Privacy Policy
Last updated: June 11, 2026
The privacy of your data — and it is your data, not ours — is important to us. We collect only what we need. We never sell your data: never have, never will.
This policy applies to Carbro (heycarbro.com) and all services operated by Carbro. If you have questions, email us at tech@heycarbro.com.
What we collect and why
Identity and access
When you sign up, we ask for your name and email address. We use these to manage your account and send essential product updates. We will never sell your personal information or use your name in marketing without your permission.
Vehicle data
When you use Carbro to research a vehicle, we store the VINs and asking prices you enter so we can return your results and save your research history.
Document uploads
When you upload a PDF (such as a vehicle history report), we process it to extract relevant vehicle information. The original file is not retained. Only the extracted text is stored, scoped to that specific vehicle in your account. It is not accessible outside of that vehicle's context within the app.
Voluntary correspondence
When you email us with a question or for support, we keep that correspondence so we have context for future interactions.
When we access or share your information
To run the service. We use a small set of third-party subprocessors: Supabase (database and authentication) and Vercel (hosting). These providers process your data only as needed to provide the service.
To investigate abuse. Accessing a customer's account is a last resort. If we find a user is abusing the service, we may take action including notifying relevant authorities.
When required by law. We will comply with lawful requests from law enforcement only when compelled by valid legal process. We will notify affected users before disclosing their data unless legally prohibited from doing so.
In a business transfer. If Carbro is acquired or merges with another company, we will notify you before your data is transferred or becomes subject to a different privacy policy.
We do not and will never sell your data to advertisers or third parties.
Your rights
- Right to know. You can ask what data we hold about you.
- Right to access. You can request a copy of your data.
- Right to correction. You can update your account information at any time.
- Right to deletion. You can delete your account. We will remove your data within 60 days. Some data may be retained longer if required by law.
- Right to restrict processing. You can ask us to stop using your data for certain purposes.
- Right to portability. You can request an export of your data.
To exercise any of these rights, email us at tech@heycarbro.com.
How we secure your data
All data is encrypted via TLS in transit. Our database provider (Supabase) encrypts data at rest. We use row-level security to ensure users can only access their own data.
Data retention
We keep your data for as long as your account is active. If you delete your account, your data will be removed from our systems within 60 days.
Changes and questions
We may update this policy to reflect new practices or legal requirements. When we do, we will update the date at the top of this page. For questions, email tech@heycarbro.com.
This privacy policy is adapted from the Basecamp open-source policies and used under the Creative Commons Attribution license.