Version 2026-08-04 · Effective August 4, 2026
What we collect, and the shorter list of what we do with it.
This policy covers VIN Index: vinindex.ai, the dealer subdomains and custom domains we publish on, our dashboard, and our agent endpoint.
It is worth being precise about roles up front, because we sit on both sides of one and that shapes every answer below.
For a dealership's own account and business information, we are the organization responsible. For a car shopper who submits an inquiry on a dealer's listing page, the dealership is the organization responsible, and we handle that inquiry on their instructions in order to deliver it to them. If you are a shopper with a question about your inquiry, the dealership you contacted is the right first stop, and we will help them answer you.
This page also serves as the notice given at or before the point of collection under California law.
Contents
- 1. What we collect from a dealer
- 2. What we take from your inventory feed
- 3. What we collect when someone submits an inquiry
- 4. What we log about visits, and what we deliberately do not
- 5. Credit bands, and what we are not
- 6. Why we use what we collect
- 7. What we never do with any of it
- 8. Who else processes it
- 9. Where information is held
- 10. How long we keep it
- 11. Your rights, and how to exercise them
- 12. US state privacy rights
- 13. Security, and what happens if we get it wrong
- 14. Children
- 15. Changes to this policy
1. What we collect from a dealer
When a dealership signs up and uses the service, we collect:
- Account details: the work email that owns the account and a password, which is stored hashed by our authentication provider and is never visible to us.
- Business profile: dealership name, street address, city, region, postal code, phone, website, brand, and where applicable the dealer licence or registration number. Some of this is prefilled from a one-time read of your own public website, which you consent to at signup.
- Geographic coordinates derived once from the business address you give us, so your listings carry a correct location and market comparisons are regional rather than national. These describe a dealership, not a person, and we do not collect the precise location of any individual.
- Feed connection details, including the host and credentials for the inventory source you nominate.
- Billing information: your plan, billing period, currency, and a customer identifier from our payment processor. Card numbers go to the processor directly and are never stored on our systems.
- Your consent record: which version of the terms and this policy you accepted, and when.
- Configuration you enter, including lead destination, branding, and on paid plans your lender rate settings.
2. What we take from your inventory feed
We ingest the vehicle records your feed sends: VIN, stock number, specification, mileage, price, description, and photographs, which we re-host so they load quickly and stay available. We store a snapshot of each feed payload so we can tell what changed and avoid reprocessing what did not.
This is business data about vehicles, not personal information about people. If your feed contains personal information, for example a salesperson's name in a free-text description, it is published as part of that listing, so do not put anything in a feed you would not want on a public page.
3. What we collect when someone submits an inquiry
A lead form on a dealer's listing page collects the name, email, phone, and message the shopper enters, along with the vehicle they were looking at and how they arrived.
We store that inquiry and deliver it to the dealership, by email or to their CRM. The dealership decides how it is then used and how long they keep it. We keep our copy so the dealer has a record and so delivery failures can be retried and audited.
We do not sell inquiries, broker them, share them with any other dealership, or use them to market anything of our own. This is not only a policy: charging for or reselling leads would break the model the whole product is built on.
4. What we log about visits, and what we deliberately do not
The point of this product is telling a dealer that AI systems are reading and citing their inventory. That takes measurement, so it is worth stating exactly how much.
When a page on a dealer surface is requested, we may write one row recording: which dealer, which vehicle, what kind of visitor it was (a crawler, a verified agent, a person arriving from an AI answer, or an agent tool call), which AI platform it is attributable to, the referring URL, the path, the browser or bot user agent string, and the time.
We do not log IP addresses. There is no column for one. We do not build a profile of a visitor, we do not track anyone across sites, we do not run advertising or analytics tags from third parties on dealer surfaces, and we do not use cookies to recognize a returning person.
One first-party cookie is used, and only for attribution. When an AI crawler or a verified agent fetches a vehicle page, we set a cookie named __ai_ref that holds the name of that platform and nothing else. It lives for five minutes, it is read once and then cleared, and its only job is to connect the AI system that looked at a page to the person who arrives moments later with no referring URL. It carries no identifier and cannot be read by JavaScript or by another site.
On our own marketing site we use the same first-party, server-side measurement. There are no third-party trackers there either.
5. Credit bands, and what we are not
Some pages let a shopper pick a credit band, such as excellent or rebuilding, to see a realistic estimated monthly payment. That selection is something the shopper tells us about themselves in order to get useful arithmetic back. It is not a credit check.
We do not pull your credit. We do not obtain, request, or receive a consumer report or a credit score about you from anyone, we are not a consumer reporting agency, and choosing a band has no effect of any kind on your credit. Nothing on this platform runs a credit application.
A self-selected band is never attached to your identity in anything we publish or analyse. Where we report on shopping patterns, credit band appears only as an aggregate dimension across many people and is never joined to a name, an email, or an inquiry.
6. Why we use what we collect
We use the information above to do the things the service exists to do, and not for other purposes:
- To publish a dealership's inventory across its listing pages, agent endpoint, category pages, and syndication feeds.
- To deliver buyer inquiries to the dealership they were sent to.
- To show a dealership which AI systems read and cited their inventory.
- To bill for a plan, and to send service messages about an account.
- To keep the platform working and secure, including detecting abuse and diagnosing failures.
- To meet legal, tax, and record-keeping obligations.
7. What we never do with any of it
Some of these are commercially tempting, which is why they are written down.
- We never sell personal information, and we do not share it for cross-context behavioural advertising. Under the US state privacy laws that give those phrases a defined meaning, we do neither, and we have not in the preceding 12 months.
- We never publish a dealer's lender rates or rate sheets, in any form. Not as an aggregate, not as a market study, not anonymized. They are calculator input and nothing else.
- Buyer inquiry data never reaches any published dataset, report, or study we produce. Where we publish research about AI shopping behaviour, it is built from aggregated and de-identified request patterns, never from inquiry records.
- Free-text a person typed, such as a natural-language search, is never republished verbatim. Only extracted patterns are used.
- We never send buyer personal information to a language model. The enrichment step that writes listing copy sees vehicle and market data only.
- We do not use personal information to make automated decisions that produce legal or similarly significant effects about anyone.
8. Who else processes it
We use a small set of service providers, each for a stated purpose and under an agreement that limits them to it. None of them is permitted to use the information for their own purposes.
- Supabase: database and authentication. Holds dealer accounts, inventory, inquiries, and analytics.
- Vercel: application hosting and content delivery for every page we serve.
- Cloudflare R2: storage for re-hosted vehicle photographs and generated syndication feed files.
- Stripe: payment processing and subscription billing. Card data goes to Stripe and not to us.
- Resend: transactional email, including delivering inquiries to dealerships.
- Anthropic: generating listing copy from vehicle and market facts. Vehicle data only, never buyer data.
- Firecrawl: the one-time read of a dealer's public website at signup, to prefill their profile.
- MarketCheck: VIN decoding and market context for vehicles.
- Google Maps Platform: converting a dealership address to coordinates once at signup.
- The NHTSA vPIC database: public VIN validation.
9. Where information is held
Our infrastructure and our service providers operate in Canada and the United States, and information may be processed in either country. While it is in another country it is subject to the laws of that country, including lawful access by its courts and authorities.
Where information leaves the country it was collected in, it stays protected by our agreements with those providers and remains subject to this policy. We remain accountable for it.
10. How long we keep it
We keep information only as long as it serves the purpose it was collected for, or as long as the law requires. In practice that means:
- Dealer account, profile, and configuration data: for as long as the account is open, then for up to seven years, which is the tax and business-record retention period that applies to us.
- Consent records: for as long as the account is open and for seven years afterwards, because the point of a consent record is being able to show what was agreed and when.
- Buyer inquiries: kept for the dealership's use while their account is open, and deleted on request from the dealership or the individual.
- Feed snapshots: kept only while they are useful for detecting what changed, and then discarded.
- Visit rows: kept in detail for 24 months, then retained only in aggregate, which carries no identifiers by construction.
- Billing records: for the seven-year period tax law requires.
11. Your rights, and how to exercise them
Write to hello@vinindex.ai and mark it for the Privacy Officer. That address reaches the person accountable for privacy here, and it is the route for every request described in this section and the next. A postal address is available on request.
You can ask us for access to the personal information we hold about you, ask us to correct anything inaccurate, ask us to delete it, ask for a portable copy, and withdraw a consent you previously gave, subject to the limits the law puts on each of those. Withdrawing consent may mean we can no longer provide part of the service, and we will tell you plainly if that is the case rather than letting it fail quietly.
We acknowledge requests within 10 business days. We respond substantively within 30 days for requests under Canadian federal privacy law, and within 45 days for requests under a US state privacy law, with one further extension where the statute allows it and we tell you why. We do not charge for this.
We need to be able to tell it is you. We verify a request against information we already hold rather than asking you for new identity documents, and if we genuinely cannot verify you we will say so rather than handing your information to someone else.
If you think we have got something wrong, tell us and we will look at it again. You can also complain to the Office of the Privacy Commissioner of Canada, or to your state Attorney General, and you do not have to come to us first.
12. US state privacy rights
If you live in California, Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Montana, or another state with a comprehensive privacy law, this section sets out what those laws give you and how our practices map onto their defined terms.
The categories of personal information we collect, in the statutory vocabulary, are: identifiers (name, email address, phone number, account identifier); customer records information (name, address, phone number); commercial information (plan, billing history, and the vehicle someone inquired about); internet or other electronic network activity information (the path requested, the referring URL, and the user agent string); and professional information (a person's role at a dealership). We collect these from you directly, from a dealership that gave them to us, from a dealer's inventory feed, from a one-time read of a dealer's own public website, and from the request itself when a page is fetched.
We do not collect biometric information, precise geolocation of an individual, sensory data, education records, or protected classification characteristics, and we do not generate inferences or profiles about anyone. The only category of sensitive personal information we hold is a dealer account credential, used solely to log that dealer in. We do not use or disclose sensitive personal information for any purpose beyond providing the service, so the right to limit its use has nothing to act on here.
You have the right to know and access what we hold, to correct it, to delete it, to obtain a portable copy, and to opt out of sale, sharing, targeted advertising, and profiling. On that last one: we do not sell personal information, we do not share it for cross-context behavioural advertising, we do not use it for targeted advertising, and we do not profile anyone, so there is nothing here to opt out of. We do not serve third-party advertising trackers, so a Global Privacy Control signal has nothing on our surfaces to act against, and we do not override one.
If we refuse a request, we will tell you why, and you may appeal by replying to that decision. We will respond to an appeal in writing within 45 days. If we deny the appeal we will give you a way to complain to your state Attorney General.
An authorized agent may make a request for you if you give them written permission and we can verify it. We will never deny you a service, charge you a different price, or give you a lower quality of service because you exercised a privacy right.
We do not sell or share the personal information of anyone under 16, and we have no actual knowledge of ever having done so.
13. Security, and what happens if we get it wrong
Access to the database is denied by default and granted per row, so one dealer's data is not reachable from another dealer's session. Administrative credentials are used only on the server and are never sent to a browser. Traffic is encrypted in transit. Passwords are stored hashed. Webhooks we send are signed so the receiver can verify them.
No system is perfectly secure, and we will not claim otherwise.
If a breach of our safeguards creates a real risk of significant harm to you, we will notify you and report it to the Office of the Privacy Commissioner of Canada, and to any US state regulator the law requires, as soon as feasible. We keep a record of every breach of security safeguards for at least 24 months, whether or not it was reportable, and we will give that record to the Commissioner on request.
14. Children
This service is for dealerships and for adults shopping for a vehicle. It is not directed to children, and we do not knowingly collect information from them. If you believe a child has given us information, tell us and we will delete it.
15. Changes to this policy
This policy carries a version. When we make a substantive change we publish a new version and ask dealers to accept it. The version a dealer accepted, and when, is recorded on their account.
We review this page at least once every 12 months and update the version stamp when we do, so the date at the top is a date someone actually looked, not the date the file was created.
Privacy questions and requests
Write to hello@vinindex.ai, marked for the Privacy Officer. That is the designated contact accountable for privacy at VIN Index, and it is where access, correction, deletion, portability, and appeal requests should go. A postal address is available on request.
You can also complain to the Office of the Privacy Commissioner of Canada, or to your state Attorney General, without contacting us first.
This page describes our own practices. Each dealership publishing through us has its own privacy practices for the information you send it directly.
Version 2026-08-04 · Effective August 4, 2026