Privacy Policy
Last updated: 24 September 2026
This policy explains what personal data Flipilo collects, why, how long we keep it and what rights you have. Flipilo is a service that finds used cars listed for sale in the UK and estimates how their asking prices compare with similar cars. It is currently in a closed beta.
1. Who we are
Flipilo is a service operated by Michu Ltd. Şti. (full legal name: MICHU YİYECEK İÇECEK GIDA HİZMETLERİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ), a company registered in Türkiye, with its address at İkitelli OSB, Başakşehir, 34490 Istanbul, Türkiye, which is the controller of your personal data. You can contact us about anything in this policy at [email protected].
2. Data we collect and why
2.1 When you request access
The access request form on our website asks for your name, email address, postcode, how you buy cars, and optionally how many cars you buy a month, your budget, your mobile number and a free text message. We also record the IP address the request came from and the time it was sent. We use this to review your request, contact you about it and, if approved, set up your account. The IP address is used only to stop automated abuse of the form (we limit how many requests one connection can send per hour) and is deleted after 30 days.
Lawful basis: steps taken at your request before entering into a contract, and our legitimate interest in protecting the form from abuse.
2.2 Your account and signing in
Accounts are created by us; there is no public sign-up. For each account we store your email address (which is how you sign in), an internal member name, whether the account is active or suspended, whether it is an administrator, when it was created, when you last signed in and when you confirmed your sign-in email. Some early accounts also have a 4 digit PIN, stored only as a salted, one-way hash, never in readable form.
Sign-in links. To sign in you enter your email address and we email you a link that works once. The link contains a random code; we store only a one-way hash of that code, with the account it belongs to and when it was created, expires and was used. Sign-in links expire after 15 minutes (a welcome link sent when we create your account expires after 72 hours). If you change your sign-in email, we send a link to the new address and store the new address with that link until you confirm it. We only send an email if the address belongs to an account, but the page shows the same message either way so nobody can find out whether an address has an account. Expired links are deleted within a day.
Devices. When you sign in we create a random session token, store it on our server and place it in a cookie on your device (see our Cookie Policy). An account can be signed in on up to 2 devices; signing in on a third signs out the one used longest ago, together with its notification subscription. With each session we store the time it was created and last used, how you signed in (email link or PIN), a short device label worked out from your browser's user agent (for example "Safari on iPhone"), the country your connection came from as reported by Cloudflare, and your IP address shortened to its network (the last part is removed, for example 81.2.69.0/24), so you and we can tell your devices apart.
Protecting accounts and the service. To stop abuse we limit how many sign-in links can be requested per email address and per connection, and how many car pages each member can open per day (currently 300). The sign-in and request limits are counted in memory only and never written to disk. For the daily limit we store which listings you opened on each day, deleted after 2 days. For each day you use the service we store the shortened networks and countries you connected from, deleted after 30 days. We use these to raise a flag for our review if an account hits the daily limit, is used from more than 2 networks or more than 1 country in a day, or replaces its devices more than 3 times in a week, which can indicate a shared or compromised account. A flag records the reason and date; we review flags ourselves and no decision is made about you automatically. Flags are kept for 12 months or until your account is deleted. For PIN sign-in we also count failed attempts per member name, with the time of the last attempt, and temporarily lock sign-in after repeated failures; this counter does not record your IP address and is cleared after a successful sign-in.
Bot check. The sign-in page may use Cloudflare Turnstile to check that a person, not a bot, is asking for a sign-in link. Turnstile runs in a small frame loaded from challenges.cloudflare.com and processes technical signals from your browser and device, together with your IP address, to tell people from bots. It does not see what you type into our page, and we do not use Turnstile's optional pre-clearance cookie.
Lawful basis: performance of our contract with you (providing the service), and our legitimate interest in keeping accounts and the service secure and preventing account sharing.
2.3 Using the service
To provide the service we store, linked to your username:
- the alerts you set up (a name, your search filters, which can include your postcode and its approximate map coordinates, and your alert thresholds);
- the cars you star to follow, with the date and the price at the time;
- a record of the cars each alert has matched, when a notification was sent and whether you have opened it.
When you type a postcode to search by distance, it is sent to our server and looked up with postcodes.io (a free UK postcode service) to get its approximate coordinates. We send only the postcode itself, not your name or IP address.
Lawful basis: performance of our contract with you.
2.4 Notifications
If you turn on notifications, your browser creates a push subscription. We store its endpoint address and encryption keys, a shortened copy of your browser's user agent string (so you can tell your devices apart), when it was created and when a notification was last delivered. The notification itself is delivered by your browser maker's push service (for example Apple, Google or Mozilla), which receives the encrypted message and the endpoint address. You can turn notifications off in your browser or device settings at any time.
Lawful basis: performance of our contract with you. We only send notifications you have asked for.
2.5 Area check and valuation on our public pages
Our public page lets anyone check how many deals are near a postcode and value a car. We do not store the postcodes or car details entered there. A postcode entered in the area check is looked up with postcodes.io in the same way as in section 2.3. To limit abuse we keep a short-lived, in-memory count of recent requests per IP address; it is not written to disk and is lost when our server restarts.
2.6 Site usage statistics
We use Cloudflare Web Analytics to understand how our website is used, for example how many people visit a page. It works through a small script loaded from static.cloudflareinsights.com. It does not set cookies or use local storage, does not build a profile of you and does not follow you across other websites. We only see aggregated figures. We also count visits and requests from our own server logs (see 2.7), without storing IP addresses anywhere else.
Lawful basis: our legitimate interest in understanding and improving our website.
2.7 Server logs
Like most websites, our web server records each request: the IP address, the time, the page requested (without search parameters), the browser's user agent and the response. We use these logs to keep the service running and secure. Web server logs are deleted after 14 days; application logs after 7 days.
Lawful basis: our legitimate interest in operating a secure and reliable service.
3. Data about car sellers
Flipilo reads car adverts that sellers have published openly on third party marketplaces, currently mainly AutoTrader. For each advert we store the vehicle details (make, model, year, mileage, registration year, price and price history, history and MOT information shown in the advert), the advert's link and reference number, the town it is listed in, whether it is a private or trade seller, a reference to the main photo, and the seller's description text. We do not store sellers' names, phone numbers or email addresses as separate data. The description text is written by the seller, and in some cases a seller may have included personal details in it.
We show this information to our members so they can find and assess cars for sale, and we use it to estimate market prices. Photos are loaded directly from the marketplace's own image servers and are not copied to ours. Members contact sellers through the original advert; Flipilo never contacts sellers.
Lawful basis: our legitimate interest, and that of our members, in finding and comparing cars that sellers have chosen to advertise publicly for sale. We consider the impact on sellers is low because the data is limited to what they published to attract buyers, and it is used for that same purpose. Sellers can object at any time using the contact details above, and we will remove their advert data unless we have a compelling reason not to.
To help filter out damaged, modified or unsuitable cars, advert titles and description text (not any member's data) are sent to an AI model provider through OpenRouter, which classifies the text and returns the result.
4. Who we share data with
We do not sell personal data and we do not use it for advertising. We use the following service providers, who process data on our behalf or as needed to deliver the service:
| Provider | What they do | Data involved | Location |
|---|---|---|---|
| Hostinger International Ltd | Hosts our server and database | All data described in this policy | Lithuania (EU) |
| Cloudflare, Inc. | Security and network delivery in front of our website | IP address, request details, cookies in transit | Global, including the USA |
| Cloudflare, Inc. (Web Analytics) | Aggregated statistics on how our website is used | Page visited, referrer, browser type and IP address as seen in the request; no cookies | Global, including the USA |
| Apple, Google, Mozilla and other browser push services | Deliver notifications to your device | Push endpoint and encrypted notification | Global, including the USA |
| Resend (Plus Five Five, Inc.) | Sends our sign-in and account emails | Your email address and the email content, which includes a sign-in link | EU (Ireland) for sending; company in the USA |
| Cloudflare, Inc. (Turnstile) | Bot check on the sign-in page | IP address and technical browser and device signals; not what you type | Global, including the USA |
| postcodes.io | Converts a postcode into approximate coordinates | The postcode only | UK |
| OpenRouter and the AI model providers it routes to | Classifies public advert text | Advert title and seller description text only, no member data | USA |
We may also disclose data if required by law, or to protect our rights, our users or the public.
5. International transfers
Our server is in the European Economic Area, which the UK recognises as providing adequate protection. Some providers above process data in the USA or elsewhere. Where they do, we rely on the UK Extension to the EU US Data Privacy Framework where the provider is certified, or on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses included in the provider's data processing terms.
6. How long we keep data
| Data | How long |
|---|---|
| Access requests | IP address: 30 days. Other details: until we have decided on the request, then 12 months after the decision if declined, or for as long as your account exists if approved. You can ask us to delete them sooner. |
| Account, alerts, starred cars and alert matches | For as long as your account exists. Deleted within 30 days of the account being closed, except where we must keep something by law. |
| Session tokens and device details | Up to 90 days after last use, until you sign out, or until the session is replaced by a newer device. |
| Sign-in links | Valid for 15 minutes (welcome links 72 hours), deleted within a day after expiry. Only a hash is stored. |
| Daily car views | 2 days. |
| Shortened network and country per day of use | 30 days. |
| Abuse flags | 12 months, or until your account is deleted. |
| Failed sign-in counter | Cleared on your next successful sign-in. |
| Push subscriptions | Until you turn notifications off, the subscription stops working, or your account is closed. |
| Web server logs / application logs | 14 days / 7 days. |
| In-memory request limits | Until the server restarts, never written to disk. |
| Backups | Daily backups of our database are kept on our server for 7 days, then deleted automatically. |
| Car advert data | Kept while the advert is live and afterwards as market price history, used to estimate prices. |
7. Security
All traffic is encrypted with HTTPS. PINs are stored only as salted hashes, and sign-in links only as one-way hashes. Session cookies cannot be read by page scripts. Administrators must have signed in within the last 24 hours before they can suspend or delete accounts, reset devices, change sign-in emails or change keys.
8. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict how we use your data;
- object to processing based on legitimate interests;
- receive data you gave us in a portable format, where processing is based on contract.
To use any of these rights, email [email protected]. We will reply within one month. There is normally no fee.
9. Complaints
If you are unhappy with how we handle your data, please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator: ico.org.uk/make-a-complaint, telephone 0303 123 1113.
10. Changes to this policy
We will update this page when our practices change and change the date at the top. If a change materially affects you, we will tell you in the app or by email.