CARMAUTO PRIVACY POLICY

(A Delaware Corporation)

Effective Date: April 8, 2025

Last Updated: December 15, 2025

Carmauto Inc. (“Carmauto,” “CarmAuto,” “we,” “us,” or “our”) is committed to protecting your privacy and handling personal information responsibly. This Privacy Policy explains how we collect, use, disclose, store, secure, and retain information when Users (“you,” “your,” or “User”) access or use the Carmauto website, the Carmauto progressive web application (“PWA”) downloaded directly from our website, or any communication or transaction facilitated through the Carmauto Platform (collectively, the “Platform”).

The Platform is not distributed through the Apple App Store or Google Play Store; all data collection occurs solely through Carmauto-controlled systems unless otherwise disclosed. By using the Platform, you acknowledge that you have read, understood, and agreed to this Privacy Policy. If you do not agree, you must discontinue use immediately.

1. Information We Collect

Carmauto collects information you provide directly, information collected automatically during your use of the Platform, and information received from third parties such as payment processors, mechanics, and fraud-prevention providers.

Information You Provide Directly.

We collect information you voluntarily submit when creating an account, booking or providing services, communicating with Mechanics or Carmauto, or participating in Platform features. This includes your name, email address, phone number, username, business name (for Mechanics and Vendors), and verification documents required to claim a business listing. When booking services, we collect vehicle information such as make, model, year, VIN, service descriptions, photos or videos of vehicle condition, preferred location, scheduling details, and notes. We also collect payment-related information such as billing address and transaction metadata; however, Carmauto does not store full card or bank account numbers. Sensitive payment information is handled by our PCI-compliant Third-Party Payment Provider. We also collect communications you send to Mechanics or to us, including reviews, ratings, comments, support inquiries, dispute submissions, and any multimedia you choose to upload.

Information Automatically Collected.

When you access the Platform, we may automatically collect device and technical data such as IP address, browser type, device identifiers, operating system, screen resolution, error logs, and other diagnostic information. We collect usage data including pages viewed, categories browsed, search terms, clickstream activity, session duration, referral URLs, and timestamps. We may collect approximate location using your IP address and may collect precise location only if you explicitly enable it for service-delivery or Mechanic- dispatch purposes. Location sharing is optional but may be required for certain mobile services.

Information from Third Parties.

We may receive information from Mechanics and Vendors, including service updates, job completion notes, and photos of completed work. Our payment processors provide information about payment status, chargebacks, disputes, and fraud-risk assessments. We may use public records or open-source business data solely to populate “unclaimed business listings.” Fraud-prevention and analytics providers may supply bot-detection data, authentication validations, and risk-assessment signals. Carmauto does not purchase consumer profiles from data brokers.

2. How We Use Information

Carmauto uses information only for legitimate business purposes, including operating and maintaining the Platform, facilitating transactions, ensuring security, and improving the User experience.

We use information to create and manage accounts, authenticate Users, display relevant services, process bookings and payments, issue receipts and notifications, and enable communication between Users. We use information to verify identities, detect and prevent fraud, protect against unauthorized activity, and maintain system integrity. We analyze usage patterns to optimize search results, personalize Platform experiences, improve reliability and performance, and store User preferences. We may also generate aggregated, anonymized, or statistical datasets for internal use or for sharing with advertisers, sponsors, or partners; this data does not identify individual Users. Carmauto may communicate with you regarding transactions, account activity, service updates, policy changes, and customer support.

Automated Decision-Making and Machine-Assisted Processing. Carmauto may use automated tools or machine-assisted analysis to detect fraud, assess Platform risks, recommend services or Mechanics, and prevent misuse. These tools do not make decisions that produce legal or similarly significant effects without human review.

3. Consent and Legal Basis for Processing

We process personal information based on your explicit consent (for example, when checking a box, enabling location, or uploading content), implied consent from continued Platform use, contractual necessity when facilitating bookings or payments, and legitimate interests in security, fraud prevention, analytics, and communications. You may withdraw consent by deleting your account, adjusting device settings, or contacting Carmauto. Withdrawal does not affect the legality of prior processing.

4. How We Share Information

Carmauto does not sell personal information. We share information only as described in this Policy.

Mechanics receive only the information necessary to perform services, including your name, service location, vehicle details, service photos, and communication messages. Mechanics operate their own independent businesses and maintain their own privacy practices. We may share data with third-party service providers such as payment processors, hosting companies, analytics partners, customer-support platforms, and security vendors, who may access information only as needed to provide their services.

We may share aggregated or de-identified data for advertising sponsorships, investor materials, market insights, and industry benchmarking. This data cannot be used to identify you. We may disclose information in connection with mergers, acquisitions, financing, dissolution, or sale of assets. We also disclose information to comply with subpoenas, legal processes, law-enforcement requests, regulatory obligations, or when necessary to protect Users or Carmauto from harm.

Public Content Disclaimer. Any reviews, ratings, photos, comments, or other content you submit for public display may be visible to other Users and may be indexed by search engines. Carmauto is not responsible for how third parties may view, copy, distribute, or use publicly posted content.

Review of Communications for Safety, Compliance, and Dispute Resolution. Carmauto may access and review User messages, photos, videos, and other content when necessary to investigate fraud, enforce our Terms, resolve disputes under the Dispute Resolution & Refund Policy, or comply with legal obligations. We do not otherwise monitor private communications.

No Sale or Sharing of Personal Information (CPRA / U.S. State Laws). Carmauto does not “sell” or “share” personal information as defined under the California Consumer Privacy Act (CCPA/CPRA) or similar U.S. state privacy laws. If these practices ever change, Carmauto will provide required notice and opt-out mechanisms before doing so.

5. Cookies and Tracking Technology

We use session and persistent cookies, analytics tools, performance monitoring, device fingerprinting for fraud prevention, and local storage for PWA functionality. Additional details are available in our Cookie Policy.

6. Do Not Track Disclosure

The Platform does not respond to “Do Not Track” browser signals due to a lack of industry standards governing DNT behavior. Users who wish to limit tracking may instead adjust their browser settings, manage cookie preferences, use built-in privacy controls, or opt out of certain analytics or advertising tools through the mechanisms provided in this Privacy Policy. These methods offer more reliable ways to control data collection than DNT signals.

7. Data Security

We use commercially reasonable safeguards, including encryption, hashed and salted passwords, firewalls, limited administrative access, intrusion detection, and periodic audits, to protect personal information. However, no system can guarantee perfect security, and Users acknowledge inherent risks.

Breach Notification. If Carmauto becomes aware of a data breach affecting personal information, we will provide notice as required by applicable law.

8. Data Retention

We retain personal information only as long as necessary to provide services, fulfill legal obligations, resolve disputes, enforce agreements, and maintain tax or regulatory records. Deleted accounts undergo secure removal except where retention is legally required.

Retention of Communications and Evidence. Carmauto may retain communications, photos, videos, dispute evidence, and related content for safety investigations, fraud prevention, legal compliance, and dispute resolution, even after account deletion.

9. User Rights

Users in certain U.S. states, including California, Colorado, Connecticut, Virginia, and Utah, may have rights to access, correct, delete, or obtain a copy of their personal information; restrict or object to certain processing; or opt out of targeted advertising or profiling. Requests may be submitted to the contact information below. If we decline a request, Users may appeal as required by state law.

10. Third-Party Links

The Platform may contain links to external websites. Carmauto does not control and is not responsible for third-party privacy practices. Users should review the privacy policies and terms of any third-party site before providing personal information or interacting with those services. Your use of third-party websites is entirely at your own risk, and this Privacy Policy does not apply to information collected by third parties.

11. Children’s Privacy

Carmauto does not knowingly collect information from children under 18. Accounts identified as belonging to minors will be deleted.

12. International Use

The Platform is intended for Users located in the United States. Individuals outside the U.S. use the Platform at their own risk and must comply with local laws.

13. Changes to This Privacy Policy

Carmauto may update this Privacy Policy at any time. Updates are effective upon posting. Continued use of the Platform after revisions constitutes acceptance of the updated Policy.

14. Contact Information

Carmauto Inc.

16192 Coastal Highway

Lewes, Delaware 19958

Email: michelle@carmauto.net

ACKNOWLEDGMENT

By accessing or using the Platform, you acknowledge that you have read, understood, and consent to the collection, use, disclosure, and retention of your information as described in this Privacy Policy.