IMMO-OFFv1

Privacy Policy

Last updated: 2026-05-20

What we collect

  • Account: email address, bcrypt-hashed password, role.
  • Payments: Stripe customer ID and payment metadata. We never see your card number — Stripe handles it.
  • Uploaded ECU binaries (in the course of processing): stored encrypted at rest, deleted after 30 days.
  • Job audit metadata: job ID, file sha256, detected variant, processing timestamp, success/failure status. Retained indefinitely so refunds can be honored.

What we DO NOT do

  • Train AI models on your uploaded binaries.
  • Share or sell your binaries to other customers, partners, or third parties.
  • Use your binary to learn ECU patterns we'll then sell to others. Algorithm research is conducted on dumps we own (donor ECUs we purchased) or dumps you explicitly consent to as part of our research program.
  • Send marketing emails without your opt-in.

Who we share with

  • Stripe — payment processing. Stripe is PCI-DSS Level 1 compliant.
  • Vercel — hosting our frontend.
  • Render — hosting our worker API.
  • Resend — transactional email (job notifications, password resets).
  • Law enforcement when required by valid legal process. We will notify you unless the process forbids it.

Cookies

We use one HTTP-only cookie named immo_sessionto keep you signed in. No third-party analytics, no marketing trackers, no ad pixels. We may add Vercel Analytics (anonymous, server-side) and Sentry (error tracking) — these don't read your binaries or your form input.

Your rights

  • Access: request a copy of all data we hold about you.
  • Deletion: request deletion of your account and binaries. Audit metadata may be retained where required for compliance.
  • Correction: update your account email at any time from /dashboard.
  • Portability: export your job history as JSON or CSV on request.
  • Withdrawal of consent: if you previously consented to your binaries being used for research, you can revoke at any time. We will stop using your specific binaries; derived factual offset data already integrated into the patch registry cannot be unilaterally retracted, but no future research will use your files.

Email hello@immolocksmith.com for any of the above. We respond within 30 days.

Where your data lives

Our infrastructure is in the United States (Vercel + Render). The Service is offered to US customers only; we don't market or actively sell to other regions.

Children

The Service is not directed at people under 18. Don't create an account if you're under 18.

Changes

Material changes are notified by email at least 14 days before effect.

Contact

v0 boilerplate. Review with counsel before real-customer launch, particularly for CCPA (California) and any state-specific data-broker requirements.