Privacy
Last updated 10 September 2026
Briefly: we need your email so you can have an account, and nothing else. We never see your payment details.
What we store about you
- your email address (lower-cased, as the account identifier),
- a bcrypt hash of your password — we do not store the password itself and cannot read it,
- the date your account was created and when the trial ends,
- your account status (trial, subscribed, cancelled),
- identifiers from Paddle: customer and subscription id, the subscription management links, the time of the last event, and a scheduled cancellation date if you set one,
- the campaign tag from the address, when there was one — it tells us which post or advert worked, not who you are,
- a login token and the time it was created, so you stay signed in.
- when you confirmed your email and the language you signed up in (we write to you in it),
- a one-time link token for confirming your address or resetting your password — we store only its sha256 hash, it lives for hours and is used once,
- which of our four emails we have sent you and when, so we never send one twice.
Payment details
Card numbers and other payment details never reach our server. Paddle handle the payment in their own window and return only a customer identifier and the subscription status to us.
Car data
The listings we collect are public content published by the portals. Phone numbers are stripped from listing text at collection time and are never stored.
Your rights
You can ask us for a copy of what we hold about you, for a correction, or for your account to be deleted. On deletion we remove the email address, the password hash and the login tokens. Payment records have to be kept by Paddle for tax purposes.
Cookies
We use exactly one cookie, the login session. There are no advertising or tracking cookies. Both the site language and the campaign tag are part of the address rather than a cookie.
Something on this page unclear? Email us and we will answer.