Privacy Policy

Last updated: April 2, 2026

This Privacy Policy describes how Warehouse Tire Direct ("we," "us," or "our") collects, uses, and protects information from users of the Fitment API ("Service"). By using our Service, you consent to the data practices described in this policy.

1. Information We Collect

Account Information

When you request API access, we collect:

  • Your name
  • Email address
  • Company or organization name
  • Business type and intended use case
  • Website or application URL (if provided)

API Usage Data

When you use the Service, we automatically collect:

  • API requests made (endpoints called, parameters used)
  • Request timestamps and frequency
  • IP addresses from which requests originate
  • API key identifiers
  • Response status codes and latency
  • User-agent strings and client identifiers

Technical Information

We may also collect:

  • Error logs and debugging information
  • Rate limit events and quota usage
  • Browser and device information when accessing documentation or dashboards

2. How We Use Your Information

We use the information we collect for the following purposes:

Account Management

  • To create and manage your API account
  • To authenticate API requests
  • To communicate with you about your account, including service updates and support
  • To process payments and manage your subscription (if applicable)

Service Operation

  • To provide, maintain, and improve the Service
  • To monitor system performance and reliability
  • To diagnose technical issues and errors
  • To enforce usage limits and quotas

Abuse Prevention

  • To detect and prevent unauthorized access, scraping, or abuse
  • To identify patterns indicating Terms of Service violations
  • To protect the integrity and security of our data and systems
  • To investigate and respond to suspicious activity

Service Improvement

  • To analyze usage patterns and optimize API performance
  • To identify popular endpoints and improve data coverage
  • To develop new features and capabilities
  • To create aggregate, anonymized statistics about Service usage

3. Data Storage & Retention

Where We Store Data

Your data is stored on secure servers located in the United States. We use industry-standard cloud infrastructure providers with appropriate security certifications.

How Long We Keep Data

  • Account information: Retained for the duration of your account, plus 12 months after termination
  • API usage logs: Retained for 90 days in detailed form, then aggregated
  • Aggregated analytics: May be retained indefinitely in anonymized form
  • Security and abuse logs: Retained for up to 24 months

Data Backup

We maintain regular backups to ensure data integrity and business continuity. Backups are encrypted and subject to the same security controls as primary data.

4. Data Sharing

We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes. Your data is not used for advertising or shared with data brokers.

When We May Share Data

We may share your information only in the following circumstances:

  • With service providers who assist in operating our Service (hosting, payment processing) under strict confidentiality agreements
  • If required by law, subpoena, court order, or government request
  • To protect our rights, property, or safety, or that of our users or the public
  • In connection with a merger, acquisition, or sale of assets (with notice to affected users)
  • With your explicit consent

Aggregated Data

We may share aggregated, anonymized data that cannot reasonably be used to identify you. For example, we may publish statistics about API usage patterns or popular vehicle models.

5. Data Security

We implement appropriate technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction:

  • API keys are transmitted over encrypted connections (HTTPS/TLS)
  • Sensitive data is encrypted at rest using industry-standard algorithms
  • Access to user data is restricted to authorized personnel only
  • We conduct regular security reviews and vulnerability assessments
  • API access includes rate limiting and abuse detection systems
  • We maintain incident response procedures for security events

While we strive to protect your information, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your API key.

6. Your Rights

Depending on your location, you may have certain rights regarding your personal data:

Access

You can request a copy of the personal information we hold about you. We will provide this information in a commonly used electronic format.

Correction

You can request that we correct inaccurate or incomplete personal information. You may update your account information directly or contact us for assistance.

Deletion

You can request deletion of your account and personal information. Note that:

  • Some data may be retained as required by law or for legitimate business purposes
  • Aggregated, anonymized data that cannot identify you may be retained
  • Deletion requests will be processed within 30 days

Data Portability

You can request your data in a structured, machine-readable format for transfer to another service.

Objection

You can object to certain processing of your personal data. We will consider your request and respond within 30 days.

To exercise any of these rights, contact us at privacy@warehousetiredirect.com

7. Cookies & Tracking

The API itself does not use cookies. However, if you access our documentation, dashboard, or website, we may use:

  • Essential cookies required for site functionality
  • Analytics cookies to understand how our documentation is used
  • Session cookies to maintain your login state

You can control cookie settings through your browser. Disabling cookies may affect some features of our website but will not affect API functionality.

8. Third-Party Services

Our Service may integrate with or link to third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

Third parties we may use include:

  • Cloud hosting providers (for infrastructure)
  • Payment processors (for subscription billing)
  • Analytics services (for usage insights)
  • Email services (for communications)

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses where required.

10. Children's Privacy

The Service is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on this page with a new "Last Updated" date
  • Sending notice to your registered email address
  • Displaying a notice when you access the Service

Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us: