Privacy

Privacy

DealScore (also called Deal Score) at https://cardealscore.com grades a used car's asking price against market comps. This page says what we collect to do that, and who else handles it.

Who operates this

The service is operated as DealScore at https://cardealscore.com. The same product is referred to as Deal Score.

What the product does

You can grade an asking price from the web form, from REST (POST /api/score), or from the MCP tool score_deal. A signed-in Free account can score 40 deals per UTC month. Paid plans are Stripe subscriptions: Starter ($15/month, 250 scored deals) and Builder ($45/month, 1000 scored deals). Homepage, REST, and MCP share one counter. Only coverage: scored counts.

Data we collect

  • Email for magic-link sign-in. The login token is stored as a hash. The address is the account id for keys, OAuth consent, and billing.
  • API keys are shown once, then stored as a SHA-256 hash plus a short prefix. We do not keep the full secret.
  • OAuth tokens (access and refresh) are stored as hashes, tied to your user id, the client, and the requested scope.
  • Score requests include the vehicle attributes you send (year, make, model, trim, VIN, asking price, mileage, and an optional ZIP, or a listing URL or pasted listing text). Those fields are used to compute the grade and to decide whether the request counts on the meter. The stored meter is a count for the UTC month, plus an event of kind, user id, and time. We do not keep a library of the listings you scored.
  • Stripe ids (customer id and subscription id) and your plan name, so paid access can be turned on and off.
  • Usage and analytics. A signed-out first score can set a cookie and store the request IP with a daily count so that one look is not repeated. Vercel Web Analytics records basic page views.

Who else handles that data

  • MarketCheck receives vehicle attributes so we can fetch live comps, taxonomy, and VIN decode when that provider is configured.
  • NHTSA vPIC may receive a VIN or year/make/model when MarketCheck is not used for decode or taxonomy.
  • Browserbase may fetch a listing page when you submit a listing URL on the web form.
  • Stripe processes paid subscriptions. We store the customer and subscription ids Stripe returns.
  • Resend sends the magic-link email.
  • Neon hosts the Postgres database for accounts, hashed credentials, meter counts, and Stripe ids.
  • Vercel hosts the site and provides Web Analytics.

We do not sell personal data. We do not share it for other companies' advertising.

Contact

Privacy contact address on https://cardealscore.com: privacy@cardealscore.com.

Service rules are on the terms page.