Privacy Policy
Last updated: 28 March 2026
1. Preamble: Our Commitment to Data Protection
This Privacy Policy ("Policy") describes in a transparent and detailed manner how Kevin Leci Mobility collects, uses, stores, and communicates the personal data of users who access the website www.glint-out.ch and the online booking system integrated therein (collectively, the "Platform"), as well as those who use the professional mobile vehicle cleaning services offered by Glint Out. The processing of personal data is carried out in compliance with the Swiss Federal Act on Data Protection (FADP, SR 235.1), in its total revision that entered into force on 1 September 2023 (commonly referred to as "nFADP"), as well as the related implementing provisions contained in the Data Protection Ordinance (DPO, SR 235.11). To the extent that the Services are accessible to persons physically present in the territory of European Union Member States, the relevant provisions of Regulation (EU) 2016/679 (GDPR) also apply. This Policy applies to every natural person ("Data Subject") whose personal data are processed by Glint Out in connection with the use of the Platform or the provision of the Services.
2. Identity and Contact Details of the Data Controller
The Data Controller, i.e. the entity that determines the purposes and means of processing personal data pursuant to Art. 5(j) nFADP, is: Kevin Leci Mobility Owner: Kevin Leci Othmarstrasse 20, 8008 Zurich, Switzerland VAT Number: CHE-210.582.467 Website: www.glint-out.ch Email: info@glintout.ch For any questions, requests for clarification, or to exercise the rights set out in Section 9 of this Policy, the Data Subject may contact Glint Out at the email address above, specifying "Privacy Request" in the subject line to enable prompt handling.
3. Types of Personal Data Processed
3.1. Data Provided Directly by the User During the booking process and use of the Platform, we collect the following categories of personal data: Identification and Contact Data: First name, last name, email address, and mobile phone number, required for creating the user profile, managing the booking, and operational communications. Vehicle Data: Vehicle make, model, and licence plate, essential to allow the assigned Washer to unambiguously identify the vehicle on which to perform the Service, which must be on private property. Service Execution Address: Precise address or geographic location of the vehicle at the time of service, provided by the User at the time of booking. Vehicle Condition Information: Any reports of excessive dirt, pet hair, damaged parts, or special components communicated by the User before the Service. User Content: Reviews, service ratings, feedback, and the content of communications sent to our customer service via email or WhatsApp. 3.2. Data Collected During Service Execution Our staff (Washers) are required to document each service by photographing the vehicle before and after the Service. These images serve as documentary evidence for quality control, complaint management, and the legal protection of both parties. Photographs are processed in accordance with this Policy and retained for the periods set out in Section 8. 3.3. Financial Data Payments made via Stripe are processed directly by the payment service provider. Glint Out does not store or access the User's credit card data, CVV code, or other sensitive financial data. We receive only a technical confirmation of payment and, for Stripe payments, a non-sensitive token for transaction management. 3.4. Technical Data Collected Automatically When the User accesses the Platform, our systems automatically record technical information including: IP address, browser type and version, operating system, device type, pages visited, browsing session duration, and date and time of interactions. Such data are processed in aggregate form for statistical and security purposes, unless necessary for managing specific technical or security issues.
4. Purposes of Processing and Legal Bases
Each processing of personal data carried out by Glint Out is based on a specific legal basis under the nFADP (SR 235.1). 4.1. Service Provision and Management (Legal basis: contractual necessity, Art. 31(2)(a) nFADP) Identification data, vehicle information, and the execution address are processed to process the booking, assign the competent Washer, perform the Service at the agreed location, and manage payment. Without such data, the provision of the Service is objectively impossible. 4.2. Service Communications (Legal basis: contractual necessity) Contact data are used to send essential operational communications, including booking confirmation, appointment reminders, Washer arrival notifications, payment receipts, and the management of cancellations or modifications. Such communications do not have promotional purposes and are not subject to prior consent. 4.3. Photographic Documentation of the Service (Legal basis: legitimate interest of Glint Out, Art. 31(1) nFADP) Photographs taken before and after the Service are processed in the legitimate interest of Glint Out to document the vehicle's condition, transparently manage complaints, and protect itself in potential disputes. 4.4. Platform Security and Fraud Prevention (Legal basis: legitimate interest) Technical browsing data are processed to monitor and ensure the integrity and security of the Platform, prevent unauthorised access, detect fraudulent behaviour, and respond to cyber incidents. 4.5. Service Improvement and Statistical Analysis (Legal basis: legitimate interest) Platform usage data, processed in aggregate and anonymised form, are analysed to understand user navigation patterns and improve the site's structure, content, and functionality. 4.6. Compliance with Legal and Accounting Obligations (Legal basis: legal obligation, Art. 31(2)(c) nFADP) Transaction data are retained for the period required by Swiss tax and accounting legislation, in particular under Art. 958f of the Code of Obligations (CO), which requires the retention of accounting records for ten years. 4.7. Marketing and Promotional Communications (Legal basis: explicit consent of the Data Subject, Art. 31(2)(b) nFADP) Only with the free, informed, and specific consent of the Data Subject may contact data be used for sending newsletters, special offers, or communications about new services. Consent may be withdrawn at any time by writing to info@glintout.ch without prejudice to the lawfulness of processing carried out prior to withdrawal.
5. Disclosure of Data to Third Parties
Glint Out does not sell users' personal data to third parties for any purpose. Data disclosure is strictly limited to the following categories of recipients: 5.1. Employees (Washers) Information necessary for the execution of the Service, including the User's name, the address or location of the vehicle, and the vehicle's specifications, is communicated internally to the Washer assigned to the service. 5.2. Payment Service Providers Data necessary for payment processing are transmitted to Stripe, Inc. (https://stripe.com/privacy), which acts as a data processor for the secure processing of financial transactions. 5.3. Mapping Service Providers To provide location services, the Platform integrates with Google Maps (Google LLC). The use of this service may involve the transmission of location data to Google. Google's Privacy Policy is available at https://policies.google.com/privacy. 5.4. Public and Judicial Authorities In the presence of a specific legal obligation, court order, or binding request from a competent Swiss judicial, tax, or administrative authority, Glint Out may be required to disclose users' personal data to the requesting authorities. 5.5. Transfers in Corporate Operations In the event of a merger, acquisition, business unit transfer, or corporate restructuring, personal data may be transferred to the acquiring or succeeding party, always in compliance with the commitments made in this Policy.
6. International Data Transfers
Some service providers used by Glint Out, including Stripe (headquartered in the United States) and Google LLC, may process data in countries outside Switzerland that do not guarantee an adequate level of protection under the nFADP. In such cases, Glint Out ensures that the transfer takes place in compliance with adequate safeguards, including the Standard Contractual Clauses recognised by the FDPIC or the application of the exceptions provided for in Art. 17 nFADP.
7. Data Security Measures
The protection of users' personal data is a fundamental technical and organisational responsibility for Glint Out. In compliance with Art. 8 nFADP and Art. 1 DPO, we adopt security measures proportionate to the risks associated with processing, including: Transit Protection: All communications between the user's device and our servers take place through encrypted connections using the SSL/TLS protocol. At-Rest Protection: Data stored in our systems is protected by encryption mechanisms appropriate to its level of sensitivity. Access Control: Access to personal data is limited, through a permission system based on the principle of least privilege, to personnel with an actual operational need. Anomaly Detection: We are equipped with monitoring systems designed to identify unauthorised access or anomalous activity on the Platform. Breach Notification: In the event of a data security breach posing a high risk to the rights and freedoms of Data Subjects, Glint Out will notify the FDPIC within the timeframes required by Art. 24 nFADP and, where necessary, directly inform the affected Data Subjects. No computer system can guarantee absolute security; however, Glint Out is committed to constantly updating its procedures in response to the evolving threat landscape.
8. Data Retention Periods
Personal data are retained exclusively for the time necessary to achieve the purposes for which they were collected, in compliance with the principle of storage limitation under Art. 6(3) nFADP. At the end of the applicable period, data are securely deleted or irreversibly anonymised. Account and Booking Data: Retained for the duration of the contractual relationship with the User. In the event of an account deletion request, data are deleted within 30 days, subject to legal retention obligations. Transaction and Accounting Data: Retained for 10 years in compliance with Art. 958f CO. Vehicle Photographs: Retained for a maximum of 12 months from the Service execution date, unless required for the management of an ongoing complaint or dispute. Technical Browsing Data: Retained for a maximum of 12 months from collection. Dispute Management Data: Retained until the expiry of the applicable limitation periods under the CO. Customer Service Communications: Retained for 3 years from the date of the last communication.
9. Data Subject Rights and How to Exercise Them
In accordance with Articles 25 et seq. of the nFADP (SR 235.1), every Data Subject has the following rights, exercisable at any time against Glint Out: Right of Access (Art. 25 nFADP): The right to obtain confirmation as to whether personal data concerning them are being processed and, if so, to receive a readable copy thereof. Right to Rectification (Art. 32 nFADP): The right to obtain the correction of inaccurate or incomplete data. Right to Erasure: The right to request the deletion of personal data where processing is no longer necessary for the original purposes and no legal retention obligations exist. Right to Data Portability: The right to receive personal data in a structured, machine-readable format. Right to Object (Art. 21 nFADP): The right to object to processing based on the legitimate interest of Glint Out. Right to Withdraw Consent: The right to withdraw consent given for data processing for marketing purposes. Right to Restriction of Processing: The right to request the temporary suspension of processing under specific conditions provided by the nFADP. To exercise one or more of the above rights, the Data Subject must send a written request to info@glintout.ch, specifying the right to be exercised and attaching a copy of a valid identity document. Glint Out undertakes to respond within 30 days of receiving the complete request. If the Data Subject believes that the processing of their personal data violates the provisions of the nFADP, they have the right to lodge a complaint with the competent supervisory authority: Federal Data Protection and Information Commissioner (FDPIC) Feldeggweg 1, CH-3003 Bern, Switzerland Website: https://www.edoeb.admin.ch
10. Protection of Minors
The Platform and the Services of Glint Out are intended exclusively for persons who have reached 18 years of age. We do not knowingly collect personal data from minors. Should we become aware that we have processed data of a minor without the verifiable consent of the holder of parental responsibility, we will immediately take the necessary measures to delete such data from our systems.
11. Cookies and Tracking Technologies
The Platform uses cookies and similar tracking technologies to ensure the proper functioning of the site, remember User preferences, and collect aggregate statistical data. Detailed information about the cookies used, their purposes, and the methods for managing or revoking consent is contained in the Glint Out Cookie Policy, available in the same legal section of the site.
12. Updates to This Policy
Glint Out reserves the right to modify this Policy at any time to adapt it to regulatory developments, operational changes, or new data processing methods. The updated version will be published on the Platform with the date of the last modification. In the event of substantial changes affecting the rights of Data Subjects, Glint Out will provide proactive notification via email or through a prominent notice on the Platform before the changes take effect.
13. Contacts
For any questions, requests for information, or exercise of the rights recognised by the nFADP, please contact: Kevin Leci Mobility Othmarstrasse 20, 8008 Zurich, Switzerland Email: info@glintout.ch Website: www.glint-out.ch