Skip to main content

Privacy Policy

How we collect, use, and protect your personal data.

Last updated: 25 March 2026

1. Who We Are

Carslink.ai is a trading name of AutoProv Ltd ("we", "us", "our"). We operate Carslink.ai, an AI-powered vehicle search engine for the UK market. AutoProv Ltd is the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Data We Collect

2.1 Information You Provide

  • Account data — email address and display name when you create an account.
  • Search queries — the natural-language searches you submit.
  • Saved listings — cars you bookmark for later.
  • Dealer contact details — business name, email, phone when dealers register.

2.2 Automatically Collected Data

  • IP address, browser type, device information.
  • Pages visited, timestamps, referral URLs.
  • Cookies and similar technologies (see Section 7).

2.3 Data from Third-Party AI Assistants & API Integrations

When users interact with Carslink.ai through third-party AI assistants (such as our ChatGPT app) or when partners consume our public API, we may receive:

  • Query text — the search question or instruction sent to Carslink.ai.
  • Conversation context — limited prior turns passed by the assistant to disambiguate the request.
  • Technical metadata — IP address and user-agent of the calling service (the assistant or partner application), not the end user's device.
  • No direct account linkage — we do not receive your AI assistant identity (e.g. OpenAI account) unless you explicitly authenticate with Carslink.ai.

3. How We Use Your Data

  • To provide and improve our AI car search service.
  • To personalise search results and recommendations.
  • To communicate service updates and respond to enquiries.
  • To onboard dealer partners and manage stock feeds.
  • To send dealers periodic performance reports by email (listing views, click-through rates). Dealer email addresses provided at registration are used solely for this purpose and are not shared with third parties.
  • To respond to queries received from third-party AI assistants (e.g. our ChatGPT app) and API consumers.
  • To monitor API usage for abuse prevention, rate limiting, and billing.
  • To detect fraud and ensure platform security.
  • To comply with legal obligations.

4. Legal Basis for Processing

Consent

Where you opt in to marketing communications.

Contractual necessity

To provide the service you requested.

Legitimate interests

To improve the platform, prevent abuse, and analyse usage.

Legal obligation

To comply with applicable laws.

5. Data Sharing

We do not sell your personal data. We may share data with the following categories of recipient:

  • Infrastructure providers — cloud hosting and database services under strict data processing agreements.
  • AI assistant platforms — when you interact with Carslink.ai through a third-party AI assistant such as our ChatGPT app, your queries are processed by that platform (e.g. OpenAI) under their own privacy policy. We receive only the query text forwarded to us, not your assistant account identity.
  • API partners — third-party developers and dealers consuming the Carslink.ai public API receive only listing data and aggregated metadata. No end-user personal data is shared via the API.
  • AI model providers — OpenAI and Google (Gemini) are used to generate search results, listing descriptions, and email replies. Queries may be processed by these providers but, under their enterprise/API terms, are not used to train their models.
  • Law enforcement — where required by law or court order.

6. Finance Referrals

If you click the Finance This Car button on a vehicle listing page you will be directed to Hawkstone Motor Finance, a trading style of Hawkstone Farley Group Ltd (FRN: 987531). Your contact details and the details of the vehicle you were viewing may be shared with Hawkstone Motor Finance for the purpose of assessing your finance enquiry. Hawkstone Motor Finance's privacy policy is available at https://www.hawkstonemotorfinance.co.uk. Autoprov Ltd trading as Carslink.ai acts as an unregulated introducer only and does not participate in the credit broking process.

7. Data Retention

Account data: Retained while your account is active.

Search logs: Anonymised after 90 days.

Dealer records: Retained for 6 years after partnership ends (regulatory compliance).

You may request deletion at any time.

8. Cookies

A cookie is a small text file stored on your device when you visit a website. We use cookies as follows:

8.1 Essential Cookies

Strictly necessary for the site to function — no consent required:

CookiePurposeExpiry
sb-*-auth-tokenAuthentication session7 days
carslink_consentRecords your cookie preference1 year
carslink_sidFunctional session identifier — anonymous, contains no personal data. Maintains session state for platform features. Fires regardless of analytics consent and does not require opt-in.Session

8.2 Analytics Cookies (Require Consent)

We use Google Analytics (gtag.js) to understand how visitors use the site. These cookies are only loaded if you click "Accept" on the cookie banner. If you reject, no analytics cookies are set and no data is sent to Google.

CookiePurposeExpiry
_gaDistinguishes unique visitors2 years
_ga_*Maintains session state2 years

IP addresses are anonymised. We do not enable advertising features.

8.3 No Advertising Cookies

We do not use advertising, remarketing, or third-party tracking cookies.

8.4 Managing Your Preferences

Clear your browser cookies and revisit the site to change your preference — the consent banner will reappear. You can also disable cookies in your browser settings, though this may affect site functionality.

9. Your Rights

Under the UK GDPR you have the right to:

Access the personal data we hold about you
Rectify inaccurate or incomplete data
Erase your data ("right to be forgotten")
Restrict or object to processing
Data portability — receive data in machine-readable format
Withdraw consent at any time

You can also lodge a complaint with the ICO at ico.org.uk.

10. Third-Party AI Assistants & API Access

10.1 Carslink.ai ChatGPT App

Carslink.ai is available as an app within ChatGPT. When you use it, your messages to ChatGPT are first processed by OpenAI, who acts as an independent data controller for the conversation. OpenAI then forwards the relevant query to Carslink.ai so we can return matching listings and answers. We receive only the query content (and limited prior turns where needed for context) — we do not receive your OpenAI account, email, or payment details. For information about how OpenAI handles your data, please see the OpenAI Privacy Policy.

10.2 Public & Partner API

Authorised dealers, DMS providers, and third-party developers may integrate with Carslink.ai using authenticated API keys. API requests are logged for security, abuse prevention, rate-limiting, and billing. Only listing data and aggregated metadata are exposed via the API; no end-user personal data is shared with API consumers.

10.3 AI Provider Training

The AI providers we use (OpenAI and Google Gemini) operate under enterprise / API terms that prohibit the use of Carslink.ai user data for training their underlying models.

11. International Transfers

Your data may be processed in countries outside the UK. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the ICO.

12. Security

We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest, role-based access controls, and regular security audits.

13. Children's Privacy

Our service is not directed at individuals under 16 years of age. We do not knowingly collect data from children.

14. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or prominent notice on the platform.

15. Contact Us

For privacy enquiries or to exercise your rights, contact us at privacy@Carslink.ai