Pistoni
Legal NoticeTermsContractPackageRefundsPrivacyCookiesComplaints
SQENITDEFRES
Version 1.1 · Effective 2026-07-12

Privacy Policy

This policy applies to pistoni.eu, Pistoni Assistance purchases, document verification, memberships, roadside incidents, customer support and official WhatsApp communications.

1. Controller and contact

Pistoni determines why and how personal data are used for the services described here. Privacy enquiries and rights requests may be sent to hello@pistoni.eu or +355 684441034.

2. Data collected

Pistoni may process contact details, country and language, vehicle and driver data, plate and VIN, registration and driving-licence images, extracted document fields, verification results, package and membership data, payment references, support messages and complaint records.

For roadside incidents Pistoni may also process location, incident details, photographs, passenger information, provider updates and call or WhatsApp metadata.

3. Sources

Data normally come from the customer, an authorised driver, the customer's device, payment and communications providers, roadside partners and records created while Pistoni performs the contract.

A person providing another individual's data must have a lawful reason and should inform that individual where appropriate.

4. Purposes and legal bases

Pistoni processes data to verify eligibility, form and perform contracts, take payment, activate memberships, prevent abuse, coordinate roadside help, answer requests, handle complaints, keep accounting records and defend legal claims.

The legal basis is normally contract performance, steps requested before contract, legal obligation or legitimate interests in security, service quality and claim protection. Consent is used only where it is genuinely optional, such as certain marketing or non-essential cookies.

5. Document verification

Uploaded documents are stored privately and may be analysed with automated extraction tools to read relevant fields and identify obvious quality or consistency problems.

A rejection that materially affects activation can be reviewed by a person. Pistoni does not use facial recognition or make solely automated legal decisions about the customer.

6. Payments

Payment checkout and payment status are handled with the payment provider. Pistoni receives identifiers, amount, currency, status, timestamps and limited customer information needed to reconcile the purchase.

Pistoni does not store the customer's full card number or card security code.

7. WhatsApp, location and dispatch

When a customer contacts Pistoni through WhatsApp or phone, Pistoni processes the message, number, profile name, location and attachments needed to identify the membership and handle the case.

Necessary case data may be shared with the selected roadside provider, such as contact, vehicle, location and incident details. Providers may use them only to perform and document the authorised service.

8. Recipients and service providers

Data may be handled by infrastructure supporting the Appwrite database, private Cloudflare R2 document storage, Cloudflare Email Service transactional messages, Whop payments, Meta and WhatsApp communications, OpenRouter-supported document analysis, professional advisers and roadside providers.

Pistoni shares only information reasonably needed for the stated purpose and requires appropriate confidentiality and data protection where applicable.

9. International transfers

Some technology or roadside providers may process data outside the customer's country. Pistoni uses available contractual, organisational and security safeguards and considers the destination and service before transferring data.

Customers may ask for further information about safeguards relevant to their data.

10. Retention

Purchase, membership, payment, incident and contract evidence is kept while needed to perform the service and afterwards for accounting, complaints, fraud prevention and legal claims. Document images are retained only while needed for verification, membership administration and defensible records, then deleted or anonymised unless law or an active dispute requires longer retention.

Incomplete drafts remain in the browser session where possible. Technical logs and unsuccessful attempts are kept for shorter security and troubleshooting periods. Pistoni reviews retention by data category rather than keeping all personal data indefinitely.

11. Rights

Depending on applicable law, a person may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier lawful processing.

Pistoni may request proportionate identity evidence and will respond within the applicable legal deadline. A person may also complain to the competent personal-data authority or court.

12. Security and changes

Pistoni uses access controls, private storage, limited signed links, transport encryption, audit records and operational controls intended to protect personal data. No system can guarantee absolute security.

Material policy changes apply prospectively. The version and effective date identify the policy relevant to a particular acceptance or acknowledgement.