Your privacy matters to us. This Privacy Policy explains what information VINdicated.ai collects, how we use it, how we protect it, and what rights and choices you have. We do not sell your personal information to third parties. We do not share your deal-specific details with dealerships or automotive industry third parties.
1. Who We Are
VINdicated.ai ("VINdicated," "we," "us," or "our") is a consumer car-buying education platform headquartered in Crown Point, Indiana. We operate the website at vindicated.ai, associated tools, and a forthcoming mobile application. If you have questions about this policy, please contact us using the information in Section 14.
2. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically, and information from third parties.
2.1 Information You Provide
- Contact and Account Information: Name, email address, and phone number when you book a service, sign up for early access, or contact us.
- Payment Information: Billing details processed through our third-party payment processor (e.g., Stripe). We do not store full credit card numbers on our servers.
- Tool Inputs: Budget figures, trade-in information, vehicle preferences, dealer quotes, and similar financial inputs you enter into our calculators and tools. This data is used to generate your results and improve our tools.
- Communications: Messages, emails, or inquiries you send us, including any deal details you share with a concierge advisor.
- User-Generated Content: Feedback, reviews, or responses you submit.
2.2 Information Collected Automatically
When you visit our website or use our app, we may automatically collect:
- Log Data: IP address, browser type and version, pages visited, time and date of visit, time spent on pages, referring URL.
- Device Information: Device type, operating system, unique device identifiers.
- Cookies and Similar Technologies: See Section 7 for full details.
- Usage Data: How you interact with our tools, which features you use, and the actions you take.
2.3 Information from Third Parties
- Payment Processors: Transaction confirmations and limited billing information from Stripe or similar services.
- Analytics Providers: Aggregated and anonymized usage data from analytics platforms.
- Scheduling Tools: Appointment details from calendar or booking integrations (e.g., Calendly).
3. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Legal Basis (where applicable) |
|---|---|
| Provide, operate, and maintain our services and tools | Contractual necessity; legitimate interest |
| Process payments and fulfill service bookings | Contractual necessity |
| Send service-related communications (confirmations, receipts, updates) | Contractual necessity |
| Respond to inquiries and provide customer support | Legitimate interest |
| Send marketing communications (with your consent or where permitted by law) | Consent; legitimate interest |
| Improve and personalize our tools and content | Legitimate interest |
| Analyze usage trends and platform performance | Legitimate interest |
| Detect, prevent, and address fraud, security, or technical issues | Legitimate interest; legal obligation |
| Comply with legal obligations | Legal obligation |
| Enforce our Terms of Use | Legitimate interest; contractual necessity |
We will not use your personal information for purposes materially different from those described above without first notifying you and, where required, obtaining your consent.
4. How We Share Your Information
We do not sell your personal information. We do not share your deal-specific financial details or vehicle preferences with dealerships, manufacturers, or auto industry advertisers.
We may share your information in the following limited circumstances:
4.1 Service Providers
We share information with trusted vendors who perform services on our behalf — such as payment processing (Stripe), email delivery, analytics, scheduling, hosting, and customer support tools. These providers are contractually required to use your data only to perform services for us and to maintain appropriate security standards.
4.2 Business Transfers
If VINdicated.ai is involved in a merger, acquisition, restructuring, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our website before your information is transferred and becomes subject to a different privacy policy.
4.3 Legal Requirements
We may disclose your information if required to do so by law, court order, or government regulation, or if we believe disclosure is necessary to: (a) protect our legal rights; (b) protect the safety of our users or the public; or (c) investigate fraud or security issues.
4.4 With Your Consent
We may share your information for any other purpose with your explicit consent.
5. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. Our general retention guidelines:
- Account and contact information: Retained while your account is active and for a reasonable period afterward for business and legal purposes.
- Transaction records: Retained for a minimum of 7 years for tax and accounting compliance.
- Tool inputs and deal details: Retained for up to 30 days after session completion, then permanently deleted from our active systems unless you request earlier deletion.
- Communications: Retained for up to 3 years for quality, training, and compliance purposes.
- Analytics data: Generally retained in anonymized or aggregated form indefinitely for product improvement.
You may request deletion of your personal information at any time (see Section 9). Note that we may retain certain information as required by law or for legitimate business purposes even after deletion requests.
6. Data Security
We implement commercially reasonable technical, administrative, and physical safeguards designed to protect your personal information from unauthorized access, use, alteration, or disclosure. These measures include:
- HTTPS encryption for all data transmitted to and from our website
- Secure third-party payment processing (no full card numbers stored by us)
- Access controls limiting employee and contractor access to personal information on a need-to-know basis
- Regular security reviews
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.
7. Cookies and Tracking Technologies
7.1 Types of Cookies We Use
- Strictly Necessary: Essential for the website to function (e.g., session management, security). Cannot be disabled.
- Functional: Remember your preferences to enhance your experience (e.g., language settings).
- Analytics: Collect aggregated data about how visitors use our site (e.g., Google Analytics). Help us understand what works and improve our services.
- Marketing: Track activity across websites to serve relevant advertising. Currently limited; we will provide notice before implementing any broad retargeting programs.
7.2 Your Cookie Choices
You can control cookies through your browser settings. Most browsers allow you to refuse new cookies, be notified when new cookies are set, or delete existing cookies. Disabling strictly necessary cookies may impair site functionality. Third-party analytics can also be opted out of via tools such as the Google Analytics Opt-out Add-on.
8. Third-Party Links and Services
Our website may contain links to third-party websites, vehicle valuation tools, lender directories, and scheduling platforms. This Privacy Policy applies only to VINdicated.ai. We are not responsible for the privacy practices of third-party sites and encourage you to review their policies before providing personal information.
9. Your Rights and Choices
Depending on where you live, you may have certain rights regarding your personal information. We honor these rights for all U.S. users to the extent practicable, regardless of your specific state:
9.1 Access and Portability
You may request a copy of the personal information we hold about you, in a portable format where technically feasible.
9.2 Correction
You may request that we correct inaccurate or incomplete personal information.
9.3 Deletion
You may request that we delete your personal information. We will honor deletion requests unless retention is required by law, necessary to complete a transaction, or needed for legitimate business purposes (such as fraud prevention or legal compliance).
9.4 Opt-Out of Marketing Communications
You may opt out of marketing emails at any time by clicking the "unsubscribe" link in any marketing email, or by contacting us directly. Note that you may still receive transactional or service-related communications even after opting out of marketing.
9.5 California Residents (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to:
- Know what categories of personal information we collect, use, and share;
- Request deletion of personal information (subject to exceptions);
- Opt out of the sale or sharing of personal information (we do not currently sell or share personal information for cross-context behavioral advertising);
- Limit use and disclosure of sensitive personal information;
- Non-discrimination for exercising your rights.
California residents may submit requests to the email address in Section 14. We will respond within 45 days, with a possible 45-day extension with notice.
9.6 Virginia, Colorado, Connecticut, and Other State Residents
Residents of states with comprehensive consumer privacy laws (including Virginia, Colorado, Connecticut, Texas, and others) may have similar rights. We will process requests from these residents in accordance with applicable law. Please contact us using the information in Section 14.
9.7 How to Submit a Request
To exercise any of the above rights, contact us at: privacy@vindicated.ai
We may need to verify your identity before processing your request. We will not discriminate against you for exercising your privacy rights.
10. Children's Privacy
VINdicated.ai is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will delete it promptly. If you believe we may have collected such information, please contact us immediately.
Users between the ages of 13 and 17 should use our services only with parental or guardian supervision and consent.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and, where we have your contact information and the change is significant, notify you by email.
We encourage you to review this policy periodically. Your continued use of our services after any changes become effective constitutes your acceptance of the revised policy.
12. International Users
VINdicated.ai is operated in the United States. If you access our services from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those in your country. By using our services, you consent to this transfer.
We do not currently direct our services to individuals in the European Economic Area (EEA), United Kingdom, or other jurisdictions subject to the GDPR. If this changes, we will update this policy accordingly.
13. Do Not Track
Some browsers transmit "Do Not Track" (DNT) signals to websites. We currently do not respond to DNT signals in a standardized way, as there is no industry consensus on what constitutes a meaningful response. We will continue to monitor developments in this area.
14. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact:
- VINdicated.ai — Privacy Inquiries
- Crown Point, Indiana
- Privacy Requests: privacy@vindicated.ai
- General: support@vindicated.ai
- Website: vindicated.ai
We will respond to all privacy-related inquiries within a reasonable timeframe, and no later than as required by applicable law.