Privacy Policy

Effective date: June 01, 2025

vinstate.com ("we", "us", or "our") operates vinstate.com (the "Site"), which provides VIN lookup services. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use and share it, your rights, and how to contact us.

Quick summary:
  • Core VIN lookup features are free and available without logging in.
  • We collect VIN queries, technical data (IP, device), and optionally account info if you register.
  • We may share data with third-party providers (data suppliers, analytics). We do not guarantee third-party practices.
  • You can request access, correction, or deletion of your personal data — see the "Your rights" section.

1. Information we collect

We collect information directly from you, automatically when you use the Site, and from third parties.

A. Information you provide

  • Account information: If you register, we may collect your name, email address, password (hashed), and any profile information you provide.
  • VIN queries & inputs: VINs and other search inputs you enter into the Site. Query results and any optional notes or flags you save.
  • Support & communications: Content of emails or messages you send to us (e.g., support requests).

B. Information collected automatically

  • Usage data: pages visited, timestamps, click events, query volume and patterns, search errors.
  • Technical data: IP address, browser type and version, operating system, device identifiers, and network information.
  • Cookies & similar technologies: cookies, local storage and other technologies to recognize your device, remember preferences, and measure Site performance.

C. Information from third parties

We may receive data (such as vehicle data) from third-party data providers, public records, or partners. The accuracy of third-party data is not guaranteed by us.

2. How we use your information

We use personal and non-personal data for purposes including:

  • Providing and improving the VIN lookup service;
  • Operating your account, if you register (authentication, saved searches, notifications);
  • Detecting, preventing, and addressing fraud, abuse, security incidents and technical issues;
  • Personalizing, measuring and analyzing usage and performance (analytics);
  • Responding to support requests and communicating important notices (policy changes, security alerts);
  • Complying with legal obligations and enforcing our Terms of Service.

3. Legal bases for processing (if you are in the EEA)

If you are located in the European Economic Area (EEA), our legal bases for processing your personal data include:

  • Performance of a contract: processing necessary to provide the services you request (e.g., account management).
  • Legitimate interests: for security, fraud prevention, analytics and improving the Site — we balance these interests against your rights.
  • Consent: where required (e.g., non-essential cookies or marketing communications), we will ask for your consent.
  • Compliance with law: where required to comply with legal obligations.

4. Sharing and disclosure

We may share data with:

  • Service providers: hosting, analytics, email delivery, security, and customer support providers who process data on our behalf under contract.
  • Data providers: vehicle-data suppliers and third-party sources whose information we display or aggregate.
  • Legal & safety: if required by law, to respond to legal process, or to protect rights, property or safety.
  • Business transfers: in connection with a merger, acquisition or sale of assets, with notice and appropriate protections on personal data.

We do not sell personal information for money. If your jurisdiction uses a broader definition of “sale” (e.g., CCPA), please see the “Your rights” section for opt-out options where applicable.

5. Cookies & tracking technologies

We use cookies and similar technologies to operate the Site, remember preferences, enable account sessions, and measure performance. You can control cookie preferences via your browser settings or any on-site cookie banner (if provided). Blocking certain cookies may limit functionality.

6. Data retention

We retain personal data as long as necessary to provide the service, fulfill the purposes described in this policy, comply with legal obligations, resolve disputes, and enforce our agreements. Typical retention examples:

  • Account data: retained until you delete your account or as reasonably necessary afterwards for legal or security reasons.
  • VIN queries / logs: retained for a period to support analytics, abuse detection, and operational troubleshooting (e.g., 12–36 months), unless otherwise required by law.

If you want to request deletion of specific personal data, see the "How to contact us" section below.

7. Security

We take reasonable technical and organizational measures designed to protect personal data from accidental loss, destruction, misuse, unauthorized access, disclosure, alteration and damage. However, no service is 100% secure — we cannot guarantee absolute security. If a data incident affects you, we will notify you as required by law.

8. International transfers

Our systems and service providers are located in various countries. If we transfer your personal data outside your country (including transfers to servers in the United States), we will take steps to ensure it is protected in accordance with this Policy and applicable law (e.g., standard contractual clauses or other safeguards where required).

9. Your rights

Depending on your jurisdiction, you may have rights including:

  • Access: request a copy of personal data we hold about you.
  • Correction: request correction of inaccurate or incomplete data.
  • Deletion: request deletion of your personal data (subject to retention for legal reasons).
  • Portability: request export of your personal data in a common format.

To exercise rights, contact us at [email protected]. We may need to verify your identity before fulfilling requests. We will respond as required by applicable law.

10. Additional disclosures for California residents (CCPA/CPRA)

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know, delete, and opt out of the sale of personal information. We do not knowingly sell personal information for monetary consideration. To exercise California privacy rights, please contact [email protected].

11. Children

The Site is not intended for children under 13 (or a higher age where required). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us; we will take steps to delete the information as required by law.

12. Links to other sites

The Site may contain links to third-party websites. This Policy does not apply to those sites. We are not responsible for third-party privacy practices — please review their privacy policies.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide prominent notice (e.g., banner or email) and update the "Effective date" above. Continued use after changes constitutes acceptance of the updated Policy.

14. How to contact us

If you have questions, requests, or complaints about this Privacy Policy or our practices, contact:

Email: [email protected]

If you are a data protection authority or regulator and need additional information, please include "Privacy/Compliance Request" in the subject line.