Skip to content
VINLytix

Legal

Privacy Policy

What happens to the VIN you type, in plain language before the formal version.

Last updated: this policy describes the service as currently built. It should be reviewed by a qualified legal professional before commercial launch, and adapted to the operating entity and jurisdiction.

1. Who we are

VINLytix provides vehicle information reports derived from a Vehicle Identification Number. Contact: support@vinlytix.com.

2. What we collect

Vehicle Identification Numbers

When you request a report, the VIN is transmitted to our server and used to query the NHTSA vPIC and recall APIs. It is not written to a database, not associated with you, and not retained after the request completes.

Because a VIN identifies a specific vehicle, we treat it carefully by design: it is sent in a POST request body rather than a URL query string, so it does not appear in server access logs, browser history or the Referer header sent to third parties.

Optional details you supply

Mileage, ZIP code, asking price and listing details are used only to compute your report and are handled exactly as the VIN is: processed, returned, not retained.

Report storage

Your completed report — including the full VIN, so you can refine the report without retyping it — is stored in your browser’s sessionStorage. This is per-tab, stays on your device, is never transmitted to us, and is discarded when you close the tab.

Technical data

Our hosting provider processes standard request information such as IP address and user agent for delivery and security. To rate-limit expensive external API calls, IP addresses are hashed with a per-process random value and held in memory only — the rate-limit table cannot be read back as a list of visitor addresses, and it is lost when the process restarts.

3. What we do not do

  • We do not sell or rent any information.
  • We do not build profiles of vehicles or of the people who look them up.
  • We do not publish VIN-indexed pages that could be found by searching a VIN.
  • We do not send full VINs to analytics or advertising services.
  • We do not require an account, so we hold no credentials.

4. Cookies and analytics

This deployment uses Google Analytics to understand aggregate usage. It is configured with Google Consent Mode defaults set to denied before any tag loads, and IP anonymisation enabled. No VIN or report content is transmitted to it.

The site is built to be compatible with a Google-certified Consent Management Platform for visitors in the EEA, the UK and Switzerland. We have deliberately not shipped a cookie banner that does not actually control anything — a banner that gates nothing is worse than no banner, because it implies a protection that is not there.

This deployment shows no advertising and loads no advertising scripts.

5. Third parties

To produce a report, the VIN and derived vehicle details are sent to the National Highway Traffic Safety Administration’s public APIs. NHTSA is a US federal agency and its handling of requests is governed by its own policies.

If a market valuation or vehicle history provider is connected in future, relevant vehicle details would be sent to that provider to produce those sections. The data sources page always reflects which providers are currently active.

6. Data retention

VINs and the details you supply are not retained after your request completes. Reports are retained only in your own browser tab, under your control. Hashed rate-limit entries expire within minutes and exist only in server memory.

7. Your rights

Depending on where you live, you may have rights to access, correct, delete or port personal data held about you, and to object to processing. Because VINLytix operates without accounts and does not retain VINs or the details you supply, in practice there is usually nothing held about you to act on. If you believe otherwise, write to support@vinlytix.com and we will tell you precisely what exists.

8. Children

VINLytix is not directed at children and we do not knowingly collect information from them.

9. Security

Traffic is served over HTTPS. Provider API keys are held server-side only and are never exposed to the browser. Because we do not store VINs or personal data, the volume of information at risk in any incident is deliberately minimal — the strongest privacy protection available is not holding the data in the first place.

10. Changes

Material changes to this policy will be reflected on this page. Connecting a new data provider counts as material and will be reflected here and on Data Sources.