Buyer data stays buyer-owned.
This implementation is designed for data minimization, ownership-scoped records, auditable consent, and deletion. Final production language requires legal review before launch.
What the product stores
Search briefs, structured preferences, saved vehicles, comparison records, inquiry drafts and approvals, quote fields, alerts, and audit events needed to deliver the workflow. Development inventory is synthetic.
How records are isolated
Every user-owned database query is scoped by the server-resolved actor identifier. Browser UI state is never treated as authorization. Production identity and administrator access require configured providers and allowlists.
Uploads
Production uploads must use encrypted object storage with owner-scoped metadata, type and size validation, malware scanning, retention controls, and deletion. Text is treated as untrusted and embedded instructions are ignored.
Retention and deletion
Search and workflow records use soft deletion for safety and auditing. A production retention schedule, export endpoint, account deletion workflow, and backup-expiration policy must be approved before launch.
Contact
Publish an operating-company address and privacy contact before production cutover.