Devtema, MB
Privacy Policy
Effective: 2026-08-07Last updated: 2026-08-07
This Privacy Policy explains how Devtema, MB (“we”, “us”, “our”), established in Lithuania, processes personal data when you use Collabdog (collabdog.com), including our web application, related APIs, and partner white-label browse Hosts that resolve to our platform. It is written for a marketplace that intermediates high-value vehicle rentals between renters (guests) and hosts (individuals and fleet businesses), and it reflects privacy-by-design choices built into our product: we do not store card numbers, and we do not store identity-document images.
1. Who is the controller
The data controller for the Collabdog marketplace platform is:
- Legal entity: Devtema, MB
- Company code (įmonės kodas): 307585851
- VAT code (PVM): LT100019742017
- Registered address: Taikos g. 263F-7, 05265 Vilnius, Lithuania
- Country of establishment: Lithuania
- Phone: +370 677 99940
- Privacy contact: info@devtema.com
- Operator website: https://devtema.com
- Marketplace: https://collabdog.com
Collabdog is a B2C peer-to-peer luxury car rental marketplace. Hosts list vehicles; guests search, book, and pay deposits/trip amounts through our platform. Fleet and garage partners may operate a branded browse experience on a custom domain that CNAMEs to our edge; account, authentication, document verification, and payment checkout remain on the marketplace origin.
2. Scope
This Policy applies to personal data processed in connection with:
- Visiting or using https://collabdog.com and https://www.collabdog.com
- Using partner white-label Hosts (including our platform demo Host demo.collabdog.com) that display partner inventory through Collabdog
- Creating and using a renter or host account
- Listing vehicles, managing availability, and publishing inventory
- Booking, deposits, payouts, refunds, and related support
- Identity / document verification required for trust and safety
- Communications about your account, bookings, or security
It does not replace a host’s or partner’s own privacy notice for processing they perform outside our platform (for example, offline handovers, their own CRM, or insurance claims handled directly with their insurer). Where a partner publishes their own rental terms URL, that document is theirs — this Policy still governs how we process data as the marketplace operator.
3. Roles: marketplace, processors, and hosts
Devtema, MB is the controller for platform account data, session security, marketplace listings metadata we host, booking records we maintain, trust-and-safety statuses we store, and operational logs needed to run Collabdog.
Specialised vendors act as processors or independent controllers under their own terms for regulated rails we deliberately do not build in-house:
- Payments and payouts: Stripe (including Stripe Connect). We never store full payment card numbers (PANs) or CVV. Card data is collected by Stripe under PCI DSS; we operate toward PCI SAQ-A patterns.
- Document authentication / KYC / IDV: Stripe Identity (or an equivalent specialised provider such as Persona if configured). We store verification status, provider session/inquiry identifiers, and timestamps — not passport, licence, or selfie images.
Hosts and fleet partners remain responsible for their own lawful basis when they process guest data for their rental relationship beyond what the platform requires (for example, collecting additional documents at vehicle handover). We disclose guest contact and booking details to the counterparty only as needed to fulfil the trip.
4. Categories of personal data we process
Depending on how you use Collabdog, we may process:
- Account credentials and identity: email address, password (stored only as a salted one-way hash; never in reversible form), display name, role (guest/host/admin), and session tokens (browser cookie / Bearer). Session secrets are stored server-side as cryptographic hashes — plaintext tokens are not retained in our database.
- Contact and profile: phone number, country of residence / primary market.
- Host / business operator data: company name, registration code, website, VAT, address, support and billing contacts, brand assets (logo), navigation links, and optional custom domain for white-label browse.
- Listing and inventory data: vehicle descriptions, location (country/city and coordinates used for discovery), pricing, availability windows, and media you upload. Photos may incidentally depict people — upload only media you are entitled to publish.
- Booking and trip data: selected dates, listing identifiers, amounts, booking status, and messages or notes required to operate the reservation.
- Payment metadata: Stripe customer/account identifiers, PaymentIntent / Connect references, payout readiness — never full card numbers.
- Trust and safety: document-verification provider, external session id, verification status (e.g. not started / pending / verified / failed / requires input), and verification timestamps.
- Technical and security data: IP address and coarse location signals used for locale defaults, user-agent, request diagnostics, rate-limit counters, and signed webhook delivery metadata.
- Cookies and similar technologies: essential session cookie (`cardog_session`, httpOnly), locale preference cookie, and any strictly necessary edge/CDN cookies. We do not use the session cookie for advertising.
We do not intend to collect special-category data (e.g. health, biometric templates). Biometric or document images processed during identity verification are handled by the specialised IDV vendor in their environment; Collabdog retains status and identifiers only.
5. Purposes and legal bases
We process personal data only for specified purposes and on a GDPR legal basis:
- Contract performance (Art. 6(1)(b)): create and secure your account; enable search and booking; run deposits, charges, refunds, and host payouts via Stripe Connect; deliver booking confirmations and trip-critical notices; operate host inventory and partner white-label browse.
- Legitimate interests (Art. 6(1)(f)): protect the platform against fraud, abuse, and account takeover; enforce rate limits; maintain service integrity and availability; improve reliability and security; assert or defend legal claims. We balance these interests against your rights and expectations for a high-value rental marketplace.
- Legal obligation (Art. 6(1)(c)): retain records required by applicable tax, accounting, consumer, AML/CFT, or law-enforcement requests where lawfully compelled.
- Consent (Art. 6(1)(a)): only where we ask for it (for example, non-essential cookies or optional marketing if introduced). You may withdraw consent without affecting processing that relies on another basis.
Identity verification before hosting go-live (and before certain high-value guest bookings as product rules require) is necessary for contract performance and our legitimate interest in trust and safety for luxury vehicles.
6. Payments and identity verification
Money movement and document authentication are third-party rails by design. Collabdog orchestrates; vendors authenticate money and documents.
- Stripe processes card and Connect payout data under Stripe’s privacy notice and DPA. Cardholder data enters Stripe’s fields / hosted flows — not our servers.
- Stripe Identity (or configured equivalent) runs document and selfie/liveness checks. Webhooks signed by the vendor are the source of truth for verification status on your Collabdog account.
- In local/demo environments without live Stripe keys, verification may be simulated as “demo mode” without uploading identity images. Production verification requires the vendor flow.
8. International transfers
Devtema, MB is established in Lithuania (EEA). Some processors (notably Stripe and global cloud/CDN providers) may process data in the United States or other countries. Where personal data leaves the EEA/UK, we rely on an adequacy decision where available, or appropriate safeguards such as the European Commission’s Standard Contractual Clauses, plus supplementary measures assessed for the transfer.
9. Retention
We keep personal data only as long as needed for the purposes above, then delete or irreversibly anonymise it, unless a longer period is required by law.
- Account profile: for the life of the account, then a short closure period for recovery/abuse prevention, unless legal holds apply.
- Sessions: until expiry, revocation (sign-out), or security invalidation.
- Bookings, ledger references, and tax-relevant records: for the statutory retention period applicable in Lithuania / the markets we operate (typically multi-year for accounting).
- Document-verification status and vendor session ids: for the account lifecycle and any dispute/AML retention need; raw ID images are not stored by us.
- Security and access logs: short operational windows unless investigating an incident.
- Listing media: until you remove it or the listing is archived/deleted per product rules.
10. Security and privacy by design
We apply organisational and technical measures appropriate to a marketplace handling identity, money, and high-value assets, including:
- TLS encryption in transit for public endpoints
- Encryption at rest for primary datastores where provided by our infrastructure
- Password hashing with modern one-way algorithms (scrypt / equivalent); opaque session tokens hashed at rest
- HttpOnly session cookies; CSRF-aware cookie practices for browser sessions
- Server-side authorisation on every sensitive action — never rely on client UI alone
- Webhook signature verification and idempotency for payment and identity events
- Least-privilege access for operators and deploy automation; secrets outside source control
- Rate limiting and abuse controls on authentication and expensive endpoints
- Separation of duties: no in-house IDV/OCR; no storage of PANs on Collabdog systems
- Partner Host isolation: browse may be white-labelled; checkout and auth remain on the marketplace origin
No method of transmission or storage is perfectly secure. If we become aware of a personal-data breach likely to result in a high risk to your rights, we will notify you and the competent authority as required by GDPR.
12. Your rights
Under the GDPR (and applicable Lithuanian law), you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data (“right to be forgotten”) where applicable
- Restrict processing in certain cases
- Data portability for data you provided where processing is automated and based on contract or consent
- Object to processing based on legitimate interests
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
To exercise rights, email info@devtema.com from the address on your account (or with enough detail for us to verify your identity). We may need to confirm identity before fulfilling a request. Some rights are limited where we must retain data for contracts, legal claims, or legal obligations (for example, completed booking ledger rows).
You may complain to the State Data Protection Inspectorate (VDAI) (https://vdai.lrv.lt/) or, if you live in another EEA state, to your local authority. We would appreciate the chance to resolve concerns first at info@devtema.com.
13. Children
Collabdog is intended for adults who can enter binding rental and payment contracts. We do not knowingly collect personal data from children under 16. If you believe a child has created an account, contact info@devtema.com and we will take appropriate steps.
14. Automated decision-making
We may use automated rules for fraud prevention, rate limiting, and eligibility gates (for example, requiring verified document status before publishing a listing). These measures do not produce solely automated decisions that produce legal effects without meaningful human involvement in disputes or account termination reviews. You may contest a decision that affects you by contacting info@devtema.com.
15. Changes to this Policy
We may update this Policy when our product, vendors, or legal requirements change. Material changes will be reflected by updating the effective / last-updated dates on this page and, where appropriate, notifying account holders by email or in-product notice. Continued use after the effective date constitutes acknowledgement of the updated Policy to the extent permitted by law.
16. Contact
Controller: Devtema, MB, company code 307585851, VAT LT100019742017.
Registered address: Taikos g. 263F-7, 05265 Vilnius, Lithuania.
Privacy requests: info@devtema.com · Phone: +370 677 99940 · https://devtema.com
Product: Collabdog — https://collabdog.com