Privacy Policy
Last updated: October 27, 2025
At TurboScore ("we", "our", or "us"), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our services, in compliance with the General Data Protection Regulation (GDPR) and applicable Norwegian data protection laws.
1. Information We Collect
1.1 Information You Provide
When you create an account and use TurboScore, we collect:
- Account Information: Name, email address, and password (encrypted)
- Search Preferences: Car search criteria, budget preferences, saved searches
- Favorites & Bookmarks: Cars you save or mark as favorites
- Communication: Messages you send us, feedback, and support requests
1.2 Automatically Collected Information
When you use our services, we automatically collect:
- Usage Data: Pages visited, search queries, features used, time spent
- Device Information: Browser type, operating system, IP address
- Analytics Data: User behavior, conversion funnels, feature usage (only with your consent)
- Session Data: Session ID, authentication tokens
1.3 Third-Party Data
We collect publicly available car listing data from third-party websites (FINN.no, Blocket.se) to provide our services.
2. Legal Basis for Processing
Under GDPR, we process your personal data based on:
- Consent: For analytics cookies and marketing communications (you can withdraw anytime)
- Contract: To provide the services you requested when creating an account
- Legitimate Interest: To improve our services, prevent fraud, and ensure security
- Legal Obligation: To comply with applicable laws and regulations
3. How We Use Your Information
We use your information to:
- Provide and maintain our car search and comparison services
- Generate personalized TurboScore ratings and car recommendations
- Process your searches and display relevant results
- Send you notifications about saved searches and price drops (with your consent)
- Improve our services through analytics (with your consent)
- Communicate with you about your account and our services
- Prevent fraud, ensure security, and enforce our terms
- Comply with legal obligations
4. Cookies and Tracking Technologies
We use cookies and similar technologies to provide and improve our services. For detailed information about the cookies we use, please see our Cookie Policy.
- Necessary Cookies: Required for the website to function (authentication, session management)
- Analytics Cookies: Track usage patterns and performance (only with your consent)
You can manage your cookie preferences through our cookie consent banner.
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
- Service Providers: Hosting (Digital Ocean), database services, email providers (only as necessary)
- Legal Requirements: When required by law, court order, or to protect our rights
- Business Transfers: In the event of a merger, acquisition, or sale of assets
All third-party service providers are contractually bound to protect your data and use it only for specified purposes.
6. Data Retention
We retain your personal data only as long as necessary:
- Account Data: Until you delete your account, plus 30 days for backup purposes
- Analytics Data: Anonymized after 13 months
- Session Data: Deleted after session expires
- Legal Obligations: Some data may be retained longer if required by law
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for analytics cookies at any time
- Right to Complain: Lodge a complaint with your data protection authority
To exercise these rights, contact us at gunnar@solheimsolutions.no
8. Data Security
We implement industry-standard security measures to protect your data:
- SSL/TLS encryption for data transmission
- Encrypted password storage using bcrypt
- Secure database access controls
- Regular security updates and monitoring
- Limited employee access to personal data
While we take reasonable measures to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
9. International Data Transfers
Your data is stored on servers located in the European Economic Area (EEA). If we transfer data outside the EEA, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses, adequacy decisions).
10. Children's Privacy
TurboScore is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice on our website. Continued use of our services after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us:
- Email: gunnar@solheimsolutions.no
- Company: Solheim Solutions
- Product: TurboScore
For data protection concerns, you may also contact the Norwegian Data Protection Authority (Datatilsynet) at www.datatilsynet.no