waiting for prices · age unavailable

data-use boundaries

Privacy at Carconomics

Carconomics is designed to answer rental-price questions without building a browsing profile. Searching needs no account; an account exists only if you create one for paid features. This page lists what is processed or saved in each case.

Searches and approximate location

Rental filters, dates, group, and market may appear in a shareable URL. If you enter a ZIP code, city, or address for distance sorting, the text is used to resolve a public ZIP or city centroid for that session. The raw address is not placed in the URL, retained as a profile, or exposed to listings or hosts. Results are straight-line approximations, not routes or precise host locations.

Favorites and browser state

Any favorites or interface settings the site keeps between visits — saved favorites, your last search, the page to return to after sign-in — live only in your browser’s local storage under the fixed keys “tesla-window-favorites”, “tesla-window-last-search”, and “tesla-window-return-to”. Local storage is never sent to Carconomics servers and is not linked to an account. You can clear it through the site or your browser storage controls.

Accounts and sign-in

Creating an account — by email magic link or Google sign-in; there are no passwords — is needed only for paid plans, report credits, and saved listing watches. The account record stores the verified email address; verification, sign-in, and last-activity timestamps; and the plan, report-credit, and beta-price-lock state billing needs. Saved watches store the listing, market, and watch settings you choose and contain no email address.

A sign-in link works once and expires 15 minutes after it is issued. The link ledger stores a SHA-256 hash of the email address, never the raw address. Google sign-in reads only the verified email claim from Google’s token service — no profile, contact, or calendar data.

Signing in sets one first-party cookie, “__Host-cc_session”: HttpOnly, secure, and expiring after 30 days. It carries a signed snapshot of the account’s plan so most requests skip a database read; it is not an advertising or cross-site tracking cookie. Signing out clears it, and “sign out everywhere” invalidates every outstanding copy.

Billing through Stripe

Stripe processes every payment for Carconomics. Carconomics stores the Stripe customer, subscription, and checkout identifiers plus the mirrored status fields needed to grant access — plan tier, market, period end, amount paid, refund state. Carconomics never sees, stores, or transmits card numbers; card and eligible Apple Pay or Google Pay details go directly to Stripe and are governed by Stripe’s own privacy terms. Stripe Tax calculates and collects tax where Carconomics has an active tax registration.

Sign-in email delivery

Resend, a transactional email provider, delivers sign-in emails and processes the destination address for that purpose. A bounded send log, keyed by hashed address only, is kept for 90 days. A do-not-send suppression list — unsubscribes, bounces, complaints — is honored fail-closed: when the list cannot be read, nothing is sent. Requesting a sign-in link always returns the same generic response, so nothing reveals whether an address exists or is suppressed.

Host Pro interest submissions

If you explicitly submit the Host Pro interest form, Carconomics stores the normalized email address, tracked listing ID, selected Tesla or Luxury collection, observed market, two product-preference booleans, consent version, and submission/activity timestamps. The record does not verify identity, email ownership, host status, listing ownership, or control. It stores no name, billing data, score, review text, or public profile.

Inactive interest rows become eligible for removal after 180 days. You can remove a matching record from the removal form on the Host Pro interest page by entering the same email, listing, and collection; the response does not disclose whether a row existed.

Retention and deletion

An account with no paid history is deleted after 365 days without activity. Billing mirrors are bounded: closed subscription and purchase records purge 400 days after they end, and the send log clears at 90 days. A weekly backup of the account and billing tables exists for recovery and keeps only the newest eight copies.

Deleting your account is self-serve from the account page and immediate. Active subscriptions are canceled at Stripe first — if any cancellation fails, nothing is deleted — then the account, its watches, and its subscription and purchase records are removed in one step. Two things outlive deletion: do-not-send suppression entries, so an unsubscribe is never forgotten, and Stripe’s own transaction records, retained under Stripe’s terms.

Analytics, Search Console, and infrastructure

Carconomics sells no personal data and shows no ads. It does not currently load Google Analytics or Google Tag Manager and does not intentionally set advertising or analytics cookies. Google Search Console provides aggregate search and crawl reporting without adding a tracking script to the site. Cloudflare hosts and protects the application and may process ordinary request and security metadata as infrastructure provider.

External services

Links to Turo and official data sources, the Stripe payment form and billing portal, and Google sign-in use third-party services with their own privacy practices. Stripe’s payment form is embedded on the Carconomics account page when available, but its fields remain Stripe-controlled. Carconomics is not responsible for data you provide directly to those services.

Current-state policy: This page describes the shipped product, accounts and billing included. If a new personal-data use is introduced, this policy and any applicable consent flow are updated before it takes effect.