Privacy Policy
Auto AI Services · Estimate Auditor for CCC ONE · Effective 14 August 2026
This explains exactly what the Estimate Auditor reads, what it keeps, and what it never keeps. It is written to be checked against the product rather than to cover us — where a sentence below says we do not collect something, the software does not have the code to do it.
What the product does
The Estimate Auditor is a Chrome extension and a hosted service. On a repair estimate you have open in CCC ONE, it reads the written estimate, checks it against repair-procedure rules and the vehicle's own federal equipment record, and proposes lines that appear to be missing. Nothing is added to an estimate unless you tick it and press Apply.
What we collect
From your CCC ONE estimate
When you press Audit this estimate, the extension reads the open workfile and sends the following to our service so the audit can run:
- The line items on the estimate — operation, part, labour hours, amounts
- The vehicle — year, make, model, and the VIN (see below)
- Your labour and material rates, so proposed lines are priced at your rates
- Your part-code list, so a proposed line lands on a code you actually use
- The workfile number and your CCC shop number
We do not read, request, or receive the vehicle owner's name, address, telephone number, email address, insurance claim number, or policy number. The extension does not look at those fields. They are not part of an estimate audit, so they are not part of what crosses the wire.
We also never receive payment card details — see Payments.
The VIN, specifically
The VIN is sent to our service and used once, to ask the U.S. National Highway Traffic Safety Administration's public vPIC database which equipment the manufacturer built into that vehicle — which is how the audit knows whether a car has, for example, a camera that requires calibration after a windshield replacement.
The VIN is not stored. What we cache is the build pattern: VIN positions 1–8 and 10–11. That is the segment describing the make, model, body, engine and model year, and it deliberately excludes position 9 and positions 12–17 — the check digit and the serial number, which are the parts unique to one individual vehicle. Thousands of vehicles share a build pattern, and it cannot be resolved back to a car, an owner, or an address. It is cached so the same build is not looked up twice.
Against each completed audit we record a plain description such as “2022 GMC Sierra”, never the VIN.
About your shop
| What | Why |
|---|---|
| Email address and shop name | Your account, and how we reach you about it |
| Estimator names you add | So each audit is credited to whoever ran it. First names are enough, and this is optional — audits run and are counted without it |
| Browser and operating system of each connected computer | Shown on your Settings page so you can recognise a computer and disconnect one |
| Audits run, findings produced, and what you accepted | Your dashboards, and the count your subscription is billed on |
We never store your part-code price list. It is used to derive a map of which of your codes each rule should write to, and we keep that map and a fingerprint of the list — not the list. Your labour rates and margins are yours.
How we use it
To run audits, show you your own results, count usage against your subscription, and improve the rules. Rule improvement uses aggregate patterns across shops — for example, that a particular operation has no matching code in many catalogues. It does not involve reading one shop's estimates to inform another's.
We do not sell your data, share it with insurers or carriers, or use it for advertising. We do not use it to train third-party or general-purpose AI models.
Who else processes it
We use a small number of service providers, each for one job:
| Provider | For | Where |
|---|---|---|
| Google Cloud Run | Running the service | United States (us-east1) |
| Neon | The database | United States (us-east-1) |
| Clerk | Sign-in and accounts | United States |
| Stripe | Subscriptions and payment | United States |
| NHTSA vPIC | The federal equipment lookup | United States (a public government database) |
Payments
Subscriptions are handled by Stripe. Card details are entered on Stripe's own hosted checkout and never reach our servers. We store only Stripe's customer and subscription identifiers, and the number of audits you have run.
Retention and deletion
Audit history is kept while your account is open, because it is the record your dashboards are built from and shops refer back to past jobs. You can ask us to delete your account and everything associated with it at any time, and we will do so within 30 days.
Removing an estimator deactivates them rather than deleting them, so audits they already ran keep their attribution. Say so if you want a person's name removed entirely and we will remove it.
Disconnecting a computer revokes its access immediately.
Your choices
- Naming estimators is optional. Audits run and are billed the same without it.
- Any connected computer can be disconnected from Settings, at once.
- You can request a copy of your data, or its deletion, at the address below.
Security
Everything travels over TLS. Each connected browser holds a revocable token rather than your password, and only a hash of that token is stored — a copy of our database does not yield a working credential. Access to production data is limited to Auto AI Services personnel who need it.
Limited use of Chrome Web Store data
Our use of information received from Google APIs, and of data obtained through the Chrome extension, adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Specifically: the extension collects estimate data solely to provide the audit feature; it is not sold, not transferred except to the service providers listed above, not used for advertising, and not read by humans except with your permission, to resolve a problem you have reported, or where required by law.
Children
This is a tool for collision repair businesses. It is not directed to anyone under 18 and we do not knowingly collect data from children.
Changes
If we change this policy we will update the date at the top, and we will tell account holders by email before any change that materially affects what we collect or how we use it.
Contact
Questions, a copy of your data, or a deletion request: support@estimateaudits.com.