Privacy Policy
Effective from 2026-06-01. Compliant with the Kazakh Personal Data Protection Law and GDPR (for EU users).
What we collect
- Email and password (or Google OAuth identifier / phone number) — for sign-in.
- Name — if you provided it at registration.
- VIN codes you've checked.
- Order history — plan, amount, payment method, status.
- IP address and User-Agent — for bot and fraud protection (kept for 90 days).
- Analytics — anonymized events via Vercel Analytics and Firebase Analytics (no cookie tracking).
What we do NOT collect
- Bank card number — processed via Polar.sh and Kaspi, we only receive transaction status.
- Biometrics, passport details, IIN — we don't ask for these.
- Phone contacts and calls — there's no mobile app.
Why we keep this
- Report access — so you can return to a report without paying again.
- Cache — provider responses are cached 14–60 days per VIN to make re-checks cheaper.
- Billing — for refunds, disputes, and tax reporting.
- Security — protection from bots, fraud, DDoS.
Who we share with
- Firebase / Google Cloud — hosting and auth. Data is stored in Europe (europe-west1).
- Vercel — application hosting.
- Kaspi and Polar.sh — payment processing. They receive only what's needed for the transaction.
- Data providers (VinAudit, vini.az, car-history.kr, etc.) — receive only the VIN, without your personal info.
Who we do NOT share with: car sellers, marketing, ad networks. Carvin does not disclose which VINs you've checked.
How long we keep things
- Profile and order history — as long as the account exists.
- Provider response cache — 14–60 days based on source TTL.
- Logs (IP, User-Agent) — 90 days.
- Accounting (receipts, invoices) — 5 years (Kazakh tax requirement).
Your rights
- Download all your data — email support@carvin.app, we reply within 30 days.
- Delete your account — button in Dashboard → Settings (or email). Full deletion within 30 days, except accounting.
- Correct your data — in the dashboard or via support.
- Complain: Kazakh Consumer Rights Protection Committee.
Cookies
We use only functional cookies (session cookie for sign-in) and Vercel Analytics without cookie tracking. No advertising or marketing cookies, no consent banner.
Privacy contact
All privacy questions — privacy@carvin.app.
Last updated: June 1, 2026