Last updated: April 14, 2026
This Privacy Policy explains how Stephanos Economou, operating CarsAI ("CarsAI", "we", "us", or "our"), collects, uses, stores, and shares personal data when you use our platform and services. CarsAI is subject to the General Data Protection Regulation (GDPR) as Cyprus is a member state of the European Union.
CarsAI is operated by Stephanos Economou. For the purposes of GDPR, Stephanos Economou is the data controller for personal data processed through the Service.
Contact: hello@carsaicy.com
We collect the following categories of personal data:
| Category | Examples | How collected |
|---|---|---|
| Account data | Name, email address | Provided by you at sign-up via Clerk |
| Authentication data | Session tokens, user ID | Generated automatically by Clerk |
| Usage data | Pages visited, features used, search filters applied, time on platform | Collected automatically as you use the Service |
| Communication data | Email address, notification preferences, watchlist items | Provided by you when you set up alerts or contact us |
| Payment data | Billing name, payment method details, transaction records | Collected and processed by our payment provider — we do not store full card details |
| Technical data | IP address, browser type, device type, operating system | Collected automatically via server logs and session handling |
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account | Contract performance (Art. 6(1)(b)) |
| Providing the Service and its features | Contract performance (Art. 6(1)(b)) |
| Processing subscription payments | Contract performance (Art. 6(1)(b)) |
| Sending watchlist price alerts and notifications you opted into | Consent (Art. 6(1)(a)) |
| Responding to support enquiries | Contract performance / Legitimate interest (Art. 6(1)(b)/(f)) |
| Analysing usage to improve the Service | Legitimate interest (Art. 6(1)(f)) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
We use third-party service providers to help operate the Service. These providers process personal data on our behalf and are contractually required to handle it securely and only for the purposes we specify.
You may request the names of specific processors we use by contacting us at hello@carsaicy.com.
We do not sell your personal data to any third party.
We use cookies and similar technologies to operate the Service. These include:
We do not use advertising cookies, cross-site tracking, or third-party analytics services that track you across the web (e.g. Google Analytics).
As a data subject under GDPR, you have the following rights. To exercise any of them, contact us at hello@carsaicy.com.
We will respond to requests within 30 days. If you believe your rights have been violated, you have the right to lodge a complaint with the Commissioner for Personal Data Protection in Cyprus: www.dataprotection.gov.cy ↗
Some of our third-party processors operate outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as the EU Standard Contractual Clauses (SCCs) or reliance on an adequacy decision, as required by GDPR Chapter V.
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include encrypted connections (HTTPS), access controls, and use of reputable infrastructure providers.
No method of transmission or storage is completely secure. If you believe your account has been compromised, please contact us immediately.
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top when we do. For material changes, we may also notify you by email or via a notice within the Service.
Continued use of the Service after updates constitutes acceptance of the revised policy.
For any questions, requests, or concerns about this Privacy Policy or how we handle your data, contact us at: