Privacy Policy
Your privacy matters. This Policy explains what data Carlinks Verify (https://carlinks.xyz) collects, why we collect it, and how we protect it.
1. Information we collect
Search data — when you look up a chassis number, we log the chassis text, your IP address, country, browser user-agent, and timestamp. This is required for fraud prevention and rate-limiting.
Customer information — when you purchase a full auction sheet, we collect your name, email, and mobile number to send your receipt and the verified report.
Payment data — card and bank details are submitted directly to SSLCommerz. We never see or store your full card number, CVV, or PIN.
Technical data — Cloudflare Web Analytics collects anonymous pageview counts (no personal identifiers, no cookies set by us).
2. How we use it
- To deliver the service you paid for
- To prevent fraud, abuse, and unauthorized access
- To comply with legal requirements (e.g. payment audit)
- To improve service performance (aggregate metrics only)
3. Who we share data with
- SSLCommerz — for payment processing only. Your card data goes directly to SSLCommerz, not through Carlinks.
- Upstream auction data providers — your chassis number is sent to verify against the auction archive. No personal data is sent.
- Cloudflare — our edge / hosting provider. Cloudflare may process request metadata for security and performance.
- Bangladeshi regulators — only if legally compelled (e.g. court order or VAT audit).
We do not sell your data to advertisers or data brokers. We do not share customer lists with third parties for marketing.
4. Cookies
We do not set marketing or tracking cookies. Cloudflare may set first-party security cookies (e.g. for Turnstile bot challenge). Your browser may set cookies set by challenges.cloudflare.com for verification — these are managed by Cloudflare.
5. Data retention
- Search logs: 90 days (for fraud / abuse investigation)
- Customer info + orders: 7 years (Bangladesh VAT/audit requirement)
- Payment records: per SSLCommerz retention policy
6. Your rights
You can request:
- A copy of the data we hold about you
- Correction of inaccurate data
- Deletion of your personal data (subject to legal retention)
- Withdrawal of consent
Email hello@carlinks.xyz with your request. We respond within 30 days.
7. Security
We use HTTPS everywhere (HSTS preload), Cloudflare WAF, edge rate-limiting, encrypted references for upstream data, and strict CSP. Customer data is stored in Cloudflare D1 (SQLite at the edge). Payment data is handled exclusively by SSLCommerz.
8. Children
The service is not directed at children under 18. We do not knowingly collect data from minors.
9. Third-party advertising
Carlinks Verify does not display third-party advertisements and does not share customer information with advertisers.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced on this page.
11. Contact
Data Protection Officer:
Email: hello@carlinks.xyz
Address: Dhaka, Bangladesh
Trade License: 1230049110