Privacy Policy

Last updated: June 2026

1. Information We Collect

We collect: account information (name, email, phone number), VINs you search, payment transaction records (via Paystack — we do not store card details), and usage data (pages visited, report history).

2. How We Use Your Information

We use your information to: provide vehicle history reports, process payments, send report notifications via email, improve our service, and comply with legal obligations.

3. Data Sharing

We share data with: Paystack (payment processing), ClearVin/NMVTIS (vehicle data retrieval), SendGrid (email delivery), and Anthropic (AI report summaries). We do not sell your personal data to third parties.

4. Data Security

We use industry-standard encryption (TLS/HTTPS) for all data transmission. Passwords are hashed and never stored in plain text. JWT authentication tokens are stored in secure httpOnly cookies.

5. Data Retention

Account data is retained for the duration of your account. Report data is retained for 12 months. Payment records are retained for 6 years as required by Nigerian tax law (FIRS guidelines).

6. Your Rights (NDPA 2023)

Under the Nigeria Data Protection Act 2023, you have the right to: access your personal data, correct inaccurate data, request deletion of your data, and withdraw consent. Contact us at support@carhaki.com to exercise these rights.

7. Cookies

We use httpOnly cookies for authentication (JWT tokens). We do not use tracking or advertising cookies. You can clear cookies at any time through your browser settings.

8. Contact

Data Controller: CarHaki Nigeria | Suite 211, Fabdal Plaza, Wuse Zone 4, Abuja, Nigeria | privacy@carhaki.com