Privacy Policy
Last updated: August 14, 2026
1. Introduction
Vinrack ("we," "our," or "us") is a vehicle verification app for iOS and Android. You paste a used-car listing link or a VIN, and Vinrack returns a report: open recalls, safety ratings, owner complaints, fuel economy, where the asking price sits against comparable listings, and the selling dealer's review score. This Privacy Policy explains what data we collect, what we don't, and how it moves between your device, our backend, and the providers that supply the underlying data.
Vinrack is built by one developer. We don't sell ads, we don't track you across other apps, and we don't sell your data.
2. How Your Data Flows
- Device ↔ Firebase (your account and history): Your account, your preferences, and the history of the vehicles you have checked are stored in Google Firebase under your user ID, governed by security rules scoped to your account.
- Device ↔ our Cloud Functions: The app never calls a third-party data provider directly. It sends the VIN or listing URL you entered to our own Firebase Cloud Functions, which call the providers below on your behalf and cache the results. This keeps provider keys off your phone and means the providers do not receive your identity or your device details.
- Cloud Functions ↔ public vehicle data (NHTSA, EPA): The VIN is sent to U.S. government APIs (NHTSA vPIC decoding, recalls, crash-test ratings and complaints, and fueleconomy.gov) to build the free part of the report. A VIN describes a vehicle, not a person, and is not sent with any account identifier.
- Cloud Functions ↔ market listing data: Vehicle attributes are sent to Marketcheck to work out where an asking price sits against comparable active listings, and to build the optional paid dossier.
- Cloud Functions ↔ dealer review sources: To score a dealership we collect its published review ratings from sources such as Google, Cars.com, BBB, and DealerRater. This is information about a business, not about you, and your identity is never attached to those requests.
- Cloud Functions ↔ OpenAI (the in-app assistant): If you use the AI assistant, the question you type plus the relevant vehicle or dealer context is sent to OpenAI to generate a reply. Your name, email, and account ID are not sent. OpenAI does not use API content to train its models.
- Device ↔ Apple / Google (sign-in): You sign in with Apple, Google, or email. The provider authenticates you and returns a token to Firebase Auth. We never see your Apple or Google password.
- On device ↔ Face ID: If you enable the app lock, authentication happens entirely on your device through Apple Face ID / Touch ID or Android biometrics. Your biometric data never leaves your device and is never sent to us.
- Device ↔ RevenueCat ↔ Apple / Google: When you buy a subscription or a paid report, the purchase is processed by the App Store or Google Play. RevenueCat reports whether your entitlement is active and receives an anonymous user ID we generate plus the store receipt data. We never see your payment method.
- Device ↔ PostHog (product analytics):The app sends a small set of anonymous behavioural events (for example "car checked," "paywall viewed") keyed to your user ID so we can understand which parts of the app work. Session recording and screen replay are disabled.
3. Information We Collect
Account information
- Email address (Apple may relay a private address)
- A Firebase Authentication user ID (UID)
- The sign-in method you used (Apple, Google, or email and password)
Your activity in the app
- The VINs and listing URLs you check, kept as your check history so you can return to a report
- Dealers you look up and reports you save
- Questions you ask the in-app assistant, and its replies, so a conversation has context
Location
- Approximate location, only while the app is in use and only if you allow it, so Vinrack can surface dealers near you first. You can decline and still check any listing or VIN.
Subscription state
- Whether your entitlement is active and its expiry, as reported by RevenueCat and the app store
Product analytics (PostHog, anonymous events)
- Event names and coarse metadata (which screens you used, whether a check was run) keyed to your user ID
- Crash and error reports without the content that triggered them
What we do NOT collect
- No advertising identifier (no IDFA-based tracking)
- No camera, photos, contacts, calendar, or microphone access
- No biometric data (Face ID / Touch ID stays on your device)
- No third-party ad networks, ad SDKs, or retargeting trackers
- No cross-app or cross-site tracking of any kind
- No session recording or screen replay
- No driver's licence, insurance, financing, or credit information. Vinrack never asks for it.
4. Tracking & Advertising
Vinrack does nottrack you across other companies' apps or websites, and does not use Apple's IDFA. The app does not present an App Tracking Transparency prompt because no cross-app tracking occurs.
5. Third-Party Services
- Google Firebase (Authentication, Firestore, Cloud Functions): hosts your account, your history, and the backend that builds a report.
- Apple: Sign in with Apple, App Store distribution, and billing.
- Google: Google Sign-In, Google Play distribution and billing, and Google Places for dealer review ratings.
- NHTSA and fueleconomy.gov: free U.S. government APIs for VIN decoding, recalls, crash-test ratings, complaints, and fuel economy.
- Marketcheck: market listing data used for price comparison and the paid dossier.
- Dealer review sources (Google, Cars.com, BBB, DealerRater): published ratings for businesses, used to compute a dealer score.
- OpenAI: generates the in-app assistant's replies. Receives your question and vehicle or dealer context, not your identity.
- RevenueCat: reports your subscription status. Receives an anonymous identifier and store receipt data. Processes data in the United States.
- PostHog: product analytics and error monitoring. Anonymous events only. Session recording disabled.
6. Data Retention & Deletion
Your account, preferences, and check history live in Vinrack so you can return to a report you have already run. You can clear individual checks in the app, and you can delete your account from settings, which removes your data from our backend and deletes your authentication record. This is irreversible. Cached vehicle and dealer data is not personal to you and expires on its own schedule.
7. Legal Basis for Processing (GDPR)
- Contractual necessity (Art. 6(1)(b)): account creation, running the checks you request, and storing your history, all necessary to provide the app.
- Consent (Art. 6(1)(a)): location access, which you grant and can withdraw.
- Legitimate interest (Art. 6(1)(f)): basic operation, caching, and abuse prevention.
8. International Data Transfers
Firebase, Marketcheck, OpenAI, RevenueCat, and PostHog process data in the United States. If you use Vinrack from outside the U.S., your data is transferred there. These providers offer Standard Contractual Clauses for cross-border transfers.
9. Your Rights
- EEA/UK (GDPR): access, portability, restriction, objection, and the right to complain to your data protection authority.
- California (CCPA/CPRA): the right to know, delete, and opt out of "sale" or "sharing." We do not sell or share your personal information.
10. Children's Privacy
Vinrack is not directed to children under 13 (or 16 in the EEA). We do not knowingly collect data from children. If you believe a child has signed up, contact us and we will delete the account.
11. Security
Authentication tokens are stored securely in the device keychain (Expo Secure Store), and you can add a biometric app lock. All traffic uses HTTPS, provider API keys live only on our server, and Firestore security rules restrict your data to your own account.
12. Changes to This Policy
We may update this Privacy Policy. Material changes will be announced on this page and, if significant, in the app.
13. Contact
Questions or requests, write to support@moetalaat.com.
