Privacy policy

Privacy with explicit boundaries

This policy explains what the marketplace processes, why it is needed, who can access it, and how retention, export, and deletion are handled.

Effective August 9, 2026

Information collected

The service processes account and profile details, authentication and security events, notification preferences, seller-provided listing information, original photos, coarse public location, favorites and saved searches, private conversations, reports and appeals, payment records for platform advertising fees, and operational request data.

Verification may include optional phone challenges, encrypted full VIN data, derived VIN checks, possession evidence, private evidence metadata, Cloudflare bot-challenge results, country-level network location, and limited network or device signals used to prevent abuse. Public listing responses expose only city/state, VIN last four when allowed, specific verification signals, and authorized listing media—not a precise address, full VIN, identity document, or private evidence.

How information is used

Data supports account security, listing publication, search and distance calculations, buyer tools, private messaging, notification delivery, platform-fee checkout and receipts, verification, abuse and fraud prevention, moderation, appeals, support, service reliability, and legal compliance. Hotjar behavior analytics may process page visits, clicks, scrolling, and browser or device details to help improve usability. Product analytics use minimized events; private message surfaces are suppressed and sensitive verification evidence is not included.

Chrome listing importer

The optional Airstream Buy Sell Listing Importer reads only a supported seller-listing page selected by the user. It may process the listing title, seller description, asking price, source URL, listing details, and up to 24 listing photos to create a private Airstream Buy Sell draft. Nothing is published automatically.

The extension stores the prepared import temporarily in local Chrome extension storage and sends it to Airstream Buy Sell only after the user selects the import action. Temporary extension data is removed after a successful handoff. The extension does not sell imported data, use it for personalized advertising or credit decisions, or load executable code from remote servers. Use of browser-permission data is limited to providing and improving the user-facing import feature.

Automated safety analysis and human access

Versioned deterministic rules and selected providers may assess listing, account, message, and URL signals. These systems may warn, rate limit, reduce distribution, quarantine, or open a staff case; permanent severe enforcement requires authorized human action. Access to private messages or evidence is role-limited, purpose-bound, and audited where required. Messages are not a general-purpose model training corpus.

Providers and disclosure

Configured providers may process only the information needed for hosting, managed PostgreSQL, private object storage, transactional email, optional phone verification, Cloudflare bot and country checks, VIN data checks, malicious-link checks, Stripe platform-fee checkout, error monitoring, and uptime monitoring. Data may also be disclosed to behavior-analytics providers such as Hotjar, comply with law, protect users or the service, or complete a user-directed request.

Retention, deletion, export, and legal hold

Account and marketplace records are retained while needed to provide the service and for documented security, fraud, financial, dispute, and legal purposes. Sensitive possession evidence and network windows use shorter configured retention periods and are physically purged. Deletion removes access and schedules eligible data for deletion; append-only financial, moderation, security, and audit records may be retained or minimized when required. A lawful legal hold can pause deletion for the affected records only.

Sold listing pages and seller-authorized listing text and photos may remain public as historical archives. Account deletion removes the seller's public identity and live verification signals from those archives, while the archived listing content may remain subject to correction, privacy, legal, safety, and intellectual-property removal requests. Available and sale-pending listings are withdrawn when an account is deleted.

Authenticated users can request a portable export and account deletion through account settings. Identity must be re-established before a sensitive export or deletion is completed.

Security and choices

The service uses encrypted transport, HTTP-only sessions, access controls, private storage, encryption or isolation for sensitive verification data, request limits, and audit records. No system is risk-free. Users can manage notification preferences, block accounts, report content, and contact support about access, correction, export, deletion, or privacy questions.