Last updated: 13.04.2026
1) Who we are
This Privacy Policy (“Policy”) describes how VinReportOnline.com (“we”, “us”, the “Site”) processes personal data when you visit and use the Site.
Important clarification: VinReportOnline.com is an informational website and is not a provider of vehicle reports. The Site provides information and directs users to a partner service (e.g., carVertical), where the actual check and any potential purchase of a report take place.
2) What data we process
2.1 Data you voluntarily provide
When you use the check form, you enter a VIN number (17 characters).
As a rule, the VIN number itself does not directly identify a natural person, but in certain situations it may be linked to a specific vehicle and indirectly to a person. Therefore, we treat it as data that we process with increased care.
We do not require registration, an email address, or a phone number to use the Site.
2.2 Data collected automatically
When you visit the Site, limited technical data may be processed, which is typically generated in the operation of websites and hosting services, for example:
- IP address
- date and time of access
- pages visited
- device/browser type
- technical logs for security and diagnostics
We do not use Google Analytics and we do not perform tracking via marketing pixels.
3) How we use the data (purposes)
We process data only for the following purposes:
- to validate the VIN number entered in the form
- to redirect you to the partner website to perform the check and/or purchase a report
- to maintain the security and stable operation of the Site (prevention of abuse, protection, diagnostics)
4) Storage of VIN numbers
VinReportOnline.com does not store the VIN number you enter in a database or in user profiles.
The VIN number is used momentarily (only for validation and redirection purposes) and is not saved by us as a check history.
5) Cookies
The Site may use only strictly necessary cookies and/or technical mechanisms required for basic functionality and security.
We do not use analytical cookies via Google Analytics.
You can manage cookies through your browser settings. Please note that blocking strictly necessary cookies may affect the operation of the Site.
6) Affiliate links and third parties
The Site contains affiliate links to external websites (e.g., carVertical). When you click such a link:
- you leave our Site
- data processing is governed by the privacy policy and terms of the respective third party
We do not control and are not responsible for the practices of external websites.
The partner website may use cookies/identifiers to track affiliate sales (affiliate tracking). Details should be checked in the policy of the respective third party.
7) Legal basis (GDPR)
We process data on the following GDPR bases:
- Legitimate interest (Art. 6(1)(f)): for security, prevention of abuse, maintenance and protection of the Site, as well as ensuring proper operation of functionalities (validation and redirection).
- Consent (Art. 6(1)(a)): only if in the future we enable non-essential cookies/tools that require consent (e.g., analytics or marketing).
8) Retention periods
- VIN number: not stored by us.
- Technical logs (if processed by the hosting provider): retained for the period necessary for security and diagnostics, in accordance with standard hosting practices and applicable law.
9) Data recipients
Depending on how you use the Site, data may be processed by:
- Hosting provider (as a processor) – for hosting, security, and maintenance
- Partner website (e.g., carVertical) – as an independent data controller for activities on their site after redirection
10) International transfers
Some providers (e.g., hosting/partner services) may process data outside the European Economic Area. In such cases, transfers should be carried out with appropriate safeguards under the GDPR (e.g., Standard Contractual Clauses). Details are contained in the policies of the respective providers.
11) Your rights
Depending on applicable law, you have the right to:
- access
- rectification
- erasure (“right to be forgotten”)
- restriction of processing
- objection to processing
- data portability
- withdrawal of consent (where processing is based on consent)
- lodge a complaint with a supervisory authority
In Bulgaria, the supervisory authority is the Commission for Personal Data Protection (CPDP).
12) Security
We apply reasonable technical and organizational measures to protect the Site against unauthorized access, loss, or misuse. However, no method of transmission or storage of data on the internet is 100% secure.
13) Contact
If you have questions about this Policy, you can contact us using the contact details published on the Site.
14) Changes to this Policy
We may update this Policy periodically. Changes take effect from the date of publication on this page.