Privacy Policy
Last updated: August 26, 2026 · Effective: August 26, 2026
We do not sell your personal information, we do not use it for advertising, and we do not train AI models on your documents. This policy explains what we collect, why, who processes it, and the choices you have.
1. Who We Are and What This Covers
1ownr LLC ("1ownr," "we," "us") operates www.1-ownr.com. This policy explains what personal information we collect, why, who we share it with, and the choices you have.
This policy covers the 1ownr website and application. It does not cover third-party sites you reach from our Service.
We offer the Service only in the United States and do not knowingly collect information from individuals in the European Economic Area, the United Kingdom, or Switzerland.
2. Information We Collect
2.1 Information you provide
| Category | Examples |
|---|---|
| Account information | Name, email address, password (stored hashed), account settings |
| Vehicle information | Year, make, model, trim, nickname, VIN, license plate, purchase date, current mileage |
| Uploaded documents | Photographs and PDFs of receipts, service invoices, inspection reports, and any other file you choose to upload |
| Content within documents | Whatever appears in the files you upload — which may include your name, home address, phone number, signature, service advisor notes, partial payment card numbers printed on receipts, insurance information, and similar details |
| Communications | Messages you send to support, and their contents |
| Text-message intake | If you turn it on: the mobile number you register, the messages you send to our intake number, and any photos attached to them |
| Forwarded email intake | If you turn it on: emails you forward to your private 1ownr address, including sender, subject, body text and attachments |
| Business and workspace details | Workspace name and type, your role, invitations you send or accept, and business contact details you submit through a lead or interest form |
| Sign-in provider details | If you sign in with Google or Apple, we receive the name, email address and provider account identifier those services return — never your provider password |
| Preferences | Settings such as your light/dark theme choice and notification choices, which we store on your profile so they follow you between devices |
Please note: we do not control what appears in a document you photograph. Receipts frequently contain personal information beyond what the Service needs. You may redact sensitive details before uploading.
2.2 Information collected automatically
- Usage data — pages viewed, features used, actions taken, timestamps.
- Device and connection data — IP address, browser type, operating system, device identifiers, approximate location derived from IP address (city/region level).
- Image metadata — photographs may contain embedded EXIF data, including precise GPS coordinates and the device that captured them. For JPEG and PNG photos we strip this metadata in your browser before the file is uploaded, so we never receive it. Other formats (for example HEIC or PDF) are stored as you provide them; we do not read, display, or use their embedded metadata.
- Anti-spam signals on our forms — a hidden field that only automated scripts fill in, plus how long the form was open before submission. We do not use a CAPTCHA of any kind, third-party or our own, and no biometric or behavioral profile is created.
- Cookies and similar technologies — see Section 10.
2.3 Payment information
Payments are processed by Stripe, Inc. You provide card details directly to them. We never receive or store your full card number, CVC, or expiration date. We receive only a payment token, the last four digits, card brand, billing ZIP, and transaction status.
2.4 Information about other people
Documents you upload may contain information about third parties, such as a service advisor's name or a prior owner's details. You are responsible for having the right to upload that information.
3. How We Use Information
We use personal information to:
- create and maintain your account and authenticate you;
- store, organize, and display your documents and timelines;
- run automated extraction on uploaded documents to propose structured data for your review (Section 5.2);
- generate and serve Vehicle Passports you create;
- operate any AI assistant or agent connection you authorize, and act on the requests it makes on your behalf (Section 5.6);
- receive and file records you send by text message or forwarded email, when you enable those channels (Section 12);
- generate maintenance forecasts and send the alerts you have enabled (Section 14);
- operate workspaces, invitations and shared access for shops and dealers you choose to work with (Section 13);
- process payments and one-time purchases, confirm app store entitlements, and send billing notices;
- provide customer support;
- monitor, secure, debug, and improve the Service, including analyzing aggregated and de-identified usage patterns;
- detect and prevent fraud, abuse, and unlawful use;
- send service and transactional communications (billing, security, changes to terms) — you cannot opt out of these while you have an account;
- send product update or marketing emails, if you opt in — you may unsubscribe at any time;
- comply with legal obligations and enforce our Terms.
We do not use your uploaded documents or their contents to train artificial intelligence or machine learning models, and we do not permit our vendors to do so.
We do not use your information for targeted or cross-context behavioral advertising.
4. Legal Bases and Sensitive Information
We do not intentionally collect information that state privacy laws classify as sensitive — such as Social Security numbers, precise geolocation, health data, or biometric identifiers. If such information appears in a document you upload, we process it only as part of storing that document for you, and we ask that you redact it first.
Vehicle Identification Numbers and license plate numbers can identify a vehicle and, indirectly, its owner. We treat them as personal information and, by default, exclude them from Vehicle Passports unless you affirmatively choose to include them.
5. How We Share Information
We do not sell your personal information, and we have not sold or shared personal information for cross-context behavioral advertising in the preceding 12 months.
5.1 At your direction — Vehicle Passports
When you create a Vehicle Passport, the records and fields you select become visible to anyone who has the link, until the link expires or you revoke it. This is a disclosure you initiate and control. We cannot retrieve information from someone who has already viewed, copied, or forwarded a Passport.
5.2 Service providers
We share information with vendors who process it on our behalf under contract, limited to what they need:
| Purpose | Provider | What they receive |
|---|---|---|
| Application hosting | Lovable, on Cloudflare infrastructure | Application data, IP addresses |
| Database and file storage | Supabase | Account data, uploaded documents |
| Automated document extraction (AI/OCR) | Google Gemini models, accessed through the Lovable AI Gateway | The content of documents you upload |
| Payment processing | Stripe, Inc. | Name, email, payment details, transaction data |
| In-app purchases (mobile) | Apple App Store | Purchase receipt and entitlement status; Apple handles the payment itself |
| Text-message (MMS) intake | Twilio Inc. | Your registered mobile number, message text, and attached photos |
| Transactional and account email, including forwarded-invoice intake | Lovable managed email delivery (sent from notify.1-ownr.com) | Name, email address, message content, and forwarded emails and their attachments |
| Error monitoring | Lovable error reporting | Usage data, device data, IP address |
| Customer support | 1ownr in-app contact inbox | Your messages and account identifiers |
Automated extraction means the contents of your uploaded documents are transmitted to a third-party AI provider for processing. We use API-tier terms under which that provider does not use your content to train models and retains it only transiently for abuse monitoring.
We update this table when our vendors change.
5.3 Legal and safety
We may disclose information when we believe in good faith it is necessary to comply with law, a subpoena, court order, or government request; to enforce our Terms; to investigate fraud or security incidents; or to protect the rights, property or safety of any person. Where permitted by law, we will make reasonable efforts to notify you of a legal demand for your data before responding.
5.4 Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify you by email at least 30 days before your information becomes subject to a materially different privacy policy, and you will have the opportunity to delete your account and data first.
5.5 Aggregated and de-identified data
We may create and use aggregated or de-identified data that cannot reasonably identify you or your vehicle. We commit to maintaining such data in de-identified form and not attempting to re-identify it.
5.6 At your direction — connected AI assistants and agents
1ownr offers an agent integration that lets an AI assistant you choose (for example a chat assistant that supports connected tools) work with your records. Nothing is connected by default. A connection only exists after you sign in and approve it on our consent screen, and it acts strictly as you — it can see the same vehicles, service events and document listings your own account can see, and it can add a service entry when you ask it to. It cannot reach another member's data, change your billing, or administer your account.
Whatever you ask a connected assistant to retrieve is disclosed to that assistant's provider and handled under that provider's own privacy policy, not ours. You can end a connection by disconnecting 1ownr in the assistant that holds it, or by asking us through our contact form — once removed, the connection can no longer read or write anything in your account.
5.7 The in-app Garage Assistant
The Garage Assistant is the chat available inside your signed-in account. Your messages, and the answers it returns, are saved to your account so the conversation continues on your other devices. To answer a question it looks up only your own vehicles, service records, costs and document listings; it cannot reach another account's data.
Your messages and the vehicle details needed to answer them are sent to the AI provider listed in Section 5.2 under API-tier terms that prohibit training on your content. You can clear the conversation at any time from the chat itself, which deletes the stored messages.
6. Data Categories, Where They Live, and How Long We Keep Them
6.1 What we store and where it lives
This map shows each category of data we hold, the systems it lives in, and how long we keep it. Every system listed is described in Section 5.2.
| Category | Examples | Where it lives | Retention |
|---|---|---|---|
| Account and profile | Email, name, sign-in provider (Google/Apple), theme preference, role | Supabase (managed authentication and database, US region) | While your account is active |
| Vehicles and service history | Year/make/model, VIN, mileage, service dates, vendors, costs, notes | Supabase database | While your account is active |
| Uploaded documents | Receipts, invoices, inspection reports, photos | Supabase object storage (private bucket, signed expiring URLs) | While your account is active, or until you delete the file |
| Extracted document data | Shop name, totals, mileage, line items, confidence scores | Supabase database; document contents pass transiently through Google Gemini via the Lovable AI Gateway during extraction | While the related record exists; not retained by the AI provider for training |
| Passport share links | Link tokens (stored hashed), redaction settings, expiry, view counts | Supabase database | Until you revoke or delete the link, or it expires |
| Pro access grants | Which business you shared a vehicle with, what it can see, documents it uploaded, grant and revocation times | Supabase database | Until you revoke the grant; uploaded documents remain on the vehicle unless deleted |
| Workspaces and team membership | Workspace name and type, member roles, invitations, onboarding progress | Supabase database | While the workspace exists |
| Text-message intake | Registered mobile number, inbound message text, attached photos, delivery status | Supabase database and storage; messages transit Twilio | Photos follow the document schedule; message logs 12 months |
| Forwarded-email intake | Your private forwarding address, inbound sender/subject/body, attachments, parse status | Supabase database and storage; delivery through our managed email provider | Attachments follow the document schedule; intake logs 12 months |
| Maintenance forecasts and alerts | Predicted service items, urgency, alert read state, notification preferences | Supabase database; mileage and service summaries pass transiently through Google Gemini via the Lovable AI Gateway | Until regenerated or the vehicle is deleted |
| Lead and interest form submissions | Name, business email, vertical, message | Supabase database | 24 months, or sooner on request |
| Billing and purchases | Purchases, status, Stripe customer and payment identifiers, and Apple in-app purchase entitlement status where applicable | Stripe and the Apple App Store (card data stays with them; we never see full card numbers) and a mirrored record in our database | 7 years for transaction records, as required for tax and accounting |
| Support correspondence | Contact form messages, replies, associated email address | Supabase database; delivery through Lovable managed email | 24 months, then deleted automatically by a scheduled job |
| Security, access, and audit logs | Activity log entries, Passport access attempts and alerts, email bounce and spam-report records, IP address, user agent | Supabase database | 12 months, then deleted automatically by a scheduled job |
| Device and diagnostic data | IP address, browser type, error reports | Lovable hosting and error reporting, on Cloudflare infrastructure | Short-lived operational retention by our hosting provider |
| Local browser storage | Session token, theme choice, cookie-consent choice, onboarding progress | Your own device (localStorage and first-party cookies) | Until you sign out or clear your browser storage |
We do not store payment card numbers, we strip location metadata from JPEG and PNG images in your browser before upload, and we do not run third-party advertising or analytics trackers.
6.2 Retention summary and deletion
| Data | Retention |
|---|---|
| Account and uploaded documents | While your account is active |
| After account deletion | Your account, vehicles, records and uploaded files are erased from production systems immediately when you delete your account; residual copies age out of our provider's encrypted backup rotation within 90 days |
| Expired or revoked Passports | Access terminated immediately; underlying records follow the schedule above |
| Billing and transaction records | 7 years, as required for tax and accounting |
| Security, access, and audit logs | 12 months, then deleted automatically by a scheduled job |
| Support correspondence | 24 months, then deleted automatically by a scheduled job |
We may retain information longer where required by law or where necessary to resolve a dispute or enforce our agreements.
7. Security
We use commercially reasonable safeguards, including:
- encryption of data in transit (TLS) and at rest;
- row-level database rules that scope every record to the account that owns it, so one member's data is not reachable from another member's session;
- role-based internal access: administrative tools (support inbox, member roles, site diagnostics) are restricted to accounts explicitly granted an admin role, and that role is required on every request, not just in the interface;
- access controls limiting employee and contractor access to what is necessary;
- storage of documents in access-controlled object storage with signed, expiring URLs;
- hashed password storage, with sign-in also available through Google and Apple so no additional password is created;
- logging and monitoring of access to production systems.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please note that our safeguards do not constitute end-to-end encryption: because we perform automated extraction and generate Passports on your behalf, our systems and our processing vendors can access document contents. Do not upload material you are unwilling to have processed under these conditions.
If a breach affecting your personal information occurs, we will notify you and applicable regulators as required by law, including Connecticut General Statutes § 36a-701b.
8. Your Choices and Rights
8.1 Available to everyone
- Access and export — download your records at any time from account settings.
- Correct — edit any vehicle, record, or extracted value directly in the Service.
- Delete — delete individual records or your entire account from account settings.
- Revoke Passports — revoke any active Passport link at any time.
- Marketing emails — unsubscribe using the link in any marketing message.
- Notifications — turn maintenance alert emails on or off, and remove a registered text-intake number or forwarding address, in Settings.
8.2 State privacy rights
Depending on your state of residence — including Connecticut (Connecticut Data Privacy Act), California (CCPA/CPRA), Colorado, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws — you may have the right to:
- know what personal information we collect, use, and disclose, and obtain a copy in a portable format;
- correct inaccurate personal information;
- delete personal information we hold about you;
- opt out of the sale of personal information, targeted advertising, and profiling with legal or similarly significant effects (we do not engage in any of these);
- not be discriminated against for exercising a right.
How to exercise: use the controls in account settings or reach out through our contact form. We will verify your identity through your account credentials or by confirming information we already hold. We respond within 45 days, extendable once by an additional 45 days with notice. Authorized agents may submit requests on your behalf with proof of authorization.
Appeals: if we decline your request, you may appeal through our contact form with "Appeal" in the subject line. We will respond in writing within 60 days with our decision and reasoning. If we deny the appeal, Connecticut residents may contact the Connecticut Attorney General at portal.ct.gov/AG; residents of other states may contact their state attorney general.
8.3 California-specific
We have collected the following CCPA categories in the past 12 months: identifiers; commercial information; internet activity; approximate geolocation; and, within uploaded documents, categories of personal information described in Cal. Civ. Code § 1798.80. Sources, purposes and recipients are described in Sections 2, 3 and 5.
We do not sell or share personal information as those terms are defined by the CCPA, and we do not have actual knowledge of selling or sharing the personal information of consumers under 16.
8.4 Global Privacy Control
We honor the Global Privacy Control (GPC) and similar universal opt-out signals as required by Connecticut and California law. When your browser sends GPC, we automatically turn off optional analytics cookies without requiring you to interact with the cookie banner. We do not sell personal information or conduct targeted advertising, so no other processing changes.
9. Children
The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect personal information from children. If we learn we have collected information from a person under 13, we will delete it. Contact us through our contact form if you believe a child has provided us information.
10. Cookies and Tracking
We use strictly necessary cookies, functional cookies, and first-party analytics. We do not use advertising cookies, third-party ad networks, or cross-site tracking pixels. See our Cookie Notice for the full breakdown.
You can block or delete cookies in your browser, though the Service may not function properly without necessary cookies. We do not respond to browser "Do Not Track" signals, which lack a common standard; we do honor GPC as described in Section 8.4.
11. Vehicle Passports and Privacy
A Vehicle Passport is a public-by-link resource. Anyone with the URL can view it. We recommend that you:
- keep VIN, license plate, costs, and personal details excluded (the default);
- set the shortest practical expiration and revoke the link once a transaction is complete;
- share links only with people you have chosen.
Passport pages are served with directives instructing search engines not to index them, but we cannot prevent a recipient from copying, screenshotting, or forwarding what they see.
12. Text-Message and Forwarding-Email Capture
Two optional intake channels are off until you turn them on:
- Photo by text — if you register a mobile number, we store that number, the messages you send to our intake number, and any attached images. Messages travel through our telecom provider, which processes them on our behalf and applies its own carrier logging. We use the number only to receive your uploads and to reply about them; we do not sell it, and we do not use it for marketing. Reply STOP or remove the number in Settings to end it. Message and data rates may apply.
- Forwarding email — we generate a private forwarding address for your account. Email you forward to it, including headers, body text and attachments, is received by our email provider, parsed for service details, and filed as a draft record for your review. Anyone who learns that address can send material into your account, so treat it as a credential; you can rotate or disable it in Settings.
Incoming items are handled exactly like documents you upload directly: they are stored in your private vault, may be processed by our extraction vendor (Section 5.2), and follow the retention schedule in Section 6. Messages we cannot match to an account are discarded.
13. Workspaces, Shops, and Dealers
If you join or create a workspace for a shop, dealer or fleet, the workspace's owners and admins can see the workspace's vehicles, records, shared Passports, invitations, member list and activity, including your name and email as a member. We act on the workspace owner's instructions with respect to that content.
If you grant a shop or dealer access to one of your vehicles, that business can view the records you shared and can upload documents to that vehicle. Its name is shown alongside what it adds. Revoking a grant ends future access but cannot retrieve anything already viewed or downloaded. You can see and revoke every active grant from your account.
Business contact details submitted through a lead or interest form on our marketing pages — name, email, business type and any message — are stored so we can respond, and are kept for 24 months unless you ask us to remove them sooner.
14. Maintenance Forecasts and Alerts
We may analyze your vehicle's mileage and service history, including with an AI vendor listed in Section 5.2, to estimate upcoming maintenance and to notify you or your workspace when an item becomes due. This is automated processing that produces an estimate; it does not produce a legal or similarly significant decision about you, and no profile is sold or shared.
Alert emails are optional and can be turned off in Settings. Transactional messages — billing, security, and changes to these documents — continue while you have an account.
15. Mobile Applications
Our mobile apps collect the same categories described above. In addition, the operating system may provide us a per-app device identifier for delivering notifications, and, where you buy inside the app, the app store gives us a purchase receipt and entitlement status — never your payment card. We do not use mobile advertising identifiers, and we do not track you across other companies' apps or websites.
16. Changes to This Policy
We may update this policy. We will change the "Last updated" date and, for material changes, notify you by email or in-app at least 14 days in advance. Continued use after the effective date constitutes acceptance.
17. Contact Us
Questions? Reach us through our contact form or email support@1-ownr.com.