Until closure of the abandoned cart process or withdrawal of consent |
The User may unsubscribe from the newsletter at any time free of charge via the unsubscribe link in the newsletter or by sending an e-mail to [email protected].
Unsubscribing from the newsletter does not affect system messages related to orders, payment, delivery or account operation.
14. Cookies and similar technologies
The website and online store may use cookies and similar technologies to ensure operation, improve user experience, perform statistical analysis and support marketing purposes.
| Cookie type | Purpose | Legal basis | Retention period |
|---|---|---|---|
| Necessary cookies | Website operation, cart, login, security, session management | GDPR Article 6(1)(f) – legitimate interest; necessary for the requested service under electronic communications rules | Until the end of the session or as defined by the cookie settings |
| Statistical cookies | Measuring visits and analysing website usage | GDPR Article 6(1)(a) – consent, unless measurement is fully anonymous or technically necessary | Depending on cookie settings and service provider |
| Marketing cookies | Ad measurement, remarketing, personalized offers | GDPR Article 6(1)(a) – consent | Depending on cookie settings and service provider |
The User may delete or restrict cookies in browser settings. Consent may be requested for non-essential cookies and may be withdrawn at any time.
If necessary cookies are disabled, certain functions of the online store, such as the cart or login, may not work properly or may be limited.
15. Google Analytics, Google Ads and other online marketing tools
The website may use Google Analytics, Google Ads or other online marketing and analytics services to measure website traffic, improve the website, measure advertising campaigns and perform remarketing.
| Purpose of processing | Processed data | Legal basis | Recipients |
|---|---|---|---|
| Web analytics and statistics | IP address in shortened or technically processed form, device data, page views, events, conversion data | Consent, unless measurement is fully anonymous or technically necessary | Google Ireland Limited / Google LLC |
| Ad measurement and remarketing | Cookie identifiers, advertising identifiers, visit and conversion data | Consent | Google Ireland Limited / Google LLC |
Further information on data processing related to Google services is available in Google’s own privacy policies.
16. Mobile application data processing
The CarColor Android mobile application provides information and convenience functions. No direct purchase is made in the application; products are ordered in the online store.
16.1. Data processed in the application
| Purpose of processing | Processed data | Legal basis | Retention period |
|---|---|---|---|
| Operation of the application | Device type, operating system version, application version, language and country settings, technical log data | GDPR Article 6(1)(f) – legitimate interest | For as long as necessary for operation; log data generally up to 6 months |
| Sending push notifications | FCM device token, notification settings, notification events | GDPR Article 6(1)(a) – consent; for certain system messages, legitimate interest | Until notifications are enabled, the application is deleted, or the token remains valid |
| Investigating application errors | Crash logs, error reports, device data, application version, technical events | GDPR Article 6(1)(f) – legitimate interest | Typically 3–24 months |
| Usage statistics | Screen views, feature usage events, campaign openings, aggregated statistics | GDPR Article 6(1)(f) – legitimate interest, or consent where required by the technology used | Typically up to 26 months; aggregated data may be retained longer |
| Handling deep links | Opened route, campaign identifier, in-app navigation data | GDPR Article 6(1)(f) – legitimate interest | For as long as necessary for the function |
16.2. Push notifications
The application may send promotional, informational or system-type push notifications. Notifications may be disabled at any time in the application or in Android system settings.
On Android 13 or newer systems, device-level permission from the User is required to send notifications.
16.3. Firebase and Google services
The application may use Google Firebase services for operation, sending notifications, statistics or error reporting, in particular:
- Firebase Cloud Messaging – delivery of push notifications,
- Firebase Analytics – usage statistics,
- Firebase Crashlytics – error reports and crash analysis.
When using Firebase services, Google may in certain cases act as processor on behalf of the Data Controller. Through Google services, personal data may also be transferred outside the European Union. In such cases, the transfer may be based on appropriate safeguards, such as Standard Contractual Clauses adopted by the European Commission.
16.4. Google Play Data Safety
The “Data Safety” section displayed in the Google Play Store is a summary of this Privacy Policy. In the event of any discrepancy, this Privacy Policy shall prevail.
17. VIN information and external service provider
VIN-based information may be displayed on the CarColor website or in the mobile application. VIN information originates from an external service provider and is not produced or operated by CarColor 2000 Kft.
| Purpose of processing | Processed data | Legal basis | Retention period |
|---|---|---|---|
| Retrieving VIN-based vehicle or color information, where such function is active | VIN, query data, technical log data | GDPR Article 6(1)(b) – provision of service; or GDPR Article 6(1)(f) – legitimate interest | For as long as necessary for the query; log data up to 6 months, longer in case of dispute |
A VIN may in certain cases qualify as personal data if it can be linked to a natural person. The Data Controller processes VIN data only for the purpose necessary for the operation of the service.
The Data Controller does not guarantee the accuracy, completeness or up-to-date nature of VIN information, as it originates from an external data source.
18. Fraud prevention, abuse handling and IP logging
The Data Controller has a legitimate interest in protecting the online store, customers, payment processes, delivery and its business operations. For this purpose, the Data Controller may process technical data for abuse prevention and security purposes.
| Purpose of processing | Processed data | Legal basis | Retention period |
|---|---|---|---|
| Filtering fictitious, false or abusive orders | IP address, order data, e-mail address, telephone number, delivery address, order history, fact of failed or uncollected order | GDPR Article 6(1)(f) – legitimate interest | For as long as necessary for claim enforcement and abuse prevention |
| Handling abusive use of cash-on-delivery orders | Data of uncollected order, delivery and return delivery data, customer contact details | GDPR Article 6(1)(f) – legitimate interest | For as long as necessary to prevent repeated abuse |
The purpose of such processing is not unjustified monitoring of Users, but maintaining the proper and secure operation of the online store.
19. Processors and recipients
The Data Controller may use the following processors or recipients:
| Service provider / recipient | Activity | Scope of data |
|---|---|---|
| Börzsey és Társa Pénzügyi Tanácsadó Kft. | Accounting service | Billing and accounting data |
| GLS General Logistics Systems Hungary Kft. | Courier service, parcel delivery | Name, address, telephone number, e-mail address, parcel data, cash-on-delivery data |
| Magyar Posta Zrt. / MPL | Courier service, parcel delivery, parcel locker and parcel point service | Name, address, telephone number, e-mail address, parcel data, cash-on-delivery data |
| Barion Payment Zrt. | Online payment service | Transaction data, payment data, order ID, payment status |
| ININET Kft. | Hosting, system administration or IT operation | Technical and order data related to website, online store and system operation |
| Google Ireland Limited / Google LLC | Firebase, Analytics, Ads, Play Console, push notifications, error reporting, statistics | Technical data, device data, application usage data, cookie and advertising identifiers |
| Invoicing software provider, where an external provider is used | Invoice generation and storage | Billing data, order data |
| Newsletter service provider, where an external provider is used | Sending newsletters and marketing messages | Name, e-mail address, subscription and activity data |
The Data Controller uses only processors that provide appropriate guarantees for the protection of personal data.
20. Transfer of data to third countries
When using certain services, especially Google/Firebase, Google Analytics, Google Ads or other external technology services, personal data may be transferred to third countries, including countries outside the European Union.
Such transfers may take place only with appropriate legal safeguards, such as an adequacy decision of the European Commission, Standard Contractual Clauses or other safeguards under the GDPR.
21. Data security
The Data Controller applies appropriate technical and organizational measures to protect personal data.
Such measures may include in particular:
- limiting access rights,
- use of password-protected systems,
- SSL / HTTPS encrypted connection,
- logging and security checks,
- regular updates and maintenance,
- contractual commitments of processors,
- incident management processes.
The Data Controller makes every effort to prevent unauthorized access, alteration, transmission, disclosure, deletion or destruction of personal data.
22. Handling data breaches
In the event of a data breach, the Data Controller examines the circumstances, impact and risk of the breach and takes the necessary measures.
If the breach is likely to result in a risk to the rights and freedoms of data subjects, the Data Controller will notify the National Authority for Data Protection and Freedom of Information in accordance with legal requirements.
If the breach is likely to result in a high risk to the data subjects, the Data Controller will also inform the affected data subjects.
23. Rights of data subjects
Under the GDPR, the data subject has the following rights:
- Right of access: the data subject may request information on whether the Data Controller processes their personal data and, if so, what data are processed.
- Right to rectification: the data subject may request correction of inaccurate data or completion of incomplete data.
- Right to erasure: the data subject may request deletion of their personal data where the legal conditions are met.
- Right to restriction of processing: the data subject may request restriction of processing in certain cases.
- Right to data portability: the data subject may request to receive their data in a machine-readable format where processing is based on consent or contract and is carried out by automated means.
- Right to object: the data subject may object to processing based on legitimate interest.
- Withdrawal of consent: where processing is based on consent, the data subject may withdraw consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
24. Submitting data subject requests
The data subject may submit data protection requests through the following contact details:
E-mail: [email protected]
Postal address: CarColor 2000 Kft., 1195 Budapest, Vas Gereben utca 4/d., Hungary
The Data Controller shall inform the data subject of the measures taken in response to the request within a maximum of 1 month from receipt of the request. If necessary, taking into account the complexity and number of requests, this period may be extended by a further 2 months.
Before fulfilling the request, the Data Controller may request proof of the data subject’s identity if there are doubts concerning the identity of the requester.
25. Legal remedies
If the data subject believes that the processing of their personal data violates the GDPR or other data protection laws, they may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information.
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Registered office: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address: 1363 Budapest, P.O. Box 9, Hungary
E-mail: [email protected]
Website: https://www.naih.hu/
Telephone: +36 (1) 391 1400
The data subject is also entitled to turn to court. The case falls within the jurisdiction of the regional courts. The data subject may also bring the case before the regional court competent according to their place of residence or stay.
26. Amendment of this Privacy Policy
The Data Controller reserves the right to amend this Privacy Policy. The amendment enters into force upon publication on the website.
The amendment may not adversely affect the statutory rights of data subjects.
27. Final provisions
This Privacy Policy enters into force upon publication on the website and online store of CarColor 2000 Kft.
Effective date: 27 May 2026
Data Controller: CarColor 2000 Kft.
Language clause: In the event of any discrepancy or difference in interpretation between the Hungarian and English versions of this Privacy Policy, the Hungarian version shall prevail.