Privacy

Privacy Notice

Last updated: October 1, 2026

This is a plain-English version of what I do with your information when you use RebelOne. I'm not a lawyer, but I've tried to cover everything the law requires (GDPR, CCPA, and Swiss FADP) without hiding behind legal language.

If anything below is unclear, email me at privacy@rebel.one and I'll explain it.


1. Who I am

RebelOne is operated by RebelOne AG, the company responsible for your information.

Contact:

2. What I collect

Here's every piece of information I hold, broken down by how I got it.

If you gave me your email on the homepage

If you took an assessment

If you ran the recovery calculator

If you submitted a contact form

If you applied to be a founder

Collected automatically, regardless of what you do

I do not collect:

3. Why I collect it

One reason per thing:

4. Who sees it

Me. I'm the only person who sees your information.

Technology-wise, the information lives on these services, which store and process it on my behalf:

ServiceWhat it stores or doesWhereCompliance
SupabaseThe database — your email, form answers, quiz resultsUS / FrankfurtSOC 2 Type 2
NetlifyThe website and the book filesUS / global CDNSOC 2 Type 2
ResendSends the transactional emails (book delivery, quiz results, replies)USSOC 2 Type 2
LoopsSends the 5-email research drip (only if you opted in)USSOC 2 Type 1

These are called sub-processors. I've signed their data processing agreements. They can't use your information for their own purposes — only to do the job I've hired them for. These are my current providers and may change over time.

I never sell personal data. I do not share your personal information with advertisers, data brokers or anyone else for their own use.

I may create anonymous, aggregated statistics and benchmarks (for example “the average shop loses X hours a week”) and use, publish, share or sell them. Nobody — no person, shop or vehicle — can be identified from them.

I will also disclose your information if a court orders me to — and even then, I'll tell you first unless legally prevented from doing so.

5. How long I keep it

6. Your rights

GDPR and CCPA give you the following rights over your information. They work identically under Swiss FADP. Plain-English version:

How to exercise any of these rights: email privacy@rebel.one with the right you want to exercise and your email address. I don't require ID verification unless the request is unusual or doesn't match an email I have on file.

7. Cookies and tracking

The site sets a small number of cookies. None of them are advertising cookies. None of them track you across other websites.

CookiePurposeHow long
ro_sessionRemembers you during a single visit so the site works (e.g., remembers which assessment you're on)Session only — deleted when you close the tab
ro_cookie_ackRemembers that you've seen the cookie banner365 days

Beyond cookies, the site uses your browser’s local storage — a place the site keeps small amounts of information on your own device. I use it to remember what you’ve done so you can pick up where you left off: your calculator result, which assessments you’ve completed, and where you are in the journey. This stays on your device, is never used to track you across sites, and you can clear it any time by clearing site data for rebel.one in your browser.

I don't use Google Analytics. I don't use Facebook Pixel. I don't use Mixpanel, Hotjar, Segment, or any similar product. I don't run A/B tests that track individual users.

I do use server-side logs on Netlify and Supabase (how many visits, which pages, rough geography). That's all at the service level, not tied to you as an individual.

8. Children

rebel.one is intended for working mechanics and shop owners. I don't knowingly collect information from anyone under 18. If you're under 18 and have given me your information, email privacy@rebel.one and I'll delete it.

9. International transfers

Some of my sub-processors (Supabase, Netlify, Resend, Loops) are US-based. When your information is transferred from the EU / UK / Switzerland to the US, it happens under the EU-US Data Privacy Framework (for Supabase, Netlify, Resend) or Standard Contractual Clauses (for Loops). Both are approved transfer mechanisms under GDPR Article 46.

If you want copies of the DPAs or SCCs, email privacy@rebel.one and I'll send them.

10. Changes to this notice

If I change how information is handled, I update this page and stamp it with the date of the change. If the change is material — new processor, new purpose, new data type — I send a plain-English email to everyone on file telling them what changed.

11. Supervisory authorities

If you're not happy with how I've handled your data and I haven't resolved it, you can go over my head:

I'd rather you email me first, but you don't have to.


If anything in this notice is unclear, email privacy@rebel.one. I try to reply within 48 hours.

— Mike Duggan, RebelOne