Privacy Policy
Carlinks ("we", "us", "our") respects your privacy. This Privacy Policy explains what personal information we collect when you use Carlinks Verify (the https://carlinks.xyz website and the forthcoming iOS / Android mobile applications), how we use it, who we share it with, how long we keep it, and the rights you have over it. It applies to all visitors, registered users, and paying customers worldwide.
By using the Service you confirm you have read and understood this Policy. If you do not agree, please do not use the Service.
1. Who we are (data controller)
Carlinks, trading as Carlinks Verify, is the data controller for personal information processed through the Service. Our registered office is at Dhaka, Bangladesh. Our Trade License number is 1230049110. You can reach our data-protection contact at hello@carlinks.xyz.
2. Scope of this Policy
This Policy covers personal information processed by us in connection with:
- The https://carlinks.xyz website (chassis search, free preview, paid Reports, duty calculator, public report pages);
- The forthcoming Carlinks Verify mobile applications for iOS and Android (see §6);
- Our APIs and B2B integrations;
- Transactional email and SMS communications we send;
- Customer support correspondence.
It does not cover third-party websites or services we link to (SSLCommerz, the App Store, Google Play, social-media properties, news articles), each of which has its own privacy policy.
3. Categories of personal information we collect
3.1 Information you provide directly:
- Order information — full name, email address, mobile number, and (if voluntarily provided) postal address. Collected only at checkout for paid Reports.
- Communications — the content of any email, support ticket, or chat conversation you have with us.
- Voluntary submissions — anything you choose to write in a feedback form, testimonial, or business-inquiry message.
3.2 Information collected automatically when you use the Service:
- Search data — the chassis number you submit, the resulting preview, and the timestamp of the search.
- Technical & device data — IP address, IP-derived country (ISO-2 code), user-agent string, referring URL, screen size, time zone, requested language. From the mobile apps, we will also collect device model, OS version, app version, install ID, and crash diagnostics.
- Service-interaction logs — successful and failed requests, error codes, rate-limit events, bot-challenge outcomes, and the public Report token you accessed. Used for fraud prevention, debugging, and operational metrics.
- Anonymous usage statistics — aggregated, non-identifying page-view and feature-use counts. We do not set tracking cookies for analytics.
3.3 Information received from third parties:
- Payment confirmation data from SSLCommerz — transaction ID, validation ID, bank transaction ID, masked card type, payment status, and the cardholder country. We never receive your full card number, CVV, PIN, or one-time password.
- Anti-fraud signals from our bot-protection provider — a bot score / risk indicator and challenge-token verification result.
We do not knowingly collect special categories of data (race, religion, health, sexual orientation, political views, biometrics, etc.) and request that you do not submit them.
4. How we use your information (purposes & legal bases)
| Purpose | Examples | Legal basis |
|---|---|---|
| Service delivery | Returning chassis search results, generating & emailing the paid Report, hosting the public Report page | Performance of contract |
| Payment processing | Routing your payment via SSLCommerz, validating the transaction, issuing refunds | Performance of contract |
| Fraud & abuse prevention | Rate limiting, bot challenges, chargeback investigation, suspicious-pattern review | Legitimate interests (protecting our service and other users) |
| Customer support | Responding to your email, refund processing, account recovery | Performance of contract / legitimate interests |
| Transactional communications | Order confirmations, payment receipts, delivery notices, security alerts, policy-change notices | Performance of contract |
| Service improvement | Debugging, performance monitoring, aggregated feature analytics | Legitimate interests |
| Legal compliance | VAT/tax records, regulator requests, court orders | Legal obligation |
We do not use your personal information for automated decision-making that produces legal or similarly significant effects, and we do not profile you for advertising.
5. We do not sell or rent your data
We do not sell, rent, or trade your personal information to advertisers, data brokers, or any other third party for monetary or other valuable consideration. We do not share customer lists with third parties for marketing purposes.
6. Mobile applications — forthcoming data practices
We are preparing native iOS and Android applications (see Terms §4). When released, the apps will collect:
- Device identifiers — a non-resettable install ID generated locally by the app for crash-correlation and offline-cache binding;
- Push-notification token — required to send order-status and Report-ready alerts. You can disable notifications at any time in OS settings;
- Camera permission (optional) — only if you opt-in to the chassis-plate OCR feature, used solely on-device to recognise the number. Photos are not uploaded to our servers;
- Storage permission (optional) — to cache previously purchased Reports for offline viewing;
- App diagnostics — crash reports, ANR (Android) / launch-failure (iOS) traces, and basic performance metrics, anonymised before transmission.
The apps will not collect contacts, microphone audio, precise GPS location, advertising IDs, or app-usage outside our own app. Apple's App Tracking Transparency prompt will not be shown because we do not track across third-party apps.
7. Who we share your information with
We share personal information only with the categories of recipients listed below, and only as needed for the purposes in §4.
- Payment processing — SSLCommerz Bangladesh Ltd (PCI-DSS-compliant gateway, regulated by Bangladesh Bank). Receives the data needed to charge your payment method.
- Edge hosting & security — our infrastructure provider hosts the Service and processes request metadata to deliver content securely. A current subprocessor list is available on written request.
- Bot protection — our enterprise bot-challenge provider verifies that requests come from real browsers. It receives the IP address, user-agent, and a short-lived challenge token.
- Transactional email delivery — our email-sending provider delivers receipts, Report links, and security notices. It receives the recipient's name, email address, and the message body.
- Upstream auction-data providers — receive only the chassis number you submit. No personal information is sent.
- App store platforms — when the mobile apps launch, Apple and Google will process basic install / crash data per their own privacy policies.
- Professional advisors — accountants, lawyers, auditors bound by confidentiality, as needed.
- Successors — in connection with a merger, acquisition, or sale of assets, subject to a binding obligation that the recipient honour this Policy.
- Authorities — courts, tax officials, or law enforcement, only when legally compelled (subpoena, court order, regulator notice).
8. International data transfers
The Service runs on a global edge network. Personal information may therefore be processed in countries other than your own (including, but not limited to, Bangladesh, the United States, the European Union, Singapore, and India). When we transfer personal information across borders, we rely on appropriate safeguards (the recipient's binding data-protection terms, encryption in transit, and minimisation of the data shared).
9. Cookies & similar technologies
We do not set advertising or cross-site tracking cookies. We use only the following:
- Strictly necessary cookies — for session integrity, CSRF protection, and Turnstile-style challenges from our bot-protection provider. These cookies do not identify you personally.
- Local-storage entries — for your theme (light/dark) and language (EN/বাং) preference. Stored only in your browser; not transmitted to us.
You can clear local storage at any time via your browser settings. Disabling strictly necessary cookies may break the Service.
10. Data retention
| Category | Retention | Reason |
|---|---|---|
| Free chassis search logs | 90 days | Fraud / abuse investigation |
| Customer order records (name, email, phone, chassis, amount) | 7 years | Bangladesh VAT & income-tax audit requirement |
| Cached chassis Reports (anonymised — no PII) | Indefinite | Re-served to subsequent customers at $0 cost — see About |
| Payment records | Per SSLCommerz policy | Regulatory obligation on processor |
| Refund / dispute correspondence | 5 years | Statute of limitations |
| Bot-event & security logs | 180 days | Operational security |
| Admin audit log | 2 years | Internal governance |
When a retention period ends, we either delete the data or fully anonymise it.
11. Data security
We protect personal information with a defence-in-depth posture, including:
- HTTPS-everywhere with HSTS preload;
- Strict Content-Security-Policy;
- An edge Web Application Firewall and per-IP rate limits;
- Enterprise bot-challenge before every state-changing request;
- AES-256-GCM sealed references for upstream tokens;
- Encrypted edge database storage;
- Principle-of-least-privilege admin access, password hashing with PBKDF2;
- Server-to-server payment validation with SSLCommerz (no client-side card data);
- Regular security review of dependencies and infrastructure changes.
No system is perfectly secure. If we become aware of a personal-data breach affecting you, we will notify you and the relevant Bangladeshi authority as soon as reasonably practicable, and in any event within 72 hours of becoming aware, in line with applicable breach-notification standards.
12. Your rights
Regardless of where you live, you can ask us to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Delete your data (subject to legal retention obligations such as the 7-year VAT record);
- Restrict certain processing, while a dispute is being resolved;
- Object to processing based on our legitimate interests;
- Port your order history to another provider in a structured, machine-readable format;
- Withdraw consent at any time, where consent is the legal basis.
Send your request to hello@carlinks.xyz from the email address associated with your order. We respond within 30 days. If you believe we have not handled your data properly, you may lodge a complaint with the relevant data protection authority in your country.
13. Children's privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact us and we will delete it.
14. Marketing & notifications
We send only transactional communications related to your order (receipt, Report link, refund notice, security alert) or required policy updates. We do not run marketing mailing lists. The mobile apps will allow you to opt-in to push notifications; you can withdraw that opt-in at any time in your OS settings without affecting paid Reports already delivered.
15. Do-Not-Track & Global Privacy Control
Because we do not engage in cross-site tracking, "Do Not Track" or "Global Privacy Control" signals do not change our behaviour — we already minimise data collection by default.
16. Changes to this Policy
We may update this Policy from time to time. The "Effective Date" at the top changes when we do. Material changes will be highlighted via an in-Service banner or an email to recent customers. The previous three versions are available on written request.
17. Contact
For privacy questions or to exercise your rights:
Privacy contact: hello@carlinks.xyz
Phone: +880 1700-000000
Postal address: Carlinks, Dhaka, Bangladesh
Trade License: 1230049110