Privacy policy
Last updated: 2026-06-10 · TheCarApi
1. Who we are
TheCarApi is operated in connection with thecarapi.com. Contact: api@thecarapi.com.
2. Data we process
When you request API access or contact us, we process identity and contact data (name, email, company, message content) to evaluate access and provide support. API usage may generate technical logs (IP, request path, timestamps, request IDs, auth failure counters) for security and reliability.
3. Auction inventory data
The API returns vehicle auction inventory aggregated from third-party marketplaces. That inventory is not personal data about you as a customer; it is product data licensed/accessed under our platform terms. Do not use the API to attempt re-identification of private individuals beyond lawful business use of public listing data.
4. Legal bases & retention
We process contact data under legitimate interest and/or contract steps prior to providing a service. Logs are retained as needed for security (including brute-force lockouts) and then deleted or anonymized. Contact records are kept while an active commercial relationship exists or as required by law.
5. Your rights
Subject to applicable law, you may request access, correction, deletion, or restriction of personal data we hold about you by emailing api@thecarapi.com.
6. Security
API keys must be kept secret. Failed key attempts are rate-tracked per IP. Transport should use HTTPS. We do not ask for platform bidding credentials from end customers for the data API product.