1. Information We Collect
We collect the following categories of information when you use SOZOMOTO:
- Personal Identifiers: Name, email address, date of birth
- Driver's License Information: License number, state of issuance, license status
- Location Data: Street address, city, state, ZIP code
- Driving History: Years of driving experience, accident history, violations
- Financial Information: Credit score range, loan application details
- Insurance Information: Current coverage details, policy preferences
- Vehicle Interests: Cars viewed, saved vehicles, comparison history
- Usage Data: Pages visited, cars viewed, features used, session duration
2. How We Use Your Information
We use the information we collect to:
- Generate personalized insurance quotes from multiple carriers
- Facilitate loan pre-qualification with lending partners
- Calculate total vehicle ownership costs including insurance, financing, taxes, and fees
- Improve our services, features, and user experience
3. How We Share Your Information
We share your information with third-party partners only when you initiate a specific action (such as requesting a quote or applying for pre-qualification). We share data with:
- Insurance Carriers: Progressive, GEICO, State Farm, Allstate, and Liberty Mutual — to generate real-time insurance quotes
- Lending Partners: Capital One Auto, Chase Auto, Ally Financial, Bank of America, and LightStream — to facilitate loan pre-qualification
- Dealer Partners: Authorized dealerships in our network — to facilitate vehicle inquiries and purchase transactions
- AI Service Provider (Anthropic): We use Anthropic, Inc. as a data processor for two specific features:
- Personalised cost narration. Only an anonymised profile is sent: age bracket, the first three digits of your ZIP code, credit-tier band, household type, and (if applicable) the name of your current insurance carrier. Your name, exact date of birth, email, phone number, and full address are never transmitted.
- Driver's-license data extraction. When you use the “Scan License” feature on your profile page, your license image is transmitted to Anthropic's vision model to extract structured fields (name, address, license number, dates). The image is processed in memory only — it is never written to disk on our servers, never logged, and is dropped from memory the moment extraction completes. Only the extracted text fields are returned to your browser, and they are saved to your profile only after you explicitly confirm the extraction is correct.
Anthropic processes this data under contractual terms that prohibit training on customer data; their data-processing agreement is available at anthropic.com/legal/dpa.
Your data is only shared when you explicitly initiate a request. We do not sell your personal information for marketing purposes.
4. Data Retention
Your profile and associated data are retained for as long as your account remains active. Upon receiving an account deletion request, we will delete your personal data within 30 days. Audit logs and compliance records are retained for 7 years as required by applicable regulations.
5. Your Rights Under CCPA/CPRA
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request details about the personal information we collect, use, and disclose.
- Right to Delete: You may request the deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out: You may opt out of the sale or sharing of your personal information.
- Right to Non-Discrimination: You will not receive different pricing or service quality for exercising your privacy rights.
To exercise any of these rights, contact us at privacy@sozomoto.com. We will respond to verified requests within 45 days.
6. GLBA Financial Privacy Notice
In connection with loan pre-qualification services, we collect nonpublic personal information (NPI) as defined under the Gramm-Leach-Bliley Act (GLBA). This information is collected solely to facilitate loan applications with our lending partners.
NPI is protected by encryption and role-based access controls. We do not share nonpublic personal information with third parties for marketing purposes without your explicit consent.
7. Data Security
We implement the following measures to protect your data:
- Encryption at rest and in transit (TLS 1.2+)
- Role-based access controls with least-privilege principles
- Comprehensive audit logging of all data access
- Regular security reviews and vulnerability assessments
8. Children's Privacy
SOZOMOTO is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 16, we will promptly delete it.
9. Driver's License Data
We collect driver's license information for the purpose of identity verification and generating accurate insurance quotes from our carrier partners. When you use our license scan feature, the following applies:
- License images are processed entirely in-memory and are never written to disk or stored on our servers.
- Only your license number (encrypted using AES-256) and state of issuance are retained in your profile.
- Extracted fields such as name, address, and date of birth are used to pre-fill your driver profile and are subject to the same protections described in our Data Security section.
- You may delete your stored license data at any time by deleting your driver profile.
10. Data Sharing with Dealers
When you submit a lead or inquiry to a dealer through SOZOMOTO, we share only the minimum information necessary to facilitate your vehicle inquiry:
- Shared with dealers: Your name, email address, phone number, and the specific vehicle(s) you expressed interest in.
- Never shared with dealers: Your financial information, credit score range, driving history, accident or violation records, insurance details, or driver's license data.
Dealers in our network are contractually prohibited from using your information for purposes other than responding to your vehicle inquiry. They may not sell, share, or use your data for unrelated marketing without your separate, explicit consent.
11. Cookie Policy
SOZOMOTO uses a minimal set of cookies to operate the platform. The following table describes the cookies we use:
| Category | Cookie Name | Purpose | Duration |
|---|
| Essential | sozomoto_consent | Tracks your cookie consent preference | 1 year |
| Essential | supabase auth cookies | Session management and authentication | Session duration |
| Analytics | None | No analytics cookies are currently used | N/A |
| Marketing | None | No marketing cookies are currently used | N/A |
You can manage your cookie preferences at any time through our cookie consent banner or by adjusting your browser settings.
12. Automated Decision-Making
SOZOMOTO uses automated calculations to generate insurance quotes and loan pre-qualification estimates based on the information you provide in your driver profile. These automated processes work as follows:
- Insurance quotes are generated by submitting your profile data to carrier rating APIs, which return premium estimates based on their underwriting algorithms.
- Loan pre-qualification estimates are calculated using the financial information you provide and our lending partners' published rate tables.
- No fully automated decisions with legal or similarly significant effects are made without the opportunity for human review.
- You may request human review of any automated insurance quote or loan pre-qualification result by contacting us at privacy@sozomoto.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you via email at the address associated with your account. We encourage you to review this page periodically for the latest information.
14. Contact
If you have questions about this Privacy Policy or your personal data, contact us at: privacy@sozomoto.com