Privacy Policy
Vinlo ("we," "our," or "us") is a car ownership app built by Andrew Kasper. This policy explains what data the app collects, how it is used, and your rights. The short version: Vinlo stores your vehicle data locally on your device. We do not require an account. We do not sell your data.
1. Data Stored Locally on Your Device
The following information is stored in a local SQLite database on your iPhone and never transmitted to our servers:
- Vehicle records you add (VIN, make, model, year, nickname, odometer, photo)
- Service log entries (date, mileage, shop, cost, notes, receipt photos)
- Recall records fetched from the NHTSA database
- Vehicle history reports purchased through the app
- Maintenance schedule data and service intervals
This data remains on your device. If you delete the app, this data is deleted with it. There is no cloud backup provided by Vinlo.
2. Data Sent to Third-Party APIs
Vinlo communicates with the following external services:
NHTSA (National Highway Traffic Safety Administration)
Your vehicle's VIN is sent to the free, public NHTSA API to decode vehicle specifications and fetch recall information. NHTSA is a U.S. government agency. Their privacy practices are governed by federal law. No personal information is sent — only the VIN.
Vinlo Report Worker (Cloudflare)
When you purchase a Vehicle History Report, your VIN and a StoreKit transaction token are sent to our Cloudflare Worker at api.getvinlo.com. The Worker validates your purchase and fetches the report from GoodCar (an NMVTIS-approved data provider). We do not log or store your VIN or transaction data beyond what is needed to complete the request. Cloudflare processes requests in accordance with their privacy policy.
GoodCar / NMVTIS
Vehicle history report data is sourced from GoodCar, which accesses the National Motor Vehicle Title Information System (NMVTIS) — the same federal database used by Carfax and AutoCheck. Only your vehicle's VIN is submitted. GoodCar's use of this data is governed by their privacy policy and federal NMVTIS regulations.
Kelly Blue Book (KBB)
The "Check Market Value" feature opens a KBB link in Safari with your VIN pre-filled. Vinlo does not have access to any data on the KBB website. KBB's privacy policy applies once you leave the app.
3. In-App Purchases
Vinlo offers a one-time app purchase ($3.99) and an optional Vehicle History Report ($6.99 per report) as an in-app purchase. All payment processing is handled exclusively by Apple through StoreKit. Vinlo never receives or stores your credit card or payment information. Apple's privacy policy governs all payment transactions.
4. Push Notifications
Vinlo uses local push notifications to alert you when a new recall is detected for your vehicle. These are generated entirely on-device by background polling of the NHTSA API. No notification data passes through Apple's Push Notification Service (APNs) — notifications are scheduled locally and never leave your device.
You can disable notifications at any time in iOS Settings → Notifications → Vinlo.
5. Analytics and Tracking
Vinlo does not use any third-party analytics, crash reporting, or advertising SDKs. We do not track your behavior in the app. We do not use cookies or similar tracking technologies.
6. Camera and Photo Library
Vinlo requests access to your camera and photo library for two purposes:
- VIN scanning: The camera is used to scan VIN barcodes and optionally capture a photo of the VIN label using on-device OCR (Apple Vision). No images are uploaded or stored externally.
- Vehicle photos: You may optionally attach a photo to your vehicle profile or service log entry. These photos are stored locally on your device.
Camera and photo access is only activated when you explicitly initiate a scan or photo action. You can revoke access at any time in iOS Settings → Privacy & Security → Camera or Photos.
7. Children's Privacy
Vinlo is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through the app, please contact us and we will take steps to delete it.
8. Data Retention
All data created by the app is stored locally on your device and is retained until you delete it from within the app or uninstall the app. Vinlo does not retain user data on our servers. Cloudflare may retain request logs for a short period in accordance with their standard practices.
9. Your Rights
Because Vinlo stores data locally on your device with no account system, you have full control over your data at all times. You can delete individual vehicles, service entries, or the entire app to remove all stored data. If you have questions about data handled by our third-party services (NHTSA, GoodCar, Cloudflare), please refer to their respective privacy policies.
10. Changes to This Policy
We may update this privacy policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.
11. Contact
Questions about this privacy policy? Contact us at:
info@getvinlo.com