1. Who I am
RebelOne is operated by RebelOne AG, the company responsible for your information.
Contact:
- General: mike@rebel.one
- Privacy questions: privacy@rebel.one
- Physical address: 2764 Pleasant Road, Suite A #778, Fort Mill, SC 29708, USA
2. What I collect
Here's every piece of information I hold, broken down by how I got it.
If you gave me your email on the homepage
- Your email address
- Your first name (if you gave it)
- Whether you ticked the research-drip box
If you took an assessment
- Everything in the homepage section above
- Every answer you gave on the quiz
- The score I calculated for you
- Which assessment you completed, and when
If you ran the recovery calculator
- Everything in the homepage section above
- Every number you entered (mechanics, rate, jobs per week, friction minutes, unbilled minutes, comebacks)
- The calculated leakage figures
- Your shop name, if you gave it
If you submitted a contact form
- Everything in the homepage section above
- Your full name (if you gave it)
- The message you wrote
If you applied to be a founder
- Everything in the homepage section above
- Every answer you gave on the application
- Your shop details
- My private notes on your application (written after I read it)
Collected automatically, regardless of what you do
- Your IP address (kept for 30 days, used for rate limiting)
- Your browser and device type (helps me spot bot traffic)
- Which pages you visited on RebelOne
- The domain that referred you (if any)
I do not collect:
- Payment information (there's nothing to pay for)
- Location beyond what IP address implies
- Information from third-party platforms about you
- Anything from tracking pixels, advertising networks, or social media
3. Why I collect it
One reason per thing:
- Email address. So I can send you what you asked for (the book, a quiz result, a recovery report, a reply to your message, a decision on your application). And, if you ticked the box, so I can send you the research drip.
- First name. So emails can open "Hi Sarah" instead of "Hi". If you didn't give me one, the email opens "Hi there".
- Quiz or calculator inputs. So I can generate your result. Without them, I can't give you a score or a report.
- Shop name. So the recovery report can say "Here's your recovery plan for Grimshaw's Garage" instead of "Here's your recovery plan".
- Contact form message. So I can reply to the question you asked.
- Application details. So I can decide whether it's a fit as a founder, and so I can reply honestly either way.
- IP address. So I can stop one person submitting the form 10,000 times.
- Browser and device type. Same reason — spotting abusive traffic.
- Pages visited. So I know which parts of the site are useful. I look at this in aggregate, not per person.
4. Who sees it
Me. I'm the only person who sees your information.
Technology-wise, the information lives on these services, which store and process it on my behalf:
| Service | What it stores or does | Where | Compliance |
|---|---|---|---|
| Supabase | The database — your email, form answers, quiz results | US / Frankfurt | SOC 2 Type 2 |
| Netlify | The website and the book files | US / global CDN | SOC 2 Type 2 |
| Resend | Sends the transactional emails (book delivery, quiz results, replies) | US | SOC 2 Type 2 |
| Loops | Sends the 5-email research drip (only if you opted in) | US | SOC 2 Type 1 |
These are called sub-processors. I've signed their data processing agreements. They can't use your information for their own purposes — only to do the job I've hired them for. These are my current providers and may change over time.
I never sell personal data. I do not share your personal information with advertisers, data brokers or anyone else for their own use.
I may create anonymous, aggregated statistics and benchmarks (for example “the average shop loses X hours a week”) and use, publish, share or sell them. Nobody — no person, shop or vehicle — can be identified from them.
I will also disclose your information if a court orders me to — and even then, I'll tell you first unless legally prevented from doing so.
5. How long I keep it
- Until you ask me to delete it. If you email privacy@rebel.one and ask for deletion, it's gone within 90 days.
- Or until three years after your last interaction with RebelOne. If you haven't engaged in three years, I'll delete your information automatically.
- Anonymous, aggregated statistics and benchmarks (things like "12,000 people completed an assessment last quarter") that don't identify anyone individually I keep indefinitely. They're research, not personal data.
- Legal audit trail of data requests (GDPR Article 30) I keep for six years. This is a separate record that contains no personal data — just "someone requested deletion on 14 May 2026, it was completed on 17 May 2026".
6. Your rights
GDPR and CCPA give you the following rights over your information. They work identically under Swiss FADP. Plain-English version:
- Right to know. You can ask me what I hold about you. I'll send you a copy within 30 days.
- Right to get it in a useful format. If you want the data in a machine-readable file (JSON / CSV) so you can take it somewhere else, I'll give it to you that way.
- Right to correct it. If anything I hold is wrong, tell me and I'll fix it.
- Right to delete it. You can ask me to delete everything I hold about you. It'll be gone within 90 days, excluding the minimal audit trail mentioned in section 5.
- Right to object. You can object to how I'm using your information. If you object to marketing, I stop marketing. If you object to other processing, I'll explain the basis I was relying on and you can challenge it.
- Right to restrict. You can ask me to pause processing while I work something out.
- Right to withdraw consent. The unsubscribe link at the bottom of every marketing email does this in one click. You can also withdraw privacy acknowledgement retroactively — email privacy@rebel.one.
- Right to complain. If you think I've handled your information badly and I haven't fixed it when you told me, you can complain to your local data protection authority. EU subjects: your national DPA. California subjects: the California Attorney General. Swiss subjects: the Federal Data Protection and Information Commissioner (FDPIC).
How to exercise any of these rights: email privacy@rebel.one with the right you want to exercise and your email address. I don't require ID verification unless the request is unusual or doesn't match an email I have on file.
7. Cookies and tracking
The site sets a small number of cookies. None of them are advertising cookies. None of them track you across other websites.
| Cookie | Purpose | How long |
|---|---|---|
ro_session | Remembers you during a single visit so the site works (e.g., remembers which assessment you're on) | Session only — deleted when you close the tab |
ro_cookie_ack | Remembers that you've seen the cookie banner | 365 days |
Beyond cookies, the site uses your browser’s local storage — a place the site keeps small amounts of information on your own device. I use it to remember what you’ve done so you can pick up where you left off: your calculator result, which assessments you’ve completed, and where you are in the journey. This stays on your device, is never used to track you across sites, and you can clear it any time by clearing site data for rebel.one in your browser.
I don't use Google Analytics. I don't use Facebook Pixel. I don't use Mixpanel, Hotjar, Segment, or any similar product. I don't run A/B tests that track individual users.
I do use server-side logs on Netlify and Supabase (how many visits, which pages, rough geography). That's all at the service level, not tied to you as an individual.
8. Children
rebel.one is intended for working mechanics and shop owners. I don't knowingly collect information from anyone under 18. If you're under 18 and have given me your information, email privacy@rebel.one and I'll delete it.
9. International transfers
Some of my sub-processors (Supabase, Netlify, Resend, Loops) are US-based. When your information is transferred from the EU / UK / Switzerland to the US, it happens under the EU-US Data Privacy Framework (for Supabase, Netlify, Resend) or Standard Contractual Clauses (for Loops). Both are approved transfer mechanisms under GDPR Article 46.
If you want copies of the DPAs or SCCs, email privacy@rebel.one and I'll send them.
10. Changes to this notice
If I change how information is handled, I update this page and stamp it with the date of the change. If the change is material — new processor, new purpose, new data type — I send a plain-English email to everyone on file telling them what changed.
11. Supervisory authorities
If you're not happy with how I've handled your data and I haven't resolved it, you can go over my head:
- EU / EEA: your national Data Protection Authority. List at edpb.europa.eu.
- UK: the Information Commissioner's Office (ico.org.uk).
- Switzerland: the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
- California: the California Attorney General (oag.ca.gov).
I'd rather you email me first, but you don't have to.
If anything in this notice is unclear, email privacy@rebel.one. I try to reply within 48 hours.
— Mike Duggan, RebelOne