Privacy Policy
TheiaScan — Effective Date: April 1, 2025
Last updated: August 2026
No data selling
We never sell your personal information
Private by default
Your deal data is visible only to you
Right to delete
Request deletion anytime from Profile
1. Who We Are
TheiaScan is a car-deal analysis tool ("Service") operated for individual consumer use. We help buyers evaluate finance, lease, and cash vehicle purchase deals before signing. This Privacy Policy explains how we collect, use, store, and protect your information when you use TheiaScan via web browser or mobile app.
2. Information We Collect
- Account Information: Email address and name provided during account registration via our authentication provider.
- Deal Data: Vehicle details, sale price, APR, monthly payment, loan term, fees, trade-in values, and other numbers you enter or upload (photos/PDFs) for analysis.
- Usage Analytics: Anonymized page views and feature interactions used in aggregate to improve the app. No personally identifiable information is attached.
- Device & Technical Data: Browser type, operating system, and IP address. IP addresses are associated with your account only for security, fraud prevention, and abuse detection — never sold or used for advertising.
3. How We Use Your Information
- To provide the Service: Processing your deal data to compute a score, grade, and coaching recommendations.
- To improve accuracy: De-identified, aggregated deal data (no names, no VINs, no contact info) may be used to refine our scoring benchmarks.
- To communicate with you: Service-critical emails only (account confirmation, payment receipts). We do not send marketing emails without explicit opt-in.
- Security & fraud prevention: IP logs and session data used to detect and block abusive behavior.
4. Data We Do NOT Collect
- No VINs in deal records: VINs read from documents you upload for analysis are used during that analysis only and are not saved to your deal record. A VIN you enter for an optional trade-in appraisal is stored with that trade-in until you delete it or your account.
- No precise GPS: We do not collect or store your precise GPS coordinates. State/region is inferred from optional zip-code prefix only.
- No biometrics: We do not collect fingerprints, face scans, or any biometric data.
- No third-party ad profiles: We do not share your data with advertising networks or data brokers.
5. Data Sharing
We do not sell, rent, or trade your personal information. We may share data only with:
- Service providers: Hosting, authentication, payment processing (Stripe), and analytics tools that operate under strict data processing agreements.
- Legal requirements: If required by law, court order, or to protect the rights and safety of our users.
6. Data Retention
Your complete deal analysis records are retained for up to 240 days, after which they are automatically de-identified (all personal information removed) and the original record is permanently deleted. You may also delete individual analyses from the Dashboard, or delete your entire account and all associated data from the Profile page at any time. Account deletion is permanent and irreversible. De-identified, aggregate records that can no longer identify you may be retained indefinitely to improve scoring accuracy.
7. Security
We use industry-standard encryption (TLS) for all data in transit. Data at rest is stored in encrypted databases. Access to your personal deal data is restricted to your authenticated account. No system is 100% secure, and we cannot guarantee absolute security, but we take reasonable and appropriate technical and organizational measures to protect your data.
8. Your Privacy Rights
Depending on your state of residence, you may have the following rights:
- Right to Know: Request a copy of the personal information we hold about you.
- Right to Delete: Request deletion of your account and all associated personal data.
- Right to Correct: Request correction of inaccurate information.
- Right to Opt Out: Opt out of any sale or sharing of personal information. We do not sell personal information.
- Right to Limit (CPRA): California residents may limit our use of Sensitive Personal Information (financial deal data). Manage this from your Profile page or the consent banner.
- Non-Discrimination: We will never deny, charge differently, or provide a different level of service based on you exercising your privacy rights.
9. California Residents — CCPA/CPRA
TheiaScan complies with the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). California residents have the right to: (1) know what categories of personal information are collected; (2) know if personal information is sold or disclosed; (3) opt out of the sale of personal information; (4) request deletion; (5) limit use of Sensitive Personal Information; and (6) not be discriminated against for exercising these rights. To submit a request, contact us at the email below or use the in-app controls on your Profile page.
10. Children's Privacy
TheiaScan is not intended for users under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided personal information through our Service, contact us immediately and we will delete it.
11. Third-Party Links
Our Service may reference third-party websites (e.g., Edmunds, Kelley Blue Book) for informational purposes. We are not responsible for the privacy practices of external sites. We encourage you to review their privacy policies.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the 'Last updated' date at the top of this page and, for significant changes, via email or in-app notification. Continued use of the Service after the effective date constitutes acceptance.
13. Contact Us
For privacy requests, questions, or to exercise your rights, contact us at:
Privacy Contact
TheiaScan
Email: support@theiascan.com
Response time: within 45 days of a verified request (as required by CCPA).