Skip to content

Privacy Policy

Last updated: July 28, 2026

1. Introduction

carsage ("we", "our", or "us") operates the carsage developer portal, VIN decode API, and related services. This Privacy Policy explains how we collect, use, store, and protect personal and account information when you visit carsage.dev, create an account, buy prepaid token packs, or call our APIs.

2. Information We Collect

We may collect:

  • Account information such as email, name, username, and organization name when you register or update your profile.
  • Billing and payment metadata processed by Stripe (we do not store full card numbers on carsage servers).
  • API usage data including endpoint paths, timestamps, response status, and token consumption for billing, rate limiting, and product improvement.
  • Technical logs such as IP address, user agent, and approximate location for security, fraud prevention, and debugging.
  • Communications you send to support (for example integration questions or partnership inquiries).

3. How We Use Your Information

We use this information to provide and improve the VIN decode and vehicle data API, authenticate requests, process prepaid token purchases, enforce plan and rate limits, send transactional email (receipts, security alerts), and maintain service security. We do not sell personal data to third parties. Aggregated, non-identifying usage statistics may inform product roadmap decisions.

4. Legal bases and sharing

Where applicable (for example GDPR), we process data to perform our contract with you, to comply with law, and for legitimate interests such as securing the API. Processors include hosting providers, Stripe for payments, and email delivery vendors. They may only process data under our instructions.

5. Data Retention & Security

We retain account and billing records while your organization is active and for a reasonable period afterward for audits, chargebacks, and legal obligations. API logs are retained for operational windows needed for billing disputes and abuse investigation. We apply technical and organizational controls appropriate to an API platform, including encrypted transport (HTTPS) and access controls on production systems.

6. Your Rights

Depending on your jurisdiction, you may request access, correction, deletion, or export of personal data, or object to certain processing. Contact us to exercise these rights. You may also close your account from the dashboard or by emailing support. Some records may be retained where legally required.

7. Cookies and analytics

We use essential cookies for authentication and preferences, and may use privacy- respectful analytics (for example Vercel Analytics) to understand traffic. See the cookie banner on the site for consent controls where required.

8. Contact

Privacy questions: email carsage.info@gmail.com or use our contact page. Related policies: Terms of Service.

← Back to home