Privacy Policy

Last updated: February 2026

1. Introduction

vindecode.app ("we," "our," or "us") provides window sticker management services and VIN decoding tools for auto dealerships, including through our website and Chrome extension. This Privacy Policy explains how we collect, use, and protect information when you use our services.

2. Information We Collect

Website & Dealer Service

We collect information that you provide directly to us:

  • Contact information (name, email address)
  • Dealership information (dealership name, address)
  • Vehicle Identification Numbers (VINs) for window sticker retrieval
  • Vehicle inventory data
  • Communications you send to us

Chrome Extension

When using our Chrome extension, the following data is collected locally on your device:

  • VINs you enter manually or that are auto-detected on web pages
  • Cached VIN decode results (expires after 24 hours)
  • Extension preferences and settings (e.g., VIN highlighting toggle)
  • Dealer authentication token (if signed in)
  • Recent VIN history

We do not collect browsing history, personal information, analytics data, or location data through the extension.

3. How We Use Information

Website & Dealer Service

We use the information we collect to:

  • Retrieve and display window stickers for your vehicles
  • Provide inventory management features
  • Generate shareable links for window stickers
  • Improve our services
  • Comply with legal obligations

Chrome Extension

  • VINs are sent to the NHTSA API (vpic.nhtsa.dot.gov), a free public U.S. government service, for decoding
  • For signed-in dealers, VINs and authentication tokens are sent to vindecode.app for window sticker generation
  • If you click to view a vehicle history report, the VIN is passed to carVertical (carvertical.com) via a link opened in a new tab. No data is sent to carVertical automatically
  • All network requests are made over HTTPS

4. Information Sharing

We do not sell your personal information. We may share information with:

  • OEM data providers to retrieve window sticker information
  • Service providers who assist our operations
  • Authorities when required by law

Chrome Extension

The Chrome extension transmits data only to:

  • NHTSA API (vpic.nhtsa.dot.gov) — for VIN decoding
  • vindecode.app — for dealer authentication and window sticker generation (dealer users only)
  • carVertical (carvertical.com) — only when you explicitly click to view a vehicle history report

No data is shared with advertisers or analytics providers.

5. Data Storage (Chrome Extension)

All extension data is stored locally on your device using Chrome's built-in storage API (chrome.storage.local). No extension data is stored on external servers beyond what is necessary to provide the dealer window sticker service. Uninstalling the extension removes all locally stored data.

6. Data Retention

We retain VIN and vehicle information for the period necessary to provide our services. Contact information may be retained to maintain business relationships and provide ongoing service.

7. Security

We implement appropriate technical and organizational measures to protect the information we collect. However, no method of transmission over the Internet is completely secure.

8. Your Rights

Depending on your location, you may have rights regarding your personal information, including the right to access, correct, or delete your data. Contact us to exercise these rights.

9. Contact Us

If you have questions about this Privacy Policy, please contact us through the contact form on our website.