Legal

Privacy policy

Last updated 2 October 2026Effective 1 September 2026

The short version

We collect your email, the VINs you check and what you bought. Our servers keep a request log, including your IP address for 30 days, to keep the service secure and to see which pages bring people here. If you allow it, we also record what happens on the page, as a replay we can watch back with everything you type blanked out. We use all of that to see which screens break, not to build a profile of you, and we never sell personal data. Vehicle records are about cars, not people, and we strip any owner detail that reaches us. You can export or delete your account from Settings, or by emailing us.

1. What we collect

Four categories, and nothing else:

  • Account data. Your email address, and a display name if you sign in with Google or Apple. Authentication is handled by Firebase Authentication; we never see or store your password.
  • Product data. The VINs you check, the reports you’ve unlocked, the vehicles you’ve saved, and your preferences. This is what lets you reopen a report you paid for.
  • Server logs. Every request to this website is logged on our own servers: your IP address, the approximate country, region and city the network resolves it to, your browser and device type, the page you arrived on, the site or search that sent you, and the time. It is how we keep the service secure, find abuse and automated scraping, and see which pages actually bring people here. It is not a cookie and nothing is stored on your device for it, which is why there is no switch for it below. We keep the IP address itself for 30 days and then erase it automatically, leaving a one-way scrambled form we cannot turn back into an address.
  • Diagnostic data. Product events (a check ran, a paywall was seen, a report was purchased) and crash reports, through PostHog. The set is deliberately small on both our mobile apps and this website, and automatic capture of every click is switched off on both: what we record is a fixed list of moments we chose, not everything you touch. On this website, if you allow it, PostHog also records the pages you open, any error the site throws, and a replay of the visit we can watch back. Everything you type into a field is blanked out of that replay, and so is your email address where a page shows it. Once you are signed in, this activity is held against your account rather than anonymously.

We do not collect precise location, contacts, photos, or advertising identifiers, and Vinrack carries no third-party advertising SDKs.

Payment details are not on that list. Card numbers, billing addresses and tax identifiers are entered on Whop, our merchant of record, and never reach this site or our servers. What comes back to us is the order: which VIN was bought, the email it was bought with, and whether the payment succeeded.

2. Vehicle records are about cars

The records we compile describe vehicles: specifications, recalls, listings, prices, mileage readings, title and accident indicators. They are keyed to a VIN, not to a person.

Where a source record happens to carry a name, a signature or a street address, we drop those fields at ingestion rather than storing them. Dealer names and business addresses are commercial information and are kept, because a buyer needs to know which lot a car sat on.

Not a consumer report. Vinrack is not a consumer reporting agency and our data may not be used for employment, tenancy, insurance underwriting or credit decisions.

3. Why we process it

  • To run the Service. Returning a check, delivering a report you bought, and keeping it reachable afterwards.
  • To take payment. Recording which vehicle a purchase unlocked, so a report can’t be charged twice or lost with a device.
  • To keep it working. Diagnosing crashes and slow endpoints, and finding abuse or automated scraping.
  • To keep it secure. Recording who called our servers, so a rejected payment webhook, a rate limit being hit repeatedly, or a form being flooded can be investigated rather than guessed at.
  • To know where you found us. Counting which search, which site and which page brought a visit, and which of those led to a purchase, so we spend our time on the ones that work. This is counting, not profiling: it is not used to decide anything about you, it is never combined into a profile, and it is never sold or shared with an advertising network.
  • To email you. Receipts, report links and material changes to these documents. Marketing email is opt-in and separately unsubscribable.

Where GDPR applies, our bases are performance of a contract for the first two, and legitimate interests for the rest, balanced against the minimal, non-profiling nature of what we keep.

4. Who processes data for us

We use a small number of subprocessors, each bound by a data-processing agreement:

  • Google Firebase. Authentication, database and serverless functions. Hosts your account and your saved vehicles.
  • Vercel. Hosting and edge delivery for this website.
  • Google Analytics. If you allow it, audience measurement on this website: how many people open each page and how far a visit gets. It is described under "Cookies and local storage" and it loads only with your consent. We have turned off Google Signals and ad personalisation on the property, so it may not be used to build advertising audiences, and we never send it your email address or your account id.
  • Whop. Payments made on this website, and, if you allow it, purchase attribution. Whop, Inc. is our merchant of record rather than a processor acting on our instructions: it is the seller of the transaction, so for your payment, billing and tax data it is an independent controller under its own privacy policy. It passes us the order, the email you paid with and whether it succeeded. We never receive your card number. Its tracking tag, described under "Cookies and local storage", loads only with your consent, and while it is on it sends Whop your email address and account id with each of the five funnel steps listed there. It is the only measurement on this website whose recipient is not acting on our instructions.
  • RevenueCat and the app stores. Purchase verification for Full Reports bought inside our mobile apps. Nothing bought on this website goes through them.
  • PostHog. Product analytics and error tracking, on the reduced event set described above, on our mobile apps and on this website alike. On this website, if you allow it, session replay as well: a recording of the pages you open and what you do on them, with every field you type into blanked out. Its traffic is routed through vinrack.io rather than sent to a PostHog domain from your browser, which changes nothing about what it collects and does not make it exempt from your consent. It processes this for us under our instructions, it never receives your card details, and none of it is used for advertising.
  • Meta. If you allow advertising measurement, the Meta pixel described under "Cookies and local storage", and a copy of the same steps sent from our servers to Meta directly: the page, your IP address and browser, the Meta identifiers the pixel set, and, while you are signed in, your email address, first name and account id, each hashed before it leaves our servers. When you buy a Full Report, the purchase and its price are sent the same way, and only if you had allowed advertising measurement when you pressed Unlock. Meta uses it to measure and target our ads on Facebook and Instagram, under its own terms for business tools.
  • OpenAI. Generates the written summary sections of a report from record data we send. We do not send your account details, and the content is not used to train their models under our agreement.
  • Marketcheck and Visor. The two licensed vehicle-listing aggregations behind a Full Report. Each receives a VIN, and a ZIP code when a report needs comparable cars nearby. Neither receives your name, your email address or your account id, and neither is told who asked.

Data feed providers (NHTSA, the EPA, Marketcheck, Visor and the review platforms) receive a VIN or a dealer identifier from us. They receive nothing about you.

We never sell personal data. There is no data-broker relationship, and no advertising exchange, at any tier.

5. How long we keep it

  • Account and purchase records. For as long as your account exists, then up to 7 years for the transaction record where tax and accounting law requires it.
  • Check history and saved vehicles. Until you delete them, or your account.
  • Cached vehicle data. Between one hour and ninety days depending on the source, because a listing price changes hourly and a VIN decode never does.
  • IP addresses in server logs. 30 days. A scheduled job erases the address itself and keeps only a one-way scrambled form of it, which cannot be turned back into an address and is what still lets us tell a repeat visitor from a new one, or spot the same source abusing a form.
  • The rest of a server log. The page, the referrer, the country and the browser stay, because that is the record of where our traffic comes from and it stops being about you once the address is gone.
  • Diagnostic events. 12 months, then deleted.
  • Session replays. 30 days, then deleted. They exist to diagnose something that went wrong last week, not to keep a record of you, so they are the shortest-lived thing we hold.

6. Your rights

You can access, correct, export or delete your personal data. Deleting your account from Settings removes your profile, saved vehicles and check history, and is irreversible; purchase records are retained as described above.

If you’re in the EEA, the UK, California or another jurisdiction with equivalent law, you also have the right to object to processing, to restrict it, and to complain to your supervisory authority. We don’t discriminate against anyone for exercising a right.

7. Removing a vehicle record

If you believe a record we show about a vehicle is inaccurate, or that a listing of yours should not appear, email support@vinrack.io with the VIN and what’s wrong. We respond within 10 business days.

Where the record came from an upstream source we license, we correct our copy and pass the correction on, but we can’t change the source. Where a record is a public government filing, we can annotate it but we won’t suppress it.

8. Cookies and local storage

This website keeps nine things on your device, and the last six of them are optional:

  • Sign-in token (cookie, one hour). Carries your session to the server so a page can load your account. It is refreshed while you are signed in and deleted when you sign out.
  • Firebase session (browser storage). The same sign-in, held by the authentication SDK so you are still signed in tomorrow and on your second tab.
  • Language (cookie, one year). Written only when you pick a language from the switcher, so the site opens in it next time.
  • Audience measurement (Google Analytics cookies, optional). A script loaded from googletagmanager.com, and the _ga cookies it writes here for up to two years, which count how many people open each page and how far a visit gets. It is what tells us that a page is being read or that nobody reaches the second step of something. We have turned off Google Signals and ad personalisation on the property, so this traffic may not be used to build advertising audiences, and we never send Google your email address or your account id.
  • Session replay and product analytics (PostHog, optional). Identifiers PostHog stores here, and the recording they belong to: the pages you open, a fixed list of moments we chose (a check was run, a record was read, the Full Report offer was opened, Unlock was pressed, a report was read), any error the site throws, and a replay of the visit we can watch back. It is what tells us that a control was pressed three times because nothing happened, rather than that a page was merely opened. We do not log every click as its own entry: automatic capture is switched off, so the list of things recorded is one we chose rather than everything you touch. Everything you type into a field is blanked out before the recording leaves your browser, and so is your email address where a page shows it. Once you are signed in, the recording is held against your account. It shares one switch with the Google Analytics entry above, because both are the same purpose reported to processors acting on our instructions, and it is why we asked everyone again when it arrived: agreeing to be counted is not agreeing to be recorded.
  • Purchase attribution (Whop tag, optional). A script loaded from t.whop.tw, and an identifier it stores here, which record the pages you open on this site and five steps in particular: creating an account, a VIN check that returned a vehicle, opening the Full Report offer, pressing Unlock, and sending a dealer enquiry. On those five, while you are signed in, it also sends Whop your email address and your account id. Whop, Inc. sells and checks out the Full Report for us, so its checkout sits on a different domain to this one, and that is what lets an order there be matched back to the visit that led to it. We do not advertise with it and it is not shared with an ad network.
  • Advertising (TikTok pixel, optional). A script loaded from analytics.tiktok.com, and the _ttp identifier it writes here, used to measure and retarget TikTok ad campaigns against the same steps named above: creating an account, a VIN check that returned a vehicle, opening the Full Report offer, and starting checkout. While you are signed in it also sends TikTok your email address and your account id, so a conversion can be matched to a person rather than just a browser. It is one of two advertising tags on this website; the Meta pixel below is the other. In the European Economic Area and the UK it is not loaded until you say yes, the same as every optional tool above. Outside those regions it loads by default, because nothing in US law asks a business our size to gate it behind a prompt; "Cookie settings" below still turns it off for anyone who wants that, wherever they are.
  • Advertising (Meta pixel, optional). A script loaded from connect.facebook.net, and the _fbp and _fbc identifiers it writes here, used to measure and target our Facebook and Instagram ads against these steps: a VIN search, a VIN check that returned a vehicle, opening the Full Report offer, creating an account, and starting checkout. Each of those is also sent from our servers to Meta under the same reference, so the two copies count once; while you are signed in, that server copy carries your email address, first name and account id, hashed before they leave us. A Full Report purchase is sent only from our servers, after the payment, and only if this switch was on when you pressed Unlock. It shares the advertising switch with the TikTok pixel above, and loads by default outside the European Economic Area and the UK for the same reason.
  • Referral credit (vinrack_aff cookie, optional). Written only when you arrive through a link that carries a referrer's code (an ?a= in the address), and kept for 30 days. It holds that code and nothing else: no identifier of yours, and nothing about what you looked at. If you buy a Full Report within those 30 days, the code is sent to Whop with the order so the person who sent you is paid their commission. It shares the attribution switch with Whop's tag above because it serves the same purpose, telling the merchant of record where an order came from, and it loads no script.

The first three are exempt from consent under the ePrivacy Directive: they are storage you asked for by signing in or by choosing a language, and none can be switched off without breaking the thing it serves. The last six are not exempt. In the European Economic Area and the UK, none is loaded or written until you say yes: you did not ask to be counted, you did not ask to be recorded, and you did not ask to be recognised on a later visit or matched to your email address by an ad platform. Outside those regions, where GDPR and ePrivacy do not reach and where no US privacy law asks a business our size to gate a script behind a prompt, all six load by default rather than waiting for an answer that is not legally required — "Cookie settings" below still turns any of them off, wherever you are. Measurement and attribution are two separate switches, not one, because they are two different purposes and you may reasonably allow one and refuse the other; the two measurement tools share a switch because they are the same purpose, and Whop, TikTok and Meta share the other for the same reason, though attributing one order and building an advertising audience are different enough questions that TikTok arriving asked everybody again rather than treat an old yes as covering it, same as PostHog did, and Meta arriving asked again too. Switching the history off deletes the list immediately; switching measurement or attribution off stops any recording in progress, deletes what was stored and reloads the page, because a script already running cannot be stopped any other way.

Your answer is kept in this browser’s local storage rather than in a cookie, so it never reaches our servers and it is specific to this browser: clearing site data means we ask again. You can change it whenever you like, here or from the footer of any page:

There are two advertising tags on this website: the TikTok and Meta pixels above. Of the other three optional tools, none is an advertising tag: two count pages and record what happens on them so we can fix what breaks, and Whop's attributes a purchase without advertising anything to anyone. Until 16 September 2026 this paragraph said there were no advertising cookies and no ad networks on this website at all. That is no longer true, and the sentence is withdrawn.

We also count pages without storing anything. Separately from all of the above, our own servers log each page you open, along with the site or search that sent you, described under "What we collect". It puts nothing on your device, which is why it is not in the list of nine and why there is no switch for it: the consent rules on this page are about what is stored in your browser, and there is nothing to consent to when nothing is stored. It is a server log, kept under legitimate interest, with your IP address erased after 30 days. We are telling you about it here because it would be strange to describe nine small things kept on your device and stay quiet about the one kept on ours.

9. Children

Vinrack is not directed at children under 13 and we don’t knowingly collect their data. If you believe a child has created an account, email us and we’ll delete it.

10. Contact

Privacy & data removal

support@vinrack.io

Everything else

support@vinrack.io

Version 3.5 · superseded 3.4 (Sep 2026)