Privacy Policy

Last updated: April 12, 2026

1. Introduction

CarXit (“we,” “us,” or “our”) operates the CarXit platform, including our website, mobile applications, and related services (collectively, the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Information You Provide

  • Account information: Name, email address, phone number, and password when you create an account.
  • Vehicle information: Vehicle Identification Number (VIN), license plate number, make, model, year, mileage, condition details, maintenance history, accident history, title status, and ownership details.
  • Vehicle photographs: Interior and exterior photos of your vehicle, including images of any damage, wear, or mechanical issues.
  • Location information: Your address or zip code to match you with local dealers.
  • Communication content: Messages exchanged with dealers through our in-app chat, voice recordings during AI-assisted onboarding, and any other communications through the Service.
  • Payment information: Payment details processed through our third-party payment processor (Stripe). We do not store full payment card numbers on our servers.
  • Dealer information: Business name, dealership license number, address, and business contact information for dealer accounts.

2.2 Information Collected Automatically

  • Device and usage data: IP address, browser type, operating system, device identifiers, pages visited, actions taken, time spent, and referring URLs.
  • Analytics data: We use PostHog to track product usage patterns including feature interactions, session duration, and conversion funnels.
  • Location data: Approximate location derived from IP address. With your permission, precise location from your mobile device for dealer matching and real-time ETA tracking during transactions.

2.3 Information from Third Parties

  • Vehicle data services: Vehicle history, specifications, and market valuation data from automotive data providers using your VIN.
  • AI analysis: Photo analysis results from Google Vision API and AI-generated assessments from OpenAI to evaluate vehicle condition and market positioning.

3. How We Use Your Information

We use the information we collect to:

  • Facilitate vehicle sales: Share your vehicle information, photos, and condition details with participating dealers so they can evaluate your vehicle and submit offers.
  • Operate the marketplace: Match sellers with dealers, process competitive bids, manage transactions, and enable in-app communication between parties.
  • Provide AI-assisted features: Power conversational onboarding, vehicle photo analysis, market intelligence, and chat moderation.
  • Process payments: Handle commissions, payouts, and other financial transactions.
  • Send communications: Deliver transaction updates, offer notifications, onboarding reminders, and marketing messages (with your consent).
  • Improve the Service: Analyze usage patterns, conduct A/B testing, measure feature performance, and develop new features.
  • Ensure safety and compliance: Detect fraud, enforce our Terms of Service, comply with legal obligations, and maintain platform integrity.
  • Create marketplace listings: If you opt in to our ListAssist feature, use your vehicle information to create listings on external marketplaces on your behalf.

4. How We Share Your Information

4.1 With Dealers

When you list a vehicle, your vehicle information, photos, condition details, and general location are shared with participating dealers in your area so they can evaluate your vehicle and submit offers. Your personal contact information (phone number, email) is not shared with dealers until you accept an offer and a transaction is initiated.

4.2 With Service Providers

We share information with third-party service providers who perform services on our behalf:

  • Supabase: Database hosting, authentication, and real-time messaging infrastructure.
  • Stripe: Payment processing.
  • Google Cloud: Voice AI services (text-to-speech, speech-to-text) and image analysis.
  • OpenAI: AI-powered chat moderation and market analysis.
  • GoHighLevel: Automated email and SMS communications.
  • PostHog: Product analytics.
  • OneSignal: Push notifications.
  • Vercel: Web hosting.

4.3 External Marketplace Listings (ListAssist)

If you use our ListAssist feature, we may publish your vehicle information and photos on third-party marketplaces (such as Facebook Marketplace, Craigslist, or similar platforms) to increase the visibility of your listing. You can opt out of this feature at any time.

4.4 Legal and Safety

We may disclose your information if required by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

4.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information is subject to a different privacy policy.

5. Vehicle Information and Photos

Because vehicle information is central to our Service, we want to be specific about how it is handled:

  • VIN and vehicle details are used to retrieve vehicle specifications, history reports, and market valuations from third-party automotive data providers.
  • Vehicle photographs are analyzed by AI services to assess condition, verify completeness, and detect potential issues. Photos are stored securely and shared with dealers evaluating your vehicle.
  • Condition and history information you provide is combined with third-party data to create a comprehensive vehicle profile that dealers use to formulate offers.
  • Offer and deduction data, including dealer-submitted photos documenting deductions, are stored as part of the transaction record.
  • Vehicle information may be retained after a transaction completes for record-keeping, dispute resolution, and to improve our market valuation models.
  • You may request deletion of your vehicle information as described in Section 8.

6. Voice and AI Data

Our Service uses AI-powered features including voice-guided onboarding and conversational chat:

  • Voice recordings during AI-assisted onboarding are processed by Google Cloud speech services to transcribe your responses. Transcriptions are used to populate your vehicle listing.
  • Chat conversations may be processed by AI services for moderation and to provide contextual assistance.
  • We do not sell voice recordings or AI-processed data to third parties.
  • You may use text-based onboarding as an alternative to voice at any time.

7. Data Security

We implement appropriate technical and organizational measures to protect your information, including encryption in transit (TLS) and at rest, secure authentication through Supabase Auth, and access controls limiting who can view your data. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information.
  • Deletion: Request deletion of your personal information, including vehicle data and photos. Note that some information may be retained for legal or legitimate business purposes.
  • Opt-out of marketing: Unsubscribe from marketing communications at any time using the link in our emails or by contacting us.
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
  • Data portability: Request your data in a structured, machine-readable format.

To exercise any of these rights, contact us at privacy@carxit.com.

9. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. Transaction records, including vehicle information and offer history, are retained for a minimum of three (3) years after transaction completion for regulatory compliance and dispute resolution. You may request earlier deletion, subject to our legal obligations.

10. Children's Privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

CarXit
Email: privacy@carxit.com