Legal
Privacy Policy
Last updated: 2026-07-12
1. Who we are
This policy covers ARBEX, an inventory acquisition intelligence platform that helps dealers decide which vehicles to buy, where, when, and at what price. Questions about privacy? Reach us any time through contact.
2. What ARBEX does
ARBEX ingests public vehicle listings, scores each candidate for acquisition profit and risk, and surfaces the opportunities worth pursuing. It is a paid, account-based tool for vehicle-dealing businesses — so most of what we hold is market data about vehicles, plus the account data we need to run the service for you.
3. Information we collect
What we do NOT collect
- We don't collect payment card numbers directly — those go straight to our payment processor.
- We don't buy or ingest your customer lists, and we don't track your precise location.
- We don't build advertising profiles or sell personal data.
What we do collect
- Account data — your name, work email, and the dealership profile information you choose to share.
- Usage data — application events (pages visited, filters created, opportunities watched) so we can improve the product and catch bugs.
- Payment data — processed by our payment processor (Stripe); we store only the billing status and the last four digits / card brand it returns, never the full card.
- Public listing data — vehicle listings from third-party sources (dealer websites, marketplaces, and auction feeds), plus vehicle reference and recall data (including NHTSA). That's market information about vehicles, not about you.
4. How we use information
- Authenticate your account and secure your sessions.
- Send the alerts and digests you explicitly opt into under Settings → Notifications.
- Improve the scoring engine and surface bugs before you hit them.
- Comply with legal obligations (tax records, subpoenas, fraud prevention).
AI & training: ARBEX uses AI models (Anthropic) to help score vehicle listings. Scoring runs on market data about vehicles, and your account data is not used to train AI models — our AI provider does not train on data sent through its API.
5. Cookies
We use a small number of cookies: an essential session cookie to keep you logged in, and analytics cookies (PostHog) to measure aggregate product usage. We don't use advertising cookies or cross-site tracking. You can block non-essential cookies in your browser; essential session cookies are required for the app to function.
6. Who we share it with
Only with the subprocessors who make ARBEX work, each under its own data-processing agreement:
- Vercel — application hosting.
- Supabase — database and authentication.
- Stripe — payment processing.
- Resend — transactional and alert email.
- PostHog — product analytics.
- Sentry — error monitoring.
- Anthropic — AI-assisted listing scoring.
We do not sell your data or share it with advertising networks.
7. Data retention
- Account data — kept while your account is active, plus the minimum we're required to retain for tax and audit. Delete your account and we clear identifiable data within 30 days.
- Server access logs — retained around 30 days for security and debugging.
- Analytics aggregates — retained in aggregate form and may persist longer once anonymised.
8. Your rights
You can export your data, correct it, or delete your account at any time from Settings. If you're in the EU/UK (GDPR) or California (CCPA) you have additional rights — access, rectification, erasure, portability, and objection — and ARBEX does not sell personal information. Email us and we'll honour valid requests within the timeframes the law requires (generally 30 days).
9. International transfers
ARBEX is operated from the United States and your data is processed there. Where data is transferred from the EU/UK, we rely on appropriate safeguards such as Standard Contractual Clauses, and data may transit other regions as part of normal internet routing.
10. Children
ARBEX is a business tool not directed to children, and we don't knowingly collect data from anyone under 18. If you believe a minor has submitted data, contact us and we'll delete it.
11. Security
Data is encrypted in transit (TLS/HTTPS) and at rest by our infrastructure providers. We never store full payment card numbers. No system is perfectly secure, but if a breach affects your data we will notify you and the relevant authorities as required by law.
12. Changes
We may update this policy; material changes are posted here with a new "Last updated" date, and for significant changes we'll add an in-app notice or email. Please review it periodically.
13. Contact
Questions about this policy, or want to exercise a data right? Get in touch and a human will respond, typically within 30 days.