Who We Are
CarSpanner provides an AI-powered parts discovery tool for owners and restorers of classic, vintage, and historic vehicles. The service is operated by CarSpanner and accessible at carspanner.com. For privacy enquiries, contact us at contact@carspanner.com.
What Information We Collect
We collect the minimum information necessary to provide the service. The table below summarises what we collect and why:
| Data Type | Examples | Purpose | Legal Basis |
|---|---|---|---|
| Conversation content | Your messages, part queries, vehicle descriptions | Provide AI-powered responses | Legitimate interest / contract performance |
| Uploaded images | Photos of parts you upload for identification | Visual part identification | Legitimate interest / contract performance |
| Session identifiers | Anonymous session ID stored in your browser | Link conversations across a session | Legitimate interest |
| Technical data | IP address, browser type, referring page, timestamps | Service operation, security, analytics | Legitimate interest |
| Usage analytics | Page views, session duration (anonymised) | Understand how the service is used, improve it | Legitimate interest |
We do not collect your name, email address, or payment information unless you contact us directly. No account creation is required to use CarSpanner.
Cookies and Local Storage
CarSpanner uses the following in your browser:
- Session identifier: A randomly generated anonymous ID stored in
localStorageto link your conversations within a single session. It contains no personal information. - Analytics cookies: We use minimal, privacy-respecting analytics to understand usage patterns. These do not identify you personally.
- Functional cookies: Where required for the service to operate (e.g., maintaining your conversation state).
We do not use advertising cookies or cross-site tracking cookies. You can manage cookie preferences using the Cookie Preferences link in the footer.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the CarSpanner service
- Generate accurate parts identification and supplier recommendations
- Maintain conversation context within your session
- Ensure the security and stability of the service
- Understand aggregate usage patterns to improve the product
- Comply with legal obligations
We do not use your conversation data to train AI models, sell your data to third parties, or build advertising profiles.
Data Retention
We retain data only as long as necessary for the purposes described in this policy:
| Data Type | Retention Period | Reason |
|---|---|---|
| Conversation messages | 90 days from last activity | Allow users to return to recent searches |
| Uploaded images | 30 days from upload | Part identification; images are large and unnecessary to retain long-term |
| Session identifiers | Until browser data is cleared | Session continuity; no server-side record created |
| Server logs | 30 days | Security monitoring and debugging |
| Analytics data | 26 months (aggregated, anonymised) | Long-term trend analysis |
Third Parties We Share Data With
We share data only with third parties that help us deliver the service. We require all third parties to respect data security and process data only on our instruction.
| Third Party | Purpose | Data Shared |
|---|---|---|
| Anthropic (Claude AI) | AI model powering CarSpanner’s responses | Conversation content and images (processed in transit, not stored for training) |
| Render | Cloud hosting | Server logs, database (encrypted at rest) |
| Neon (PostgreSQL) | Database provider | Conversation data, session identifiers (encrypted at rest) |
| Cloudflare | CDN, DDoS protection | IP addresses, request metadata |
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
Affiliate Links
CarSpanner may recommend parts suppliers via affiliate links. When you click a supplier link and make a purchase, we may earn a small commission at no cost to you. This affiliate relationship does not influence our parts recommendations — we recommend based on quality and relevance, not commission rates. See our Affiliate Disclosure for full details.
International Data Transfers
CarSpanner operates primarily from servers based in the United States. If you access the service from the European Economic Area (EEA), United Kingdom, or other regions with data protection laws, your information may be transferred to and processed in countries that may have different data protection standards.
Where we transfer data outside the EEA or UK, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Other lawful transfer mechanisms under GDPR
You may request details of the safeguards in place by contacting contact@carspanner.com.
Your Rights
Depending on where you live, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Request we limit how we process your data
- Portability: Request your data in a machine-readable format
- Objection: Object to our processing of your data on grounds of legitimate interest
- Withdraw consent: Where processing is based on consent, withdraw it at any time
Because CarSpanner does not require account creation, we may need additional verification to locate and action requests. To exercise any right, contact contact@carspanner.com. We aim to respond within 30 days.
EU and UK users: you have the right to lodge a complaint with your local supervisory authority. UK users may contact the Information Commissioner’s Office (ICO).
Data Security
We implement appropriate technical and organisational measures to protect your information against unauthorised access, accidental loss, destruction, or alteration. These include:
- Encryption of data in transit (TLS 1.2+)
- Encryption of data at rest in our database
- Access controls limiting who can access data
- Regular security reviews
No system is perfectly secure. If you believe your data has been compromised, please contact us immediately at contact@carspanner.com.
Children’s Privacy
CarSpanner is not directed at children under the age of 13 (or 16 in the EU/UK). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact contact@carspanner.com and we will take steps to delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. For material changes, we will take reasonable steps to notify users. Your continued use of CarSpanner after changes are posted constitutes acceptance of the updated policy.
We encourage you to review this policy periodically.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please reach out: