How to lease?Karlend
Log in/Sign up

Karlend

Private cars near you. Buy now or monthly when offered — only inventory within 50 miles of you unless you change location.

karlotmanagement@gmail.com

Explore

HomeSellingAccountSettings

More

How deals workHow to leaseSeller tools

Legal

Terms of ServicePrivacy PolicyContact
© 2026 KarlendLocal inventory
HomeInbox

Legal · Version 2026-07-28.1

Privacy Policy

Effective date: July 28, 2026. This Privacy Policy explains how Karlend (“Karlend,” “we,” “us”) collects, uses, discloses, and protects information when you use our websites, apps, and related services (the “Service”).

By using the Service or creating an account, you acknowledge this Policy. For our contractual terms, see the Terms of Service.

1. Information we collect

You provide: name, email, password (processed by our auth provider), phone, address, seller type, business name, profile photo or logo, listing details, messages, application materials (including income and residency proofs), contract signatures, and support requests. Payment card and bank details for charges/payouts are typically entered on Stripe-hosted or Stripe-controlled fields—not stored as full card numbers by Karlend.

Automatically: IP address, device and browser type, approximate location (if you allow GPS or select a city), cookies and similar technologies, pages viewed, and diagnostic logs.

From third parties: authentication and database providers (e.g., Supabase), payment processors (e.g., Stripe), mapping/geocoding services, VIN or market data providers, and AI providers used to generate estimates or listing text.

2. How we use information

  • Create and secure accounts; authenticate users.
  • Operate the marketplace: listings, search, location filters, messaging, applications, contracts, and dashboards.
  • Process payments and prevent fraud, abuse, and security incidents.
  • Provide valuations, VIN decode, and AI-assisted descriptions.
  • Communicate about transactions, security, and (with required consent) product updates.
  • Comply with law, enforce Terms, and protect rights and safety.
  • Improve and develop the Service, including analytics in aggregated form.

3. How we share information

We may share information with:

  • Other Users as needed for a transaction (e.g., sellers see buyer application materials you submit; buyers see public listing and seller display information).
  • Service providers who process data for us under contractual obligations (hosting, auth, payments, email, AI, analytics).
  • Professional advisors and authorities when required by law, legal process, or to protect rights.
  • Business transfers in connection with a merger, acquisition, financing, or sale of assets.

We do not sell your personal information for money. We do not share SMS opt-in data with third parties for their marketing.

4. Sensitive documents

Income proofs, government IDs, and similar uploads are used to facilitate applications between buyers and sellers. Treat them as confidential. Sellers must use them only for evaluating applications. We implement access controls and storage practices appropriate to the sensitivity of the data, but no method of transmission or storage is completely secure—see Section 7.

5. Cookies and location

We use cookies and similar technologies. When you first visit, you can choose Essential only or Accept all. Your choice is stored for about one year (local storage and a consent cookie).

Essential cookies (always on when you use the Service):

  • Authentication / session — Supabase Auth cookies so you stay signed in securely.
  • Location preference — your selected city and coordinates for the ~50-mile inventory filter.
  • Cookie consent — remembers your banner choice so we don’t ask every visit.
  • Security / CSRF-related — platform and host protections as applicable.

Optional cookies (only if you choose Accept all): future product analytics or performance measurement. We do not currently load third-party advertising cookies by default.

You can clear cookies in your browser settings; some features (sign-in, local inventory) may stop working until you use them again. Location is also changeable in the product UI.

6. Retention

We retain information as long as your account is active and as needed for transactions, legal obligations, disputes, and legitimate business purposes. You may request deletion as described below; some records may be retained where law requires (e.g., payment or fraud records).

7. Security

We use administrative, technical, and organizational measures designed to protect personal information. No online service can guarantee absolute security. You are responsible for safeguarding your password and for activity under your account.

Account security. Authentication is handled with industry-standard providers (currently Supabase Auth). Passwords are hashed by the auth provider—Karlend does not store plaintext passwords. Session tokens are set as secure cookies where supported. There is no intentional “backdoor,” master password, or hidden admin login that bypasses your credentials.

Payments and Stripe. Card numbers, bank account details used for payouts, and related payment credentials are collected and processed by Stripe (or another designated processor), not by Karlend’s application databases as full primary account numbers (PANs). Stripe uses encryption and PCI DSS–aligned controls for payment data. Karlend stores only limited payment metadata needed to operate the marketplace (for example, payment status, amounts, Stripe PaymentIntent or Connect account identifiers, and platform fees)—not full card numbers or CVV codes. Stripe’s secret API keys and webhook signing secrets remain on our servers and are never shipped to browsers or mobile clients.

Seller payouts (Stripe Connect Express). Sellers complete identity and bank verification on Stripe-hosted flows. Connect account status is verified with Stripe before live payouts. Demo or simulated Connect accounts (used only when Stripe is not configured, e.g. local development) cannot be used to mark real charges as paid when live Stripe keys are enabled.

Access controls. Application programming interfaces (APIs) that change money, contracts, applications, or private messages require a signed-in session and ownership checks (for example, only the buyer may start their installment payment; only parties to a contract may download it). Webhooks that mark payments paid require a valid Stripe cryptographic signature.

Sensitive documents. Residency and income proofs and similar uploads are restricted to transaction participants and platform operators as needed for fraud prevention, support, and legal compliance. You should avoid uploading unnecessary sensitive data.

Incident response. If we become aware of a breach affecting your personal information in a way that requires notice under applicable law, we will notify you and/or regulators as required. Report suspected security issues to karlotmanagement@gmail.com.

7A. What we do not do (security commitments)

  • We do not intentionally provide customer-support “god mode” endpoints that let staff log in as you without an audit trail or lawful process.
  • We do not expose Stripe secret keys, webhook secrets, or database service-role keys to the public website or client apps.
  • We do not allow unauthenticated callers to mark lease payments as paid or to create live charges for another user’s installment.
  • We do not claim that encryption eliminates all risk of phishing, device compromise, or third-party processor incidents.

8. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. To exercise rights, email karlotmanagement@gmail.com. We may verify your identity before responding. You may close your account by contacting us; residual copies may remain in backups for a limited period.

California residents may have additional rights under the CCPA/CPRA (including knowledge, deletion, and non-discrimination). We do not “sell” or “share” personal information as those terms are defined for cross-context behavioral advertising in a manner that requires a “Do Not Sell or Share” link at this time; if that changes, we will update this Policy and provide required notices.

9. Children

The Service is not directed to children under 18. We do not knowingly collect personal information from children. If you believe we have, contact us and we will take appropriate steps to delete it.

10. International users

The Service is operated from the United States. If you access it from elsewhere, you understand information may be processed in the U.S. and other countries that may have different data-protection rules than your country.

11. Changes

We may update this Policy from time to time. We will post the new version and effective date on this page. Material changes may also be communicated by email or in-product notice. Continued use after the effective date means you accept the updated Policy where permitted by law.

12. Contact

Privacy questions: karlotmanagement@gmail.com.

Terms of ServiceCreate account