Privacy

Privacy

What Carvocate stores, what leaves your device, and the controls available to you.

Last updated: August 14, 2026

Plain-language summary

  • Saved vehicle reports are stored locally in this browser’s IndexedDB.
  • Theme preference is stored locally in localStorage.
  • Listing drafts are stored temporarily in sessionStorage during the listing-to-report workflow.
  • VINs, decoded vehicle details, and listing URLs may be sent to external services when you request analysis.
  • Cloudflare Pages delivers and protects the public website.
  • Carvocate currently has no user accounts, account password database, or cloud sync.
  • Feedback form submissions are stored privately through Carvocate's server-side Cloudflare database binding.
  • Carvocate may display Google-supplied advertisements on completed reports and long buyer guides when a real ad unit is configured and you allow local ad loading.

Information you provide

Depending on the workflow, you may provide VIN, listing URL, price, mileage, dealer information, vehicle details, market-value entries, comparable-market notes, repair estimates, dealer-question answers, Action Center statuses, walk-away amount, notes, inspection answers, quote information, trade and financing information, theme preference, and saved reports. These values are used to build reports, preserve provenance, compare vehicles, prepare inspections, review quotes, and keep your local workspace useful.

VINs and decoded year/make/model can be included in external source requests. Listing URLs are requested when you ask Carvocate to inspect a listing. Manual valuation entries, quote lines, inspection answers, notes, edits, and saved reports remain local unless you export them, a future licensed valuation endpoint is enabled for a specific request, or your browser/device syncs site data outside Carvocate’s control.

If you use the feedback form, Carvocate receives the selected feedback category, optional name, message, and a server-generated submission timestamp. These fields are used only to review feedback and improve Carvocate.

Information processed automatically

Normal web requests can include IP address, user agent, browser/device information, request time, requested URL, and referrer information depending on browser behavior. Cloudflare processes technical traffic information for delivery and security. The service worker caches same-origin shell assets and successful same-origin GET responses for offline use.

Current frontend code does not send runtime errors to a third-party error logger.

Local storage

LocationStored dataHow to clear
IndexedDBSaved vehicle reports, source states, edits, quote entries, inspection edits, manual valuation entries, comparable-market metadata, repair-adjustment records, Action Center statuses, dealer answers, and walk-away preferences.Garage vehicle removal or Settings local-data controls.
localStorageTheme preference and cookie/advertising consent choices.Settings, Cookie Settings, or browser site-data settings.
sessionStorageLatest listing attempt and temporary manual listing draft.Close tab/session or clear browser site data.
Service-worker/browser cacheApp shell, icons, same-origin GET responses.Browser site-data settings or service-worker cache controls.
Manage saved data

External data requests

ServiceData sentPurposeUser initiatedRetention behavior
NHTSA vPICVIN in the API URL.Decode vehicle identity and manufacturer-submitted configuration fields.User submits or opens a VIN report.Carvocate saves the resulting report locally when the report is saved or refreshed successfully. Privacy information
NHTSA safety APIsDecoded year, make, and model in API URLs.Retrieve recall and complaint records and attempt investigation/communication checks.VIN report creation or refresh.Carvocate stores returned source states inside the local vehicle report. Privacy information
EPA FuelEconomy.govDecoded year, make, model, and selected EPA vehicle option identifiers.Match configuration and retrieve standardized fuel-economy values.VIN report creation or refresh.Carvocate stores returned matches or selected estimates inside the local vehicle report. Privacy information
Dealer website entered by the userThe listing URL requested by the browser.Attempt ordinary retrieval of readable vehicle listing data.User submits a listing URL or retries extraction.Carvocate stores extracted fields and the listing URL when the user continues the analysis; raw HTML is not retained by app code. Privacy information
Cloudflare PagesNormal web request metadata for site delivery and security.Host, deliver, cache, and protect the public Carvocate site.Every visit to the website.Carvocate frontend code does not define Cloudflare log retention; Cloudflare controls its operational processing. Privacy information
Cloudflare D1 feedback storageSelected feedback category, optional name, message, and a server-generated submission timestamp.Store visitor-initiated feedback privately for product review.User submits the feedback form.Submissions remain in the private Carvocate feedback database until the owner deletes them; they are not stored in browser data. Privacy information
MarketCheck Cars APIVehicle identity, year, make, model, confirmed trim when available, mileage when known, drivetrain, engine, fuel, body or cab, bed, and market-area mode. ZIP code and radius are sent only for an optional regional comparison. Asking price, repairs, inspection notes, and quote lines are not sent.Retrieve real comparable listings for the Carvocate Market Estimate.Automatic nationwide valuation after vehicle identity exists, explicit regional search, explicit retry/refresh, or report refresh when no valid compatible sample exists.Carvocate stores normalized comparable metadata and selected listings in the local report. Provider retention is controlled by MarketCheck. Privacy information
Google AdSenseNormal browser request metadata and advertising identifiers when AdSense is configured, the visitor allows local ad loading, and Google permits serving under its consent and regional rules.Serve advertising on eligible completed reports and guide articles.Eligible page visit after advertising is configured and consented.Google controls advertising-data processing. Carvocate stores only its additional local ad-loading preference. Privacy information

External providers may receive normal request metadata. Carvocate does not control those providers’ independent data practices.

The browser sends Carvocate's market endpoint only the vehicle fields needed for matching: vehicle identity, year, make, model, VIN Series evidence, confirmed trim when available, mileage, drivetrain, engine, fuel, body or cab, bed, and market-area mode. ZIP code and radius are included only when the user chooses a regional comparison. The server sends MarketCheck a narrower bounded search using make, a documented provider model, year, active used dealer inventory, duplicate suppression, and optional regional ZIP/radius. Trim, mileage, and the remaining configuration fields are applied locally. Asking price, repair estimates, inspection notes, quote lines, and unrelated buyer notes are not sent to MarketCheck.

When the optional Cloudflare usage-accounting binding is configured, Carvocate stores period counters, a stable market-request key derived from those vehicle/configuration inputs, and the last request time. It does not store the MarketCheck API key, provider payload, asking price, repairs, or quote details in usage accounting. Without the binding, those counters are per-runtime memory only and are not durable.

Dealer listing retrieval

You supply the listing URL. Carvocate may attempt ordinary retrieval, but it does not bypass CAPTCHA, does not bypass login, and does not imitate a signed-in session. Page protections may block access. When extraction fails or is partial, Carvocate shows manual fields and preserves any extracted values.

Raw dealer HTML is parsed in memory and is not retained by app code. Extracted fields and the original listing URL can be stored in the local report when you continue.

Hosting and infrastructure

The public site is hosted through Cloudflare Pages. Cloudflare may process technical traffic information for delivery, security, fraud/abuse prevention, performance, and operational purposes. Cloudflare is not part of Carvocate and does not endorse the analysis.

Cloudflare privacy policy

Cookies and analytics

Carvocate stores its local ad-loading preference in this browser. When advertising is enabled, a valid Google AdSense unit exists, the route is eligible, and you allow ad loading, the browser may contact Google or its advertising partners. Ad personalization and storage depend on Google's consent rules, your choices, and your region. Carvocate's switch is an additional control and does not replace Google's approved consent platform. No separate analytics identifier is configured in the current source. Cloudflare may set necessary operational cookies or use security measures outside the app code.

Visible advertising and Auto Ads are currently disabled during publisher review. Carvocate does not send VINs, saved reports, user notes, financing values, quote contents, repair information, inspection findings, credit status, debt, income, or loan-eligibility information to Google merely for advertising targeting. Vehicle and financing inputs are not used as advertising audience attributes.

Retention and sharing

Local reports, settings, edit history, quote entries, and inspection edits remain until you delete them, clear browser site data, or the browser removes them. Listing drafts are session-scoped. Service-worker cache persists until the browser or service worker clears it. Carvocate frontend code does not define Cloudflare or external API log retention.

Feedback submissions are stored privately in Carvocate's Cloudflare database until the owner deletes them. They are not stored in Carvocate browser data, sent to advertising or analytics systems, or used to create an account, support ticket, or reply channel.

Carvocate has no sale of personal information through the frontend app. Advertising-related requests occur only when a real unit is configured, local ad loading is allowed, and Google's applicable consent requirements permit serving.

User choices

  • Edit or correct vehicle information from report, garage, quote, inspection, and dealership workflows.
  • Delete saved vehicles or clear all local vehicle reports from Settings.
  • Change theme preference from Settings.
  • Avoid listing retrieval by entering a VIN only or using manual listing entry.
  • Avoid saving by leaving a report unsaved or deleting local records afterward.

No internet-connected service can guarantee absolute security. Carvocate uses HTTPS delivery, input validation, local-first storage, no account password database, and dependency auditing, but users should avoid entering sensitive financial documents or private personal records into fields not intended for them.