Introduction
JP Sheet ("we", "us", "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit jpsheet.com or use our auction sheet verification services.
By using our website or services, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use our services.
💡 We never sell your personal data to third parties. Your information is only used to deliver the services you have requested.
Data Controller
JP Sheet is operated by List Networks Ltd, a company registered in England and Wales.
List Networks Ltd is the data controller responsible for your personal data collected through jpsheet.com. As a UK-registered company we are subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Information We Collect
We collect the following categories of information when you use our services:
Personal Information
- Name and email address — provided by you at checkout or during account registration
- Phone number — if you contact us via WhatsApp or our support form
- Country — collected for service delivery and fraud prevention
Vehicle Information
- Chassis number (frame number) you enter for verification
- Vehicle make, model and year — retrieved from auction databases based on your chassis
Payment Information
- Payment is processed by Stripe and PayPal — we never store your full card number or payment credentials on our servers
- We retain a payment reference, transaction ID, and amount for order records
Usage Data
- IP address, browser type, pages visited, and time spent on pages
- Referring URL and device type — used to improve our service
Authentication Data
- If you log in via Google or Facebook OAuth, we receive your name, email and profile photo from that provider — we do not store your social media password
How We Use Your Information
- Service delivery — to verify chassis numbers, process payments, and deliver your auction sheet report
- Order management — to track your orders, manage credits, and process refund requests
- Customer support — to respond to your enquiries and resolve issues
- Email delivery — to send your report, order confirmation, and support replies to the email you provided
- Fraud prevention — to detect and prevent fraudulent transactions and abuse of our service
- Service improvement — to analyse usage patterns and improve our website and verification accuracy
- Legal compliance — to comply with applicable laws and regulations
We do not use your information for unsolicited marketing without your explicit consent. You can unsubscribe from any marketing email using the link in that email.
Information Sharing & Disclosure
We do not sell, rent or trade your personal information. We may share it only in the following limited circumstances:
- Payment processors — Stripe and PayPal receive your payment details to process transactions. Their own privacy policies govern how they handle this data.
- Authentication providers — Google and Facebook receive a login request when you choose OAuth login. They do not receive your report or vehicle data.
- AI services (Google Gemini) — when you use our chassis decoder photo upload or AI-powered insights, the chassis code or image is sent to Google Gemini AI for processing. See AI & Photo Uploads below for full details.
- Hosting infrastructure — our web server provider (Namecheap/cPanel) stores website files and databases under industry-standard security.
- Legal requirements — we may disclose information if required by law, court order, or lawful request from government authorities.
- Business transfer — if JP Sheet is acquired or merged, your data may be transferred as part of that transaction, subject to the same privacy protections.
AI & Photo Uploads
Our free chassis decoder at /chassis-decoder/ uses Google Gemini AI to provide two features: extracting chassis numbers from photos you upload, and generating buyer's insights for chassis codes not in our verified database.
What we send to Google Gemini AI:
- Photo extraction: the image you upload (auction sheet, chassis plate, dashboard, etc.) — sent as a base64-encoded image to the Gemini API for one-time text reading
- AI insights: the chassis code you entered (e.g.
BNR34) and the country selected for import eligibility
What we do NOT send to AI:
- Your name, email address, phone number, or country (other than as part of import eligibility query)
- Your IP address (Google sees the request from our server, not from you directly)
- Your browsing history, account data, or order records
- Payment information of any kind
Photo handling:
- Uploaded images are sent securely (HTTPS) to Google Gemini API
- Images are processed once and immediately discarded — we do not store, archive, or reuse them
- We do not view or manually inspect uploaded photos
- The extracted chassis number (text only) may be temporarily cached on our servers for up to 90 days to improve response time for repeat searches
Google's data practices: Google Gemini operates under Google's Generative AI Terms of Service and Google Privacy Policy. According to Google's terms for paid API access (which JP Sheet uses), customer data is not used to train Google's models.
Your rights:
- The chassis decoder is fully usable WITHOUT photo upload — manual entry never invokes AI
- You can decline AI insights by ignoring the AI-generated section of any result page
- If you'd prefer a non-AI verification, our $7 auction sheet verification service uses verified database records only — no AI involved
🤖 All AI-generated content on JP Sheet is clearly labelled with an "AI-inferred" or "AI-generated" badge. Use AI insights as a starting point — always verify the actual auction sheet before purchase.
Cookies & Tracking
We use cookies and similar technologies to operate our website and improve your experience:
- Session cookies — to keep you logged in during your visit
- Preference cookies — to remember your settings (e.g. dark/light mode)
- Analytics cookies — to understand how visitors use our site (anonymised data)
- Payment cookies — set by Stripe or PayPal during checkout to secure the transaction
You can disable cookies in your browser settings. Disabling cookies may affect the functionality of our checkout and login systems.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Below is our detailed retention schedule:
- Verified report data — stored permanently (lifetime). This is the core product you purchased — your permanent link must always work.
- Order & payment records — 7 years (legal requirement for financial records)
- Account & profile data — while account is active, plus 90 days after deletion request
- Email address (for support) — 5 years after your last purchase or interaction
- Support tickets & chat history — 2 years for quality assurance and dispute resolution
- Failed verification attempts — 30 days, then auto-deleted
- Abandoned checkout data — 90 days, then auto-deleted
- Cookie / analytics data — 14 months (Google Analytics standard)
- Marketing cookie data — 90 days (Facebook Pixel, TikTok Pixel, Google Ads)
- IP logs & server logs — 12 months for security purposes
- Fraud-related records — 7 years to prevent repeat fraud and comply with legal obligations
Right to deletion: You may request deletion of your personal data at any time by emailing [email protected]. We will action your request within 30 days. Note that some data may need to be retained longer if required by law (e.g. tax records, fraud prevention).
After deletion: Identifiable personal data is permanently erased. Anonymized statistical data (e.g. "X reports verified in March 2026") may be retained indefinitely as it contains no personally identifying information.
Data Security
- All data transmitted to and from our website is encrypted using HTTPS / TLS
- Payment data is handled by PCI-DSS Level 1 certified processors (Stripe and PayPal)
- Database access is restricted to authorised personnel only
- We use firewalls, access controls and regular security audits to protect our systems
- Passwords are never stored in plain text
Despite these measures, no internet transmission is 100% secure. If you believe your data has been compromised, contact us immediately at [email protected].
Your Rights
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — request correction of inaccurate or incomplete data
- Right to erasure — request deletion of your personal data ("right to be forgotten")
- Right to restriction — request that we limit how we use your data
- Right to portability — request a copy of your data in a machine-readable format
- Right to object — object to our processing of your data for marketing purposes
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional rights regarding your personal information.
Your California Rights:
- Right to know — request disclosure of what personal information we collect, use, share or sell about you in the prior 12 months
- Right to delete — request deletion of personal information we have collected from you, subject to certain exceptions
- Right to correct — request correction of inaccurate personal information
- Right to opt-out of sale or sharing — direct us to not "sell" or "share" your personal information
- Right to limit use of sensitive personal information — restrict use of sensitive data to what is reasonably necessary
- Right to non-discrimination — we will not deny services, charge different prices, or provide a different quality of service if you exercise your rights
- Right to data portability — receive your personal information in a portable, machine-readable format
Do We "Sell" Personal Information?
JP Sheet does not sell personal information for monetary consideration. However, under CCPA's broad definition of "sharing", our use of marketing cookies (Meta/Facebook Pixel, TikTok Pixel, Google Ads) may be considered "sharing" for cross-context behavioural advertising purposes.
You may opt out of this "sharing" at any time by:
- Clicking Cookie Settings and disabling "Marketing & Advertising"
- Using the "Cookie Settings" link in our footer
- Emailing [email protected] with the subject line "Do Not Sell or Share My Information"
Sensitive Personal Information:
We do not collect "sensitive personal information" as defined by CPRA (such as government IDs, financial account details, precise geolocation, biometric data, health data, etc.) beyond what is strictly necessary to process payments and deliver our verification service.
How to Submit a Request:
California residents can exercise these rights by emailing [email protected] with the subject line "California Privacy Request". We may need to verify your identity (typically through your registered email address). We will respond within 45 days.
Authorized Agents:
You may designate an authorized agent to submit requests on your behalf. We will require written proof of authorization and verification of your identity.
Minors:
We do not knowingly sell or share the personal information of consumers under 16 years of age.
International Data Transfers
JP Sheet is headquartered in the United Arab Emirates, with operations supporting customers in 14+ countries. Your personal data may be transferred to and processed in:
- UAE — our primary servers and customer support operations
- Pakistan — secondary support team
- Japan — for retrieving auction records from our partner networks
- United States — for hosted analytics (Google) and marketing platforms (Meta, Google Ads, TikTok)
- European Union — for some payment processing (Stripe, PayPal)
For transfers from the EU/UK, we rely on Standard Contractual Clauses (SCCs) and/or adequacy decisions where applicable. You may request a copy of these safeguards by contacting us.
Children's Privacy
Our services are not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
Third-Party Links
Our website may contain links to third-party websites (e.g. auction houses, payment providers, social media). We are not responsible for the privacy practices of these websites. We recommend reading their privacy policies before providing any personal information.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. We will post the updated policy on this page with a revised "Last Updated" date. We encourage you to review this page periodically.
Continued use of our services after any changes constitutes your acceptance of the updated policy.