Privacy Policy
AuctionGate — website, browser extensions (including all white-label builds), the "Bidder Tools" mobile application, and the AuctionGate desktop application
| Version | 3.0 |
| Last updated | 14 September 2026 |
| Effective from | 14 September 2026 |
| Published at | https://auctiongate.io/us/policy |
| Applies to | Every product listed in section 3 — the Site, the Extension and each of its white-label builds (Annex A), the Bidder Tools mobile app for iOS and Android, and the AuctionGate desktop app for macOS and Windows |
| Supersedes | Privacy Policy v1.x of 10 June 2026 and v2.0 of 14 September 2026 |
PART I — GENERAL
1. Introduction and scope
This Privacy Policy explains, in deliberate detail, what data we collect, why we collect it, where we store it, whom we share it with, how long we keep it and what rights you have.
This is one single policy covering all of our products. It is the policy linked from every Chrome Web Store listing, from the Apple App Store and Google Play listings of the Bidder Tools app, and from the download page of the desktop application.
We have written it to be exhaustive rather than short. We would rather describe precisely everything we do — including the collection of behavioural data and the use of Google Analytics, Firebase and the Meta (Facebook) Pixel and SDK — than hide it behind generic wording.
How to read this Policy. Part I is general and applies to everything. Parts II to V describe each product separately: find the product you use and read that part. Part VI applies to all products — sharing, transfers, retention, security and your rights. The annexes contain the list of extensions, the list of processors, and the data-type mapping we publish in the app stores.
2. Who we are
Data controller, developer and publisher of all products
PAR SOFT, INC.
A corporation incorporated in the State of Delaware, United States of America
2810 North Church Street, PMB 29208, Wilmington, Delaware 19802-4447, USA
Operator of the AuctionGate service (auctiongate.io); publisher of the Extension and of every white-label build in the Chrome Web Store under the developer account auctiongate.io; publisher of the Bidder Tools mobile application in the Apple App Store and Google Play; and publisher of the AuctionGate desktop application, whose installers are code-signed as "PAR Soft, inc" (Apple Developer Team ID 839DG2LNQZ; Windows publisher certificate issued to PAR SOFT, INC.).
Privacy contact: [email protected] General contact: [email protected]
Joint / independent controllers — white-label licensees
Each white-label licensee listed in Annex A (a vehicle broker, importer, dealer or logistics company) is an independent controller with respect to its own customers: it determines the purposes for which it contacts its customers and serves their import and shipping requests. PAR SOFT, INC. supplies the technology, the infrastructure, the servers and the technical support, and processes data both on behalf of the licensee and, as a controller, for the operation, security, measurement and improvement of the products described here.
Where the law of your country requires a representative or a designated privacy officer, write to [email protected] and your request will be routed to the responsible person.
3. The products this Policy covers
| Product | Platform | Distributed through | Described in |
|---|---|---|---|
The Site — auctiongate.io and subdomains |
Web | — | Part II |
| The Extension — AuctionGate and every white-label build | Google Chrome and Chromium-based browsers | Chrome Web Store, publisher auctiongate.io |
Part III, Annex A |
| Bidder Tools — vehicle shipping and ocean ETA tracking | iOS, Android | Apple App Store, Google Play | Part IV |
| AuctionGate Desktop | macOS, Windows | Download from our website, signed installers | Part V |
All four products talk to the same back-end infrastructure operated by PAR SOFT, INC., use the same accounts, and are covered by the same data-handling rules. If you use more than one of them while signed in to the same account, the data they produce is associated with that one account.
4. White-label disclosure
Several extensions published in the Chrome Web Store are white-label builds of one and the same product, and some licensees also distribute branded variants of the mobile and desktop applications. We want this to be completely clear to users, to Google, to Apple and to any supervisory authority:
- Every build listed in Annex A is developed, signed, maintained and published by PAR SOFT, INC. The partner whose brand appears on the listing is a white-label licensee: it contributes the brand, local commercial content and the relationship with the end customer in its market.
- All builds share the same code base, the same server infrastructure, the same APIs and the same data-processing procedures.
- Consequently, data collected by any build is transmitted to and stored on infrastructure operated by PAR SOFT, INC., and authorised AuctionGate personnel have access to that data, on the terms described in section 22.
- Security fixes, updates and functional changes are applied centrally to all builds.
- Where a licensee publishes its own privacy policy on its own domain, that policy and this one are complementary. For the data processing performed by our products and our servers, this Policy governs.
5. Purpose of the products
AuctionGate helps a buyer of vehicles at the North American salvage and insurance auctions Copart and IAAI: it shows the vehicle's history and condition data, calculates the full landed cost of purchase, shipping and import, shows comparable-sale statistics, and tracks the vehicle from the auction yard to the destination port.
The Extension serves that purpose inside the browser; the Desktop app serves it in a standalone window; Bidder Tools serves the shipping and ocean-ETA part of it on a phone; the Site serves it on the web and is where accounts and subscriptions are managed.
Express clarification. These are tools for commercial vehicle auctions. A "bid" is a price offered for a physical vehicle at a commercial auction. None of our products is gambling, betting, a lottery, a prediction market, a financial or investment instrument, or a game of chance, and none offers a monetary prize, odds, wager or chance-based outcome of any kind.
6. Summary — what we collect and where it goes
| Category | Site | Extension | Bidder Tools | Desktop | Stored on our servers | To Google | To Meta |
|---|---|---|---|---|---|---|---|
| Account data (name, email, phone) | ● | ● | ● | ● | Yes | No | Hashed email for conversion measurement, with consent |
| Authentication data (password, session token) | ● | ● | ● | ● | Password as salted hash only | No | No |
| Payment and billing data | ● | — | ● | — | No card numbers | No | Purchase value only, with consent |
| Location (country/region from IP, time zone, language) | ● | ● | ● | ● | Yes | Coarse only | Coarse only |
| Auction browsing history (URLs, lot numbers, VINs, search queries) | ● | ● | — | ● | Yes | No | No |
| User activity (clicks, cursor, scrolling, dwell time, search typing) | ● | ● | ● | ● | Yes | Aggregated interface events only | Aggregated interface events only |
| Auction page content (public lot data) | — | ● | — | ● | Yes | No | No |
| Shipment and logistics data (container, vessel, ports, ETA) | ● | — | ● | ● | Yes | No | No |
| Push notification token | — | — | ● | ● | Yes | Yes (FCM is a Google service) | No |
| Advertising identifier (IDFA / GAID) | — | — | ● | — | No | Yes, only with ATT consent on iOS | Yes, only with ATT consent on iOS |
| Technical and diagnostic data, crash reports | ● | ● | ● | ● | Yes | Yes | Yes |
Everything not marked as shared stays on our own servers. It is not transferred to any third party, except to the infrastructure providers acting as our processors (Annex B), to the licensee that serves you, and to authorities where the law requires it.
7. Definitions used throughout
- Pseudonymous identifier — a random identifier generated when you install a product. It is not your name and cannot by itself identify you. Where you are signed in, we associate it with your account on our own servers only.
- Behavioural events — the record of interactions described for each product (clicks, screens, scrolling, dwell time, search typing).
- Processor — a supplier that handles data strictly on our instructions under a written contract.
PART II — THE SITE (auctiongate.io)
8. What the Site collects
- Data you voluntarily provide: name, email address, telephone / WhatsApp number, company name, message content, the vehicle or lot you are interested in, and anything else you enter in a form or in conversation with us.
- Account data: user ID, contact details, subscription and plan, request history, saved lots, history of imported vehicles, shipment records.
- Payment data: billing name and address, plan, amounts, invoice and transaction history. Card numbers are entered directly into the payment provider's hosted form; we do not receive or store full card numbers — only the last four digits, card brand and expiry supplied to us by the processor.
- Browsing data: IP address, pages visited, referrer, date and time, cookie and device identifiers, browser and operating-system type, screen size, approximate country and region.
- On-page behaviour: clicks, scrolling, time on page, forms started and abandoned, and the search terms you type into the Site's own search.
- Communications: support tickets, chat transcripts, call notes and emails you exchange with us or with the licensee serving you.
9. Analytics, measurement and marketing on the Site
The Site runs Google Analytics 4, the Meta (Facebook) Pixel, and may run other measurement or advertising tags disclosed in the cookie notice. These are used to measure traffic and audience, to measure how effective our advertising and communications are, to avoid showing our advertising to people who have already subscribed, and to improve the Site.
- What they receive: pages and screens viewed, interaction and conversion events (registration completed, subscription purchased, form submitted), approximate country and region, device, browser and operating system, language, referrer, the Google client identifier and the Meta browser identifier (
_fbpcookie), and — for purchases — the value and currency of the transaction. - Hashed email for conversion matching: where we use it, an email address is transmitted only as an irreversible SHA-256 hash, and only after you consent.
- What they never receive from us: your password or session token, the VIN or lot number of any vehicle, the text of your auction search queries, or the content of any auction page.
- These tags run only after you consent through the cookie notice, which you can change or withdraw at any time.
10. Cookies and similar technologies on the Site
- Strictly necessary — session, security, load balancing, language and currency preference. No consent required.
- Functional — remembering your interface settings.
- Analytics — Google Analytics 4.
- Measurement and marketing — Meta Pixel (
_fbp), and any other tag named in the cookie notice.
Analytics and marketing cookies are set only after your consent. You can withdraw consent at any time from the cookie notice at the foot of any page, and you can block or delete cookies in your browser settings. We honour the Global Privacy Control (GPC) signal.
PART III — THE BROWSER EXTENSION AND ITS WHITE-LABEL BUILDS
11. Single purpose and where the Extension runs
The single purpose of the Extension is to display, directly on the auction lot page, the vehicle's history and condition data, the landed-cost calculation and comparable-sale statistics.
The Extension activates only on:
copart.com, its subdomains and regional domains;iaai.com, its subdomains and regional domains;auctiongate.ioand its subdomains;- the white-label partner's own website domain, where the build is configured for it (Annex A).
Outside those domains the Extension injects no code, reads no page content, observes no user activity and collects no data at all. We have no access to your other tabs, to your general browsing history, to your email, to your online banking or to any other website.
12. Account and authentication data in the Extension
The Extension includes sign-in to an AuctionGate (or white-label) account. Accordingly:
- When you sign in, the Extension transmits the email address and password you enter to our servers over an encrypted TLS channel, for the sole purpose of verifying your credentials.
- The password is never stored in the Extension, is never written to local storage in readable form, is never logged, is never sent to any analytics or advertising provider, and on our servers exists only as a salted cryptographic hash.
- After successful sign-in, the Extension stores a session token in the browser's extension storage. It identifies your session, is revoked when you sign out or uninstall, and is transmitted only to AuctionGate servers.
- Your name, email address, telephone number, plan and account identifier are available to the Extension so that it can show your profile, subscription status and saved lots.
- Because the Extension handles account data, the categories "Personally identifiable information" and "Authentication information" are declared on the Chrome Web Store listing of every build that includes sign-in.
- We do not collect, read, intercept or store the credentials, cookies or session tokens of your Copart, IAAI, bank, email or any other third-party account.
13. Data collected by the Extension, by declared category
This is the complete list of the categories we declare on the Chrome Web Store listing of the Extension and of every build in Annex A.
a) Personally identifiable information
Name, email address, telephone number and account identifier, as described in section 12. Why: to authenticate you, link the Extension to your account, show your subscription and saved lots, provide support, and enforce plan limits and anti-abuse rules.
b) Authentication information
The credentials you enter in the Extension's own sign-in form, and the resulting session token, as described in section 12. Why: solely to authenticate you to the AuctionGate service and keep your session alive.
c) Location
Approximate country and region derived from your IP address; time zone and language configured in the browser. We do not use GPS, Bluetooth, nearby Wi-Fi networks or any other precise geolocation technique, and we do not know your street address or exact position. Why: to show the correct destination port and freight rates, adapt language and currency, apply the correct country's customs rules and duty calculations, comply with export-control and sanctions requirements, and detect anomalous access.
d) Web history
While the Extension is active on the domains in section 11, we record: the URL, page title and time of the Copart and IAAI pages you open; the lot number and VIN identified on those pages; the search queries and filters you apply within those sites; and the order and sequence of lot pages visited in a session. Why: to retrieve and display the vehicle report for the lot you are viewing; to provide "recently viewed" and "saved lots"; to calculate price statistics for comparable lots; to understand which vehicle categories users are interested in; and to produce usage statistics.
We do not record the URLs, titles or content of any page outside the domains listed in section 11, and we have no access to your general browser history.
e) User activity
Clicks (element and timestamp); mouse cursor position and movement over the page; scrolling and reading depth; dwell time on each screen and session duration; opening, closing and use of the Extension's panels, tabs and calculators; the text you type into the search field of the auction site and into the Extension's own search fields, including corrections and rewrites; and the success or failure of the Extension's own network requests.
Why: to auto-complete and correct the VIN or lot number you type; to suggest results as you type; to understand what users search for and fail to find; to detect interface errors, freezes and friction points; to compile behavioural statistics; and to improve the product and the commercial offer.
Important clarification about keystroke capture. We capture only text entered into search fields. We do not capture what you type into: sign-in forms of third-party sites, password fields, bank card or payment fields, bid or offer amount fields, personal-data forms, chats or messaging, or any other input field. Before transmission, captured text passes through an automatic filter that discards any string matching the shape of a password, payment card number, identity document number or email address.
f) Website content
The public vehicle data displayed on the lot page: VIN, lot number, make, model, year, trim; odometer, damage type and severity, title status, key status, engine and transmission; physical lot location and scheduled auction date; prices and bids publicly displayed, buy-now price, estimated retail value; and the URLs of the lot photographs. Why: to feed the landed-cost calculator, compare the lot with historical sales of equivalent vehicles, and compose the vehicle report shown to you.
We do not extract or store full page content, page scripts, complete HTML, or any authenticated content other than the public lot data visible on screen.
g) Technical and diagnostic data
Extension version, browser version, operating system, screen resolution, interface language, the random pseudonymous installation identifier, timestamps, and error and crash logs.
14. What the Extension does NOT collect
Health or medical information; financial or payment information inside the Extension; credentials of third-party services; personal communications; the content of tabs or websites other than those in section 11; precise geolocation, camera, microphone, clipboard or file-system contents; special categories of data within the meaning of Article 9 GDPR; data of persons under 18.
15. Browser permissions and their justification
| Permission | Why it is needed |
|---|---|
Access to data on copart.com and iaai.com (host permissions) |
Core functionality: without reading the lot page it is impossible to identify the vehicle or insert the panel with the report and the calculator. |
Access to data on auctiongate.io and the partner domain |
To link the Extension to your account and synchronise your saved lots. |
storage |
To store settings, language and currency preference, session state and a cache of recently retrieved reports. |
scripting / content scripts |
To insert the Extension's visual panel into the lot page. |
activeTab / tabs |
To determine whether the active tab is a Copart or IAAI lot page and, if so, activate the Extension. |
| Network communication with our servers | To request the vehicle report, price statistics and current tariffs, and to send the events described in section 13. |
The Extension does not request access to all websites, to the full browser history, to the clipboard, or to the camera, microphone or precise device location.
16. Chrome Web Store Developer Program compliance
PAR SOFT, INC. declares that the data handling performed by the Extension and by every white-label build listed in Annex A complies with the Chrome Web Store User Data Policy, including the Limited Use requirements:
- PAR SOFT, INC.'s use and transfer of information received from Google APIs to any other app will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
- User data is collected and used solely to provide or improve user-facing features that constitute the Extension's single purpose described in section 11.
- We do not sell user data, and we do not transfer it to third parties except in the permitted cases: (i) to provide or improve the single purpose, through processors bound by contract; (ii) to comply with applicable law; (iii) for security purposes, including investigating fraud or abuse; (iv) with the user's explicit consent.
- We do not use or transfer user data to determine creditworthiness or for lending purposes.
- We do not allow humans to read user data, except: (i) with the user's affirmative agreement for specific pages; (ii) where necessary for security purposes, such as investigating abuse; (iii) to comply with applicable law; or (iv) where the data is aggregated and anonymised and used for internal operations in accordance with applicable law. The support-personnel access described in section 22.1 occurs under cases (i), (ii) and (iv).
The data-category declaration published on each build's Chrome Web Store listing corresponds to the categories described in section 13.
PART IV — THE "BIDDER TOOLS" MOBILE APPLICATION (iOS AND ANDROID)
17. What Bidder Tools is
Bidder Tools is the AuctionGate mobile application, published in the Apple App Store and on Google Play by PAR SOFT, INC. Its purpose is to let a buyer follow a purchased vehicle through the logistics chain: the status of the vehicle and of its container, the vessel, the ports of loading and discharge, the ocean ETA and its changes, customs and delivery milestones, related documents and costs, and to receive notifications when any of that changes.
Bidder Tools does not run inside Copart or IAAI, does not read the content of auction websites and does not record auction browsing history. It talks only to AuctionGate servers and to the services listed below.
18. What Bidder Tools collects
a) Account and authentication data
Name, email address, telephone number, account identifier, plan; the credentials you enter when signing in and the resulting session token. The password is transmitted over TLS, is never stored on the device in readable form, is never logged, is never sent to any analytics or advertising provider, and exists on our servers only as a salted hash. Where the operating system offers it, you may sign in with a platform mechanism (for example Sign in with Apple), in which case we receive only the identifier and, if you allow it, an email address — which may be Apple's private relay address.
b) Shipment and logistics data
The vehicles, lots and VINs linked to your account; container and booking numbers; vessel name and voyage; ports of loading and discharge; departure and arrival dates and ETA changes; customs, inspection and delivery milestones; associated invoices, fees and documents you or your broker upload; and notes you add.
c) Usage data
Screens viewed, features used, buttons tapped, session start and duration, scrolling and dwell time within the app, searches you run inside the app's own search, and the sequence of screens in a session.
d) Device, diagnostic and crash data
Device model, operating-system version, app version and build, language and region settings, time zone, screen size, network type, approximate country and region derived from the IP address, a random pseudonymous installation identifier, the vendor identifier supplied by the platform, crash reports, stack traces and performance traces.
e) Push notification data
If you allow notifications, the app registers a push token with Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM) and sends it to our servers, so that we can notify you about ETA changes, vessel departures and arrivals, customs events, delivery, payment reminders and account or security alerts. The token identifies the installation, not you personally. You can turn notifications off at any time in the operating system settings; doing so does not affect any other function of the app. The content of a notification may include the vehicle, lot or container it concerns; if you prefer not to see that on a lock screen, disable previews in your OS settings.
f) Advertising identifier and tracking — iOS
On iOS, the app may request permission through App Tracking Transparency (ATT). If you decline — which is the default — no advertising identifier (IDFA) is collected, no data is shared with Meta for advertising purposes, and no tracking across other companies' apps or websites takes place. Declining does not restrict any feature of the app. On Android, the advertising identifier (GAID) is used only where you have not opted out in the system settings ("Delete advertising ID" / "Opt out of Ads Personalisation").
g) What Bidder Tools does NOT collect
Precise or background location — the app does not request GPS access and does not track where you are; the location of a vehicle is reported by the carrier and the ports, not by your phone. It does not access your camera, microphone, photo library, contacts, calendar, call logs, SMS, health data or files outside its own storage, and it does not read your clipboard. It collects no payment card numbers, no special categories of data within the meaning of Article 9 GDPR, and no data of persons under 18.
19. Third-party SDKs in Bidder Tools
| SDK / service | Provider | What it receives | Purpose |
|---|---|---|---|
| Google Analytics for Firebase | Google LLC / Google Ireland Ltd | Pseudonymous usage events, screens viewed, app version, device model, OS, language, approximate country and region, installation identifier | Product usage measurement and improvement |
| Firebase Crashlytics | Crash reports, stack traces, device state at the moment of the crash, installation identifier | Diagnosing and fixing faults | |
| Firebase Cloud Messaging / APNs | Google / Apple | Push token and the notification payload | Delivering notifications |
| Meta SDK (Facebook) | Meta Platforms, Inc. / Meta Platforms Ireland Ltd | App install and pseudonymous conversion events (registration, subscription purchase with its value and currency), device and OS type, approximate country and region; the advertising identifier only where you have consented through ATT on iOS or have not opted out on Android | Measuring the effectiveness of our advertising, attributing installs, and avoiding advertising to existing subscribers |
None of these SDKs receives your password or session token, your shipment documents, your container or VIN numbers, your notes, your telephone number, or your email address in unhashed form. Where a hashed email is used for conversion matching, it is transmitted only as an irreversible SHA-256 hash and only with your consent.
Analytics and marketing SDKs are activated after the consent you give on first launch (and, on iOS, after ATT where tracking is involved). You can change that choice at any time in Settings → Privacy in the app.
20. App store programme compliance
- Apple. The data-type declarations we publish in App Store Connect ("privacy nutrition labels") correspond to section 18 and to the mapping in Annex C. We follow App Store Review Guideline 5.1 and the User Privacy and Data Use rules: we request permission before accessing anything that requires it, we never require you to grant a permission that is not needed for a feature you are using, we do not collect data from children, and we do not track you across other companies' apps or websites without ATT permission. The app offers in-app account deletion, as Apple requires: Settings → Account → Delete account, which deletes or irreversibly anonymises your data on our servers subject to the retention rules in section 26.
- Google. The Data safety declaration we publish on Google Play corresponds to section 18 and to the mapping in Annex C, including which data types are collected, which are shared, whether data is encrypted in transit (it is), and whether you can request deletion (you can, both in the app and through the web form linked from our Play listing). We comply with the Google Play User Data policy, the Families policy (the app is not directed to children) and the Permissions and APIs that Access Sensitive Information policy: the app requests no sensitive or restricted permissions.
PART V — THE AUCTIONGATE DESKTOP APPLICATION (macOS AND WINDOWS)
21. What the desktop application is and what it collects
The desktop application delivers the same functionality as the Extension in a standalone application window. It contains an embedded browser component in which you open the Copart and IAAI auction sites, and it displays the AuctionGate panel — the vehicle report, the landed-cost calculator and comparable-sale statistics — alongside them. Installers are distributed from our website and are code-signed as "PAR Soft, inc" (notarised by Apple on macOS; signed with an organisation-validated certificate on Windows), so that your operating system can verify that the application comes from us and has not been altered.
a) The same data as the Extension
Inside the embedded browser, and only on the auction domains listed in section 11 and on our own domains, the desktop app collects exactly the categories described in sections 12 to 14 — account and authentication data, coarse location, auction browsing history, user activity and public lot content — for the same purposes and with the same restrictions, including the restriction that only text typed into search fields is captured and that it passes through the filter described in section 13(e).
The embedded browser does not visit, read or record anything other than the pages you open in it on those domains. The desktop application does not read the pages you open in Chrome, Safari, Edge or any other browser on your computer, does not read your browsing history, and does not interact with any other application on your computer.
b) Your third-party auction sessions stay on your device
If you sign in to your Copart or IAAI account inside the embedded browser, that session — its cookies and tokens — is stored locally on your computer, in the application's own isolated profile. It is never transmitted to us, never logged and never sent to any third party. We do not read those credentials, and we cannot act on your auction account.
c) Desktop-specific technical data
Application version and build, operating-system name and version, CPU architecture, system language and region, time zone, screen resolution and window size, the random pseudonymous installation identifier, timestamps, error and crash reports (including stack traces and the application state at the moment of the crash), and the outcome of update checks.
The application does not read your files, folders, documents, clipboard, camera, microphone, keystrokes outside its own search fields, or anything else on your computer outside its own application data directory. Data you deliberately export or save (a PDF report, a CSV) is written to the folder you choose and is not sent anywhere.
d) Automatic updates
The application periodically contacts our update server to check for a new version. That request transmits the current version, the operating system and architecture, and the pseudonymous installation identifier — so that we can serve the correct build and count active installations. Updates are verified against our code-signing signature before installation. You can disable automatic update checks in Settings → Updates, in which case you remain responsible for installing security updates manually.
e) Analytics in the desktop application
The desktop app sends the same pseudonymous product-usage events to Google Analytics 4 as the Extension, and no more: screens and panels opened inside our own interface, features used, session duration, app version, OS, language and coarse country. It does not send to Google or to Meta any VIN, lot number, auction URL, search query text or auction page content, and it does not run the Meta Pixel. As in the Extension, these events stop when you turn off Settings → Privacy → "Analytics and product improvement".
PART VI — RULES COMMON TO ALL PRODUCTS
22. Who we share data with
22.1. AuctionGate (PAR SOFT, INC.) personnel
We expressly disclose that authorised AuctionGate personnel access usage data from all four products. Employees and contractors performing technical support, account management, product analytics and development roles access the session logs, behavioural events, account records, shipment records and statistics described in this Policy, in order to:
- resolve user incidents and support requests;
- maintain usage statistics for the product and for each white-label build;
- analyse user behaviour in order to improve the interface and the features;
- detect errors, abuse, scraping and unauthorised automated use.
Such access is subject to role-based access control, audit logging, confidentiality agreements and a prohibition on using data for any purpose unrelated to operating, securing and improving the products.
22.2. The white-label licensee that serves you
If you use a white-label build, the licensee's advisers and account managers (Annex A) access your account data, your requests, your saved vehicles and your shipment records in order to serve you. Each licensee is bound by contract to use that data only to serve its customers and to comply with applicable data-protection law.
22.3. Logistics and supply-chain counterparties
To deliver the shipping and ETA features, we exchange the data necessary for the movement of the vehicle — VIN, lot, container and booking numbers, consignee name and destination — with carriers, shipping lines, freight forwarders, terminals, customs brokers and their tracking systems. This is the minimum required to arrange and track a physical shipment, and it is done to perform the contract with you.
22.4. Analytics and measurement providers
Google (Google Analytics 4, Firebase, Crashlytics, Cloud Messaging) and Meta (Pixel on the Site, SDK in the mobile app), strictly on the terms and within the limits set out in sections 9, 19 and 21(e).
22.5. Infrastructure and service providers (processors)
Cloud hosting and managed databases, content delivery network, DNS and DDoS protection, transactional email, push delivery, error and crash tracking, customer-support helpdesk, and payment processing. Each is engaged as a processor under a written contract containing confidentiality, security and sub-processing obligations. The categories are listed in Annex B.
22.6. Authorities, and corporate transactions
We will disclose data to judicial, administrative, tax or customs authorities where there is a legal obligation or a valid legal request. If PAR SOFT, INC. is involved in a merger, acquisition, financing or sale of assets, data may be transferred to the counterparty subject to this Policy continuing to apply, and we will notify you of any material change.
22.7. What we do NOT do
- We do not sell your personal data and do not disclose it to data brokers.
- We do not "share" your personal data for cross-context behavioural advertising within the meaning of the CCPA/CPRA.
- We do not use or transfer your data to determine creditworthiness or for lending purposes.
- We do not use or transfer data collected by the Extension or the desktop application for purposes unrelated to operating, securing and improving their single purpose.
- We do not build advertising profiles or retargeting segments from behavioural data collected on Copart and IAAI pages.
- We do not track you across other companies' apps and websites without your ATT permission on iOS.
- We carry out no automated decision-making producing legal or similarly significant effects on you (section 28).
23. Purposes of processing and legal bases
| Purpose | Data used | Legal basis (GDPR / equivalent) |
|---|---|---|
| Providing the functionality of the Site, Extension, mobile app and desktop app | All product sections | Performance of a contract |
| Creating and administering your account, authentication, session management | 8, 12, 18(a) | Performance of a contract |
| Arranging, tracking and reporting the shipment of your vehicle | 18(b), 22.3 | Performance of a contract |
| Sending push and email notifications about your shipments, account and security | 18(e) | Performance of a contract; legal obligation for security notices |
| Processing payments, invoicing, subscription management | 8 | Performance of a contract; legal obligation |
| Technical support and incident resolution | 13(e)(g), 18(c)(d), 21(c) | Legitimate interest; performance of a contract |
| Security, prevention of fraud, abuse, scraping and unauthorised automated use | 13(c)(e)(g), 18(d), 21(c) | Legitimate interest; legal obligation |
| Analysis of user behaviour, usage statistics, product improvement | 13(c)–(g), 18(c)(d), 21 | Consent where required by applicable law; otherwise legitimate interest |
| Audience measurement and measurement of the effectiveness of our communications and campaigns (Google Analytics, Firebase, Meta) | 8, 9, 19 | Consent (and ATT permission on iOS where tracking is involved) |
| Direct marketing — product news, offers and service communications by email | 8 | Consent, or legitimate interest in relation to existing customers for similar products, with an opt-out in every message |
| Compliance with legal, accounting, tax, customs, export-control and sanctions obligations | 8 | Legal obligation |
| Establishing, exercising or defending legal claims | All | Legitimate interest; legal claims |
Where the legal basis is consent, you may withdraw it at any time by the means in section 27, without affecting the lawfulness of processing carried out beforehand. Where the basis is legitimate interest, you may object at any time and we will stop unless we can demonstrate compelling legitimate grounds.
24. International transfers
Data is processed on servers located in the European Union (Germany) and in the United States of America, and is disclosed to PAR SOFT, INC. (United States), to the white-label licensee that serves you (which may be located in Latin America, the Middle East, Europe or the CIS — see Annex A), to the logistics counterparties involved in your shipment, and to the providers in Annex B.
- Where the GDPR or the UK GDPR applies, transfers outside the EEA or the UK rely on the Standard Contractual Clauses approved by the European Commission (and the UK International Data Transfer Addendum), on adequacy decisions where one exists, supplemented by encryption in transit and at rest, pseudonymisation and data minimisation.
- Where the Swiss FADP applies, transfers rely on the SCCs as recognised by the Swiss Federal Data Protection and Information Commissioner.
- For other jurisdictions we rely on the transfer mechanism their law provides — your consent, the necessity of the transfer to perform a contract with you, or contractual safeguards equivalent to the SCCs.
A copy of the relevant safeguards may be requested at [email protected].
25. Security
TLS encryption of all communications; encryption of data at rest; salted hashing of passwords; role-based access control and least privilege; multi-factor authentication for staff with data access; audit logging of access; segregation of production and development environments; encrypted backups; dependency and vulnerability scanning; code-signing and notarisation of desktop installers and signed mobile builds; and periodic security review of client code before each release.
In the event of a personal-data breach presenting a risk, we will notify the competent supervisory authority and, where applicable, affected users, within no more than 72 hours of becoming aware of it, or within the shorter period your local law requires.
26. Retention periods
| Category | Period |
|---|---|
| Raw behavioural events (clicks, cursor movement, scrolling, search queries, in-app screens) | 14 months from recording |
| Auction browsing history linked to an account | While the account is active; 12 months after closure |
| Saved lots and favourites | While the account is active; deleted on closure |
| Shipment and ETA records | While the account is active and for 24 months after the shipment is completed; longer where customs or tax rules require |
| Documents you or your broker upload | While the account is active; deleted on closure unless retention is legally required |
| Technical, error, crash and security logs | 90 days (up to 12 months where retained for an active security investigation) |
| Account, profile and contact data | For the duration of the relationship and 24 months thereafter, unless a longer statutory period applies |
| Authentication records (password hash, active session tokens) | Until account closure; tokens expire or are revoked on sign-out |
| Push notification tokens | Until you disable notifications, sign out, uninstall, or the platform invalidates the token |
| Billing, invoicing and import transaction records | As required by applicable tax, accounting and customs rules (generally 5–10 years) |
| Support tickets and correspondence | 36 months |
| Data in Google Analytics 4 and Firebase | 14 months |
| Data held by Meta for measurement | Per Meta's own retention rules for pixel and app-event data |
| Aggregated and anonymised statistics that cannot identify any individual | No limit |
Once these periods expire, data is deleted or irreversibly anonymised.
27. How to control data collection
In the Extension and the desktop application
- Settings → Privacy → "Analytics and product improvement" — turning it off stops the behavioural events in section 13(e) and the browsing data in 13(d) that is not strictly necessary to display the report you are requesting at that moment, and stops all transmission to Google Analytics and Meta from that product.
- The Extension does not run in incognito windows unless you enable it at chrome://extensions.
- Uninstall — chrome://extensions → the extension → Remove; or the standard uninstaller on macOS and Windows. Uninstalling deletes the product's local storage, including any Copart or IAAI session stored inside the desktop app's embedded browser.
- Settings → Updates in the desktop app disables automatic update checks.
In the Bidder Tools mobile app - Settings → Privacy — turn analytics and marketing SDKs on or off at any time. - iOS: Settings → Privacy & Security → Tracking, to grant or revoke ATT permission. Android: Settings → Privacy → Ads, to delete or opt out of the advertising ID. - Notifications — turn off in the OS settings, or per-category in the app's own notification settings. - Settings → Account → Delete account — deletes your account and, subject to section 26, your data.
On the Site - The cookie notice at the foot of any page, to grant or withdraw consent for analytics and marketing cookies at any time.
Everywhere - Global Privacy Control (GPC) — we honour the signal where the browser sends it. - Google Analytics opt-out — Google's official browser add-on. - Meta — adjust the ad settings in your Facebook or Instagram account. - Marketing emails — the unsubscribe link in any message, or [email protected]. - Server-side deletion — write to [email protected] and we will delete or irreversibly anonymise your data.
28. Automated decision-making and profiling
We carry out no automated decision-making producing legal effects concerning you or similarly significantly affecting you. The calculations our products display — landed cost, comparable-sale statistics, price estimates, estimated times of arrival — are informational estimates based on public auction data, current tariffs and carrier-supplied schedules. They are not a valuation, an appraisal, financial advice, a booking confirmation or a guarantee of arrival, and no decision about you is made on their basis. Behavioural analysis is used to improve the product and produce aggregate statistics, and results in no individual decision affecting your rights.
29. Your rights
Whatever your country, you may exercise the rights below by writing to [email protected]. We do not discriminate against anyone for exercising a privacy right.
29.1. Rights available to everyone
Access to your data; correction of inaccurate data; deletion; a copy in a portable format; restriction of processing; objection to processing based on legitimate interest; withdrawal of consent; and the right to complain to your national supervisory authority.
29.2. European Economic Area, United Kingdom and Switzerland
Under the GDPR, the UK GDPR and the Swiss FADP: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), withdrawal of consent (Art. 7(3)), the right not to be subject to automated decision-making (Art. 22 — we carry out none), and the right to lodge a complaint with your national supervisory authority or, in the UK, the Information Commissioner's Office.
29.3. California and other United States states
Under the CCPA/CPRA and the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and other states as they take effect: the right to know the categories of personal information collected, the sources, the purposes and the categories of recipients; to request deletion; to request correction; to opt out of the sale or sharing of personal information and of targeted advertising — noting that we neither sell nor share personal information within the meaning of those laws; to limit the use of sensitive personal information — noting that we do not collect the categories those laws define as sensitive; to appeal a refused request; and not to be discriminated against. An authorised agent may submit a request with proof of authorisation. California residents may also request the disclosures described in California Civil Code § 1798.83.
29.4. Canada
Under PIPEDA and the applicable provincial statutes (including Quebec's Law 25): access, correction, withdrawal of consent, de-indexing and portability, and the right to complain to the Office of the Privacy Commissioner of Canada or your provincial commissioner.
29.5. Latin America
- Brazil (LGPD): confirmation of processing, access, correction, anonymisation or deletion, portability, information about shared parties, revocation of consent, complaint to the ANPD.
- Mexico (LFPDPPP): ARCO rights — access, rectification, cancellation, opposition — complaint to the INAI.
- El Salvador: ARCO-POL rights under the Personal Data Protection Law, complaint to the State Cybersecurity Agency (ACE).
- Argentina, Chile, Colombia, Peru, Ecuador, Dominican Republic, Guatemala, Costa Rica, Panama, Uruguay: the access, rectification, cancellation, opposition and portability rights granted by the respective national statutes, and complaint to the corresponding authority.
29.6. Europe outside the EU, and the CIS
- Ukraine: the rights granted by the Law "On Personal Data Protection", complaint to the Ukrainian Parliament Commissioner for Human Rights.
- Turkey (KVKK): the rights under Article 11, complaint to the KVKK.
- Georgia, Moldova, Serbia, Kazakhstan and other states with GDPR-aligned statutes: the equivalent access, correction, deletion and objection rights under national law.
29.7. Middle East, Africa and Asia-Pacific
- United Arab Emirates (PDPL), Saudi Arabia (PDPL), Qatar, Bahrain, Oman, Kuwait, Israel: access, correction, deletion, restriction, portability and objection, complaint to the competent national authority.
- South Africa (POPIA): access, correction, deletion and objection, complaint to the Information Regulator.
- Japan (APPI), South Korea (PIPA), Australia (Privacy Act), New Zealand, Singapore (PDPA), India (DPDP Act): the access, correction, deletion, withdrawal-of-consent and complaint rights granted by those statutes.
29.8. How to exercise your rights
Write to [email protected], stating the right you wish to exercise and which product you use. If you use the Extension or the desktop app, include the installation identifier shown under Settings → About; in the mobile app, use Settings → Account (or Delete account for deletion). Those identifiers let us find your data without asking you for identity documents.
We respond within 30 calendar days, extendable by a further 30 days for complex requests, with notice to you. Exercising these rights is free of charge, except for manifestly unfounded or excessive repeat requests.
30. Minors
None of our products is directed to persons under 18, and we do not knowingly collect their data. The app-store listings are not rated for children and are not part of any children's programme. If we learn that we hold a minor's data, we will delete it. A parent or guardian may write to [email protected].
31. Changes to this Policy
We may update this Policy. The current version is always published at https://auctiongate.io/us/policy with its version number and date, and it is the version linked from every Chrome Web Store listing in Annex A, from the App Store and Google Play listings of Bidder Tools, and from the desktop download page. If a change materially affects the categories of data collected or the purposes of processing, we will announce it on the Site and inside the products and, where the law requires, ask for your consent again.
32. Contact
PAR SOFT, INC. (AuctionGate) 2810 North Church Street, PMB 29208, Wilmington, Delaware 19802-4447, USA Privacy: [email protected] · Support: [email protected]
For data processed by a white-label licensee in its own customer relationship, you may also contact that licensee directly using the details in Annex A. If you believe your rights have not been properly addressed, you may lodge a complaint with the data-protection supervisory authority of your country of residence.
ANNEXES
Annex A — Products covered by this Policy
Browser extensions. Each is published in the Chrome Web Store by the developer account auctiongate.io, is built from the AuctionGate code base and is covered by this Policy.
| # | Extension | Extension ID | White-label licensee | Partner domain |
|---|---|---|---|---|
| 1 | AuctionGate | ehpiejnmbdjkaplmbafaejdhodalfbie |
PAR SOFT, INC. (first-party) | auctiongate.io |
| 2 | Mitridat | fdljkckkhebjnbafdhanaakmmcjfkgjd |
Mitridat | mitridat-container.com |
| 3 | INTERALEX | caeecapkhmfakmcoppaimhpbfcgogjhj |
INTERALEX | auctiongate.io |
| 4 | Hernandez Auto Auction | oijclklaeblnkiokkgokednjnhkleffj |
Hernández Auto Import (El Salvador) | hernandezimport.com |
| 5 | GoJo Shipping | cffbjmjkcdfnjomcbacmmblapkpdjpjn |
GoJo Shipping | gojoshipping.com |
| 6 | Carex Auto | ckdmhlppeelklealkgefdeghcpbgjgjc |
Carex Auto | crx.ge |
| 7 | الحوت الأزرق | philabpkooplanbpnnfapdcohlcmmnkj |
الحوت الأزرق | auctiongate.io |
| 8 | BidPro | mnccalhaiokngcimjfngngjjggdhibpp |
BidPro | auctiongate.io |
| 9 | BIDAUTO-Live | enmiifnbfamffpkiaifbjhofhgomhhnp |
BIDAUTO-Live | bidauto.online |
| 10 | Bex Auto | ieipllemffmocmcmjfnijlgfecalpcgn |
Bex Auto | bex-auto.com |
Other products.
| Product | Platform | Identifier | Publisher |
|---|---|---|---|
| Bidder Tools | iOS | App Store ID 1574651674, bundle org.bidder.tool.app |
PAR SOFT, INC. |
| Bidder Tools | Android | Package com.konstantingreen.BidderTool |
PAR SOFT, INC. |
| AuctionGate Desktop | macOS | Signed and notarised as "PAR Soft, inc" (Team ID 839DG2LNQZ) | PAR SOFT, INC. |
| AuctionGate Desktop | Windows | Signed with an organisation-validated certificate issued to PAR SOFT, INC. | PAR SOFT, INC. |
| The Site | Web | auctiongate.io and subdomains | PAR SOFT, INC. |
Annex B — Categories of processors
| Category | Purpose | Location of processing |
|---|---|---|
| Cloud hosting and managed databases | Operating the services and storing data | European Union (Germany), United States |
| Content delivery, DNS and DDoS protection | Delivery, availability and security | Global edge network |
| Payment processing | Subscriptions and invoicing | United States, European Union |
| Transactional email | Account, security and service messages | United States, European Union |
| Push notification delivery (APNs, Firebase Cloud Messaging) | Delivering notifications to your device | United States, European Union |
| Error and crash tracking (including Firebase Crashlytics) | Diagnosing faults | European Union, United States |
| Customer-support helpdesk | Handling your requests | European Union, United States |
| Google LLC / Google Ireland Ltd | Google Analytics 4 and Firebase measurement | United States, European Union |
| Meta Platforms, Inc. / Meta Platforms Ireland Ltd | Meta Pixel and Meta SDK measurement | United States, European Union |
| Carriers, shipping lines, forwarders, terminals, customs brokers | Arranging and tracking the physical shipment of your vehicle | Varies by route |
A current list naming each provider is available on request at [email protected].
Annex C — Data-type declarations published in the app stores (Bidder Tools)
This annex states what we declare in Apple's privacy labels and Google Play's Data safety form, so that the declarations and this Policy match.
Apple App Store — privacy labels
| Bucket | Data types |
|---|---|
| Data used to track you | Identifiers (advertising identifier) — only where you grant ATT permission; otherwise none |
| Data linked to you | Contact info (name, email, phone); Identifiers (user ID, device ID); Purchases (purchase history); User content (documents and notes you upload); Usage data (product interaction); Diagnostics |
| Data not linked to you | Diagnostics (crash and performance data); Usage data collected before sign-in; coarse location derived from IP for regional settings |
Google Play — Data safety
| Data type | Collected | Shared | Purpose |
|---|---|---|---|
| Personal info (name, email, phone, user ID) | Yes | No | Account management, app functionality |
| Financial info (purchase history) | Yes | No | App functionality, subscription management |
| Location (approximate, from IP) | Yes | No | Regional settings, fraud prevention |
| Files and docs (documents you upload) | Yes | No | App functionality |
| App activity (interactions, in-app search) | Yes | Yes (Google, Meta — pseudonymous events) | Analytics, advertising measurement |
| App info and performance (crash logs, diagnostics) | Yes | Yes (Google) | Diagnostics |
| Device or other IDs | Yes | Yes (Google, Meta) | Analytics, advertising measurement, fraud prevention |
All data is encrypted in transit. You can request deletion of your data in the app (Settings → Account → Delete account) or through the web form linked from our Play listing. The app requests no sensitive or restricted permissions and is not directed to children.