This policy explains how CarShows.online handles information when you browse events, create an organizer account, buy a listing or ad, or contact support.
Information we collect
Account information: name or organization name, email address, password hash, account status and login timestamps. We do not store your plaintext password.
Event and advertising content: details you choose to publish, uploaded images, contact information, destination URLs and campaign settings.
Transaction records: order references, purchased product, amount, currency, PayPal order/capture identifiers, payment status and payer email when returned by PayPal. CarShows.online does not collect or store full payment-card numbers through the standard PayPal flow.
Support information: email, subject, messages and related account references.
Public-source and claim information: for publicly indexed events, we may store the source URL/domain, organizer name and factual event details visible on the source page. Organizer claim requests may include the claimant account, verification notes and a public proof URL.
Security information: The application may temporarily store hashed email and network identifiers for sign-in rate limiting and abuse prevention. These security records are automatically aged out by the included maintenance task.
Usage information: our first-party operational analytics record requested page paths, event identifiers, referring domain, device category and timestamps. Event-sharing metrics can record the public event identifier, sharing channel and timestamp. The default application analytics/share tables do not contain a raw IP-address field. If the site operator enables Google Analytics 4, GA4 loads only after the visitor selects “Allow analytics” in the cookie choice shown by this site.
Saved shows and checklists: attendee saved-event IDs and checklist progress are stored in that browser using localStorage. Opening the Saved Shows page requests the current public event records for those locally stored IDs.
Optional location: “Near me” map features ask for browser/device location only after the visitor requests the feature and grants browser permission. The default map experience uses the resulting attendee location in the browser for map centering and distance sorting rather than intentionally writing it to the CarShows.online application database.
Organizer map lookup: when an organizer manually asks the event form to find an address, the event address is sent to the configured geocoding provider (the default 3.1 package uses the OpenStreetMap Nominatim public search service). Selected event coordinates can then be stored with the public event listing.
Administrative social publishing: the site operator may connect an official Facebook Page through Meta's Pages API. The application can store the Meta App Secret and Page access token in encrypted form, plus local post drafts, schedules, publication status and returned Facebook post identifiers/permalinks. This integration is for administrator publishing and does not require visitors to sign in with Facebook.
How we use information
We use information to provide and secure accounts, publish, index and moderate listings, review organizer claims, process and reconcile purchases, measure event and campaign performance, respond to support requests, prevent abuse, maintain records and comply with legal obligations.
How information is shared
Public event and advertising information is visible to site visitors by design. Payment information is exchanged with PayPal as necessary to process transactions and refunds. If the site operator enables Facebook Page publishing, selected public event/brand post content and destination links are sent to Meta when an administrator publishes or when a scheduled post becomes due. If GA4 is enabled and you consent, analytics information is sent to Google under the operator’s configured analytics account. We may also disclose information to service providers acting on our behalf, to comply with lawful process, or to protect users, the service and legal rights.
Sale of personal information
The default CarShows.online application is not designed to sell personal information for money. If the business model later changes in a way that creates additional state-law opt-out obligations, the operator should update this policy and deploy the required preference controls before that processing begins.
Cookies and browser storage
Essential cookies support secure sessions, authentication and CSRF protection. The analytics_consent preference records your choice about optional analytics. Saved Shows and checklist progress use localStorage. See the Cookie & Local Storage Policy.
Retention
We retain information for as long as reasonably necessary for the purposes described above, including account administration, event history, payment records, dispute handling, fraud prevention and legal obligations. Retention periods may differ by record type.
Security
The application uses password hashing, parameterized database queries, CSRF protections, restricted configuration directories, content-security headers and validated image uploads. No online service can promise absolute security, so the server, database, PHP runtime, TLS certificates and administrator credentials must also be maintained securely.
Your choices and rights
You can decline optional GA4 analytics through the cookie banner. Depending on where you live, applicable law may provide rights to access, correct, delete or obtain a copy of certain personal information, or to object to or restrict certain processing. Requests can be made through Support. We may need to verify identity before fulfilling a request and may retain information when required or permitted by law.
Children
CarShows.online is a general automotive event service and is not directed to children under 13. Organizer accounts and paid services are intended for adults or persons authorized to act for an organization.
Changes
We may update this policy as the service changes. The effective date above identifies the current published version.
Contact
Privacy questions or requests can be submitted through Support or sent to payments@carshows.online.
