1. Who this applies to
This Privacy Policy applies to the VIN Verdict website and services operated under the VIN Verdict brand by The Forensic Authority. It covers visitors, one-time buyers, and account holders who use the service to request vehicle history reports or manage subscriptions.
2. Information we collect
We collect information in a few categories:
- Information you submit directly, such as a VIN, optional registration state, vehicle classification, optional notes, and any email address you provide during checkout or account use.
- Account information when sign-in is enabled, including identifiers and email address information returned by our authentication provider.
- Order and billing metadata, such as transaction IDs, subscription status, purchased plan, timestamps, and payment status.
- Report data returned by vehicle history providers after a VIN lookup request.
- Technical and security data such as IP address, browser details, device information, request logs, and cookie data needed to keep the service working.
Do not submit highly sensitive personal information in free-form notes, including Social Security numbers, bank details, driver license numbers, or card data.
3. How we use information
We use collected information to:
- validate VIN submissions and generate reports;
- store report history and purchased-access state;
- process one-time purchases and subscriptions;
- authenticate users and maintain signed-in sessions;
- send users to the correct report or dashboard state;
- detect misuse, payment fraud, abuse, or security incidents;
- respond to support, billing, and operational questions; and
- comply with legal obligations and enforce our terms.
4. Service providers and third parties
We share data with third parties only where needed to operate the service:
- Paddle processes checkout and recurring billing as merchant of record. Paddle may collect payment, billing, fraud, and tax-related information directly from you. See Paddle's Privacy Policy and Paddle Buyer Terms.
- Clerk may process account login, session, and user identity data when authentication is enabled. See Clerk's Privacy Policy.
- Vehicle data providers, including VinAudit when configured, receive the VIN and related lookup context needed to produce a report.
- We may also use hosting, infrastructure, logging, and database providers to run the service.
We may disclose information when reasonably necessary to comply with law, respond to valid legal process, investigate fraud or abuse, protect users or the service, or support a merger, sale, or transfer of business assets.
5. Cookies and similar technologies
VIN Verdict uses cookies and similar storage for operational needs.
- Authentication cookies may be used to remember signed-in sessions.
- One-time purchased report access currently uses a secure access cookie so the buyer can reopen a purchased report without creating an account during the active access window.
- Payment and authentication providers may place their own required cookies as part of checkout or account flows.
We do not currently describe this service as using advertising or retargeting cookies.
6. Retention
We retain data for as long as reasonably necessary to operate VIN Verdict, support purchases, preserve report history, investigate disputes, prevent fraud, and meet legal or accounting obligations.
One-time purchased report access is currently designed around a 30-day secure access window. Internal records such as orders, reports, subscription state, and event logs may remain longer than the browser access window.
7. Security
We use reasonable administrative, technical, and organizational safeguards intended to protect information under our control. No service can promise absolute security, and you use the internet-facing portions of the service at your own risk.
8. Your choices and rights
Depending on your location, you may have rights to request access to, correction of, or deletion of certain personal information, and in some cases to object to or restrict certain processing.
If you purchased through Paddle, some billing and transaction records may also be managed through Paddle's systems and subject to Paddle's policies and legal obligations.
If you need help with a request, use the business contact information made available on the service or in your purchase receipt.
9. International processing
VIN Verdict and its service providers may process data in countries other than your own. By using the service, you understand that your information may be transferred to and processed in jurisdictions with different data protection rules than those in your home country.
10. Children
VIN Verdict is not directed to children under 18, and we do not intend to knowingly collect personal information from children.
11. Changes to this policy
We may update this Privacy Policy as the service, providers, or legal obligations change. The updated version becomes effective when posted on this page unless a later date is stated.
12. Related terms
Your use of VIN Verdict is also governed by our Terms of Service.