Privacy policy
We collect only what we need to arrange your vignette, take your payment and support you afterwards. This page explains what that is, who else sees it, how long we keep it and what rights you have.
Who is responsible
The company operating toll.one, identified on the imprint page, is the data controller for the processing described here. For anything about your personal data, email support@toll.one.
What we collect and why
To take and fulfil an order we process:
- Your name and email address, to confirm your order, send you the vignette confirmation and answer your questions.
- Your vehicle's licence plate, country of registration and vehicle category, and the start date you chose. These are required to register the vignette and are passed to the road operator for that purpose.
- Your order, its price and its payment status. We never see or store your card details; Stripe handles the payment and tells us only whether it succeeded.
- Messages you send through the contact form or by email. We keep messages about an order with that order; other messages stay in the support mailbox only while the matter is open.
- Cloudflare Turnstile checks contact-form submissions for automated abuse. It receives the technical information needed to make that check, but not the message, your name or your email address.
- Technical logs needed to keep the site secure and to limit abuse, such as the time of a request and a secret-keyed identifier for its network or email address. Rate-limit windows expire after at most one hour, and stale counters are removed during later rate-limit checks.
- Vercel derives an approximate country from your network address. We use its two-letter country code only to preselect the registration-country field, which is also the first country offered for a billing address where a road operator asks for one. The hint itself is not added to your order or analytics.
Legal basis
We process your order details because they are necessary to perform the contract you enter into with us. We process support messages to answer the request you made, either as a step before an order or as part of our legitimate interest in supporting customers. We keep transaction records because accounting and tax law require it. We keep security logs and limit abuse on the basis of our legitimate interest in running the service safely. We preselect the registration country, and offer it as the first billing country where one is required, on the basis of our legitimate interest in reducing input errors, and you can replace either before ordering. Analytics and advertising measurement run only with your consent, which you can withdraw at any time in the cookie settings.
We may also send you two emails about the service you bought: one asking for a review, and one shortly before your vignette ends. We send them on the basis of our legitimate interest in telling our own customers about the service they bought from us. Each carries a link that stops both with one click, and when you use it we keep your address on a list of addresses we must not email, so that we do not write to you again.
Licence plates
We treat licence plate data as personal information. It is stored to fulfil your order and support you afterwards, it is shared only with the road operator that registers the vignette, and it is never included in analytics events.
Who receives your data
We share personal data only with the parties needed to provide the service:
- The official road operator of the country you selected, which receives the licence plate, country of registration, vehicle category and validity period needed to register the vignette. The operator's own privacy policy applies to that registration. Operators never receive your email address; their confirmations come to an address we control.
- Stripe, our payment provider, which processes your payment and receives your email address for the payment receipt.
- Resend, which delivers our emails to you, carries contact-form messages to our support mailbox and receives the operator's confirmation on our behalf.
- Cloudflare Turnstile, which checks contact-form submissions for automated abuse. Its own privacy policy applies to that check.
- Vercel, which hosts the website, and Supabase, which hosts our database. Both are configured to keep our data in the European Union, in Frankfurt.
- PostHog Cloud EU receives aggregate cookie-banner impression and choice events so we can compare clear versions of the banner. These events use a fixed aggregate identifier and no browser identifier, page address, referrer or customer data. If you allow analytics, PostHog also receives an anonymous browser identifier, shortened page addresses, interaction events, masked session recordings and technical details about browser errors. It receives the campaign labels in the link you arrived through and the name of the website that sent you, so we can tell which campaigns are worth running. For a completed order it also receives the order reference, the number of vignettes, our service fee, and the country and validity period of each vignette. Input values are masked, and private order and staff screens are blocked from recordings. It never receives your name, email address, licence plate, chassis number, travel dates or private order link.
- HeiGIT (openrouteservice, Heidelberg, Germany), when you use the route planner. Our server sends it the place names you type and the two coordinates of your route so it can calculate the roads between them. It does not receive your IP address, your dates, your vehicle or your licence plate.
- The OpenStreetMap Foundation (United Kingdom), which serves the map images on the route planner page. Your browser requests those images directly, so it receives your IP address and the map area you look at, and nothing else. No map image is requested until you have planned a route.
- Google, but only if you have allowed analytics or advertising. It receives the address of the page you are on, with the link to an order page shortened first so the private part of it is never sent, and, for a completed order, the order reference, the amount of our service fee, and the country and validity period of each vignette. It never receives your name, your email address, your licence plate or the private link to your order page.
- OpenAI, but only if advertising was allowed when checkout began. Its server receives the checkout page address without its query string and, for a paid order, the order reference, our service fee, and the country and validity period of each vignette. It never receives your name, email address, licence plate, IP address, browser identifier or private order link.
- Our own staff, who arrange orders and answer support requests.
Transfers outside the European Union
Some of these providers are based in the United States. Where personal data leaves the European Economic Area, it does so under the EU standard contractual clauses or the EU-US Data Privacy Framework, and it remains protected to the standard required by EU law.
Cookies and browser storage
We ask for your choice the first time you visit, and you can change it at any time using the Cookie settings link in the footer. Until you choose, nothing optional runs. We store:
- Your cart, kept in your browser so your selection survives a page reload. Required for the site to take an order.
- Contact and billing details you type during checkout, kept in this browser tab for 30 minutes after your last edit so returning to the cart does not mean typing them again. Expired details are removed when checkout reads them again. We clear them after a verified payment. This temporary copy contains no card details.
- Your cookie choice itself, kept in your browser so we do not ask again on every page.
- A session cookie for staff signing in to our internal order queue. It is never set for customers.
- Analytics, only if you turn it on. See below.
- Advertising measurement, only if you turn it on. It is a separate question from analytics, and answering yes to one is not answering yes to the other.
Analytics
If you allow it, we use Vercel Web Analytics to see which pages and guides people find useful, and Vercel Speed Insights to see which pages load slowly. Both are anonymous and aggregated, and neither uses advertising cookies or builds a profile of you. Analytics never receives licence plates, email addresses or names.
With the same permission we use Google Analytics 4, with Google acting as our processor. It receives the address of the page you are on and, if you complete an order, the order reference, the amount of our service fee, and the country and validity period of each vignette you bought.
We also use PostHog Cloud EU with that permission to understand the steps people complete, replay masked sessions, see which controls they use and diagnose browser errors. PostHog masks every input value, we mask displayed licence plates, and private order and staff screens are blocked from recordings. Query strings and the private parts of order and staff page addresses are removed before they leave your browser. The campaign labels in an arrival link are read on your own device and sent as plain labels, so the link itself, and any advertising click identifier in it, stays in your browser.
If you decline, or have not yet chosen, no optional analytics script is loaded and no optional analytics request is made. The separate aggregate banner measurement still records whether the banner was shown and which choice was made, without a browser identifier, page address or referrer.
Advertising
Advertising is a separate question, and the answer is no unless you say otherwise. If you allow it, we use Google Ads and OpenAI Ads to tell which adverts brought someone to this site and what winning an order costs us. Both act as our processors. Google may set advertising cookies once you have allowed it. OpenAI receives a server-side conversion after a verified payment and, once you allow advertising, also loads a browser script of its own on this site.
Google receives a short list: a page address without its query string and, for a paid order, the order reference, our service fee, and the country and validity period of each vignette. It never receives your name, email address, licence plate or private order link. OpenAI receives that same short list for its server-side conversion, plus the raw advertising attribution token it placed in the arrival link, with no user object or browser identifier attached. OpenAI's browser script goes further: on any page where you enter them, including checkout, it reads your email address, phone number, first and last name, and address details, hashes them on your own device, and sends the hashed values to OpenAI to match you to an advert. We do not send OpenAI your licence plate or your private order link, and Google never receives any of this.
Nothing from Google is loaded until you allow one of these two. Once you allow advertising, OpenAI's own browser script loads as well; it is not loaded at all if you decline or have not yet chosen. It sets no advertising cookie of its own, but it does read and hash the details described above for as long as advertising is allowed. If advertising was not allowed when checkout began, no conversion request is made to OpenAI.
You can withdraw either permission at any time using the Cookie settings link in the footer. Withdrawing reloads the page, because a script that has already loaded keeps running until it does.
How long we keep your data
We keep order records, including the licence plate and the operator's confirmation, for as long as we need them to support you and for as long as accounting and tax law require us to keep transaction records. After that they are deleted.
For a Hungarian vignette the toll operator will not take a payment without a billing address, so we collect yours at checkout and pass it to the operator with the order. Inside our own team it appears only where someone has to type it into the operator's shop: the admin pages, the operator alert email and the working files we submit to the operator. We never send it to a chat channel. We delete it 30 days after the order is completed, cancelled or abandoned, which is separate from the order record itself.
Checkouts that are started but never paid are not used for anything and are removed in routine clean-up.
Support messages are kept while the matter they concern is open. Messages about an order are then kept for the same period as that order; messages unrelated to an order are deleted when the matter is closed.
PostHog events, error details and session recordings are kept only while they help us understand and improve the checkout. We review whether they are still needed at least once a year and delete them when they no longer serve that purpose.
Security
All traffic to the site is encrypted. Card details never reach us. Access to order data is limited to the staff who need it to arrange orders and answer support requests.
Your rights
Under EU data protection law you can:
- Ask for a copy of the personal data we hold about you.
- Ask us to correct data that is wrong. A licence plate on a vignette that has already been registered cannot be changed; see our refund policy.
- Ask us to delete your data, except where we must keep it to meet a legal obligation.
- Ask us to restrict processing, or object to processing based on our legitimate interests.
- Receive the data you gave us in a machine readable form.
- Withdraw your consent to analytics or to advertising at any time using the Cookie settings link in the footer.
- Complain to the data protection authority in your country if you believe we have handled your data unlawfully.
How to exercise them
Email support@toll.one from the address you used for your order and tell us what you want. We answer within one month.
Changes
We update this page when our processing changes. The date below shows when it was last reviewed.
Ultima revisione .