Data Security Policy
Last updated: July 6, 2026
How CarfaxDeals protects your personal and payment information.
Payment Security & PCI Compliance
Card payments are handled through a PCI-DSS compliant payment gateway. Your card details are entered into secure, tokenized fields hosted by our payment processor and are transmitted directly to them. We never see, handle, or store your full card number, expiry, or security code on our own servers. Our checkout is designed to meet PCI-DSS SAQ A requirements.
Encryption in Transit
All traffic to and from our site is encrypted using TLS (HTTPS), and we enforce HTTP Strict Transport Security (HSTS). Payment tokenization and processing occur over encrypted connections.
What We Store
- Account data: your email and account/report history.
- A payment reference/transaction ID from our processor (never the card number itself).
- Vehicle history reports you have generated.
Access Controls
Access to systems and customer data is restricted to authorized personnel on a need-to-know basis, protected by authentication and least-privilege controls. Report links are protected by expiring, signed tokens.
Data Retention & Deletion
We retain personal data only as long as necessary to provide the service and meet legal obligations. You may request deletion of your account and associated personal data by emailing support@carfaxdeals.com.
Reporting a Security Concern
If you believe you have found a security vulnerability or have a concern about your data, contact us immediately at support@carfaxdeals.com.