Legal
Privacy Policy
Contents
- 1. Who we are
- 2. Information we collect
- 3. How we use information
- 4. Legal basis (GDPR)
- 5. When we share information
- 6. Third-party processors we use
- 7. We do not sell personal data
- 8. Cookies and analytics
- 9. Data retention
- 10. Your privacy rights
- 11. Children's privacy
- 12. International transfers
- 13. Security
- 14. Changes to this policy
- 15. Contact
This Privacy Policy explains how VinAssessment ("VinAssessment", "we", "us") collects, uses, and protects information when you visit vinassessment.com, use our dashboard, install our Chrome Extension, or call our APIs and MCP server (the "Services"). We wrote this in plain English. If anything reads ambiguously, ask us at [email protected] and we'll clarify.
1. Who we are
VinAssessment is the controller of the personal data described in this policy. We operate a dealer-software and automotive-data platform headquartered in the United States, serving dealerships and developers in the US and (where lawful) internationally.
2. Information we collect
Information you give us
- Account info — name, email, phone, dealership name, role, and the password (hashed) for your account.
- Billing info — billing address, tax ID, and the last 4 digits + expiry of your payment card. Full card numbers go directly to our payment processor (Stripe) and never touch our servers.
- Inventory & usage data — VINs you save, vehicles you upload, custom stickers you generate, and the searches you run inside our tools.
- Support content — anything you email, attach, or write to us during a support conversation.
Information we collect automatically
- Device & log data — IP address, browser type, OS, referring URL, pages visited, time spent. We use this for security, debugging, and product analytics.
- Cookies & similar technologies — see Section 8 below.
- API & MCP request metadata — endpoint, parameters, response code, latency, account ID. We use this to enforce rate limits, troubleshoot, and improve performance.
Information from third parties
- Public automotive data — listings, auction records, window stickers, dealer inventories. This is vehicle data, not personal data about you, but it powers our product and is described in our Terms.
- Verification & anti-fraud — Cloudflare Turnstile signals when you submit a form, and limited signals from payment processors.
3. How we use information
- Deliver, maintain, and improve the Services you signed up for.
- Process payments, send invoices, and prevent payment fraud.
- Send essential service emails (billing, security, plan changes, outages).
- Send product updates and tips — only to addresses we have a legitimate reason to email; you can opt out at any time.
- Provide customer support and respond to your inquiries.
- Detect, prevent, and investigate abuse, fraud, or security incidents.
- Comply with legal obligations and enforce our Terms.
4. Legal basis (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on one or more of the following legal bases: performance of a contract (delivering the Services you signed up for), legitimate interests (security, product analytics, fraud prevention), legal obligation (tax, accounting, court orders), and consent (where required — for example, certain analytics cookies).
5. When we share information
We share personal data only with:
- Service providers we hire to operate the platform (see Section 6). They are bound by confidentiality and may use the data only for the limited purpose we specify.
- Other people in your organization if you are part of a multi-seat account — admins can see seat usage and roster information.
- Legal authorities when required by valid legal process, or to protect rights, safety, and the integrity of the Services.
- A successor entity in a merger, acquisition, financing, or sale of assets. We will notify you of any change in controller.
6. Third-party processors we use
We rely on the following sub-processors. Each is bound by a Data Processing Agreement (DPA) with terms at least as strict as this Policy.
- Stripe — payment processing and card storage.
- Cloudflare — DNS, CDN, DDoS protection, and bot-verification (Turnstile).
- SendGrid (Twilio) — transactional email delivery.
- Bugsnag — application error monitoring (we strip secrets before logging).
- Amazon Web Services and bare-metal hosting partners — infrastructure hosting in the United States.
- Anthropic — powers the AI chat features (only the prompts you send to the chat are forwarded; account credentials are not).
We update this list as the platform evolves. The current sub-processor list is available on request.
7. We do not sell personal data
We do not sell or rent your personal data to advertisers, brokers, or any third party. We have never sold personal data, and we have no plans to. We also do not use your inventory, customer, or VIN data to compete with you or sell it on to your competitors.
8. Cookies and analytics
We use a small number of cookies:
- Essential — session, CSRF protection, login state, dark-mode preference, billing-period toggle. These cannot be turned off without breaking the site.
- Analytics — anonymous or pseudonymous metrics that help us see how the site performs and where people get stuck. We do not use advertising cookies or third-party ad trackers.
Most browsers let you block cookies, but doing so may break parts of the site (you would be signed out, for example).
9. Data retention
Active account data is retained while your account is active. After cancellation, we retain account and billing records for as long as needed to comply with tax, accounting, and dispute-resolution requirements (typically 7 years for billing). Inventory and usage data is purged from working systems within 90 days of account closure, except where law or an open dispute requires longer.
10. Your privacy rights
Depending on where you live, you may have rights to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete data ("right to be forgotten"), subject to legal exceptions.
- Export your data in a portable format.
- Object to or restrict processing, including for direct marketing.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email [email protected] from the address on your account. We respond within 30 days. California residents have additional rights under the CCPA / CPRA, including the right to know what we collect and the right to opt out of any sale or share (we do neither). You may also lodge a complaint with your local data-protection authority.
11. Children's privacy
The Services are intended for use by dealership employees and developers. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us personal data, contact us and we will delete it.
12. International transfers
Our infrastructure is hosted in the United States. If you access the Services from outside the US, your data will be transferred to and processed in the US. Where required by law (EEA, UK, Switzerland), we rely on Standard Contractual Clauses and equivalent transfer mechanisms with our sub-processors.
13. Security
We protect personal data with industry-standard controls: HTTPS everywhere, encryption at rest for backups, role-based access controls, audit logging, least-privilege engineering access, and routine security review. No system is perfectly secure — if you ever spot a vulnerability, please disclose it responsibly to [email protected] and we will respond within one business day.
14. Changes to this policy
We may update this Policy as the platform and applicable laws evolve. Material changes will be announced at least thirty (30) days before they take effect, by email to account contacts and by notice on this page. The "Last updated" date at the top always reflects the current revision.
15. Contact
Privacy questions, deletion requests, or anything you'd like us to clarify: [email protected]. We will reply from a real human — see our About page for our standing commitment on that.