PetroCheck

Informativa sulla privacy di PetroCheck

In vigore dal 10 settembre 2026

Questa informativa descrive in modo trasparente quali dati tratta PetroCheck, per quali scopi, con quali fornitori vengono condivisi e quali diritti puoi esercitare. Il titolare del trattamento è Federico Trevisani, Italia. Per richieste sulla privacy ed esercizio dei diritti: federico@federicotrevisani.dev.

1. Posizione e ricerche

Con il tuo permesso, la posizione precisa o approssimativa viene inviata al backend per trovare e ordinare i distributori vicini. Questa posizione di ricerca è usata per rispondere alla richiesta e non viene conservata come cronologia di localizzazione.

Se hai effettuato l'accesso e attivi un avviso prezzo per un'area, PetroCheck salva invece il centro geografico e il raggio scelti, collegati al tuo account, finché elimini l'avviso o l'account. Puoi usare la ricerca manuale senza concedere la posizione.

Con la ricerca sul percorso indichi una destinazione: Apple Mappe calcola l'itinerario e PetroCheck lo usa solo per selezionare i distributori già caricati lungo la strada. La destinazione non viene inviata al backend né conservata.

L'app per Apple Watch, CarPlay, i widget e l'App Clip usano la stessa regola: la posizione serve a rispondere alla ricerca del momento. I widget mostrano l'ultimo risultato salvato dall'app sul dispositivo e non fanno richieste proprie; l'App Clip mostra solo il distributore indicato nel link aperto e non usa la posizione.

2. Account, preferiti, avvisi e notifiche

L'account è facoltativo. Con Accedi con Apple riceviamo un identificativo Apple e, solo se li condividi, nome ed email. Supabase conserva l'identificativo account, i distributori preferiti, gli avvisi prezzo, i controlli sui singoli distributori e i token APNs necessari alle notifiche. Questi dati servono a sincronizzare e fornire le funzioni richieste.

3. Feedback, segnalazioni e foto

Quando invii un feedback o una segnalazione (dato sbagliato, chiusura temporanea, distributore inesistente o riaperto, bug, funzione mancante, altro) trattiamo categoria, testo libero, indirizzo email di contatto, data, versione dell'app, piattaforma e, se pertinente, ID, marchio e indirizzo del distributore. L'email di contatto è obbligatoria; se hai effettuato l'accesso viene proposta quella dell'account e la segnalazione può essere collegata al tuo identificativo. Un codice diagnostico anonimo può essere allegato in automatico per collegare la segnalazione ai log tecnici: non contiene token, email né posizione.

Per una segnalazione di distributore inesistente o temporaneamente chiuso puoi allegare facoltativamente una foto compressa. La foto richiede un account ed è conservata in un bucket privato, accessibile solo al titolare.

Riceverai email di stato dal titolare (ricezione, presa in carico, chiusura) all'indirizzo indicato, inviate tramite Resend; puoi rispondere direttamente. Una copia della segnalazione arriva al titolare. L'invio è eseguito da un processo automatico su GitHub Actions che legge solo i dati necessari all'email. Non inserire nel testo o nella foto dati personali non necessari.

4. Acquisti e RevenueCat

Gli acquisti avvengono tramite Apple StoreKit; Apple gestisce pagamento e fatturazione. L'SDK RevenueCat riceve identificativo cliente, informazioni sulla transazione e cronologia dell'abbonamento per verificare i diritti Premium, mostrare lo storico cliente e produrre metriche sugli acquisti. Quando accedi, PetroCheck identifica il cliente RevenueCat con l'UUID opaco del tuo account Supabase. Non riceviamo i dati della carta.

5. Pubblicità, consenso, analisi e diagnostica

La versione gratuita integra Google AdMob. Google UMP raccoglie le scelte di consenso applicabili; su iOS, App Tracking Transparency controlla l'accesso all'identificativo pubblicitario. Se non autorizzi il tracciamento possono comunque essere mostrati annunci non personalizzati. Gli utenti Premium non vedono annunci.

Firebase Analytics, Crashlytics e Remote Config aiutano a misurare l'uso, diagnosticare crash e prestazioni e configurare le funzioni. Consent Mode parte negato e viene aggiornato in base alle scelte applicabili. I dati tecnici possono includere identificativi del dispositivo/installazione, interazioni, diagnostica, versione dell'app e sistema operativo.

Siri, Comandi Rapidi e Spotlight funzionano sul dispositivo: i distributori che hai visto possono essere indicizzati localmente dal sistema per i suggerimenti e non vengono inviati al backend per questo scopo. Sull'app per Mac non c'è pubblicità né tracciamento.

6. Finalità e basi giuridiche

7. Fornitori, destinatari e trasferimenti

I fornitori coinvolti, secondo la funzione usata, sono Supabase (backend, database, autenticazione e Storage), RevenueCat (abbonamenti), Google/Firebase/AdMob (pubblicità, consenso, analisi e diagnostica), Resend (email operative relative al feedback) e Apple (accesso, acquisti e notifiche). Apple Mappe calcola gli itinerari della ricerca sul percorso e apre le indicazioni; GitHub esegue il processo automatico che invia le email di stato delle segnalazioni. MIMIT, Open Charge Map e OpenStreetMap forniscono dati pubblici su distributori, colonnine e servizi; le richieste a OpenStreetMap partono dal server di PetroCheck, non dal tuo dispositivo, e nessuno di questi enti riceve da PetroCheck il tuo account.

Alcuni fornitori possono trattare dati fuori dallo Spazio Economico Europeo. In tali casi il trasferimento si basa sui meccanismi dichiarati dal fornitore, come decisioni di adeguatezza, Data Privacy Framework o clausole contrattuali standard, e sui relativi accordi sul trattamento.

8. Conservazione e cancellazione

9. Le tue scelte e i tuoi diritti

Account, posizione, notifiche, feedback e foto sono facoltativi; non fornirli limita solo le funzioni che li richiedono. Puoi chiedere accesso, rettifica, cancellazione, limitazione, portabilità e opporti al trattamento; puoi revocare un consenso senza pregiudicare il trattamento precedente. Scrivi a federico@federicotrevisani.dev. Puoi inoltre proporre reclamo al Garante per la protezione dei dati personali.

10. Minori e modifiche

PetroCheck è destinato a persone dai 16 anni in su. Le modifiche a questa informativa vengono pubblicate qui aggiornando la data; se sono rilevanti, potranno essere comunicate anche nell'app.

PetroCheck Privacy Policy

Effective 10 September 2026

This privacy policy transparently describes what data PetroCheck processes, for what purposes, which service providers are involved, and your rights as a user. The data controller is Federico Trevisani, Italy. Privacy requests and rights inquiries: federico@federicotrevisani.dev.

1. Location and searches

With your permission, precise or approximate location is sent to the backend to find and rank nearby stations. This search location is used to answer the request and is not retained as a location history.

If you are signed in and enable a price alert for an area, PetroCheck instead saves the selected centre and radius with your account until you delete the alert or account. You can search manually without granting location access.

Route search takes a destination you enter: Apple Maps computes the route, and PetroCheck uses it only to pick the already-loaded stations along the way. The destination is not sent to the backend and is not retained.

The Apple Watch app, CarPlay, widgets and the App Clip follow the same rule: location is used to answer the current search. Widgets show the last result the app saved on the device and make no requests of their own; the App Clip shows only the station named in the link you opened and does not use location.

2. Account, favourites, alerts and notifications

An account is optional. Sign in with Apple provides an Apple user identifier and, only if you share them, your name and email. Supabase stores the account identifier, favourite stations, area alerts, station watches, and APNs tokens needed for notifications. This data provides and synchronises the features you request.

3. Feedback, reports and photos

When you send feedback or a report (wrong data, temporary closure, station gone or reopened, bug, missing feature, other), we process its category, free-form text, contact email address, date, app version, platform and, where relevant, station ID, brand and address. The contact email is required; when you are signed in it is pre-filled from your account and the report may be linked to your account identifier. An anonymous diagnostic code may be attached automatically to link the report to technical logs; it contains no token, email or location.

You may optionally attach a compressed photo to a report that a station does not exist or is temporarily closed. Photos require an account and are kept in private storage that only the controller can access.

You will receive status emails from the controller (received, in progress, closed) at the address you gave, sent through Resend; you can reply directly. A copy of the report goes to the controller. Sending is performed by an automated job on GitHub Actions that reads only the data the email needs. Do not include unnecessary personal data in text or photos.

4. Purchases and RevenueCat

Purchases use Apple StoreKit, and Apple handles payment and billing. The RevenueCat SDK receives a customer identifier, transaction information and subscription history to verify Premium access, provide customer history and produce purchase metrics. When signed in, PetroCheck identifies the RevenueCat customer with the opaque UUID of your Supabase account. We never receive card details.

5. Advertising, consent, analytics and diagnostics

The free version integrates Google AdMob. Google UMP collects applicable consent choices; on iOS, App Tracking Transparency controls advertising-identifier access. Non-personalised ads may still appear when tracking is not allowed. Premium users see no ads.

Firebase Analytics, Crashlytics and Remote Config help measure usage, diagnose crashes and performance, and configure features. Consent Mode starts denied and is updated according to applicable choices. Technical data may include device or installation identifiers, interactions, diagnostics, app version and operating system.

Siri, Shortcuts and Spotlight work on the device: stations you have viewed may be indexed locally by the system for suggestions and are not sent to the backend for that purpose. The Mac app carries no advertising and no tracking.

6. Purposes and legal bases

7. Providers, recipients and transfers

Depending on the feature, providers are Supabase (backend, database, authentication and Storage), RevenueCat (subscriptions), Google/Firebase/AdMob (ads, consent, analytics and diagnostics), Resend (operational feedback email), and Apple (sign-in, purchases and notifications). Apple Maps computes route-search itineraries and opens directions; GitHub runs the automated job that sends report status emails. MIMIT, Open Charge Map and OpenStreetMap supply public data on stations, chargers and amenities; OpenStreetMap requests are made by PetroCheck's server, not your device, and none of these bodies receives your PetroCheck account from us.

Some providers may process data outside the European Economic Area. Such transfers rely on the mechanisms stated by the provider, such as adequacy decisions, the Data Privacy Framework or Standard Contractual Clauses, and the relevant processing agreements.

8. Retention and deletion

9. Your choices and rights

Account, location, notifications, feedback and photos are optional; withholding them only limits the features that need them. You may request access, rectification, deletion, restriction and portability, object to processing, and withdraw consent without affecting earlier processing. Contact federico@federicotrevisani.dev. You may also complain to the Italian Data Protection Authority.

10. Children and changes

PetroCheck is intended for people aged 16 and over. Changes are posted here with a revised date and, when material, may also be communicated in the app.