Carvana

Carvana is an online used car retailer

This page is not published. While you can access it via its direct link, it is not yet displayed on the website.

Handling

Does the policy allow personally-targeted or behavioral marketing? Yes, but you can opt-out

3.5/10

Decided May 17, 2020 (revision history). This question accounts for 12% of the final score.

Possible Options

Yes0/10
Yes, but you can opt-out3.5/10
Yes, but you must opt-in7/10
No10/10

Citation

Reasons we can share your personal information: - For our affiliates to market to you - For our nonaffiliates to market to you

Note

You can opt-out by ringing 844.732.2556 or emailing "[email protected]" with the subject and body of "Opt Out." Check for the latest information before doing such.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow third-party access to private personal data? Yes, all parties specified (including non-critical service providers such as advertisers)

3/10

Decided May 17, 2020 (revision history). This question accounts for 12% of the final score.

This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).

Note that whether the policy allows sharing aggregated user data does not affect this question.

If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).

If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).

Possible Options

Yes, not all parties specified0/10
Yes, all parties specified (including non-critical service providers such as advertisers)3/10
Yes, not all parties specified (but only to critical service providers)7/10
Yes, all parties specified (only to critical service providers)8/10
No10/10

Citation

Reasons we can share your personal information: - For our every day business purposes – such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus - For our marketing purposes – to offer our products and services to you - For joint marketing with other financial companies - For our affiliates’ everyday business purposes – information about your transactions and experiences - For our affiliates’ everyday business purposes – information about your creditworthiness - For our affiliates to market to you - For nonaffiliates to market to you

[...]

Affiliates: Companies related by common ownership or control. They can be financial and nonfinancial companies.

  • DriveTime Car Sales Company, LLC (“DriveTime”) and all institutions in the DriveTime family of companies; Bridgecrest Acceptance Corporation (“Bridgecrest Acceptance”); Bridgecrest Credit Company, LLC (“Bridgecrest Credit”); Driver’s Seat, LLC and DS Nominee Titleholder, LLC (together, “Driver’s Seat”), are affiliates. Our other affiliates include companies with the DriveTime or DT name; financial companies, such as GFC Lending, LLC d/b/a GO Financial; insurance companies such as SilverRock Group, Inc., SilverRock Insurance, LLC, Motion Telematics, LLC and nonfinancial companies, such as GO Auto Exh LLC.

Nonaffiliates: Companies not related by common ownership or control. They can be financial and nonfinancial companies.

  • Nonaffiliates we share with could include insurance companies, mortgage companies, credit card companies and direct marketing companies.

Joint Marketing: - A formal agreement between nonaffiliated financial companies that together market financial products or services to you. Our joint marketing partners could include insurance companies, automobile dealers and credit card companies.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow you to permanently delete your personal data? No

0/5

Decided May 17, 2020 (revision history). This question accounts for 6% of the final score.

Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.

Possible Options

No0/5
Yes, by contacting someone3/5
Yes, using an automated mechanism5/5
N/A (no personal information collected)5/5

Note

No information provided that supports such.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


When does the policy allow law enforcement access to personal data? Not specified

0/5

Decided May 17, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

Always0/5
Not specified0/5
When reasonably requested3/5
Only when required by a court order or subpoena4/5
N/A (no personal data to share)5/5
Never (special legal jurisdiction)5/5

Note

No information is provided.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Transparency

Does the policy require users to be notified in case of a data breach? No

0/7

Decided May 17, 2020 (revision history). This question accounts for 8% of the final score.

Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.

Possible Options

No0/7
Yes, eventually5/7
Yes, within 72 hours7/7
N/A (the service collects so little personal data that notification would not be possible)7/7

Note

There is no information mentioning the announcement of a breach.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Will affected users be notified when the policy is meaningfully changed? No

0/5

Decided May 17, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

No0/5
Yes5/5
N/A (no personal data—or contact information—collected)5/5

Note

No explicit notice shows this to happen.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Is the policy's history made available? Only the date it was last modified

3/5

Decided May 17, 2020 (revision history). This question accounts for 6% of the final score.

Possible Options

No0/5
Only the date it was last modified3/5
Yes, with revisions or a change-log5/5

Citation

Rev May 2018

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the policy outline the service's general security practices? Somewhat

1/3

Decided May 17, 2020 (revision history). This question accounts for 4% of the final score.

The policy provides only a very vague overview of its security practices.

Possible Options

No0/3
Somewhat1/3
Yes2/3
Yes, including audits2.5/3
N/A (no personal data collected)3/3
Yes, including independent audits3/3

Citation

How does Carvana protect my personal information? To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Collection

Is it clear why the service collects the personal data that it does? Yes

10/10

Decided May 17, 2020 (revision history). This question accounts for 12% of the final score.

This question deals with transparency. Even if the service uses data for reasons that aren't ideal for privacy, provided they list all of those uses, the service can still receive full credit for this question. However, if they are not explicit about their uses (by employing language like "such as"), a lower score is assigned.

Possible Options

No0/10
Somewhat4/10
Mostly7/10
Yes10/10
No personal data is collected10/10

Citation

Reasons we can share your personal information: - For our every day business purposes – such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus - For our marketing purposes – to offer our products and services to you - For joint marketing with other financial companies - For our affiliates’ everyday business purposes – information about your transactions and experiences - For our affiliates’ everyday business purposes – information about your creditworthiness - For our affiliates to market to you - For nonaffiliates to market to you

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the policy list the personal data it collects? Yes, generally

7/10

Decided May 17, 2020 (revision history). This question accounts for 12% of the final score.

All general categories of collected personal data are listed, though not all types of personal data are explicitly mentioned (for example, the list might use a phrase like 'such as' when listing types of personal data).

Possible Options

No0/10
Only summarily3/10
Yes, generally7/10
Yes, exhaustively10/10
N/A (no personal information is collected)10/10

Citation

The types of personal information we collect and share depend on the product or service you have with us. This information can include: - Social Security number and income - account balances and payment history - credit history and employment information

[...]

We collect your personal information, for example, when you - visit our website - apply for financing or give us your income information - provide employment information or give us your contact information - pay your bills

We also collect your personal information from others, such as credit bureaus, affiliates or other companies.

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service collect personal data from third parties? Only for critical data

7/10

Decided May 17, 2020 (revision history). This question accounts for 12% of the final score.

For example, a blog providing user avatars or a bank conducting identity verification

This includes the use of data brokers and independent verification authorities (such as background check providers).

Possible Options

Yes0/10
Only for critical data7/10
No10/10

Citation

  • For our every day business purposes – such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.


Does the service allow the user to control whether personal data is used or collected for non-critical purposes? On an opt-out basis, but only for some non-critical data/uses

1.5/5

Decided May 17, 2020 (revision history). This question accounts for 6% of the final score.

Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.

Possible Options

No0/5
On an opt-out basis, but only for some non-critical data/uses1.5/5
On an opt-out basis, for all non-critical data/uses3/5
N/A (no data used for non-critical purposes)5/5
On an opt-in basis5/5

Citation

[Cannot Limit] - For our every day business purposes – such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus - For our marketing purposes – to offer our products and services to you - For joint marketing with other financial companies - For our affiliates’ everyday business purposes – information about your transactions and experiences [Can Limit] - For our affiliates’ everyday business purposes – information about your creditworthiness - For our affiliates to market to you - For nonaffiliates to market to you

Click here to suggest a change or to flag this conclusion as incorrect, or here for more information.



Warnings

Carvana has no warnings published on PrivacySpy. PrivacySpy publishes warnings when it learns a service has announced a data breach or is found misusing user data. If you believe a warning should be published for Carvana, submit one here.


Highlighted Policy Snapshot ALPHA

No highlighted policy snapshot has been created for this privacy policy. To view the policy at its original location, click here.

4.2/10

How we calculate ratings →


Version Added

May 17, 2020

Ratings Updated

May 17, 2020

Warnings

0

Maintained by

doamatto

Original Location
Open in New Tab
Other Versions