Privacy
Site and lookup
This site sets no cookies and uses no analytics or trackers. It loads no external fonts, scripts or images.
The lookup sends the make, model and year you type to the API. The API uses your IP address only in memory for rate limiting. The site does not store or log IP addresses, and neither does the API application. Cloudflare delivers the site and the API, so it processes every connection under its own terms and can add its own network error reporting headers.
Payments
Buying happens on a page hosted by Stripe, Inc., which is the merchant of record for purchases. Stripe collects your card, email and billing details under its own privacy policy and can set its own cookies there. This site still sets no cookies. Read Stripe's privacy policy.
We never receive or store card numbers. From Stripe we keep only identifiers and plan facts: your Stripe customer id, subscription or payment id, the plan, its status and dates, linked to your key. We do not store your name or email address.
Your API key
After payment the confirmation page asks the API for your new key using the checkout session id in the page address. The API stores a keyed hash of that id and an encrypted copy of the key until you view it once or 24 hours pass; an hourly job then deletes any copy that was never viewed. The page removes the id from the address once the key is shown or the API says it cannot be shown. While payment is still being confirmed, or if the service cannot be reached or refuses the request, the id stays in the address so you can check again.
After the one-time view, API keys are stored only as hashes, with a short display prefix for identification. The site lookup does not ask for a key.
Email sent to jorge@theusedcarindex.com is kept to answer it.
Listing diagnostics
The bot collects public listing facts for the feed: VIN, price, mileage, status, dates and the link back. No photos or dealer-written text enter the feed. Temporary public-page HTML diagnostics can contain dealer text and image references. They have a 50-file daily cap. Captures older than 7 days by folder date or file modification time are purged at run start and end, on status checks, or by an explicit purge command. Old captures are deleted each time the bot starts and finishes and when its status is checked; a capture that cannot be deleted is retried on the next run. Photos are not downloaded. See how the bot works.
Removal requests
To ask for removal of a listing, diagnostic capture, email or other information, write to the contact address with enough detail to identify it. Dealer listings are removed from the feed within 7 days of the request.