Privacy & Terms
Last updated: 1 July 2026
This policy explains what personal data the 944 Turbo Cabriolet Registry (“the registry”, “we”) collects, why we collect it, how long we keep it, and the rights you have over it. The registry is an independent, non-commercial enthusiast project.
Who is responsible for your data
The site admins. If you have any question about this policy or wish to exercise your rights, contact us through the contact form.
What we collect
When you create an account we collect:
- Your username and email address.
- Your password, stored only in a secure, strong cryptographic format — we never store or see the plaintext.
Why we use it, and our legal basis
- To provide the registry (create your account, publish the cars you document) — performance of our agreement with you.
- To keep accounts and the site secure — our legitimate interest in preventing abuse and fraud.
- To respond to your messages — our legitimate interest in answering enquiries.
- To send account-related email (e.g. password reset) — performance of our agreement with you.
Cookies
We use only strictly-necessary cookies. A secure, HttpOnly session cookie keeps you signed in, and a short-lived cookie shows your last login on the garage page and then expires. We do not use advertising or analytics cookies, and there are no third-party trackers on the site.
Who we share it with
We do not sell your data and do not share it with advertisers. Data is visible to the registry administrators, and information you choose to publish about a car is visible to other visitors. Email you send during password reset is delivered through our email provider solely to deliver that message.
Where your data is stored
Our servers are located in California, USA, and your data — including personal data — is stored and processed there. If you access the registry from outside the United States, including from the EU or UK, your information is transferred to and stored on servers in the United States, which may have different data-protection laws than your own country.
How long we keep it
We keep your account data for as long as your account exists. Security logs are kept only as long as needed for security monitoring and are then removed. When an account is deleted, associated personal data is removed; documented car records may be retained in anonymised form as part of the historical registry.
How we protect it
- Passwords are stored in strong cryptographic format; password-reset tokens are stored only as hashes.
- All traffic is served over HTTPS with HSTS enforced.
- A strict Content-Security-Policy blocks external scripts and third-party embeds.
- Sign-in and password-reset endpoints are rate-limited, with account lockout on repeated failures.
Your rights
If you are in the EU, UK, or a comparable jurisdiction, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. You can update your username, email and password from your account settings. To request a copy or deletion of your data, or to exercise any other right, contact us through the contact form. You also have the right to lodge a complaint with your data protection authority.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected in the “last updated” date above.