1. Data Controller & Privacy-First Architecture
The Data Controller for ReClaim Miles is Elektroinštalácie Poprad, s.r.o. (Fraňa Kráľa 2071/34, 058 01 Poprad, Slovakia, IČO: 48 061 999, DIČ: 2120035819, IČ DPH: SK2120035819, registered in Commercial Register of Okresný súd Prešov, Section: Sro, Insert No. 31271/P).
ReClaim Miles is engineered as a local-first desktop application. Vehicle logs, drivers, expenses, odometer records, client addresses, downloaded state maps, and generated reports are stored in a local SQLite database and files on your computer. We do not remotely collect or synchronize personal trip logs.
2. Desktop Data We Do Not Receive
- We do NOT track your real-time GPS location or phone movement.
- We do NOT collect client addresses or customer contact details entered into the address book.
- We do NOT upload or store tax identification numbers (EINs) or vehicle VIN numbers.
- We do NOT use advertising trackers or behavioral analytics in the desktop application.
3. Optional Cloud AI Processing
Our software offers an optional Smart Cloud AI OCR feature for bulk document scanning. If activated, document text is processed using your own personal API key (e.g. Google Gemini API or OpenAI API).
Requests are sent directly from your local machine to the chosen API provider. ReClaim Miles servers never act as a middleman, and we do not see or retain any uploaded receipt contents.
Your selected provider processes data under its own terms and privacy policy. Do not submit documents containing unnecessary sensitive information.
4. Website, Licensing & Purchase Data
When purchasing a license or starting the 14-day free evaluation period, we may process your email address, purchase tier, license token, activation status, and a device identifier (HWID) needed to prevent unauthorized activation. Our payment provider processes payment details; we do not receive complete payment-card numbers.
5. Lawful Bases & Retention
We process purchase and licensing data to perform our contract, secure the service, comply with accounting obligations, and pursue legitimate interests in fraud prevention and support. Consent is used where legally required.
License and transaction records are retained for the license relationship and applicable legal limitation or accounting periods. Support correspondence is retained only as long as reasonably necessary to resolve the request and protect legal rights.
6. Website Storage, Cookies & External Resources
This website's LocalStorage use is limited to three keys: your light/dark theme choice, a flag remembering that you've seen the privacy/cookie notice below, and your analytics choice (accepted/declined). Google Fonts is loaded from an external CDN for typography; that provider receives ordinary network metadata such as IP address, user agent, and request time. Icons on this site are inline SVG served from our own domain, not a third-party icon CDN.
Google Analytics (only with your consent). If you click "Accept analytics" in the cookie notice, we load Google Analytics 4 to understand aggregate site traffic (pages viewed, referring source, device type, approximate region). No script or cookie from Google Analytics loads before you accept — declining, or simply not answering, keeps it off. Google Analytics sets its own cookies (e.g. _ga, _ga_*) and processes data as Google LLC's independent controller under Google's own privacy policy; some processing occurs in the United States under Google's certification to the EU-U.S. Data Privacy Framework or another lawful transfer safeguard. We have not enabled Google Signals or advertising personalization, and this data is never sold or used for cross-context behavioral advertising. You can withdraw consent at any time by clearing your browser's site data for this domain, which shows the cookie notice again on your next visit, or by using a browser extension such as Google's Analytics opt-out add-on.
Checkout links lead to an external payment provider (LemonSqueezy). Its privacy terms apply once you reach checkout.
7. Opt-In Diagnostic Bug Reports
If you choose to submit a crash or bug report from inside the desktop application, we receive only the technical diagnostics required to fix the defect: an irreversible SHA-256 hash of your hardware identifier, the application version, licence tier, operating-system build string, the error type and sanitized message, a sanitized stack trace, and any explanation you type yourself.
Bug reports never include your mileage records, receipts, client addresses, odometer values, or database files. The lawful basis is our legitimate interest in product reliability (GDPR Art. 6(1)(f)); reports are deleted once the underlying defect is resolved and, in any case, within 24 months. Nothing is submitted unless you actively send the report.
8. GDPR Rights, Erasure & Data Export
Where GDPR applies, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting prior lawful processing. You may complain to the Slovak Data Protection Authority (Úrad na ochranu osobných údajov SR) or your local supervisory authority.
How to exercise the right to be forgotten (Art. 17) or data portability (Art. 20):
- Send the request through our contact page from the email address used at purchase or activation, stating whether you want export, erasure, or both.
- We verify the request against your licence or activation record. We may ask one confirming question; we never ask for a password or payment-card number.
- Export requests are answered with a machine-readable JSON file containing every field we hold for you (email, licence tokens, tier, activation timestamps, HWID hash, support correspondence).
- Erasure requests remove your CRM record, licence-to-device bindings, activation logs, and diagnostic reports. Statutory accounting records of a completed purchase are retained for the legally mandated period and then deleted.
- We respond within 30 days, and confirm in writing once the deletion has been executed.
Because the application is local-first, your mileage database is already exclusively under your control: deleting the local database folder and uninstalling the application erases all of your trip data permanently, with no server-side copy to request.
Some service providers may process data outside the EEA. Where required, transfers rely on adequacy decisions, Standard Contractual Clauses, or another lawful safeguard.
9. California & Other U.S. State Privacy Rights (CCPA/CPRA)
We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising — there is nothing to opt out of, but you still have rights under the California Consumer Privacy Act (as amended by the CPRA) and similar state laws (e.g. Virginia, Colorado, Connecticut, Utah):
- Right to know what personal information we hold about you and where it came from.
- Right to delete personal information we've collected, subject to the accounting/legal retention exceptions described in Section 8.
- Right to correct inaccurate personal information.
- Right to limit use of sensitive personal information — we don't collect sensitive personal information as defined by the CCPA in the first place (no government ID, precise geolocation, or health data).
- Right to non-discrimination for exercising any of the above — we will never charge you a different price or provide a different level of service.
Submit a California/U.S. state privacy request the same way as a GDPR request: through our contact page, selecting Privacy request. We verify requests the same way and respond within the timeframe required by applicable law (CCPA: 45 days, extendable once by 45 days).
10. Rights Outside the EU/UK/California
If you're located somewhere GDPR and the CCPA don't formally apply — Canada, Brazil, Australia, or elsewhere — we extend the same practical rights to you as a matter of policy, not only where a specific law (such as Canada's PIPEDA or Brazil's LGPD) requires it: you can ask what we hold about you, ask us to correct or delete it, and ask for a portable export, through the same contact page process described in Section 8.
11. Security & Local Backups
We use reasonable technical and organizational safeguards for services we operate. You control access to the local desktop database and are responsible for operating-system security, device access, backups, and secure deletion.
12. Contact & Requests
Submit privacy questions or rights requests through our contact page. We may need to verify your identity before fulfilling a request.
ReClaim Miles organizes and substantiates mileage records under the standards of IRS Publication 463 and Treas. Reg. § 1.274-5 (26 CFR § 1.274-5). It is a record-keeping and mileage substantiation tool, not a certified tax advisory firm, and it does not create proof that travel occurred. Consult a licensed CPA or tax professional for individual tax advice.