CarMDPrivacy Policy
CarMD, LLC
(Effective April 2025)
1. CarMD Values Your Privacy
This Privacy Policy is designed to provide transparency into CarMD’s privacy practices in a format that is easy to read and understand. Any and all information provided by you, your vehicle service provider, by your vehicle or by your device will be held with the utmost care and only used to further our ability to help you and others with current and future vehicle health issues, as described below.
2. Information We May Collect
We collect two main types of information related to you or your use of our products and services:
- Information from or about you or your devices
- Information from or about your vehicle
1. Information from or about you or your devices
We may collect information from you or about you (such as your name, address, phone number, email address, payment information, geolocation) or your devices in a number of ways including:
Through our APP and Website. We may collect information from or about you through our software applications, websites, social media pages, email messages, through your CarMD device(s) or through third party diagnostic parts/services providers that use our diagnostic services. Several sections of our mobile software application (“APP”) and the website(s) used to provide our diagnostic services (“Website”) request and collect personal information, such as your name, billing and shipping address, email address, telephone number, vehicle identification number, payment information and/or your geolocation.
Through your browser or device: We also collect aggregated information about you, such as your Internet Protocol (IP) address to help diagnose problems with our systems and ensure your safety and security. During your visit to our Website, we monitor your experience by collecting additional data, including the duration of your visit, web browser type and version, operating system name and version, computer type, referring sites, type of product used, version of the APP you are using and other web browsing behaviors and statistics. We need this information for internal purposes for system improvements and to better serve you.
Offline: We may also collect information from or about you offline, such as when you contact customer service or our sales department about any of our products or services.
Through your internal account: If you purchase our products through our Website, you may receive an internal account which is hosted on our Website. In processing your internal account, we may collect information from you including name, shipping and billing address, email address, phone number, vehicle identification number, and payment information, as well as information regarding products that you purchase.
Through other sources: We may receive information about you from other sources, such as various state department of motor vehicle records, public databases, third-party vehicle repair or parts suppliers and social media platforms.
When you visit our Website or use our APP, we may use cookies, analytics, and other similar third-party technologies to improve our Website and APP as detailed below:
o Cookies: A cookie is a text file that is placed on your hard disk by an internet web server. Cookies cannot be used to run programs or deliver viruses to your computer. Instead, cookies are uniquely assigned to you and can only be read by a web server in the domain that issued the cookie to you. Cookies allow us to collect information such as browser type, time spent on the APP and Website, pages visited, language preferences, and other web traffic data. The APP and the Website collect “cookie” information to personalize your browsing experience and to provide you with better service and provide us with information about your needs and interests. Most web browsers can accept or decline “cookies”. Popular browsers such as Microsoft® Internet Explorer, Apple® Safari, Mozilla Firefox®, Google® Chrome, and Netscape® automatically accept cookies, but you can modify their settings to decline cookies if you desire. Some third-party websites also use cookies to provide an interactive experience, so if you choose to decline cookies you may not be able to view all features on those websites.
o Your right to opt out of Cookies: If you do not want information collected through the use of cookies when using our APP or the Website, you can automatically decline cookies. However, if you do not accept these cookies, it may affect your use of the APP or Website.
Analytics: We use website and application analytics services provided by third parties (such as Google Analytics) that use cookies and other similar technologies to collect information about your use of the Website or APP and to report trends, without identifying individual visitors. The third parties that provide us with these services may also collect information about your use of third-party websites.
Third-Party Websites: Our website and the APP may provide links to third-party web sites. We do not endorse the content on any such third-party websites, nor are we responsible for the content of linked third-party websites. Your use of third-party websites is at your own risk and subject to the terms and conditions of use for such third-party websites.
We retain the personal information we collect from or about you and your vehicle for the period necessary to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required or permitted by law. We also may collect information in a form that does not permit direct association with any specific individual. We may collect, use, transfer, and disclose non-personally identifiable data for any purpose. If we do combine non-personally identifiable data with your personal information, the combined information will be treated as personal information for as long as it remains combined.
2. Collection of information from your vehicle
We may collect a variety of information from or about your vehicle.
Diagnostic Vehicle Information: As part of the diagnostic evaluation provided by the APP and the Website, we receive and collect identifying and diagnostic information from your vehicle that identifies and indicates the operating condition of your vehicle, including the make, model, year and vehicle identification number of your vehicle. This information is compared to other stored information collected from similar vehicles and other reference materials to help identify any defects in your vehicle, to derive the most likely fix to remedy the defects, to identify parts and labor needed to repair the identified defects in your vehicle and to permit you to engage independent service providers to implement such repairs. Your vehicle information is permanently merged with our stored vehicle fix database to further enhance our ability to identify and derive fixes for current and future defects in your vehicle and similar vehicles that we may later service. In some instances, your vehicle information is deidentified (anonymized) in the course of the diagnostic process or sometime thereafter.
Geolocation Data: To provide you with suggested nearby automotive repair and parts providers to assist you in servicing your vehicle, we collect geolocation data from or about you through your use of the App which tracks the location of your vehicle.
Opting out of data sharing: If you no longer want us to share your vehicle identification number with third parties, please go to com/donotsellmyinfo, or go to the Privacy section within the Settings section of our APP.
3. How We May Use Your Information
We may use information we collect about you or your vehicle to:
- Communicate with you by electronic means on your mobile device
- Provide products and services to you
- Improve and enhance our products and services
1. To communicate with you
We may use information we collect to communicate with you including:
To respond to your inquiries and requests, such as customer support questions regarding any of the products offered on our Website and to send you product information, emails or brochures.
To alert you of new products, special offers and other information related to your vehicle repairs and diagnostic information.
To electronically communicate with you through your mobile device to provide you with vehicle diagnostic information and various repair estimates to assist you in repairing your vehicle.
To provide you with suggested nearby automotive repair and parts providers to assist you in servicing your vehicle.
To process payments and service our accounts with you.
2. To provide our products and services
We may use information we collect to provide our products and services to you, including:
To fulfill your purchases from our Website, including to process your payments, deliver products to you, and provide customer service to you.
To alert you of new products, special offers and other information related to your vehicle repairs and diagnostic information.
To monitor your use of the APP and the Website.
To assist you by providing vehicle diagnostic information and repair costs concerning your vehicle and to provide you with information from or about suggested nearby automotive repair and parts providers to assist you in servicing your vehicle.
To ensure a safe and secure web browsing experience.
our accounts with you.
3. To improve and enhance our products and services
We may use information we collect for other purposes, including:
To fulfill your purchases from our Website, including to process your payments, deliver products to you, and provide customer service to you.
To monitor your use of the APP and the Website to make enhancements and upgrades to our services.
We may use your vehicle information, including vehicle identification number and vehicle diagnostic codes, to supplement our vehicle fix database in order to enhance our diagnostic capabilities.
We may use your geolocation to provide you with suggested nearby automotive repair and parts providers to assist you in servicing your vehicle.
To improve the content and service of our Website and to improve our products.
To ensure a safe and secure web browsing experience.
4. How We May Share Your Information
We may share information we collect about you or your vehicle to:
- Third parties
- Our service providers and business partners to perform services on our or your behalf
- Other parties as required by law
1. With third parties
We may share information with third parties, such as the following circumstances:
We may share your information with unaffiliated automotive repair and parts providers in your area to enable them to provide competitive estimates to provide repair parts or perform repair services on your vehicle.
We also may share vehicle diagnostic information with third party data scientists to develop algorithm to enhance CarMD’s products.
We may share vehicle diagnostic information and your geolocation with third parties to provide you with suggested nearby automotive repair and parts providers to assist you in servicing your vehicle.
We may enhance our vehicle diagnostic information provided to you by identifying third parties, such as Car Advise®, that you can contact directly to help you find the best price for car maintenance and repairs.
2. With our service providers and business partners
We may share information we collect from you with our service providers and business partners when necessary to provide services on our behalf or on your behalf, as to the following:
We may share your information, including name, address, email, geolocation, and vehicle identification number, with our affiliated automotive service providers so that these service providers can provide you with estimates for vehicle repairs and parts.
To better service you, we may share your information with other third-party service providers such as website hosting, data analysis, payment processing, customer service, auditing, marketing, and other similar services.
3. With other third parties
We do not share information that personally identifies you with unaffiliated third parties for their marketing purposes unless you opt in to that sharing. We may transfer and disclose information, including information that may or may not personally identify you, to third parties to comply with a legal obligation when we believe the law requires it. We may also share information in the following other circumstances:
Your vehicle information, including vehicle identification number and vehicle diagnostic information, may be combined with information from other vehicles and sold in bulk to a third party. However, other than vehicle information as set forth above, we do not sell your personal information to anyone for any purpose.
Your vehicle information may also be transferred to and used by affiliated and unaffiliated third parties in the United States or other countries as part of generalized statistical analysis for evaluating vehicle condition data and generating predictive diagnostic reports for predicting defects in various make/model vehicles, such as the CarMD® Vehicle Health Index.
Opting out of data sharing: If you no longer want us to share personal information about you with third parties, please go to the Website at Carmd.com/donotsellmyinfo, or go to the Privacy section within the Settings section of our APP.
Right to delete and access information: You have the right to access and/or delete any and all personal information that you have provided to us. If you want to exercise your right to delete or access personal information, click here.
5. Our Security Practices and User Generated Content
Our Security Practices:
All information collected by our server is protected through a 128-bit encryption firewall, which prevents outside visitors from collecting any information about you. Internally, the information is redirected and stored in a secure and isolated server that is only accessible by authorized personnel.
The Website may offer some services that allow you to record and store information in a password-protected area. You are responsible for taking all reasonable steps to ensure that no unauthorized person shall have access to your passwords or your CarMD account. We do not assume any responsibility or liability for any information you store.
User Generated Content:
Any information or material that you may upload onto the Public Area of the Website (User Generated Content) is not confidential or proprietary. You grant, and warrant that you have the right to grant to CarMD, its affiliates, distributors and suppliers, a non-exclusive, non-revocable, worldwide, transferable, royalty-free, perpetual right to use your User Generated Content in any manner of media now or later developed for any purpose, commercial, advertising or otherwise, including the right to store translate, display, perform, reproduce, modify, create derivative works, sub-license, distribute, assign and commercialize without any payment due to you.
If you use a Public Area of the Website or software application, such as the discussion board, chat room, blog, bulletin board or testimonial form, you are solely responsible for your own communications, the consequences of posting those communications and your reliance on any communications found in the Public Areas. You will not post any content which you are not properly authorized to post and will indemnify and hold CarMD, along with its affiliates, distributors and suppliers harmless for any consequences arising from your breach of this provision. We also reserve the right to delete, edit, or omit any offensive comments posted at any such public areas of the Website.
Children Under 18:
Our Website and CarMD APP are not intended for children under 18 years of age. We do not knowingly collect or use personal information about children under 18 without parental consent. We have no way to determine the age of those who use our CarMD Website and APP and request that no one under the age of 18 use the CarMD Website or APP or provide any personal information. We will remove any personal information of those under the age of 18 if we discover that we have inadvertently collected it.
Notice to International Users:
The Website and APP are both hosted in the United States and are subject to U.S. law and are intended for users located only in the United States. By accessing the using the CarMD Website and APP, you consent to the transfer to and processing of your personal information in the U.S.
6. Data Privacy Choice and Transparency
We allow you to have control over the data that we collect, use, and share from or about you, or your use of our services. Some features of our APP may require access to certain native applications on your mobile device, such as Bluetooth, the camera and/or photo album, and contacts. If you decide to use these features, we will ask you for your consent prior to accessing the applications and collecting personal information. You can revoke your consent at any time by changing the settings. With your consent, we may send promotional and non-promotional push notifications or alerts to your mobile device. You can deactivate these messages at any time by changing the notification settings on your device. You may at any time ask us to stop sending you emails or other communications. To ask us to remove your information from our mailing lists or to submit a request, please contact us as described in the section “How to Contact Us.”
- If you would like to exercise your CCPA rights to access or delete information from or about you, you may click here.
- You can opt out of the sale of your personal information on the link provided on our Website www.carmd.com/donotsellmyinfo, or go to the Privacy section within the Settings section of our APP.
Notice of Collection and Use of Personal Information:
“Personal information” and “personal data” is information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, whether directly or indirectly, with a particular person. We may have collected the following categories of personal information about you in the last 12 months:
- Various identifiers, including, name, address, phone number, email address, payment methods, online identifier, Internet Protocol address, account name, vehicle identification number, vehicle registration number, vehicle license plate number, geolocation information, insurance and warranty information, vehicle service information, diagnostic information or other similar identifiers.
- Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)), including, telephone number or financial information.
- Commercial information, including records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or behavioral tendencies.
- Internet or other similar network activity, including, browsing history, search history, real time tracking information on a consumer's interaction with a website, application, or advertisement, including protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, the files viewed on our Site or APP (e.g., HTML pages, graphics, etc.), operating system, date/time stamp, and/or clickstream data in order to analyze trends in the aggregate and administer our Website or APP.
- Inferences drawn from other personal information, including, profile reflecting a person's preferences, characteristics, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
- Protected classification characteristics, including, age, race, color, national origin, marital status, sex, veteran, or military status.
We may use and collect the above categories of personal information for the purposes described in this Privacy Policy, including those purposes set forth in the section entitled “How We May Use Your Information.” We may use the categories of personal information listed above for any of the business purposes identified in the California Privacy Rights Act (“CPRA”). We will not collect additional categories of personal information or use the personal information we collect other than for the purposes stated or for materially different or incompatible purposes without first providing you with notice.
Sources of Personal Information:
We may have obtained personal information about you from any of the sources identified in this Privacy Policy, including the following categories of sources in the last 12 months: (1) directly from you, such as when you ask a question or purchase a product or service; (2) from your devices or when you visit our Website or APP; (3) from our affiliates and subsidiaries; (4) from third party vendors; (5) from our joint marketing partners; (6) from online advertising services and advertising networks; (7) from our data analytics providers; (8) from government entities; (9) from our operating systems and platforms; (10) from social networks; or (11) from data brokers.
Retention of Personal Information:
We retain your personal information for as long as reasonably necessary to achieve our business purposes for which it was collected, processed, or otherwise disclosed. The retention period for each category of personal information is determined by the nature and sensitivity of the information; whether such information is necessary to provide the services and/or goods to you; whether such information is required under applicable law for us to maintain; or whether such information is necessary to protect your or our rights under applicable law. All information is retained in accordance with our internal record retention policy.
California Privacy Rights Act:
Subject to certain exceptions under the CPRA, California residents may have the following rights with respect to their personal information collected by us:
- The right to know and access. California residents have the right to request we disclose: (1) the personal information that we collect about you; (2) the categories of personal information that we collected about you in the preceding 12 months; (3) the categories of purposes for which such personal information was disclosed in the preceding 12 months; (4) the categories of sources for which such personal information was collected; and (5) the categories of third parties with whom such personal information may have been shared.
- The right to deletion. California residents have the right to request that we delete the personal information that we or our vendors collected about you. There may be circumstances where we will be unable to delete your personal information. If we are unable to comply with your request for deletion, we will let you know the reason why.
- The right to correct inaccurate information. California residents have the right to request that a business maintaining inaccurate personal information about the resident correct that inaccurate personal information.
- The right to opt-out of the sale or sharing of personal information. California residents have the right to direct that a business that sells or shares his or her personal information does not sell or share such information.
- Right to no retaliation. California residents have a right of non-retaliation if they choose to exercise a consumer right. If a California resident chooses to exercise any of these rights, we will not discriminate.
- Right to limit and use and disclosure of sensitive personal information. California residents have the right to request that we limit our use of their sensitive personal information to that use which is necessary to perform the services or provide the goods reasonably expected by an average consumer of such services or goods.
- The right to opt out of automated decision-making technology. If automated decision-making technology like profiling is used, California residents have a right to request meaningful information about the logic involved in automated decision-making technology and a description of the likely outcome of the process with respect to them.
Exercising California Privacy Rights:
To exercise any of these rights, contact us at www.carmd.com/. In connection with submitting a request, you must provide the following information: your name, email address, phone number, and state of residency and what type of request you are making.
Only a California resident may make a verifiable consumer request related to his or her personal information. A California resident may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must provide sufficient information that allows us to reasonably verify the requestor is the person about whom we collected personal information or an authorized representative and describe the request with sufficient detail that allows us to understand and respond. We cannot respond to a request or provide personal information if we cannot verify the identity or authority to make the request.
Sharing of California Resident Personal Information:
We may have disclosed your personal information identified above for a business purpose to the following categories of third parties: (a) our parent companies, affiliates, and/or joint venture partners; (b) our data analytics partners; (c) social media networks; (d) our service providers and security partners and (e) third parties. We may have shared your personal information set forth in the categories identified above to government agencies, law enforcement and our service providers.
Do Not Track Signals
Some web browsers have “Do Not Track” or similar features that allow you to tell each website you visit that you do not want your activities on that website tracked. Presently, our Website and App does not respond to “Do Not Track” signals and will continue to collect information about you even if your browser’s “Do Not Track” feature is activated.
Shine the Light Law
California's "Shine the Light" law (Civil Code Section § 1798.83) permits California residents who are users of our Website and APP to request information regarding our disclosure of personal information to third parties for direct marketing purposes. To make such a request, please send an email to support@carmd.com.
7. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make any material changes to the Privacy Policy, we will post notice of the changes and the updated Privacy Policy on the Website, along with its effective date, and any other notifications as required by law.
By using our CarMD Website, APP or other services, you accept the terms of our Privacy Policy. If you do not agree with any proposed changes to the Privacy Policy, you should discontinue your use of the Website and the APP. Your continued use of the CarMD Website or the APP after we have posted changes to the Privacy Policy will indicate that you agree that your information can be collected and processed in accordance with the updated Privacy Policy.
CarMD Children’s Privacy Notice
This privacy notice supplements our Privacy Policy and provides additional information about how we collect, use and disclose personal information from children under the age of 18 (a “Child” or “Children”).
CarMD is committed to Children’s privacy.
Protecting the privacy of Children is especially important to CarMD. For that reason, we created certain features designed to help protect personal information relating to Children (“Child Users”). When a Child creates an account, we collect their information in compliance with applicable laws, including by seeking the consent of a parent or legal guardian (“Parent”) for creation of that account.
CarMD does not collect, use, or disclose a Child’s personal information online unless the Parent consents or as permitted by law.
How Children can use and register for our Service
Users may view our content and do exercises without creating an account. Functionality is limited if users do not create an account.
CarMD does not knowingly permit Child Users to create an account without the consent of a Parent. If CarMD learns that personal information of a Child User has been collected on our Service without Parent consent, CarMD will take appropriate steps to delete this information. If you are a Parent and discover that your child under the age of 18 has registered a personal account with our Service without consent, please Contact Support@carmd.com and request that we delete that child’s personal information from our systems.
Child Users can sign up for a CarMD account in one of the following ways:
A Child User may sign up for a CarMD Account with parent consent.
When a Child User registers for our Service, we request a username, birthdate, password, and a Parent’s email address so that we can email the Child User’s Parent in order to seek consent for the Child to use the Service. CarMD does not ask the Child User for any more information than is necessary to provide the Service to the Child User or to seek Parent consent. The Child User is permitted to use the Service for 7 days through a Restricted Account while we notify the Parent and request consent. If we do not receive consent from the Parent within 7 days, the Child User’s Restricted Account is closed, and the Child’s personal information is deleted from our systems. CarMD may rely on a School to provide consent on behalf of a Parent, as described below.
Methods for providing Parental consent
Parents may provide consent for a Child User to use the Service through a Restricted Account by responding affirmatively to an email sent by CarMD to the Parent’s email address provided by the Child User during registration. If we do not receive consent from the Parent within 7 days, the Child User’s account will be closed, and the Child’s personal information will be deleted from our systems. Restricted Accounts may access and use certain features of the Service in a limited manner.
Parent accounts
To enable additional functionality for the Child User account and to enable full access and control over the Child User’s account activity, the Parent must create a “My Group Account” on the Service and connect to the Child User’s account by clicking on the account creation link in the Parental consent notice. My Group Accounts control the settings and functionality of the Child User’s account. The Parent can maintain the Child’s Restricted Account, and can enable additional account functionality and features, if desired. Parents can revoke a Child User’s permissions to use the Service at any time by deleting the account.
Restricted Accounts for Child Users
CarMD attempts to restrict a Child User’s access to certain features that could result in disclosure of the Child’s personal information. A Restricted Account limits sharing and displaying private information about the Child User in various ways.
For example, a Child User with a Restricted Account cannot:
- Display personal information other than a username. Restricted Accounts contain the Child’s username and do not include other personal information or profile information. Because the username may be displayed on the Service, we strongly recommend selecting a username that does not relate to or identify the real name of the Child. The Child’s username can be selected or revised by the Parent by creating a My Group Account.
- Add or edit personal information associated with a Restricted Account.
- Post to public community forums, or post questions or answers on lessons.
- Receive emails from CarMD (all emails are sent to the Parent email on file).
- Communicate with or disclose personal information to other drivers other than a username. Similarly, other drivers cannot communicate with a Child User with a Restricted Account except to assign content for the Child User.
What information we collect from a Child User, and how we use this information
We collect a username, birthdate, and Parent’s email address when a Child User registers for the Service, as well as any other personal information a Parent adds to a Child User’s account, as described above. We collect information about the Child User’s use of the Service. We also collect usage and device information, as described in Collection of information.
We use information collected about Child Users to provide the Services, personalize their experience, to communicate with them, to improve our services, to develop new offerings, and for purposes of protecting the safety of our users and complying with legal requirements. For more information about how we use information about Child Users, see our description of Use of information. We use the Parent’s email address to communicate messages about the account.
How we disclose information relating to a Child User
As described above, Restricted Accounts have limited information sharing capabilities. A username and progress information, along with any personal information the Parent added to the Child’s profile, is disclosed to other drivers, though a My Group Account may restrict the Child User from adding other drivers to the account. Parents may also enable additional information sharing features through a My Group Account, for example, by adding profile information and permitting the profile to be disclosed to other drivers and other users or enabling the Child User to post content (e.g., questions and answers) to the Service. Parents that enable content-posting features should be aware that a Child User could post personally identifiable information in free-form content on the Service and should monitor the Child User’s posts and delete personal information if needed. We may also disclose personal information of Child Users for business purposes, as described in Disclosure of information.
No Third-Party Tracking and No Targeted Advertising
CarMD does not display any targeted advertising on the Service. We do not disclose personal information of Child Users for direct marketing purposes or for targeted advertising purposes. In addition, we take steps to disable third party ad networks on webpages with child-directed content or when a Child User logs into a Restricted Account on the Service.
How to access, modify and delete your Children Accounts
As a Parent, you have the ability to access and control information about your Child User in your My Group Account. To refuse future collection or use of your child’s personal information, you can delete your Child User’s Account. Please note, you must delete your Child User’s account before you delete the My Group Account.
If you do not have a Parent Account associated with your Child User’s Restricted Account, you may contact us at our Support page to access or delete the Child User’s account. Please note you will need the Child User’s username, and we may take steps to authenticate your identity before we can provide access to the Restricted Account.
Contact Information
Do you have questions or comments regarding this website or our policies? Please contact:
CarMD, LLC
Customer Service Department
17352 Von Karman Avenue
Irvine, California 92614
Phone: 1-888-692-2763
Email: Support@CarMD.com