Draft under attorney review. Not in effect: nothing on this page applies to anyone yet, and the text may change before it does.
DRAFT: starting point for attorney review. Not legal advice. Every statement here is checked against docs/data-inventory.md, the list of everything the product stores or sends; change the two together.
Lot Current Privacy Policy
Last updated: [date]. [Lot Current entity name] ("we") makes the Lot Current browser extension and related services: the manager view, our website and its demo request form. This policy says what we collect, why, who processes it, how long we keep it and how to reach us.
What we collect and why
| Data | Where it lives | Why |
|---|---|---|
| Dealership website inventory (vehicle records: VIN, year, make, model, trim, price, mileage, stock number, status, location, features, description and photo addresses) | In the User's own browser (chrome.storage.local), read from the dealership's public website and its inventory search each scan. The photos themselves are downloaded only to attach them to the listing form and are not kept, unless the User clicks Download photos, which saves them as files in the User's Downloads folder | To check each car is pre-owned and ready, to prepare listings, and to detect sold cars and price changes |
| Settings (salesperson name and role, dealership name, city, state, ZIP, the stores ticked, price basis, price note, daily cap, listing defaults for title status and condition, automatic rescan and notification choices, when the posting rules were read, which edition of the Terms and this policy was accepted and when, rewrite-service address and key) | In the User's browser. The profile (name, role, dealership name and address, the stores ticked, price basis, note, cap, listing defaults, the rewrite-service address and whether it is on, Terms acceptance, and the website it was saved on and when) is also kept in Chrome's sync storage under the User's own Google account, so it follows the User's Chrome sign-in. The rewrite-service key is never synced; it is sent only to the rewrite service it belongs to | To fill the listing and sign the description |
| Sign-in session (access and refresh tokens, their expiry, the account's id and email) | In the User's browser only, never in Chrome's sync storage. The manager view keeps its own session in the local storage of the browser it is opened in | To call our services as the signed-in User |
| Posted-listing registry (VIN, car name, posted price, times, listing link the User saved or Lot Current detected, salesperson name) | In the User's browser. When the User signs in to a Lot Current account, also in our database for the User's dealership, where every member of that dealership can see it; colleagues' entries come back to the User's browser the same way | To keep listings accurate and, for managers, to see who posted what |
| Scan results | The lists of changes (cars to take down, prices to update, new arrivals, with VIN, name and prices) stay in the User's browser, except the cars to take down and the price changes on the User's own listings, which become to-do items (see Usage numbers). When the User is signed in, our database also gets each scan's time and counts (cars, ready, to take down, price changes) | Rescans and the manager view |
| Usage numbers: when each post started and ended and its outcome, the car's VIN and name, which form fields could not be filled, the to-do items (a sold car to take down or a price change on the User's own listings, with the car's VIN and name, when it was flagged and fixed and, for a price change, the old and new price), and the salesperson name from Settings | Kept in the User's browser, pruned automatically to the newest 500 entries per list and nothing older than 90 days (open to-do items excepted). When the User is signed in, the post attempts and the to-do items (not the form-field records) are also kept in our database for the User's dealership, where they are not pruned and stay until the dealership's records are deleted. Otherwise they leave the browser only as the CSV the User chooses to export | Pilot check-ins and the manager view |
| Account details (email for sign-in; the name given when joining a dealership; dealership membership and role; invite codes made or used, and when; failed invite-code attempts; self-serve sign-up attempts, with when and whether they started a dealership) and the sign-in records our database host keeps (when the account was created and last signed in, and a sign-in log with IP address when the project keeps one) | Our database (Supabase) | Sign-in, access control and limits on guessing codes and on sign-ups |
| Billing details (on the Stripe customer: the dealership's name and website address and the email of the manager who first opened checkout; the subscription's status, dates and seat count; each billing event Stripe sends us, as Stripe sent it, with its ids, statuses, amounts and the billing contact's details it carries) | Our payment processor (Stripe), which collects card and billing details on its own pages; we never see or store card numbers. Our database keeps the subscription's standing and the billing events | Billing |
| Rewrite requests (the car's year, make, model, trim, mileage, stock number, colours, body, engine, transmission, drivetrain, fuel type, features, whether the website links a Carfax report and says one owner, and the website description's own sentences, as the website wrote them; the dealership's name and city; the salesperson's name and role; the price note. The VIN and the price are not among the fields sent) and, for a colour guess, up to four photo addresses and the list of colour words | Sent to our rewrite service and on to Anthropic's API only when the description writer is turned on in Settings. The service also receives the dealership website's address, to know which dealership the request is for, and does not pass it on. We keep the time, the account, the model, token counts and cost of each call, and a log line with the car's year, make and model; not the facts or the description [Pending attorney answer: questions-for-attorney.md 8.9] | To draft a description, and to guess colours the website does not give |
| VIN checks (the VIN) | Sent to NHTSA's free VIN decoder only when the User clicks "Check with NHTSA" | To compare the website's details with the VIN |
| Support messages (name, dealership, role, email, phone, what the message says, and any problem report the User pastes in: the versions, the dealership website's address and platform, the last scan and its errors, the counts on each tab, which form fields the last fill could not do, the Chrome version and time zone) | Our inbox and the support log | To respond |
| Demo requests from our website (name, dealership, dealership website, email, phone, message, and when and from which website address it was sent) | Our database (Supabase), or our inbox when the form opens the visitor's own mail app instead. The sender's IP address is used, in scrambled form and only in memory, to slow floods of requests; it is not stored | To respond |
We do not collect Facebook passwords, cookies, session tokens, messages, buyer information, or anything from the User's Facebook account. From Facebook pages Lot Current keeps only the listing address the User saves or Lot Current detects on the User's own tab. While a post or an update is under way it reads back the form fields it filled and, on a listing the User opened to update or take down, that listing's title, price and sold status, to tell the User what the page shows; it keeps these only with that post or update and sends them nowhere. Lot Current reads only the dealership's website and the Marketplace pages the User opens through it, and does not track browsing anywhere else. Lot Current sends nothing to Facebook: the User reviews the listing in their own tab and publishes it themselves. Our website sets no cookies and runs no analytics.
Processors
- Supabase: our database, sign-in, the server functions (sync, the description writer, billing, demo requests) and their logs. Everything above that lives in "our database" is kept there.
- Anthropic: drafts descriptions and guesses colours through its API, only with the description writer on. It receives the rewrite request above and up to four photo addresses. Anthropic's API terms apply.
- Stripe: billing. It receives the dealership's name and website address and a manager's email, and collects the card and billing details itself.
- Google: Chrome's sync storage keeps the profile under the User's own Google account, and the Chrome Web Store distributes the extension; Google's terms apply. [Pending attorney answer: questions-for-attorney.md 8.8]
- jsDelivr: serves the database library the manager view loads, unless we serve that file ourselves; like any download, it sees the manager's IP address and browser. [Pending attorney answer: questions-for-attorney.md 8.8]
- [hosting provider]: serves our website and the manager view; its access logs see visitors' IP addresses and browsers.
- [email provider]: sends the sign-in emails (our database host's own sender does until we set this up) and holds our inbox.
Lot Current also reaches services that are not our processors: the dealership's website (with the inventory search it uses, if any), which Lot Current reads as the User's browser would; the photo servers the dealership's website names for its cars' photos, which may belong to another company, and from which Lot Current downloads a car's photos, without cookies, only when the User fills in a listing form or clicks Download photos, and whose photos the side panel shows as pictures, the way any web page shows a picture, while the User picks which ones to post (an https server Lot Current may not read yet is first asked for in Chrome's own prompt, from the User's click, and after a no its photos are not requested); and NHTSA, when the User checks a VIN.
We do not sell personal data and do not use it for advertising. [Pending attorney answer: questions-for-attorney.md 8.7]
Retention
Browser data stays until the User clears it or removes the extension. "Clear everything for this website" (Settings) removes that website's scans, settings, posted list, usage numbers, queue, drafts, set-up progress, any post under way and its sync state, and takes the website off the automatic rescans. The usage numbers are deleted by "Clear the numbers" in the Numbers tab and by "Clear everything for this website" in Settings. Lot Current also prunes them automatically each time it records one: each list (post attempts, form fills, to-do items) keeps its newest 500 entries and nothing older than 90 days, except open to-do items, which stay until they are closed. The sign-in session stays until the User signs out in Settings or removes the extension. The profile in Chrome's sync storage (name, role, dealership name and address, the stores ticked, price basis, note, cap, listing defaults, the rewrite-service address and whether it is on, Terms acceptance) is not removed by "Clear everything for this website"; "Forget my synced profile" in Settings removes it, and it also goes when the User clears their Chrome sync data. Saving Settings re-creates it.
Database records for a dealership are deleted within 30 days of the subscription ending unless the law requires longer, and so are the accounts of its people that then belong to no other dealership. An account whose person has left a dealership that carries on, and its sign-up attempts, are kept until the person asks us to delete them. Failed invite-code attempts stop counting after an hour and are deleted at the next attempt by anyone, or with the account. Billing events are kept as the accounting record after a dealership's other records are deleted. Demo requests are kept until we delete them. [Pending attorney answer: questions-for-attorney.md 8.5] Rewrite logs keep the vehicle's year, make and model and a cost figure, not the description. Those logs, the other logs our processors keep, our database host's backups and Stripe's own records are kept on the processors' schedules. [Pending attorney answer: questions-for-attorney.md 8.6] Support and billing records are kept as required for accounting and legal purposes. [Pending attorney answer: questions-for-attorney.md 8.5]
Security
Data in the browser is under the browser's protection. Our services use encrypted connections, per-dealership row-level access in the database, the signed-in User's token on every call the extension and the manager view make to our server functions, and a shared key for a self-hosted rewrite service. No method is perfect; report concerns to the contact below.
Your choices and rights
Users can see their scans, posted list, settings and usage numbers in the extension, and can clear what it keeps: "Clear everything for this website", "Forget my synced profile" and "Sign out" in Settings, or removing the extension. Customers can ask us to export or delete their dealership's records. A person can ask us for a copy of their own data, to correct it, or to delete their account; we finish each request within 30 days of verifying it. Residents of states with privacy laws (and EU/UK residents, if we ever serve them) have rights of access, correction, deletion and portability; write to us. [Attorney: confirm which state laws apply given B2B use and Pennsylvania location.]
Children
Lot Current is for dealership staff, not for anyone under 18.
Changes
We will post changes here and update the date; material changes will be notified to the Customer.
Contact
[Lot Current entity name], [postal address], blawrence@lotcurrent.com.
Lot Current is not affiliated with Meta Platforms, Inc.