Skip to main content
NitroVIN

Privacy Policy

Last updated: April 5, 2026

1. Overview

NitroVIN ("we," "us," or "our") operates the website at https://nitrovin.com (the "Service"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

We do not sell, rent, or trade your personal information. We do not build or sell leads lists. We do not share your data with third parties except as described in this policy.

2. Information We Collect

Automatically collected data

When you use the Service, our servers automatically record information including:

  • IP address
  • Pages visited and timestamps
  • Referring URL (the page you came from, if any)
  • VINs you search (associated with your IP address for rate limiting)
  • Approximate geographic location derived from your IP address (country, region, city) using a locally-run IP geolocation database — your IP is not transmitted to any third party for this purpose

This data is stored in our database and used to operate the Service, enforce usage limits, and understand aggregate usage patterns. It is not linked to any personal identity unless you create an account (see below).

Session and attribution data

We assign each visitor a random session identifier (stored in the nv_sid cookie) to understand how often home page visitors go on to perform a VIN search. This identifier contains no personal information and is not linked to your identity.

If you arrive via a link containing UTM marketing parameters (e.g., utm_source, utm_medium, utm_campaign), those values are stored in the nv_utm cookie and associated with any searches you perform, so we can understand which channels drive usage of the Service.

Local storage (browser-side only)

We store two values in your browser's local storage that never leave your device:

  • theme — your dark or light mode preference
  • cookie-consent — whether you have acknowledged our cookie notice

Account information

If you create an account, we collect your email address and a hashed (one-way encrypted) password. We do not store your password in plain text and it cannot be recovered — only reset. Your email address is used to verify your account and send your verification code. It is not shared with third parties and is not used for marketing without your consent.

When you are signed in, an authentication token is stored in the nv_auth cookie to keep your session active. This token is a random identifier with no personal information embedded in it.

Payment information (future)

If paid features are introduced, payments will be processed by a third-party payment processor (such as Stripe). We will not store your payment card details. The payment processor's own privacy policy will govern how they handle your payment data.

3. How We Use Your Information

We use the information collected to:

  • Deliver the VIN lookup service
  • Enforce rate limits and prevent abuse
  • Understand how the Service is used in aggregate (e.g., popular vehicle makes, geographic distribution, peak hours)
  • Measure conversion rates — how often home page visitors go on to search a VIN
  • Understand which traffic sources and marketing channels drive usage
  • Improve the Service over time
  • Comply with legal obligations

We do not build advertising profiles from your NitroVIN activity. However, our advertising partner (Google AdSense) may use cookies and similar technologies to show personalized ads based on your broader browsing history — see Section 4 for details and opt-out options.

4. Third-Party Services

NHTSA vPIC API

VIN lookups are fulfilled by the National Highway Traffic Safety Administration (NHTSA) vPIC API, operated by the US federal government. When you search a VIN, that VIN is transmitted to NHTSA's servers to retrieve vehicle data. No other information about you is sent to NHTSA.

Advertising (Google AdSense)

We display third-party advertisements on the Service through Google AdSense. We have no control over the data collected by Google's advertising services. Google may use cookies and similar tracking technologies to serve ads based on your browsing history across other websites. Their data collection is governed by Google's own privacy policies — not this one.

Signed-in users with a Premium or Admin account do not see ads.

For information on how Google uses data from sites that use its ad services, visit Google's Privacy & Terms. You can opt out of personalized advertising via Google Ad Settings or aboutads.info.

Sign-in providers (future)

We may add support for signing in with Google or Apple in the future. If offered, those providers may collect data in accordance with their own privacy policies. We only receive the profile information you authorize them to share. This policy will be updated before such options are available.

5. Data Retention

Search logs, home page visit logs, and session attribution data are stored in our database indefinitely for analytics purposes. This data is associated with IP addresses and session identifiers, but not with any named individual unless you have an account. If you have an account, your searches are additionally associated with your user ID.

Account data (email address, hashed password) is retained for as long as your account exists. You may request deletion by contacting us. VIN result data is cached for up to 30 days and then purged. Local storage data persists in your browser until you clear it.

6. Data Security

We take reasonable technical measures to protect the data we hold. However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security and are not responsible for breaches outside our reasonable control.

7. Children's Privacy

The Service is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

8. Your Rights

Depending on your location, you may have rights regarding your personal data, including:

  • The right to know what data we hold about you
  • The right to request deletion of your data
  • The right to opt out of any sale of personal data (we do not sell data)

To exercise any of these rights, contact us at the address below. We will respond within 30 days.

9. Changes to This Policy

We may update this policy from time to time, particularly as new features (user accounts, payments, sign-in providers) are introduced. We will update the "Last updated" date at the top of this page when changes are made. We encourage you to review this policy periodically.

10. Contact

If you have questions or concerns about this Privacy Policy, please contact us at contact@nitrovin.com.