Privacy Policy
Last updated: August 4, 2026 · Effective: August 4, 2026
We do not sell your personal information, we do not use it for advertising, and we do not train AI models on your documents. This policy explains what we collect, why, who processes it, and the choices you have.
1. Who We Are and What This Covers
1ownr LLC ("1ownr," "we," "us") operates www.1-ownr.com. This policy explains what personal information we collect, why, who we share it with, and the choices you have.
This policy covers the 1ownr website and application. It does not cover third-party sites you reach from our Service.
We offer the Service only in the United States and do not knowingly collect information from individuals in the European Economic Area, the United Kingdom, or Switzerland.
2. Information We Collect
2.1 Information you provide
| Category | Examples |
|---|---|
| Account information | Name, email address, password (stored hashed), account settings |
| Vehicle information | Year, make, model, trim, nickname, VIN, license plate, purchase date, current mileage |
| Uploaded documents | Photographs and PDFs of receipts, service invoices, inspection reports, and any other file you choose to upload |
| Content within documents | Whatever appears in the files you upload — which may include your name, home address, phone number, signature, service advisor notes, partial payment card numbers printed on receipts, insurance information, and similar details |
| Communications | Messages you send to support, and their contents |
Please note: we do not control what appears in a document you photograph. Receipts frequently contain personal information beyond what the Service needs. You may redact sensitive details before uploading.
2.2 Information collected automatically
- Usage data — pages viewed, features used, actions taken, timestamps.
- Device and connection data — IP address, browser type, operating system, device identifiers, approximate location derived from IP address (city/region level).
- Image metadata — photographs may contain embedded EXIF data, including precise GPS coordinates and the device that captured them. We do not display or use this data, and it is removed from files we serve on a Vehicle Passport.
- Cookies and similar technologies — see Section 10.
2.3 Payment information
Payments are processed by Stripe, Inc. You provide card details directly to them. We never receive or store your full card number, CVC, or expiration date. We receive only a payment token, the last four digits, card brand, billing ZIP, and transaction status.
2.4 Information about other people
Documents you upload may contain information about third parties, such as a service advisor's name or a prior owner's details. You are responsible for having the right to upload that information.
3. How We Use Information
We use personal information to:
- create and maintain your account and authenticate you;
- store, organize, and display your documents and timelines;
- run automated extraction on uploaded documents to propose structured data for your review (Section 5.2);
- generate and serve Vehicle Passports you create;
- process payments, manage subscriptions, and send billing notices;
- provide customer support;
- monitor, secure, debug, and improve the Service, including analyzing aggregated and de-identified usage patterns;
- detect and prevent fraud, abuse, and unlawful use;
- send service and transactional communications (billing, security, changes to terms) — you cannot opt out of these while you have an account;
- send product update or marketing emails, if you opt in — you may unsubscribe at any time;
- comply with legal obligations and enforce our Terms.
We do not use your uploaded documents or their contents to train artificial intelligence or machine learning models, and we do not permit our vendors to do so.
We do not use your information for targeted or cross-context behavioral advertising.
4. Legal Bases and Sensitive Information
We do not intentionally collect information that state privacy laws classify as sensitive — such as Social Security numbers, precise geolocation, health data, or biometric identifiers. If such information appears in a document you upload, we process it only as part of storing that document for you, and we ask that you redact it first.
Vehicle Identification Numbers and license plate numbers can identify a vehicle and, indirectly, its owner. We treat them as personal information and, by default, exclude them from Vehicle Passports unless you affirmatively choose to include them.
5. How We Share Information
We do not sell your personal information, and we have not sold or shared personal information for cross-context behavioral advertising in the preceding 12 months.
5.1 At your direction — Vehicle Passports
When you create a Vehicle Passport, the records and fields you select become visible to anyone who has the link, until the link expires or you revoke it. This is a disclosure you initiate and control. We cannot retrieve information from someone who has already viewed, copied, or forwarded a Passport.
5.2 Service providers
We share information with vendors who process it on our behalf under contract, limited to what they need:
| Purpose | Provider | What they receive |
|---|---|---|
| Application hosting | Cloudflare | Application data, IP addresses |
| Database and file storage | Supabase | Account data, uploaded documents |
| Automated document extraction (AI/OCR) | Google (Gemini API) | The content of documents you upload |
| Payment processing | Stripe, Inc. | Name, email, payment details, transaction data |
| Transactional email | Resend | Name, email address |
| Error monitoring | Sentry-class error reporting | Usage data, device data, IP address |
| Customer support | 1ownr in-app contact inbox | Your messages and account identifiers |
Automated extraction means the contents of your uploaded documents are transmitted to a third-party AI provider for processing. We use API-tier terms under which that provider does not use your content to train models and retains it only transiently for abuse monitoring.
We update this table when our vendors change.
5.3 Legal and safety
We may disclose information when we believe in good faith it is necessary to comply with law, a subpoena, court order, or government request; to enforce our Terms; to investigate fraud or security incidents; or to protect the rights, property or safety of any person. Where permitted by law, we will make reasonable efforts to notify you of a legal demand for your data before responding.
5.4 Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify you by email at least 30 days before your information becomes subject to a materially different privacy policy, and you will have the opportunity to delete your account and data first.
5.5 Aggregated and de-identified data
We may create and use aggregated or de-identified data that cannot reasonably identify you or your vehicle. We commit to maintaining such data in de-identified form and not attempting to re-identify it.
6. How Long We Keep Information
| Data | Retention |
|---|---|
| Account and uploaded documents | While your account is active |
| After account deletion | Deleted from production systems within 30 days; purged from encrypted backups within 90 days |
| Expired or revoked Passports | Access terminated immediately; underlying records follow the schedule above |
| Billing and transaction records | 7 years, as required for tax and accounting |
| Security, access, and audit logs | 12 months |
| Support correspondence | 24 months |
We may retain information longer where required by law or where necessary to resolve a dispute or enforce our agreements.
7. Security
We use commercially reasonable safeguards, including:
- encryption of data in transit (TLS) and at rest;
- access controls limiting employee and contractor access to what is necessary;
- storage of documents in access-controlled object storage with signed, expiring URLs;
- hashed password storage;
- logging and monitoring of access to production systems.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please note that our safeguards do not constitute end-to-end encryption: because we perform automated extraction and generate Passports on your behalf, our systems and our processing vendors can access document contents. Do not upload material you are unwilling to have processed under these conditions.
If a breach affecting your personal information occurs, we will notify you and applicable regulators as required by law, including Connecticut General Statutes § 36a-701b.
8. Your Choices and Rights
8.1 Available to everyone
- Access and export — download your records at any time from account settings.
- Correct — edit any vehicle, record, or extracted value directly in the Service.
- Delete — delete individual records or your entire account from account settings.
- Revoke Passports — revoke any active Passport link at any time.
- Marketing emails — unsubscribe using the link in any marketing message.
8.2 State privacy rights
Depending on your state of residence — including Connecticut (Connecticut Data Privacy Act), California (CCPA/CPRA), Colorado, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws — you may have the right to:
- know what personal information we collect, use, and disclose, and obtain a copy in a portable format;
- correct inaccurate personal information;
- delete personal information we hold about you;
- opt out of the sale of personal information, targeted advertising, and profiling with legal or similarly significant effects (we do not engage in any of these);
- not be discriminated against for exercising a right.
How to exercise: use the controls in account settings or reach out through our contact form. We will verify your identity through your account credentials or by confirming information we already hold. We respond within 45 days, extendable once by an additional 45 days with notice. Authorized agents may submit requests on your behalf with proof of authorization.
Appeals: if we decline your request, you may appeal through our contact form with "Appeal" in the subject line. We will respond in writing within 60 days with our decision and reasoning. If we deny the appeal, Connecticut residents may contact the Connecticut Attorney General at portal.ct.gov/AG; residents of other states may contact their state attorney general.
8.3 California-specific
We have collected the following CCPA categories in the past 12 months: identifiers; commercial information; internet activity; approximate geolocation; and, within uploaded documents, categories of personal information described in Cal. Civ. Code § 1798.80. Sources, purposes and recipients are described in Sections 2, 3 and 5.
We do not sell or share personal information as those terms are defined by the CCPA, and we do not have actual knowledge of selling or sharing the personal information of consumers under 16.
8.4 Global Privacy Control
We honor the Global Privacy Control (GPC) and similar universal opt-out signals as required by Connecticut and California law. Because we do not sell personal information or conduct targeted advertising, the signal does not change our processing, but we will not disregard it.
9. Children
The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect personal information from children. If we learn we have collected information from a person under 13, we will delete it. Contact us through our contact form if you believe a child has provided us information.
10. Cookies and Tracking
We use strictly necessary cookies, functional cookies, and first-party analytics. We do not use advertising cookies, third-party ad networks, or cross-site tracking pixels. See our Cookie Notice for the full breakdown.
You can block or delete cookies in your browser, though the Service may not function properly without necessary cookies. We do not respond to browser "Do Not Track" signals, which lack a common standard; we do honor GPC as described in Section 8.4.
11. Vehicle Passports and Privacy
A Vehicle Passport is a public-by-link resource. Anyone with the URL can view it. We recommend that you:
- keep VIN, license plate, costs, and personal details excluded (the default);
- set the shortest practical expiration and revoke the link once a transaction is complete;
- share links only with people you have chosen.
Passport pages are served with directives instructing search engines not to index them, but we cannot prevent a recipient from copying, screenshotting, or forwarding what they see.
12. Changes to This Policy
We may update this policy. We will change the "Last updated" date and, for material changes, notify you by email or in-app at least 14 days in advance. Continued use after the effective date constitutes acceptance.
13. Contact Us
Questions? Reach us through our contact form or email support@1-ownr.com.