Document 2 of 4
Privacy notice
This notice covers the data of people who buy from vincode. Processing of the data held in the vehicle database — information about vehicles and, indirectly, about the people who have owned them — is described in a separate notice, as Art. 14 GDPR requires for data not collected from the data subject.
Why there is a summary at the top
In its decision of 14 July 2026 against Lusha Systems Inc., the Italian data protection authority treated it as a violation in its own right that the notice "was not clear and easily accessible". A plain-language summary at the start of the document is not an editorial courtesy: it is part of the obligation.
In short
- We collect information about vehicles, not about people: events attached to a VIN, not to a name.
- We do not collect, store or display the name, address or contact details of any owner, past or present.
- The data we do collect about you as a customer exists to deliver your Report, take the payment and meet tax obligations.
- We do not sell your data, and we do not use your email address for marketing without your consent.
- Ownership-change dates are shown as month and year only, location at province level only, and plates and faces in photographs are blurred at ingest.
If you are, or were, the owner of a vehicle and want to know what we hold, write to [email protected]. To protect other people we will ask for an identity document and evidence of your connection to that vehicle: clause 11 explains why.
1. Controller and data protection officer
- Data controller
- JANJOR CARS LTD, Flat 1, 61 Morpeth Street, Hull, HU3 1RF, United Kingdom — company number 16568399 (England and Wales) — telephone +44 7537 174486.
- Privacy contact
- [email protected], for exercising your rights and for any question about this notice.
- Data protection officer
- [email protected], for requests concerning the vehicle database and for complaints.
Appointing a data protection officer is recommended by the compliance research and, in all likelihood, mandatory: vincode's core activity consists of regular and systematic monitoring, on a large scale, of data attached to vehicle identifiers (Art. 37(1)(b) GDPR). Once appointed, the DPO's contact details must be notified to the Garante through its dedicated portal (Art. 37(7)).
2. Is a VIN personal data?
It is the most argued-over question in this sector, and the honest answer is: it depends who holds it.
In Case C-319/22 (Gesamtverband Autoteile-Handel eV v Scania CV AB, judgment of 9 November 2023) the Court of Justice of the European Union took a relative approach: a VIN is not personal data in itself, but it becomes personal data for anyone who reasonably has the means to associate it with a specific person. Account must be taken of all the means likely reasonably to be used either by the controller or by any other person. The Court adds that it is not necessary for all the information enabling a person to be identified to be in the hands of a single entity: that is the limit that weighs most on us, because "we do not hold the plate mapping" is not, on its own, an answer.
In Italy the position is stricter. In order no. 4648 of 21 February 2024 the Court of Cassation held that a licence plate is personal data, because it allows the registered keeper to be identified and profiled. Since the Italian vehicle register is searchable by plate, the means of identification are available to anyone, cheaply and lawfully: the "means reasonably likely to be used" test is met almost by construction.
The EDPB, in Guidelines 01/2020 on connected vehicles (adopted 9 March 2021), makes a related point: technical data such as driving style, distance driven and wear concerns the driver or passenger because, cross-referenced with other data such as the VIN, it can be linked to an individual.
vincode's operating conclusion is: design as though the answer were yes, and build the system so that in our hands it becomes no. These are the rules that follow, and they bind the people writing the code as much as the people writing the documents.
- VIN on its own
- The key of the event database. No name, address or contact detail is ever attached to the record.
- Licence plate
- Treated as personal data in every case: encrypted at rest, short retention, access logged.
- Plate-to-VIN mapping
- The bridge that makes everything else identifiable. Isolated from the event store, encrypted, purged after 90 days.
- VIN together with a name or address
- Not ingested, not stored, not displayed. Ever, from any source, for any purpose.
- Photographs from historic listings
- Plates and faces blurred at ingest, before the image enters the archive.
3. Three distinct processing streams
Keeping the three streams apart is the most useful thing in this notice: they have different data subjects, different purposes and different lawful bases, and conflating them is the fastest way to get this wrong.
| Stream | Data subjects | Purpose | Lawful basis |
|---|---|---|---|
| A · Customers and orders | People who buy from vincode | Creating the account, generating and delivering the Report, support, taking payment, tax compliance | Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) (legal obligations) |
| B · Vehicle database | Previous owners and keepers, insofar as identifiable | Building and maintaining VIN-keyed event records | Art. 6(1)(f) GDPR — legitimate interest in fraud prevention, Recital 47 |
| C · Marketing | Customers and prospects | Sending commercial emails | Art. 6(1)(a) GDPR — consent; art. 130 of the Italian Privacy Code |
We do not use consent as the lawful basis for stream A. It would be the wrong choice: it would make a processing operation that is necessary to perform the very contract you asked us to perform revocable at any moment, and it would oblige us to stop delivering a Report you had already paid for.
We do not use consent for stream B either, for a different reason: it is not possible to obtain consent from a previous owner we cannot contact, and a consent you cannot evidence is worse than none. Before launch, both the legitimate interests assessment (LIA) and the data protection impact assessment (DPIA) must be written down.
4. What we process about you
- Contact and account data
- Email address, password stored as a hash, language and country, communication preferences.
- Order data
- Package purchased, amount, currency, VAT rate applied and country of taxation, transaction identifier, credits bought and consumed.
- Evidence of the withdrawal waiver
- The literal text you accepted, the version number, the date and time, the language, the state of the checkbox before submission, the order-button label, the confirmation email identifier and the moment the Report was unlocked.
- VAT location evidence
- Declared billing country, country derived server-side from the IP address, card-issuing country, and the outcome of comparing them.
- Searches you have run
- The VINs and plates you searched, with the date. Plates are encrypted and purged on the schedule in clause 7.
- Support data
- The content of messages you send us and the related correspondence.
- Technical logs
- IP address, date and time, resource requested, outcome, user agent.
We do not process special categories of data within the meaning of Art. 9 GDPR and we do not ask for any. We neither receive nor store your card details: Stripe handles those, and we see only the outcome, the issuing country and the last four digits.
Providing contact and order data is necessary to conclude the contract: without it we cannot deliver the Report or issue tax documents. Everything else is optional.
5. Lawful basis, purpose by purpose
| Purpose | Lawful basis | Note |
|---|---|---|
| Creating the account and delivering the Report | Art. 6(1)(b) — contract | Without this data the service cannot be provided. |
| Taking payment and payment fraud prevention | Art. 6(1)(b) and Art. 6(1)(f) | Payment fraud checks are carried out by Stripe as an independent controller. |
| Receipts, invoices and accounting records | Art. 6(1)(c) — legal obligation | Italian tax law; art. 2220 of the Civil Code. |
| Keeping evidence of the withdrawal waiver | Art. 6(1)(c) and Art. 6(1)(f) | It is the only defence to a late refund claim, and the law sets its preconditions. |
| VAT location evidence | Art. 6(1)(c) — legal obligation | Implementing Regulation (EU) 282/2011, Arts. 24b and 24f. |
| Customer support | Art. 6(1)(b) — contract | Includes handling complaints, withdrawals and error reports. |
| Security, logging and abuse prevention | Art. 6(1)(f) — legitimate interest | Interest in protecting the service, other users and the data subjects behind the vehicle database. |
| Aggregate usage statistics | Art. 6(1)(f) — legitimate interest | Cookieless analytics, IP anonymised, no cross-site identifiers. |
| Commercial emails | Art. 6(1)(a) — consent | Withdrawable at any time, in one click at the foot of every message. |
6. Where the data comes from
The data about you as a customer comes from you, with two exceptions: technical data collected automatically by the server, and the information we receive from Stripe about the payment — outcome, card-issuing country and last four digits.
The data in the vehicle database, by contrast, does not come from the data subjects. It comes from registration registers, roadworthiness archives, insurance claims administrators, theft reports, networks of garages and authorised repairers, historic sales listings and manufacturer recall campaigns.
That is why Art. 14 GDPR applies to that stream rather than Art. 13, and why the vehicle-data notice must be public, indexable by search engines and reachable without an account and without setting any cookie. The source must also be disclosed, including whether it is a publicly accessible source (Art. 14(2)(f)).
7. How long we keep data
Every category has a stated period and a stated reason. A period without a reason is not a retention policy, it is an invented deadline.
| Data | Retention | Why |
|---|---|---|
| Account, orders, invoices and accounting records | 10 years from the transaction | Art. 2220 of the Civil Code; ordinary limitation period (art. 2946) |
| Evidence of the withdrawal waiver | 10 years | The withdrawal period can extend to 12 months and 14 days where the information given was defective (art. 53 Consumer Code) |
| VAT location evidence | 10 years from the end of the year of the transaction | Art. 63c of Implementing Regulation (EU) 282/2011 |
| Server-side copy of the generated Report | 24 months from generation | Support and reconstruction of what was shown; deleted thereafter |
| Plate-to-VIN lookup cache | 90 days | The highest-risk table we hold: keep it small and short-lived |
| Vehicle event records, keyed on the VIN | 15 years (proposed) | Covers the average useful life of an EU vehicle and is easier to defend than the leading competitor's 30 years. Decision to be confirmed |
| System and access logs | 6 months | The Garante's long-standing benchmark for traffic-data-adjacent logs |
| Marketing consent and evidence of it | Until withdrawal, then 5 years | Art. 130 of the Italian Privacy Code; accountability |
| Cookie consent record | 6 months, rolling | Matches the period after which the banner may be shown again |
| Data-subject request case file | 5 years from closure | Accountability: we must be able to show how it was handled |
8. Who else processes your data
We use suppliers who process data on our behalf. They are appointed as processors under Art. 28 GDPR and bound by a written contract setting out purpose, duration, security measures and deletion obligations.
| Supplier or category | Role | What it processes |
|---|---|---|
| Application hosting and CDN | Processor | Request logs, content served |
| Managed database | Processor | Accounts, orders, consent evidence |
| Stripe | Independent controller for payment; processor for some ancillary services | Card data, outcome, issuing country, fraud checks |
| Transactional email provider | Processor | Email address, content of the order confirmation |
| Error tracking | Processor | Technical data, with personal-data scrubbing configured |
| Upstream vehicle-data suppliers | Independent controllers or processors, depending on the contract | VIN-keyed data |
We do not sell, share or rent personal data to third parties for marketing. We do not enrich profiles and we do not buy lists.
9. Transfers outside the European Union
We prefer suppliers established in the European Union or the EEA. Where a US supplier is unavoidable we do not rely on the adequacy decision alone: we sign the Commission's standard contractual clauses in any event and carry out a transfer impact assessment. If that supplier is certified under the EU–US Data Privacy Framework we check the live certification in the official register before switching it on and keep documentary evidence of the check, but we treat it as one guarantee more, not as the basis of the transfer.
Alongside the standard contractual clauses we put, where needed, supplementary measures such as encryption with keys held in the EU. The reason for this posture is practical: an adequacy decision can be annulled or suspended with immediate effect, and anyone who had relied on it alone is left, that day, with no legal basis for the transfer.
10. Risk score and automated decision-making
The Report carries a summary verdict generated automatically from the events found. That score is about a vehicle, not about a person: it produces no legal effects concerning you and does not similarly significantly affect you. It does not decide whether you may buy, it assigns you no creditworthiness, and it gates access to nothing.
A data protection impact assessment is mandatory all the same, but not because of the score. In provvedimento no. 467 of 11 October 2018 (doc. web 9058979) — the Garante's formal decision — it lists the processing types that require one, and ours falls in first because it works "by interconnecting, combining or comparing information": the event database and the plate-to-VIN mapping are exactly that, and that entry sets no size threshold at all. The DPIA must be completed before processing begins; if residual risk remained high, prior consultation with the Garante under Art. 36 GDPR would be required.
In any event you can ask us to review a verdict you consider wrong, and the review is free. It uses the same channel as error reports on the Report.
11. Your rights, and how to exercise them
You may exercise the rights in Arts. 15–22 GDPR at any time.
| Right | What you can ask for |
|---|---|
| Access — Art. 15 | To know whether we process data about you and to obtain a copy, with information on purposes, categories, recipients, retention and origin. |
| Rectification — Art. 16 | To correct inaccurate data or complete incomplete data. |
| Erasure — Art. 17 | To have data erased in the cases provided for. See clause 12: some data stays for legal reasons. |
| Restriction — Art. 18 | To freeze processing while we check contested accuracy or assess an objection. |
| Portability — Art. 20 | To receive, in a structured format, the data you provided that we process on the basis of contract or consent. It does not apply to the vehicle database, whose basis is legitimate interest. |
| Objection — Art. 21 | To object to processing based on legitimate interest, on grounds relating to your particular situation; and, always and without giving reasons, to direct marketing. |
| Withdrawal of consent — Art. 7 | To withdraw a consent at any time, without affecting the lawfulness of processing carried out before the withdrawal. |
| Complaint — Art. 77 | To lodge a complaint with a supervisory authority. See clause 14. |
How to exercise them: write to [email protected] saying which right you want to exercise. We respond without undue delay and in any event within one month; the deadline can be extended by two further months in complex cases, in which case we tell you within the first month (Art. 12(3)). Exercising your rights is free of charge (Art. 12(5)), and we do not intend to charge the fee permitted for manifestly unfounded or excessive requests.
If you are a customer we identify you through your account and ask for nothing more: you get your account, order and Report-access data. If instead the request concerns a vehicle — "tell me everything you hold about VIN X" — we ask for an identity document and evidence of your connection to that vehicle: a digital certificate of title, the registration document, or a PRA search in your own name.
12. When erasure is not possible
If you ask us to erase your data we delete the account and everything we are not required to keep. What we cannot delete are the accounting records, invoices and receipts relating to purchases you made: art. 2220 of the Italian Civil Code requires accounting records and related correspondence to be kept for ten years, and Art. 17(3)(b) GDPR excludes the right to erasure where processing is necessary to comply with a legal obligation.
For the same reason we keep the VAT location evidence used to determine the rate for ten years. We keep the evidence of your consent to immediate performance and waiver of withdrawal for just as long, where the basis is also Art. 17(3)(e): the establishment, exercise or defence of legal claims.
We would rather say this plainly than promise you a complete erasure that then does not happen. What actually occurs is this: the data we must keep is isolated, is no longer used for any operational purpose, enters no commercial communication, is reachable only by people with an administrative reason to look at it, and is deleted when the period expires.
A comparable logic, for different reasons, applies to erasure requests concerning the vehicle database. A request to delete the record of an odometer rollback is exactly the case where we must assess whether there are compelling legitimate grounds that override the data subject's interests (Arts. 17(1)(c) and 21(1) GDPR): fraud prevention and the road safety of whoever buys that vehicle next. We decide case by case, write the decision down and keep the log. Neither "we always delete" nor "we never delete" would be an acceptable answer.
Where we do carry out a rectification or erasure, we notify the recipients to whom the data was disclosed, as Art. 19 GDPR requires, unless that proves impossible or involves disproportionate effort.
13. Security and data breaches
Technical and organisational measures are proportionate to the risk, as Art. 32 GDPR requires. In outline:
- TLS 1.3 for all traffic in transit;
- encryption at rest for customers' personal data and for the plate-to-VIN mapping table;
- role separation between the event store and the bridge table, which do not share a logical environment;
- audit logging of every read of the bridge table, with periodic access review;
- passwords stored only as hashes, never in clear text;
- least privilege for internal access, reviewed periodically.
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, we notify the Garante within 72 hours of becoming aware of it (Art. 33) and inform the data subjects without undue delay where the risk is high (Art. 34). The response runbook has to be written before the incident, not during it.
14. Complaints to the supervisory authority
The supervisory authority for Italy is the Garante per la protezione dei dati personali (garanteprivacy.it). You may lodge a complaint under Art. 77 GDPR and the corresponding provisions of the Italian Privacy Code (Legislative Decree 196/2003), or approach the supervisory authority of the member state where you habitually reside or work.
You may also go directly to the courts (Art. 79 GDPR). A complaint to the Garante and a court claim are alternatives: once one route is taken, the other is no longer available on the same matter.
We would ask you, if you can, to write to us first: most requests resolve in a few days, and a well-argued complaint is useful to us either way.
15. Updates to this notice
Every version of this notice is numbered, dated and archived: we must be able to prove which text was published on a given date, which is an accountability obligation as much as good practice.
Where we make material changes we tell you before they take effect, if we have a suitable contact address for you. Editorial changes are published with a new version number and date.