Privacy policy
Last updated: 2026-08-21
This policy describes how ReconOS ("we", "us") collects, uses, and shares information when you use the ReconOS recon-pipeline software ("Service") through our website or applications.
Information we collect
We collect three kinds of information: information you give us directly, information we collect automatically when you use the Service, and information we receive from third parties.
Information you provide
- Account data: name, email address, password (hashed by our identity provider, so we never see the plain text), dealership name, dealership location.
- Inventory data: vehicle VINs, year/make/model, mileage, pricing, purchase records, photos you upload, and metadata such as stage transitions and assigned tech.
- Directory data: the names, roles, phone numbers, and email addresses you save for your techs and parts vendors.
- Communications: the contents of support emails, lead-capture form submissions, and SMS templates you send through the Service.
- Payment data: billing address and card-network metadata. We never receive your full card number. Stripe handles card capture and storage on our behalf.
Information collected automatically
- Usage logs: IP address, browser type, pages visited, referring URL, timestamps. We use these for security, fraud detection, and product improvement.
- Cookies: session cookies set by our identity provider to keep you signed in, and functional cookies for application state. We do not use third-party advertising cookies.
Information from third parties
- Vehicle data: when you enter a VIN, we look it up against the public NHTSA vPIC and Recalls APIs to populate year/make/model and active recall information.
How we use information
- To provide, operate, and improve the Service.
- To authenticate you, send password resets, and confirm your email address.
- To process payments and manage your subscription.
- To deliver SMS notifications (when you trigger them) to your techs and parts vendors.
- To compute aggregated, anonymized benchmarks across customers (e.g. "median time-to-line for 15 to 45 cars/month rooftops"). We never expose another customer's identifiable data to you.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To comply with legal obligations.
How we share information
We do not sell your data. We share information only with the subprocessors listed below, with our affiliates, and when legally required.
Subprocessors
- Amazon Web Services (AWS): application hosting and infrastructure. The application and its database run on AWS.
- Supabase: database, authentication, and storage software. We self-host it on our own AWS infrastructure rather than using Supabase's hosted service.
- Stripe: payment processing.
- SendGrid (Twilio): delivery of product email — daily reports, weekly digests, alerts, and team invitations. Recipient addresses and the contents of those messages pass through SendGrid.
- Twilio: outbound SMS, only when you trigger it.
- OpenRouter: routes our AI requests to the model provider below. Uploaded vehicle photos and vehicle details are sent through OpenRouter to reach that provider.
- Anthropic: the model that scores uploaded vehicle photos and drafts listing copy, reached via OpenRouter. For photo scoring, only the image itself is sent.
- Sentry: error and performance monitoring.
- NHTSA: public vehicle database; we send only the VIN, year, make, and model.
The current subprocessor list is also available in our Data Processing Addendum. We will notify customers before adding a new subprocessor that materially affects how their data is processed.
Data retention
- Active account data: retained while your account is active.
- Closed accounts: retained after cancellation. We do not currently run an automatic deletion schedule — see “Deletion” below for how to have your data removed.
- Recon-event logs: retained for the life of the account.
- Aggregated benchmarks: the benchmark comparison set is a fixed sample of seeded reference data. It is not built from customer accounts, so no customer data is retained in it.
- Backups: database backups are retained for up to 30 days, so data may persist in a backup for that period after it is deleted from the live system.
Your rights
Depending on where you live, you may have rights under GDPR, CCPA, or similar laws to access, correct, export, or delete your personal information; to object to or restrict processing; and to lodge a complaint with a supervisory authority. To exercise these rights, email privacy@reconos.com. We will acknowledge your request within 30 days and tell you how long it will take to complete.
Export
Owners can export their dealership's data at any time from Settings, without contacting us.
Deletion
We do not yet offer self-service account deletion. Deletion requests are carried out manually by our team on request to the address above. Deleting your live data does not immediately remove it from backups; those are overwritten on the retention cycle described above.
Security
Data in transit is encrypted with TLS, and requests over plain HTTP are redirected to HTTPS. Customer data is isolated by PostgreSQL row-level security, so users at one dealership cannot read another dealership's records. Data at rest is encrypted by our cloud provider. Passwords are hashed and never stored in readable form, and API keys are stored only as a keyed hash.
We are a small team and we would rather describe our security honestly than impressively. Two limitations are worth stating plainly. Access to production systems is currently held by a single administrator rather than a rotated, individually-audited group. And uploaded vehicle photos are served from unguessable public URLs rather than time-limited signed ones, so anyone who obtains a photo's link can view that photo. We are working on both.
Where your data is processed
The Service is operated from the United States and all of the subprocessors listed above process data in the United States. We do not currently offer data residency in any other region. If you are subject to EEA, UK, or Swiss data-protection law, contact us before signing up so we can discuss whether we are an appropriate processor for you.
Children
The Service is intended for business use. We do not knowingly collect personal information from anyone under 16. If we learn that we have, we will delete it.
Changes
We may update this policy from time to time. The "last updated" date above reflects the most recent change. For material changes that affect how we process your data, we will notify customers in advance by email.
Contact
Questions or requests? Email us at privacy@reconos.com or write to ReconOS, Attn: Privacy, [postal address pending].