Privacy

Privacy policy

This policy explains what CarHub collects, why we use it, who receives it, how long we keep it and the choices available to you. It distinguishes data CarHub controls from customer content processed only on a customer's instructions.

Last updated 1 September 2026 · 14 clauses · Terms of service

01

Scope and our roles

This Privacy Policy applies to the CarHub website, dashboard, APIs, SDKs, account and support services. It does not govern a customer's own product or privacy practices.

  • CarHub as controller. We decide how to use website, account, billing, security, analytics, sales and support information for the purposes described below.
  • CarHub as processor. A business customer decides why and how personal data contained in vehicle media, identifiers, documents and API results is processed. We process that Customer Content on its documented instructions to provide the Service. The Terms of Service and any signed data processing agreement govern that processing.
02

Who we are

The controller is Carhub, Inc., a Delaware corporation trading as CarHub, Delaware file no. 10748504. Our mailing address is 390 NE 191st St, STE 75548, Miami, FL 33179, United States.

Privacy questions and verified rights requests may be sent to [email protected]. Security reports may be sent to [email protected].

03

Information we control

Depending on how you interact with CarHub, we collect the following categories:

  • Identity and contact data: name, work email, organisation, role and account identifiers.
  • Authentication data: password hash, verification status, sessions, and profile or provider identifiers received if you choose Google or GitHub sign-in. We do not store plaintext passwords.
  • Organisation and billing data: company details, billing address, tax identifiers, plan, credit balance, invoices, ledger entries and transaction references. Stripe handles payment-card details; CarHub does not receive full card numbers.
  • Usage data: endpoints called, units consumed, job status and timing, rate-limit events and API-key metadata. Secret API-key values are shown only when issued; we store a verification hash.
  • Device, network and security data: IP address, timestamp, requested path, response status, browser or device information, authentication and audit events, and suspected abuse indicators.
  • Analytics data: pages visited and the limited product actions we intentionally record after any consent required by law.
  • Communications: sales enquiries, support requests, feedback and related correspondence.

We collect this information from you, your organisation, your browser or device, use of the Service, authentication providers you select, Stripe, and colleagues who invite you to an organisation.

04

Why we use it

We use controller data for the following purposes and legal bases where those concepts apply:

  • Provide the Service and manage the account: to perform our contract or take requested pre-contract steps.
  • Meter usage, take payment and maintain records: to perform our contract and comply with tax, accounting and corporate obligations.
  • Authenticate users, prevent fraud, secure and troubleshoot the Service: our legitimate interests in protecting CarHub, customers and the public.
  • Respond to sales, support and legal requests: contract performance, legitimate interests in operating our business, and legal obligations where applicable.
  • Improve usability and performance using limited analytics: consent where required; otherwise our legitimate interest in improving the Service.
  • Establish, exercise or defend legal claims and enforce our terms: legitimate interests and legal obligations.

Account and billing information is required to create and operate a paid account. If it is not provided, we may be unable to provide that part of the Service. Analytics is optional and refusing it does not affect Service access.

CarHub does not sell personal data, use it for cross-context behavioural advertising, or use controller data to make solely automated decisions that produce legal or similarly significant effects about individuals.

05

Cookies and analytics

Strictly necessary cookies and browser storage keep sessions secure, remember privacy choices and preferences, and support requested features. They cannot be disabled through our consent control because the relevant feature may not work without them.

With your permission where required, we use PostHog for limited product analytics. We disable automatic element capture, exception capture and session recording. We intentionally record page paths and selected events such as account creation or use of a dashboard feature. For a signed-in user, PostHog receives the CarHub user identifier, name and work email. We configure analytics not to send passwords, API secrets, Customer Content or URL query parameters.

You may accept or reject analytics using the privacy control displayed on your first visit and change the choice later using Privacy choices in the site footer. Where a browser opt-out signal is legally binding, we treat it as a rejection for analytics that would require consent. We do not currently respond differently to a legacy Do Not Track signal because there is no agreed interpretation of that signal.

06

Customer content processed on instructions

Customer Content can include vehicle photographs and video, faces or bystanders captured in a frame, registration plates, VINs, location or device metadata, registration certificates, invoices, service and insurance documents, claim information, lookup results and model Output. Depending on context, this may be personal or sensitive information.

The customer is responsible for its lawful basis, notices, collection choices, data minimisation and instructions. CarHub processes Customer Content to receive the submitted material, run the requested model or lookup, return and store Output, provide support at the customer's request, maintain security and comply with law. We do not use Customer Content to advertise, build cross-customer profiles or train general models unless the customer separately opts in to a specifically described programme in writing.

If your information was submitted by a CarHub customer, contact that customer first to exercise your rights. We will help the customer respond and will not independently disclose Customer Content unless instructed by the customer or required by law.

07

Vehicle media, identifiers and lookups

Our models are designed to analyse vehicles, not identify people. We do not offer facial recognition or intentionally create profiles of people visible in vehicle media. Customers should avoid collecting people and documents unnecessarily and should redact incidental data when doing so will not interfere with their purpose.

Vehicle identifiers can be linked to owners or keepers and should be treated as personal data where that link is reasonably possible. A Layer 3 request may send a plate or VIN and country to the applicable vehicle-data provider to return information in domains such as identity, specs, battery, value, history, compliance, financing, parts, risk. The provider may receive technical connection data necessary to complete that request. Provider-derived data is retained as part of the requesting job under the customer's configured retention period.

08

Service providers and other disclosures

We disclose relevant data only as needed to the following recipient categories:

  • cloud hosting, storage, database, network, security and observability providers;
  • model and inference providers used by the endpoint selected by a customer;
  • country-specific vehicle-data providers used for requested lookups;
  • Stripe for checkout, subscription, tax and billing services;
  • PostHog for consented product analytics;
  • Google or GitHub when a user chooses the corresponding sign-in method;
  • email delivery, customer-support, accounting, legal and professional advisers;
  • authorities or other parties where reasonably necessary to comply with law, protect rights and safety, or investigate abuse; and
  • a buyer, investor or successor in a financing, merger, acquisition, reorganisation or sale, subject to appropriate confidentiality protections.

Service providers are contractually limited to authorised purposes. For processor services, subprocessor use and change notices are governed by the Terms and any applicable data processing agreement. A current subprocessor list is available from [email protected].

09

International transfers

CarHub is based in the United States and uses providers that may process data in the United States, the European Economic Area and other countries where they operate. Privacy protections in those countries may differ from those where you live.

Where applicable law requires a transfer mechanism, we use an adequacy decision, approved standard contractual clauses or another legally recognised safeguard. Customers may request information about the safeguard relevant to their processing by contacting [email protected].

10

Retention

We keep data only for as long as reasonably necessary for the purposes described above:

  • Customer Content: the period configured for the customer's account, currently 30 days by default after job completion. Customers may request a shorter period where technically available.
  • Job, usage and ledger records: identifying content is removed under the account retention setting; limited operational and accounting facts are retained as needed for billing, disputes, fraud prevention, audits and legal obligations.
  • Account and organisation data: while the account is active and afterwards as needed to close it, resolve disputes and meet legal obligations.
  • Payment, tax and corporate records: for the period required by applicable tax, accounting and corporate law.
  • Security and infrastructure logs: for a limited period based on security and troubleshooting needs, with longer retention where an event is under investigation.
  • Support and legal correspondence: for as long as needed to address the request and establish or defend legal claims.
  • Analytics: according to our configured PostHog retention and until consent is withdrawn, subject to earlier deletion or de-identification where appropriate.

Deletion from active systems may be followed by a limited backup-rotation period. We may retain data longer when required by law, subject to a legal hold, needed for a dispute, or necessary to prevent fraud. When possible, we restrict use during that additional period.

11

Security

We use administrative, technical and organisational safeguards designed for the nature of the data and risks involved. Measures include encryption in transit, access controls, scoped and rotatable API keys, expiring upload links, password hashing, logging and tenant separation. No online service is completely secure, and this policy is not a guarantee against every incident.

If a confirmed personal-data breach affects Customer Content, we notify the affected customer without undue delay and provide information reasonably needed for its obligations. If you believe an account or key is compromised, rotate the key where possible and contact [email protected].

12

Privacy rights and choices

Depending on where you live and subject to legal exceptions, you may have rights to know or access personal data; correct it; delete it; restrict or object to processing; receive a portable copy; withdraw consent; and opt out of sale, targeted advertising or qualifying automated profiling. We do not sell personal data or conduct those advertising or profiling activities. We will not discriminate against you for exercising a privacy right.

Send a request to [email protected]. Describe the right and account or interaction involved. We may verify identity and authority, including for an authorised agent. We respond within the period required by applicable law. You do not need to create a new account to submit a request.

If we deny a request, you may appeal by replying with Privacy appeal in the subject line and explaining why the decision should be reconsidered. You may also complain to your local data-protection or privacy regulator. EEA and UK individuals may complain to the supervisory authority where they live, work or believe an infringement occurred.

13

Children

The Service is for businesses and is not directed to children. Individuals must be at least 18 to create an account. Customers must not knowingly submit personal data of a child unless they have all legally required authority and have agreed appropriate processing terms with CarHub. Contact us if you believe a child provided account information directly to CarHub.

14

Changes to this policy

We may update this policy as the Service or law changes. We will post the revised version and update the date above. If a change materially affects how we use existing account data, we will provide additional notice, such as email or an in-product message, before it takes effect where required by law.

Questions about this policy may be sent to [email protected] or by mail to Carhub, Inc., 390 NE 191st St, STE 75548, Miami, FL 33179, United States.

Something here unclear?

Write to [email protected] and a human will answer.

Read the terms of service