Privacy Policy

Autolist, Inc. operated by CarGurus (“Autolist,” “we,” “us,” “our”), provides websites, mobile applications, and other technologies to allow our customers to list and/or locate cars, trucks, or other automobiles for sale. We believe in being transparent with respect to the personal information that we process. This Privacy Notice governs how we may process data that is reasonably capable of being linked to an individual (“you”), such as name, address, telephone number, email address, as well as certain data associated with your browser or device (“personal information”) collected through the Autolist.com website, mobile and other applications owned and operated by us (“digital property(ies)”). Please read this Privacy Notice carefully as it describes the purposes to which we may process your personal information. Depending on where you live and how you use our digital properties, additional state specific information is included below that may apply to you.

To learn about how CarGurus processes and protects your personal information when you visit our site, download our mobile application, or otherwise engage with us on our digital properties, you can visit our website (https://www.cargurus.com/), as well as read the CarGurus privacy notice (https://www.cargurus.com/Cars/privacyPolicy.html).

Last Updated: Effective as of March 21, 2024

Contents:

I. Categories of Personal Information We May Collect

II. How We Collect Personal Information

III. Other Ways Personal Information is Collected

IV. How We Use Your Personal Information

V. With Whom We Share Your Personal Information and Why

VI. Technologies We Use to Automatically Collect Personal Information

VII. Additional U.S. State Disclosures

VIII. Your Privacy Rights and Choices

IX. Publicly Posted Information

X. Storing and Retaining Your Personal Information

XI. Security - Steps we take to protect your personal information

XII. International Transfer

XIII. Children

XIV. Changes to this Privacy Notice

I. Categories of Personal Information We May Collect

We may collect the following categories of personal information:

Registration information

When you create an account or subscribe to one of our services, we may collect information, such as your first and last name, country of residence, email address, username, and password.

Transaction information

This information is processed when you engage with certain services on our digital properties, and may include your postal address, telephone number and payment information.

User Activity Information

This may include information about your use, and the use by any person(s) you authorize through your account, of our digital properties, such as the content you view or post, how often you use our services, and your preferences. This can also include information you post in public forums on our digital properties, such as your forum posts or blog comments, it could also include certain information provided using our messaging chat or other similar services where we are permitted by applicable law to collect this information.

Third-Party Information

This includes insights about the use of our digital properties whether hosted by us, or on third-party platforms or devices.

Location information

This may include location information provided by a mobile or other device interacting with our digital properties (including through beacon technologies), or associated with your IP address, where we are permitted by law to process this information.

Technical Data

Usage, viewing, technical, and device data when you visit our digital properties whether hosted by Autolist or third-party sites or platforms, or open emails we send, including your browser or device type, unique device identifier, and IP address.

See also, VII. Additional State Specific Disclosures below.

II. How We Collect Personal Information

The following describes the different ways we might collect your personal information, whether from you directly or automatically when interacting with our digital properties.

a. Personal Information You Share Directly

When Requesting to be Contacted by a Car Seller

If you request to be contacted by a car seller, both Autolist and the seller may collect personal information provided by you through the text and chat functionalities that we provide and on the contact forms on our site, which may include your name, email address, postal code, and telephone number, so that the seller can contact you to consider a car purchase or request that you submit a dealer review.

When Using Our Site to Buy or Sell a Vehicle

If you are an individual user (and not acting on behalf of a car dealer) and you want to use our services to buy or sell a vehicle, we and/or our business partners may collect information provided by you in connection with that transaction, for example to create your vehicle listing, to verify vehicle ownership, to confirm funds availability, to process payment, to populate purchase and sale documents, and to provide user support. We may collect this information from entry forms on our site or third-party sites we integrate with, or from a picture of your ID that you upload. This information may include your name, address, email address, telephone number, driver’s license number, photo, gender, date of birth, the last four digits of your social security number, bank name, and bank account and routing numbers.

Requesting Financing

When you request vehicle financing through our website, we may collect personal information to determine your eligibility, including your first and last name; email address; phone number; date of birth; social security number; information about your current and previous places of residence, including your rent or mortgage costs; information about your current and previous employment, including your income; information about your financial history; and information relevant to your financing request, such as the value of a vehicle you are trading in, your down payment amount, and the term of financing you are requesting.

Registration for Sweepstakes or Contests

We may run sweepstakes and contests. Contact information you provide may be used to reach you about the sweepstakes or contest and for other promotional, marketing and business purposes, if permitted by law. In some jurisdictions, we are required to publicly share information of winners.

When Registering with Autolist; Subscribing

If you register with us or subscribe to receive specific information or services on our site, we will also collect registration information, such as name, email address, mailing address, telephone number, username and password.

Registering with us also gives you the ability to personalize your Autolist site experience. The benefits of registering will increase over time as we get to know you better and introduce new features. We encourage you to register so that you can experience everything that Autolist has to offer!

b. Automatic Collection of Personal Information

In addition to the personal information we may collect from you directly, we also collect data from your browser or device using tracking technologies (See VI. Technologies We Use to Automatically Collect Personal Information) that is considered personal information when you engage with our digital properties. We automatically collect certain browser or device technical data in order to deliver our services to you, and to help make sure our digital properties are functioning properly. This typically includes data about your browser or device’s IP address, user agent string, your internet service provider or mobile carrier and the type of handheld or mobile device you use.

III. Other Ways Personal Information is Collected

a. Applications and Widgets for Social Media

We may display applications or widgets from social media providers that allow interaction or content sharing by their users. These widgets, such as the Facebook® "Share" or "Like" button, are visible to you on the page that you visit. This may allow the social media networks in which you participate to collect information about you, even when you do not explicitly activate the network's application or widget while on our digital property. Please visit the applicable social media network's privacy notice to better understand their data collection practices and the choices they make available to you.

In addition to social media networks, our digital properties also contain references and links to third-party sites that may offer information of interest. This Privacy Notice does not apply to those sites, and we recommend reviewing those sites’ privacy notices individually.

b. Information Collected from Other Sources

We may process personal information from third-party sources to update or supplement the information that you provide or that we collect. For instance, we may collect vehicle registration information from public databases to support a service you have engaged us for. Other sources of information include third-party advertising partners, data providers or aggregators, and search information providers.

We use this information to help us maintain the accuracy of the information we collect, personalize your experience with the site, target our communications and advertisements so that we can inform you of products and services or other offers that may be of interest to you, provide private purchase and sale transaction services, prevent fraud, and for internal business analysis or other business purposes. To learn more about our advertising activities, we encourage you to review our Interest-Based Ads Policy, and our section on Targeted Advertising below.

IV. How We Use Your Personal Information

We may process your personal information in order to:

  • send information to car sellers to complete transactions per your instruction;
  • complete your transaction(s) with us;
  • process and collect your payments;
  • send you promotional marketing material about us and our services;
  • customize, analyze, adjust and improve the site;
  • provide you with important administrative information regarding the site, such as changes to this Privacy Notice and our Terms of Use and other policies;
  • prevent fraud and other prohibited or illegal activities;
  • comply with requests from law enforcement or relevant data protection agencies;
  • provide technical and customer support;
  • seek your opinion or feedback on our services or industry questions;
  • contact you to participate in surveys;
  • event registration;
  • facilitate access to our applications to which you have subscribed;
  • enforce our legal rights or comply with legal requirements;
  • provide improved website and product experience and communications; or,
  • comply with a legal or regulatory obligation.

See also, VI. Technologies We Use to Automatically Collect Personal Information below.

V. With Whom We Share Your Personal Information and Why

Mainly to provide our services, we may share your personal information with the following entities:

Affiliates

We may share information about you, including personal information, with our corporate affiliates for specific business purposes.

Car Sellers and Manufacturers/Requests

Upon your instruction, we may share your personal information with car sellers and manufacturers who use that information for purposes of marketing their own products or services to you directly.

Lead generation

When you submit your e-mail address and/or phone number to a particular seller through the site, you agree to being contacted by the seller, including by phone at the number provided, text message, email, automatic telephone dialing system and/or an artificial or pre-recorded voice.

Vendors

We may provide third-party vendors (such as market research firms, marketing partners, advertising agencies, and payment processing partners) access to your personal information to perform services on our behalf. We contractually require our vendors to protect and limit the use of such personal information solely for the purposes of providing the specified services on our behalf.

Other Providers of Products and Services

Upon your direction, we may disclose your personal information to other third-party providers of products and services (for example financing providers). We contractually require such providers to protect your personal information and to limit the use of such information for the purposes you agreed to when submitting such personal information on our site. By submitting personal information on our site in connection with receiving products and/or services from these providers, you acknowledge that your request to have your personal information transmitted to such providers means it will be subject to their privacy notices, and that you should contact them directly for more information concerning their personal information processing activities.

Share Content with Friends or Colleagues.

Our services may offer various tools and functionalities. For example, we may allow you to provide information about your friends through our referral services. Our referral services may allow you to forward or share certain content with a friend or colleague, such as an email inviting your friend to use our services.

Legal Authorities

We cooperate with legal authorities and may in some instances be required to disclose personal information in response to requests from law enforcement authorities, or in response to a subpoena or other legal process. We also share information about you if we believe we should in order to: (i) prevent a violation of the law; (ii) protect or defend our interests and our legal rights or property; (iii) protect the rights, interests, safety and security of users of the site or members of the public; (iv) protect against fraud or for risk management purposes; or (v) comply with other applicable law or legal process. We also may share your information in connection with a corporate transaction, such as a divestiture, merger, consolidation, or asset sale, and in the unlikely event of bankruptcy.

See VIII. Your Privacy Rights and Choices below to learn about how you can exercise your privacy rights with Autolist.

VI. Technologies We Use to Automatically Collect Personal Information

We may collect certain information automatically when you use the services. This information may include your Internet protocol (IP) address, user settings, MAC address, cookie identifiers, mobile carrier, mobile advertising and other unique identifiers, details about your browser, operating system or device, location information, internet service provider, pages that you visit before, during and after using the services, information about the links you click, and other information about how you use the services. Information we collect may be associated with accounts and other devices.

  • Cookies. Cookies are small text files placed in visitors’ computer browsers to store their preferences. Most browsers allow you to block and delete cookies. However, if you do that, the services may not work properly.
  • Pixel Tags/Web Beacons. A pixel tag (also known as a web beacon) is a piece of code embedded in the services that collects information about users’ engagement on that web page. The use of a pixel allows us to record, for example, that a user has visited a particular web page or clicked on a particular advertisement.
  • APIs/SDKs. We may use third-party APIs and software development kits (“SDKs”) as part of the functionality of our services. APIs and SDKs may allow third parties including analytics and advertising partners to collect your personal information for various purposes including to provide analytics services and content that is more relevant to you.
  • Analytics. We may also use Google Analytics and other service providers to collect information regarding visitor behavior and visitor demographics on our services. For more information about Google Analytics, please visit <www.google.com/policies/privacy/partners/>. You can opt out of Google’s collection and processing of data generated by your use of the services by going to http://tools.google.com/dlpage/gaoptout.

Cross-Device Tracking

Your browsing activity may be tracked across different websites and different devices or apps. For example, we may attempt to match your browsing activity on your mobile device with your browsing activity on your laptop. To do this our technology partners may share data, such as your browsing patterns, geo-location and device identifiers, and will match the information of the browser and devices that appear to be used by the same user.

To learn more about how we employ these technologies and the choices you have concerning our processing of your personal information for digital advertising purposes, see VIII. Your Privacy Rights and Choices below.

Consistent with IV. How We Use Your Personal Information above, the purposes for which we use tracking technologies include:

PurposeExplanation
ProcessesMake digital properties work in the way that it is expected, as well as improving, upgrading or enhancing our current services, and for the development of new products and services. For example, we use a cookie that tells us whether you have already signed up for an account.
Authentication, Security, and ComplianceEnsuring internal quality control, identify verification, prevent fraud, protect user data from unauthorized parties, and for compliance with legal requirements. For example, we use cookies to determine if a suspicious IP address (based on geography) is logged in through your account.
PreferencesTrack how our digital properties are used and remember preferences. For example, we monitor and store your browsing activity to customize your experience and better understand your vehicle shopping interests.
NotificationsAllow notices of information or options that we think could improve the use of the site or app. For example, send out notifications of price drop in a vehicle that you previously showed interest in.
AdvertisingMake advertising more relevant to users and more valuable to our advertisers. For example, we may use cookies to serve you targeted ads, such as ads that are displayed to you based on your visits to other websites, or to tell us if you have recently clicked on an ad. See VIII. Your Privacy Rights and Choices below.
AnalyticsIntended to help us understand how visitors use our digital properties. For example, we use a cookie that tells us how our search suggestions correlate to your browsing while on the site or app.

VII. Additional U.S. State Disclosures

This section supplements the above by providing additional information about how we may process your personal information. Unless stated otherwise, all terms defined in our Privacy Notice have the same meaning below.

Sensitive Information

In order to support the services we provide, we may process the following types of personal information, which are generally considered sensitive under certain U.S. state privacy laws:

  • Social security number, driver’s license number, and passport number;
  • Credit/debit card number plus expiration date and security code (CVV), and financial account number and routing number;
  • Username and password; and
  • Precise geolocation data.

We may process this information for the purposes set out above (See IV. How We Use Your Personal Information), consistent with our obligations under applicable law.

De-Identified or Aggregate Information

We may at times receive or process personal information to create data sets that can no longer reasonably be used to infer information about, or otherwise be linked to, a particular individual or household. Where we maintain de-identified or aggregate information, we will maintain and use the data in de-identified or aggregate form and not attempt to re-identify the data.

a. California

We share this notice of collection to comply with the California Consumer Privacy Act of 2018 (CCPA). Any terms defined in the CCPA have the same meaning when used in this Privacy Notice.

Sharing Personal Information

Autolist does not generally sell information as the term “sell” is traditionally understood. However, to the extent a “sale” under the CCPA is interpreted to include advertising technology activities such as those disclosed in this notice as a “sale,” we comply with applicable law as to such activity.

Information We Collect:

CategoriesExamplesDo we sell?
IdentifiersName, alias, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, account name, social security number, driver’s license number, or other similar identifiersYes
Customer records informationName, signature, social security number, physical characteristics or description, address, telephone number, driver’s license or state identification card number, bank account number, credit or debit card number, other financial informationYes
Characteristics of protected classifications under California or federal lawRace, religion, sexual orientation, gender identity, gender expression, ageNo
Commercial informationRecords of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendenciesNo
Internet or other electronic network activity informationBrowsing history, search history, and information regarding a consumer’s interaction with an Internet website, application, or advertisementYes
Geolocation dataPhysical locationYes
Professional or employment-related information:Current or past job historyNo
InferencesProfile reflecting a person's preferences, characteristics, aptitudesYes

b. Nevada

Nevada law (NRS 603A.340) requires each business to establish a designated request address where Nevada consumers may submit requests directing the business not to sell certain kinds of personal information that the business has collected or will collect about the consumer. A sale under Nevada law is the exchange of personal information for monetary consideration by the business to a third party for the third party to license or sell the personal information to other third parties. If you are a Nevada consumer and wish to submit a request relating to our compliance with Nevada law, please contact us at privacy@Autolist.com.

VIII. Your Privacy Rights and Choices

You have certain rights to the personal information that we process about you as part of the services we provide. Below is a detailed description of those rights, including additional state-specific rights.

Verification

Consistent with applicable law, please understand that, depending on the type of request you submit, and to protect the confidentiality of yours and others’ personal information, we will only complete your request when your identity has been verified. We will seek to match the information in your request to the personal information we maintain about you. As part of our verification process, we may ask you to: submit additional information, use identity verification services to assist, or, if you have set up an account on our website, to sign into your account as part of our identity verification process.

Right to an Authorized Agent

In certain states, consumers may designate an authorized agent to exercise their privacy rights. You may designate an authorized agent to submit requests on your behalf. However, we may require written proof of the agent’s permission to do so and verify your identity directly.

Right to Non-Discrimination

You also have the right to not receive retaliatory or discriminatory treatment in connection with a request to exercise your rights. However, the exercising of the rights described below may result in a different price, rate, or quality/level of product or service where that difference is reasonably related to the impact the right has on our relationship with you or is otherwise permitted by law.

a. Your Privacy Rights

You may have the right to exercise some or all the following rights:

Access/Right to KnowConsistent with applicable law, you may have the right to confirm in a portable and (if technically feasible) readily usable form, after making a verifiable request whether we are processing your personal information and, in some cases, to obtain certain personalized details about the personal information we have collected about you, including:
  • The categories of personal information collected;
  • The categories of sources of the personal information;
  • The purposes for which the personal information were collected;
  • The categories of personal information disclosed to third parties (if any), and the categories of recipients to whom the personal information were disclosed;
  • The categories of personal information shared for targeted advertising or CCBA purposes (if any), and the categories of recipients to whom the data were disclosed for those purposes; and
  • The categories of personal information sold (if any), and the categories of third parties to whom the data were sold.
CorrectionConsistent with applicable law, you may have the right after making a verifiable request to correct inaccurate personal information, considering the nature of the data itself and the processing activities it supports.
DeletionConsistent with applicable law, you may have the right, after making a verifiable request to have your personal information that is maintained by Autolist deleted.
Opt-Out RightsThe right to direct Autolist to not “sell” your personal information for monetary or other valuable consideration, or “share” your personal information for targeted advertising or Cross-Context Behavioral Advertising (“CCBA”) purposes. You may opt out of such processing by navigating to the Autolist My Privacy Rights form.
See Targeted Advertising for additional information about how we may process your personal information for marketing and advertising purposes.
FOR CALIFORNIA RESIDENTS
“Shine the Light”California residents that have an established business relationship with us have the right to know how their personal information is disclosed to third parties for their direct marketing purposes under California’s “Shine the Light” law, or the right to opt out of such practices (Civ. Code § 1798.83).
Limit Use and/or Disclosure of Sensitive Personal InformationAutolist does not create consumer profiles either for purposes of targeted advertising or for decision-making purposes that produce legal or similarly significant effects. We may, however, share your personal information for targeted advertising consistent with applicable law and this privacy notice. You may opt out of such processing by navigating to the Autolist My Privacy Rights form.
FOR COLORADO, CONNECTICUT OR VIRGINIA RESIDENTS
Right to Opt Out for the Purposes of Profiling for Decisions Producing Legal or Similarly Significant EffectAutolist does not create consumer profiles either for purposes of targeted advertising or for decision-making purposes that produce legal or similarly significant effects. We may, however, share your personal information for targeted advertising consistent with applicable law and this privacy notice. You may opt out of such processing by navigating to the Autolist My Privacy Rights form.
Right to Appeal Privacy Rights RequestTo appeal a refusal to take action on your request, please see the instructions in our response to your request or submit your appeal in writing by contacting privacy@Autolist.com with the subject “Appeal of Consumer Privacy Rights Request.”

b. Choices

To exercise your right to Know, Delete, Correct or Opt Out rights, please submit a request by visiting our My Privacy Rights page.

Or contact us with questions or requests regarding this Privacy Notice at:

Address:

Autolist, Inc.
55 Cambridge Parkway, 6th Floor
Cambridge, MA 02142
privacy@autolist.com

You may also opt out of any or all future marketing emails from us here or by clicking on the unsubscribe link we place at the footer of every email we send that is not in response to an action taken by the user. Please note that you cannot opt out of non-promotional emails, such as those about your account, transactions or servicing.

Targeted Advertising

Also referred to as “interest based,” “online behavioral,” “personalized” advertising, as well as “Cross-Context Behavioral Advertising,” targeted advertising is the serving of digital advertisements based on predictions generated over time from your visits across different websites, devices, mobile applications, as well as our own. We encourage you to consult the CarGurus detailed policy on Interest Based Advertising here.

We may work with advertising technology partners who allow us to personalize our ads based on your browsing behavior on our digital properties. Many of these companies are participants of the Digital Advertising Alliance (“DAA”) and/or members of the Network Advertising Initiative (“NAI”). In addition to your right under your state’s privacy law to opt out from targeted advertising by us and our own advertising partners, you can learn more about targeted ads provided by these companies as well as others we are not partnered with, and how to opt out of receiving certain targeted ads from them by visiting:

Opting out only means that the selected participants should no longer deliver certain targeted ads to the specific browser or device on which you made your request, it does not mean you will no longer receive any targeted content and/or ads from other advertising technology companies or on your other browsers or devices that have not been opted out.

We also partner with Amazon to deliver advertisements. You can opt out of delivery of targeted advertising to you by Amazon [here(https://www.amazon.com/adprefs)]. Please note that even if you opt out, you will continue to receive advertisements, but they will not be tailored to your specific interests.

We may also display interest-based ads to you when you are using Facebook and other social media platforms or websites.

IX. Publicly Posted Information.

Your member profile will be publicly viewable and identifiable via your username. Autolist will not share your email address with any other members or display it publicly. Please consider carefully before making any information public as you are solely responsible for any information you make public. Once you have posted information, you may not be able to edit or delete it.

If you choose to participate in our member-to-member communications programs, you may be contacted by other members, using us as an intermediary. All members have the option to turn off the member-to-member communication features at any time.

Information that you make available to us and others via social media networks, forums, blogs, list serves, chat rooms or similar functionality is public information that we or others may share or use in accordance with the law.

X. Storing and Retaining Your Personal Information

Your personal information is stored on servers in the U.S. Also, some of our service providers may store information in servers hosted in countries different from where you reside. As such, your personal information may be subject to the laws of other countries, where the data protection and other laws may not be as comprehensive as your country of residence.

Consistent with our recordkeeping policies and practices, we may retain your personal information so long as it is necessary to fulfill the purposes outlined in this Privacy Notice, unless a longer retention period is required by law. Once we no longer have a legitimate business reason to retain your personal information, it is either destroyed, aggregated or deidentified, however we may retain inactive archival copies consistent with applicable law.

XI. Security - Steps we take to protect your personal information

We have implemented administrative, technical, personnel, and physical security measures designed to protect the personal information stored in our systems against loss, theft and unauthorized use, disclosure or modification. We also employ processes (such as password hashing, login auditing, and idle session termination, as appropriate) designed to protect against unauthorized access to your personal information. While we endeavor to create secure and reliable digital properties for users, the confidentiality of any communication or material transmitted to/from an Autolist digital property, and the security of your personal information, cannot be guaranteed. We encourage you to take steps to protect your personal information online.

XII. International Transfer

We are based in the U.S. and the information we collect is governed by U.S. law. If you are accessing our digital properties from outside of the U.S., please be aware that information collected may be transferred to, processed, stored, and used in the U.S. and other jurisdictions. Data protection laws in the U.S. and other jurisdictions may be different from those of your country of residence. Your use of this digital property or provision of any information therefore constitutes your consent to the transfer to and from, processing, usage, sharing, and storage of information about you in the U.S. and other jurisdictions as set out in this Privacy Notice.

XIII. Children

Autolist digital properties are intended for a general audience and are not directed at children under (13) years of age.

We do not knowingly gather personal information (as defined by the U.S. Children’s Online Privacy Protection Act, or “COPPA”) in a manner not permitted by COPPA. If you are a parent or guardian and you believe we have collected information from your child in a manner not permitted by law, contact us at privacy@Autolist.com. We will remove the data to the extent required by applicable laws.

We do not knowingly “sell” the personal information of minors under 16 years old who are California residents without their affirmative authorization.

If you are a California resident under 18 years old and registered to use a Autolist digital property, you can ask us to remove any content or information you have posted. To make a request, email us at the email address set out in “Contact Us” section with “California Under 18 Content Removal Request” in the subject line, and tell us what you want removed. We will make reasonable good faith efforts to remove the post from prospective public view, although we cannot ensure the complete or comprehensive removal of the content and may retain the content as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

XIV. Changes to this Privacy Notice

We may occasionally update this Privacy Notice to reflect changes in our practices. When we post modifications to this Privacy Notice, we will revise the "Last Updated" date at the top of this page. The modified Privacy Notice will be effective immediately upon posting. Your continued use of our digital properties after the posting of the modified Privacy Notice constitutes your agreement to abide and be bound by it. We encourage you to periodically review this page for the latest information on our privacy practices. If you object to any modification, your sole recourse is to stop using the digital property.