Legal
Privacy Policy
v1 · Last updated 2026-06-25
This page explains how Market Check Cars, Inc., a Nevada corporation ("MarketCheck", "we"), handles personal information collected through the MarketCheck Developer Platform: the developer dashboard at developers.marketcheck.com, the MarketCheck APIs, the MarketCheck MCP endpoints, and related services (collectively, the "Service"). For the corporate-wide privacy practices, see the MarketCheck Privacy Policy; this page supplements it for the developer platform.
1. What we collect
- Account information you provide at sign-up and during profile completion: name, email, company, country, industry, role, and the URL of the application you intend to build.
- Billing information: card or ACH details (tokenized and stored by Stripe; we never see the full card number), invoice email recipients, billing address, tax ID where applicable.
- API usage telemetry: request timestamps, endpoint paths, response codes, response times, IP address, API key used. We use this for billing, capacity planning, abuse detection, and to power your usage dashboard.
- Device + session signals: a privacy-preserving hardware fingerprint, IP, and basic browser fingerprint at sign-up time. Used solely for fraud and abuse prevention (e.g., detecting fake-account farms).
- reCAPTCHA tokens: when you sign up or log in, we mint a Google reCAPTCHA v3 token and verify it server-side. This is subject to the Google Privacy Policy.
- Authentication metadata: when you enroll in 2FA, we store an enrolment timestamp and the hashed recovery codes. We do not store your TOTP secret.
- Communications: emails you send us, support tickets, and lifecycle / billing emails we send you. We track open rates only at aggregate level.
2. How we use it
- To provision your account, authenticate you, and provide the Service.
- To bill you accurately and to investigate billing disputes.
- To detect and prevent fraud, abuse, scraping, fake-account creation, and other Terms-of-Service violations.
- To send transactional, lifecycle, and security emails. Marketing emails are opt-in.
- To improve the Service — e.g., to spot common bug patterns, to refine onboarding, to surface usage trends.
- To comply with law and respond to lawful requests from authorities.
3. How we share it
- Service providers who help us run the platform under written confidentiality + processor agreements: Stripe (billing), Google Firebase / Firestore / Cloud Functions (infrastructure), Inngest (lifecycle email orchestration), SendGrid / SMTP relays (email delivery), Vercel AI Gateway (when you use the in-dashboard MCP Playground), Google reCAPTCHA (sign-up + login bot defense), BigQuery (usage analytics).
- Legal requirements: where required by valid legal process or to enforce our Terms.
- Corporate transactions: in a merger, acquisition, or asset sale we will give notice before personal information becomes subject to a different privacy policy.
- We do not sell personal information.
4. MCP Playground & AI processing
When you use the in-dashboard MCP Playground, your prompts and the MarketCheck API responses they elicit are routed through Vercel AI Gateway to the model you select (Anthropic, OpenAI, Google, or xAI). Each turn is logged to a secure Firestore (playground_logs) collection with input/output token counts, calculated micro-cent costs, the model selected, and truncated samples of the prompt and reply (capped to operational logs for billing verification and debugging). These logs are retained for 12 months before being deleted or anonymized. We process API requests through commercial API endpoints; your prompt data is not used by MarketCheck or our third-party inference providers to train AI models. We do not share your prompts with any party other than your selected inference provider and our internal operational/billing systems.
5. Cookies & storage
Essential cookies and storage: Essential items are required for the portal to function and cannot be switched off. These include a Firebase Auth session cookie, sessionStorage for the region switcher, sessionStorage for reCAPTCHA tokens during multi-step registration, and sessionStorage for active team context. We use Google reCAPTCHA to prevent automated abuse; reCAPTCHA may set a Google _GRECAPTCHA cookie when invoked and is governed by Google’s Privacy Policy and Terms of Service.
Analytics cookies (Optional): We use Google Analytics 4 (_ga and _ga_* cookies) to evaluate portal usage via aggregate page and funnel metrics. These are disabled by default in all regions. We set analytics cookies only after receiving your affirmative consent via our cookie banner or settings. Clicking “Reject” keeps them disabled.
Managing Choices and Global Privacy Control (GPC): You can update your preferences at any time via the “Privacy Choices” link in the footer or the controls below. If you are signed in, your preferences are saved to your account across devices alongside a record of when consent was granted or revoked. We do not run advertising cookies or cross-site tracking scripts. If your browser transmits a Global Privacy Control (GPC) signal, our platform treats it as an automatic request to disable all non-essential analytics cookies.
6. Data retention
- Account + billing data: retained while your account is active, and for the period required by tax / accounting law thereafter.
- API usage telemetry: retained for up to 24 months for billing reconciliation and capacity planning; aggregate-only after that.
- Fraud/abuse signals (blocks, abuse flags): retained for 30 days unless an active investigation requires longer.
- Email logs: retained for 12 months.
- AI concierge calls (the "Talk to us" video assistant): the details you enter before the call, the transcript of what is said and typed, and the summary we generate are retained for 12 months, then deleted automatically. We tell you this and ask you to accept it before the call starts. To have your record deleted sooner, email privacy@marketcheck.com.
7. Your choices & rights
- Update your account info in /profile; update billing in /billing.
- Cancel your subscription via /subscriptions at any time.
- Request deletion of your account by emailing privacy@marketcheck.com. Some data we are required to retain for tax / audit / legal reasons.
- If you’re a resident of the EEA, UK, California, or another jurisdiction with data-subject rights, you have the right to access, correct, or delete your personal information, and to object to or restrict processing. Contact privacy@marketcheck.com.
8. Security
We protect your data with TLS in transit, encryption at rest, role-based access control, multi-factor authentication for our staff, and a 2FA option for your developer account. We never store your full card number — Stripe does. We never store your TOTP secret. Suspected security incidents: security@marketcheck.com.
9. Children
The Service is intended for businesses and developers aged 18 or older. We do not knowingly collect personal information from anyone under 18.
10. Changes
We may update this policy from time to time. Material changes will be announced via email and posted to this page with an updated "Last updated" date.
11. Contact
Market Check Cars, Inc.
169 Madison Ave STE 57434, New York, NY 10016, USA.
General contact: business@marketcheck.com.
Privacy questions: privacy@marketcheck.com.
Security incidents: security@marketcheck.com.
Market Check Cars, Inc. · Terms of Service