Privacy policy
We collect only what we need to arrange your vignette, take your payment and support you afterwards. This page explains what that is, who else sees it, how long we keep it and what rights you have.
Who is responsible
The company operating toll.one, identified on the imprint page, is the data controller for the processing described here. For anything about your personal data, email support@toll.one.
What we collect and why
To take and fulfil an order we process:
- Your name and email address, to confirm your order, send you the vignette confirmation and answer your questions.
- Your vehicle's licence plate, country of registration and vehicle category, the start date you chose and, where required by the operator, the vehicle identification number and identity document series or number with its issuing country. These details are required to register the vignette and are passed to the road operator for that purpose.
- Your order, its price and its payment status. We never see or store your card details; Stripe handles the payment and tells us only whether it succeeded.
- Messages you send through the contact form or by email. We keep messages about an order with that order; other messages stay in the support mailbox only while the matter is open.
- Cloudflare Turnstile checks contact-form submissions for automated abuse. It receives the technical information needed to make that check, but not the message, your name or your email address.
- Technical logs needed to keep the site secure and to limit abuse, such as the time of a request and a secret-keyed identifier for its network or email address. Rate-limit windows expire after at most one hour, and stale counters are removed during later rate-limit checks.
- Vercel derives an approximate country from your network address. We use its two-letter country code only to preselect the registration-country field, which is also the first country offered for a billing address where a road operator asks for one. The hint itself is not added to your order or analytics.
Legal basis
We process your order details because they are necessary to perform the contract you enter into with us. We process support messages to answer the request you made, either as a step before an order or as part of our legitimate interest in supporting customers. We keep transaction records because accounting and tax law require it. We keep security logs and limit abuse on the basis of our legitimate interest in running the service safely. We preselect the registration country, and offer it as the first billing country where one is required, on the basis of our legitimate interest in reducing input errors, and you can replace either before ordering. Analytics and advertising measurement run only with your consent, which you can withdraw at any time in the cookie settings.
We may also send you two emails about the service you bought: one asking for a review, and one shortly before your vignette ends. We send them on the basis of our legitimate interest in telling our own customers about the service they bought from us. Each carries a link that stops both with one click, and when you use it we keep your address on a list of addresses we must not email, so that we do not write to you again.
Licence plates
We treat licence plate data, vehicle identification numbers and identity document details as personal information. They are stored to fulfil your order and support you afterwards, shared only with the road operator that registers the vignette or with the authorised distributor we buy that vignette from, and never included in analytics events.
Who receives your data
We share personal data only with the parties needed to provide the service:
- The official road operator of the country you selected, which receives the licence plate, country of registration, vehicle category and validity period needed to register the vignette. Where its form requires them, it also receives the vehicle identification number and identity document series or number with its issuing country. The operator's own privacy policy applies to that registration. Operators never receive your email address; their confirmations come to an address we control.
- The authorised distributor we buy from, where a country's operator sells only to registered account holders. Romania is the one today: roviniete.ro receives the same vehicle details as an operator, the chassis number as well where the rovinieta is registered against one, and, because it issues the invoice, the billing name and address you give at checkout. Its own privacy policy applies. It receives an email address we control rather than yours, and we delete the billing address 30 days after the order ends.
- Stripe, our payment provider, which processes your payment and receives your email address for the payment receipt. Where advertising was allowed, the advertising reference described under OpenAI below and the country your IP address places you in are filed alongside the payment, so that they survive until your payment is confirmed. Your IP address itself is not filed with it.
- Resend, which delivers our emails to you, carries contact-form messages to our support mailbox and receives the operator's confirmation on our behalf.
- Cloudflare Turnstile, which checks contact-form submissions for automated abuse. Its own privacy policy applies to that check.
- Vercel, which hosts the website, and Supabase, which hosts our database. Both are configured to keep our data in the European Union, in Frankfurt.
- PostHog Cloud EU receives aggregate cookie-banner impression and choice events so we can compare clear versions of the banner, and one more of the same kind when a payment is started, recording only which of the three cookie answers was standing at that moment. These events use a fixed aggregate identifier and no browser identifier, page address, referrer, order or customer data, so they can say how many people did something and never who. If you allow analytics, PostHog also receives an anonymous browser identifier, shortened page addresses, interaction events, masked session recordings and technical details about browser errors. It receives the campaign labels in the link you arrived through, whether that link carried an advertising click code but never the code itself, and the name of the website that sent you, so we can tell which campaigns are worth running. For a completed order it also receives the order reference, the number of vignettes, our service fee, and the country and validity period of each vignette. Input values are masked, and private order and staff screens are blocked from recordings. It never receives your name, email address, licence plate, chassis number, travel dates or private order link.
- HeiGIT (openrouteservice, Heidelberg, Germany), when you use the route planner. Our server sends it the place names you type and the two coordinates of your route so it can calculate the roads between them. It does not receive your IP address, your dates, your vehicle or your licence plate.
- The OpenStreetMap Foundation (United Kingdom), which serves the map images on the route planner page. Your browser requests those images directly, so it receives your IP address and the map area you look at, and nothing else. No map image is requested until you have planned a route.
- Google, but only if you have allowed analytics or advertising. It receives the address of the page you are on, with the link to an order page shortened first so the private part of it is never sent, and, for a completed order, the order reference, the amount of our service fee, and the country and validity period of each vignette. It never receives your name, your email address, your licence plate or the private link to your order page.
- OpenAI, but only if advertising was allowed when checkout began. Its server receives the checkout page address without its query string and, for a paid order, the order reference, our service fee, and the country and validity period of each vignette. After a paid order it also receives your email address and the customer number we file your orders under, each turned into a SHA-256 hash first, so that OpenAI can match the order to the advert you clicked. Your hashed email address is also sent at the moment you submit your contact details at checkout, before any payment, and it is sent even if you never complete the order. A hash is a one-way code that cannot be turned back into the value it was made from. For as long as advertising is allowed, the requests our server sends as you move through the site also carry the IP address the request came from, the country that address places it in, the description your browser sends of itself, and the reference OpenAI's own script stored in your browser, which is how it can recognise a visit as the one that followed its advert before you have typed anything. The paid order carries two of those four, the browser reference and the country, read from your own request to us when you go to pay, so an order can still be matched to the advert when the token from the arrival link did not survive the visit. Your IP address and your browser's description of itself are not attached to it. Where the country you selected made us ask for a billing address, the paid order carries its town, postcode and country instead of the country read from your IP address. Our server never sends your name, your licence plate, your private order link or a readable email address.
- Our own staff, who arrange orders and answer support requests.
Transfers outside the European Union
Some of these providers are based in the United States. Where personal data leaves the European Economic Area, it does so under the EU standard contractual clauses or the EU-US Data Privacy Framework, and it remains protected to the standard required by EU law.
Cookies and browser storage
We ask for your choice the first time you visit, and you can change it at any time using the Cookie settings link in the footer. Until you choose, nothing optional runs. We store:
- Your cart, kept in your browser so your selection survives a page reload. Required for the site to take an order.
- Contact and billing details you type during checkout, kept in your browser for 30 days after your last edit so returning to the cart does not mean typing them again. They stay on your own device until you send them with an order, and this copy holds nothing about your vehicle or your card. A completed order deletes them. So does opening checkout again more than 30 days after you last typed, and they are never used after that point. Clearing your browser data removes them at any time.
- Your cookie choice itself, kept in your browser so we do not ask again on every page.
- A note that one order has already been counted as a sale, kept in your browser so that opening the same order again does not count it a second time. It holds your order reference and nothing else, and only if you turned on the measurement it belongs to. Clearing your browser data removes it.
- A session cookie for staff signing in to our internal order queue. It is never set for customers.
- Analytics, only if you turn it on. See below.
- Advertising measurement, only if you turn it on. It is a separate question from analytics, and answering yes to one is not answering yes to the other.
Analytics
If you allow it, we use Vercel Web Analytics to see which pages and guides people find useful, and Vercel Speed Insights to see which pages load slowly. Both are anonymous and aggregated, and neither uses advertising cookies or builds a profile of you. Analytics never receives licence plates, email addresses or names.
With the same permission we use Google Analytics 4, with Google acting as our processor. It receives the address of the page you are on and, if you complete an order, the order reference, the amount of our service fee, and the country and validity period of each vignette you bought.
We also use PostHog Cloud EU with that permission to understand the steps people complete, replay masked sessions, see which controls they use and diagnose browser errors. PostHog masks every input value, we mask displayed licence plates, and private order and staff screens are blocked from recordings. Query strings and the private parts of order and staff page addresses are removed before they leave your browser. The campaign labels in an arrival link are read on your own device and sent as plain labels, so the link itself, and any advertising click identifier in it, stays in your browser.
If you decline, or have not yet chosen, no optional analytics script is loaded and no optional analytics request is made. The separate aggregate measurement still records whether the banner was shown, which choice was made, and, if you start a payment, which answer was standing at that moment, all without a browser identifier, page address or referrer.
Advertising
Advertising is a separate question, and the answer is no unless you say otherwise. If you allow it, we use Google Ads and OpenAI Ads to tell which adverts brought someone to this site and what winning an order costs us. Both act as our processors. Google may set advertising cookies once you have allowed it. OpenAI receives a server-side conversion after a verified payment, a further one carrying your hashed email address as soon as you submit your contact details at checkout, and, once you allow advertising, it also loads a browser script of its own on this site.
Google receives a short list: a page address without its query string and, for a paid order, the order reference, our service fee, and the country and validity period of each vignette. It never receives your name, email address, licence plate or private order link. OpenAI receives that same short list for its server-side conversion, plus the raw advertising attribution token it placed in the arrival link. If you arrive from an advert, we note that token from the link in your browser's memory straight away, before you answer the cookie banner. It is only saved and sent to OpenAI if you then allow advertising. If you refuse, or you close the page without answering, it is discarded and never leaves your browser. After a paid order, our server also sends OpenAI your email address and the customer number we file your orders under, each turned into a SHA-256 hash first, so that OpenAI can match the order to the advert you clicked. The same hashed email address is sent earlier as well, at the moment you submit your contact details at checkout. That happens before any payment, so it is sent even if you change your mind and never complete the order. Your address is turned into the hash on your own device and the readable form is never stored or sent by us. A hash is a one-way code: OpenAI can compare it with a value it already holds, but it cannot read it or turn it back into your address. Our server attaches four further things to what it sends, for as long as advertising is allowed: the IP address the request came from, the country that address places it in, the description your browser sends of itself, and the reference OpenAI's own script stored in your browser. These are what let OpenAI tell which advert a visit followed while you are still only browsing and have given us nothing to hash. Two of the four are attached to the paid order as well, the reference OpenAI's own script stored in your browser and the country, so an order can still be matched to the advert when the token from the arrival link did not survive the visit. Neither can be read from the payment itself, because that is confirmed by a message from Stripe rather than by you, so we read them from your own request to us when you go to pay and file them with the payment session until it is confirmed. Your IP address and your browser's description of itself are deliberately left out of that, because filing them with the payment would leave them with Stripe for as long as it keeps the record. The country is only ever the country your IP address places you in, never a town or a postcode. Where the country you selected made us ask for a billing address, the paid order carries the town, postcode and country you typed instead. Your name, your licence plate, your private order link and a readable email address are attached to none of it. OpenAI's browser script goes further: on any page where you enter them, including checkout, it reads your email address, phone number, first and last name, and address details, hashes them on your own device, and sends the hashed values to OpenAI to match you to an advert. We do not send OpenAI your licence plate or your private order link, and Google never receives any of this.
Nothing from Google is loaded until you allow one of these two. Once you allow advertising, OpenAI's own browser script loads as well; it is not loaded at all if you decline or have not yet chosen. It stores two references of its own in your browser, one for the advert you arrived from and one for the browser itself, and our server reads both and reports them back to OpenAI. It also reads and hashes the details described above for as long as advertising is allowed. If advertising was not allowed when checkout began, no conversion request is made to OpenAI.
You can withdraw either permission at any time using the Cookie settings link in the footer. Withdrawing reloads the page, because a script that has already loaded keeps running until it does.
How long we keep your data
We keep order records, including the licence plate, any vehicle identification number or identity document details and the operator's confirmation, for as long as we need them to support you and for as long as accounting and tax law require us to keep transaction records. After that they are deleted. Identity document details are also cleared during the sensitive-data cleanup described below.
For a Hungarian vignette or a Romanian rovinieta the shop that issues it will not take a payment without a billing address, so we collect yours at checkout and pass it to that shop with the order. For a Moldovan vignette, the identity document series or number and issuing country are passed to the official shop and shown only in the protected fulfillment surfaces where someone has to use them. An operator alert email contains a protected link rather than readable copies, and we never send it to a chat channel. We delete these sensitive checkout copies 30 days after the order is completed, cancelled or abandoned, which is separate from the order record itself. If you allowed advertising, the town, postcode and country alone are also sent to OpenAI with the paid order, so that it can match the order to the advert you clicked. Our deletion after 30 days clears our own copy and not that one, which OpenAI keeps for as long as its own policy says.
Checkouts that are started but never paid are not used for anything and are removed in routine clean-up.
Support messages are kept while the matter they concern is open. Messages about an order are then kept for the same period as that order; messages unrelated to an order are deleted when the matter is closed.
PostHog events, error details and session recordings are kept only while they help us understand and improve the checkout. We review whether they are still needed at least once a year and delete them when they no longer serve that purpose.
Security
All traffic to the site is encrypted. Card details never reach us. Access to order data is limited to the staff who need it to arrange orders and answer support requests.
Your rights
Under EU data protection law you can:
- Ask for a copy of the personal data we hold about you.
- Ask us to correct data that is wrong. A licence plate on a vignette that has already been registered cannot be changed; see our refund policy.
- Ask us to delete your data, except where we must keep it to meet a legal obligation.
- Ask us to restrict processing, or object to processing based on our legitimate interests.
- Receive the data you gave us in a machine readable form.
- Withdraw your consent to analytics or to advertising at any time using the Cookie settings link in the footer.
- Complain to the data protection authority in your country if you believe we have handled your data unlawfully.
How to exercise them
Email support@toll.one from the address you used for your order and tell us what you want. We answer within one month.
Changes
We update this page when our processing changes. The date below shows when it was last reviewed.
Ultima verificare .