Privacy Policy
Effective date: August 1, 2026
Curbside gives independent sellers a page of their own (an /@name link on our domain) to show what they are selling. This policy covers what we collect, why, and who it is shared with — both for sellers who run a page and for buyers who visit one.
1. What we collect
- Seller accounts: your email address, and a password hash if you sign up with a password. If you sign in with Google, we receive your email address and basic profile (name, avatar) from Google — nothing else.
- Your page: the name, headline, bio, city, phone number, viewing address and anything you list — photos, prices, VINs, specs. All of it is content you chose to publish; the page is public by design.
- Buyer enquiries: when a buyer books a viewing, we store the name, phone number, preferred time and message they submit — on behalf of the seller whose page it is.
- Visitor analytics: which pages were opened, how long they were read, and which share link brought the visitor. Visitors get a random session identifier stored in a cookie. We do not use Google Analytics, advertising cookies, or any cross-site tracking.
- Billing: subscription status only. Card details go directly to Creem, our merchant of record, and never touch our servers.
2. Cookies and local storage
- Sign-in cookies (Supabase Auth) — keep sellers signed in to their console.
- cb_shop — remembers which of your pages you were managing.
- cb_sid — a random visitor session id, used to count visitors without storing IP addresses.
- cb_src — remembers which share link brought you, so the seller can see which channel works.
- Local storage — small preferences like “don’t show the install prompt again”. If you add a page to your home screen, photos you viewed may be cached on your device for offline reading.
3. Google user data
If you choose “Continue with Google”, we access only your email address and basic profile through Google Sign-In, and use them solely to create and secure your account. We do not share, sell, or use Google user data for advertising, and our use complies with the Google API Services User Data Policy, including its Limited Use requirements.
4. Who we share data with
- Supabase — database, authentication and photo storage.
- Vercel — application hosting.
- Google — sign-in (if you use it), and address suggestions when a seller types in the address box (only the text being typed is sent).
- LocationIQ / Radar — alternative address-suggestion providers, same rule: only the typed address text is sent.
- NHTSA (US Department of Transportation) — when a seller enters a VIN, it is sent to the public vPIC decoder to fill in vehicle specs.
- Resend — delivers the email that tells a seller a buyer enquired.
- Creem — subscription checkout and invoicing, as merchant of record.
That is the whole list. We do not sell personal data, and there are no advertising partners.
5. Buyer data belongs to the seller
When you send an enquiry through someone’s page, that seller is the controller of your enquiry; we process it on their behalf and show it only to them. To correct or delete it, contact the seller directly — or email us and we will handle it.
6. Retention and deletion
We keep data while an account is active. Delete your account (or ask us to) and personal data is removed within 30 days, except records we are required to keep for tax or legal reasons. Buyers can request deletion of their enquiry data at any time.
7. Security
Data is encrypted in transit (HTTPS) and at rest. Row-level security restricts every seller’s data to that seller. Access to production data is limited to the operator of the service.
8. Your rights
You can request access, correction, export or deletion of your personal data at any time by emailing ye@getdetailkit.com. If you are in the EU/UK or California these rights are backed by GDPR/CCPA — and we honor them for everyone, regardless of where you live.
9. Children
Curbside is not directed at children under 13 and we do not knowingly collect their data.
10. Changes
If this policy changes in a way that matters, we note it here with a new effective date. Questions: ye@getdetailkit.com.