Privacy Policy
Last updated: September 6, 2026
The short version
We collect what is needed to run three workflows: mechanic matching, paid NearbyPro looks, and seller-provided condition records. We do not sell personal data. We keep retention windows short and delete data on schedule.
What we collect
- From inspector buyers: email, phone, item city/state/ZIP, visit address, whether they told the seller someone may visit, item description, and optional links so we can match approved pros near the item. For paid looks we also store payment references and the look form the onsite viewer submits.
- From pros: account details (name, email, password hash, phone), location, specialties, optional license info, ratings, and payment processor references (a charge card for mechanics, or a Stripe Connect payout debit card for onsite viewers).
- From Proof Before Pay buyers/sellers: item details, seller answers, photos, optional listing links, and buyer email for management-link recovery.
- Automatically: a keyed hash of your IP for rate limiting (raw IP is not stored), plus redacted operational logs.
How inspector matching works
- We may notify approved pros in your ZIP for vehicle requests and paid looks.
- Matched mechanics receive the contact details and visit address you submitted for that request.
- Mechanics and buyers communicate and transact off-platform.
- For paid NearbyPro looks, we collect the posted look price through our payment provider and show onsite viewer contact and the visit address after an onsite viewer accepts so they can call to confirm a time. We refund if the visit does not happen. After the look form is submitted, we send the onsite viewer share to the US debit card they added, once NearbyPro approves that payout.
- Buyer ratings are stored to improve recommendations; one rating is allowed per request.
How condition records are handled
- Listing links stay private on management pages.
- Images are re-encoded before appearing in reports.
- Uploads are scanned for malware before they can appear in reports.
- Analytics run only after explicit opt-in.
Retention and deletion
- Unsubmitted Proof Before Pay requests are deleted automatically after 14 days from creation unless deleted sooner.
- Inspector matching requests (buyer email, phone, visit address, listing URLs, matches, and lead events) are deleted after 14 days from creation, or on the next daily job if already closed or cancelled. Paid looks that are still in progress, or waiting on a Stripe refund, are kept until that look is settled. Submitted look jobs with an unpaid onsite viewer payout are kept until that payout is recorded.
- Expired and revoked Pro sign-in sessions are deleted by the same daily job.
- Pro password-reset tokens are stored as hashes only, expire after 30 minutes, and are deleted by the same daily job once expired or used.
- Expired and revoked ops sign-in sessions are deleted by the same daily job.
- Live capture (photos and walkaround) in Proof Before Pay must finish within 48 hours of creating a request.
- Completed and revoked records are deleted after 30 days from submission by default.
- Operational audit and consent logs are deleted after 90 days.
Service providers
We use infrastructure providers for hosting, database/storage, transactional email, bot protection, rate limiting, and observability. Each provider receives only what is required for its function.
Your choices
- You can request deletion through your management links or our removal/contact pages.
- Sellers can revoke public sharing and delete records during retention windows.
- Analytics are optional and opt-in only.
Contact
Privacy questions: see the contact page.