Privacy Policy
This Privacy Policy describes how Car Lounge ("we", "us", "the app") collects, uses, and shares information when you use our mobile application and related services.
1. Information we collect
Information you provide when you sign up:
- Email address — for account authentication and password reset. If you sign in with Apple, we receive a token from Apple; we do not store your Apple password.
- Handle and display name — chosen during onboarding, visible to other users.
- Area — the state/region you select to scope meets and local groups. We do not collect precise location unless you opt in for a specific feature.
- EULA acceptance timestamp — for compliance recordkeeping.
Information you create using the app:
- Vehicle data — make, model, year, trim, ownership status (current/previous). VIN if you choose VIN entry (decoded via NHTSA, not stored after decode).
- Vehicle photos — exterior and dashboard images you upload for verification.
- Profile content — avatar, cover photo, bio, garage customization (themes, animations, banners).
- Posts and reels — text, photos, and short videos you publish, including any vehicle tags you attach.
- Chat messages — messages you send in group chats and direct messages.
- Meet RSVPs and locations — if you host or attend a meet, the location and attendee list are part of the meet record.
- Reports and blocks — users, posts, or messages you report or block.
Information collected automatically:
- Anonymous user ID — assigned at signup, used to link your data within Car Lounge.
- Device push token — if you enable push notifications.
- Crash diagnostics and performance data — basic technical telemetry for stability.
- App version, OS version, device model — for compatibility and support.
We do not collect: precise GPS location (unless you opt in for a meet check-in), advertising identifiers (IDFA), contacts, browsing history, or biometric data outside the Stripe Identity flow described below.
2. How we use your information
- To run the app: show you feed and reel content, route your messages, host your meets, run vehicle verification.
- To verify accounts (Vehicle, Shop, Identity tiers) and award badges.
- To moderate content for safety using automated text classification (see Third-Party Services).
- To send transactional emails (signup confirmation, password reset) and push notifications you opt into.
- To maintain, secure, and improve the app (crash diagnostics, abuse prevention).
- To comply with legal obligations and respond to lawful requests.
We do not use your data for advertising, do not sell your data, and do not share it with data brokers.
3. Third-party services
To deliver Car Lounge, we transmit the minimum data necessary to the following processors:
- Supabase Inc. — authentication, Postgres database, file storage, and realtime infrastructure. Your account and content are hosted on Supabase. Supabase Privacy Policy
- Apple Inc. — Apple Sign In (if you choose that option), push notifications via APNs, and in-app purchase if you subscribe. Apple Privacy Policy
- Stripe, Inc. — if you opt into Identity Verification, your government-issued ID document and selfie are submitted to Stripe Identity. Stripe is the data controller for those documents. Stripe Privacy Policy
- OpenAI, L.L.C. — text moderation for posts and comments to catch harassment, spam, and illegal content. We send the text only; we do not send your identity. OpenAI Privacy Policy
- NHTSA vPIC API — if you enter a VIN, it is decoded by the public NHTSA Vehicle API (no account required, no data retained). NHTSA vPIC
- Vercel Inc. — web hosting for the Car Lounge website. Vercel Privacy Policy
4. Identity Verification (optional)
If you choose to become Identity Verified for the blue checkmark, you submit a government ID document and a selfie to Stripe Identity. We receive only a verification result (verified / failed / canceled) and never see or store the ID image, selfie, or sensitive fields like Social Security Number. The verification record is held by Stripe under their privacy policy; we hold only the boolean result and a timestamp.
5. User-generated content
Posts, comments, reels, vehicle photos, and chat messages you create are visible according to your audience choice (public feed, group, or direct message). Other users may see, screenshot, save, or report your content. Do not post anything you would not want preserved.
Content you delete is removed from the app within a reasonable period. Backups may retain the content for up to 30 days before purge.
6. Data retention
We retain your data while your account is active. When you delete your account (Settings → Delete account), we erase your profile, posts, vehicles, photos, chats, and badges within 30 days. We may retain transactional records (subscription invoices, abuse-report metadata) longer where required by law or for legitimate fraud prevention.
7. Your rights and choices
- Access — request a copy of the data we hold about you.
- Correction — edit your profile, vehicles, posts, and settings in the app.
- Deletion — Settings → Delete account erases your data. You can also email us to request server-side deletion.
- Portability — request your data in a portable format.
- Object / restrict — ask us to stop or limit processing.
- Push notifications — disable in iOS Settings or in-app Settings.
If you reside in the European Economic Area, the United Kingdom, or California, you have additional rights under GDPR, UK GDPR, and CCPA respectively. We honor these requests free of charge.
8. Children's privacy
Car Lounge is rated 17+ and is not directed at children under 17. We do not knowingly collect personal information from anyone under 17. If you believe a child under 17 has provided us with personal information, please contact us and we will delete it promptly.
9. Security
We use industry-standard encryption (TLS 1.2+) for data in transit, encrypted-at-rest storage via Supabase, and access controls. No system is perfectly secure; please do not transmit information through Car Lounge that you would not want third parties to see.
10. International transfers
Our servers are located in the United States. By using Car Lounge, you consent to the transfer of your information to the United States.
11. Changes to this policy
We may update this Privacy Policy. Material changes will be announced in the app and the "Last updated" date will be revised. Continued use after changes constitutes acceptance.
12. Contact
Questions, requests, or complaints:
Hummus Development LLC
Email: dev.hummus@gmail.com
Support: Car Lounge Support