Privacy Policy

Last updated: 9 September 2026

This policy explains what personal data VehDB processes, why, on what legal basis, who receives it, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR) and equivalent laws. It covers the website, the dashboard, the REST API, the MCP server, the free tools and our support channels.

1. Data controller

Savas OÜ
Sepapaja tn 6, Tallinn, Harju, Estonia 15551
Registry code 14062178 · VAT EE101896809
Privacy contact: info@vehdb.com

We have not appointed a Data Protection Officer because our processing does not meet the thresholds of Article 37 GDPR; the privacy contact above handles all requests. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

2. What the vehicle data is, and is not

The vehicle database itself, meaning makes, models, specifications, tire sizes, fuel-economy and emissions figures, recall campaigns, ratings, aggregated complaint counts, crash statistics and vehicle identification data, is about vehicles, not people, and is not personal data. We deliberately do not hold:

  • vehicle registration, title, ownership or driver records, or any data regulated by the U.S. Driver's Privacy Protection Act;
  • the text of owner complaints filed with NHTSA, or the name, location or contact details of anyone who filed one: we keep counts by vehicle, component and year only;
  • person-level crash records: from NHTSA crash datasets we keep the vehicle, its model year, the crash year and state, and counts of outcomes, never anything about the people involved;
  • VIN-to-owner links. A VIN you enter in the VIN decoder is resolved to catalogue specifications and, if you are logged in, kept in your search history as text you typed; we do not connect VINs to people.

The rest of this policy is about the personal data of the people who use VehDB.

3. Personal data we process, why, and on what basis

CategoryExamplesPurposeLegal basis (Art. 6(1))
Account dataName, email address, password hash, email-verification status, job title (optional), company nameCreating and securing your account, authentication, service emails(b) contract
Team and billing dataTeam name, members and roles, invitation emails, company name, VAT number, billing address, Stripe customer id, plan, invoicesRunning team accounts, invoicing, VAT compliance, fraud prevention(b) contract; (c) legal obligation for accounting and tax records
Signup preferencesInterests you tick at signupTailoring onboarding and the dashboard(a) consent, withdrawable in your profile
Marketing attributionUTM source, medium and campaign, referring site and landing page, captured once at signupMeasuring which channels bring customers(f) legitimate interest in understanding our marketing; no profiling of individuals
Product usageSearches and the terms you enter (including VINs), saved searches and alert settings, lists and notes, comparisons, playground useProviding the features, search history, alerts, list-based recall and complaint monitoring(b) contract
API and MCP request logsTeam and user id, timestamp, method and path, query string, response status, rows served, IP address, token idMetering quotas and rate limits, detecting abuse and bulk extraction, debugging, security(b) contract for metering; (f) legitimate interest in security and abuse prevention
OAuth dataOAuth clients registered by your MCP client, authorisation codes, access and refresh tokens, device codesLetting AI agents and MCP clients authenticate on your behalf(b) contract
Product emailsYour name, email, plan and usage level, used by staff to decide whether to write to you about features or plansOccasional one-to-one emails about VehDB features, plan options and your usage(f) legitimate interest in informing existing customers about our own similar services (existing-customer exemption); every such email carries a one-click opt-out and we send at most one per week
Support dataMessages you send by email or chat, and the name, email, plan and page context passed to the chat tool when you are logged inAnswering your requests(b) contract; (f) legitimate interest in keeping records of support
Analytics dataPages viewed, events such as sign-up, purchase, tool use and clicks on parts links, device and browser type, approximate location from IP, a pseudonymous client id; a hashed user id when logged inUnderstanding aggregate product usage and marketing performance, measuring conversions(a) consent for analytics cookies where required; (f) legitimate interest for consent-free aggregate measurement
Marketing dataAd click identifiers, conversion events (sign-up, subscription), pseudonymous pixel identifiers, hashed email for audience matchingMeasuring Google Ads and Meta ad campaigns, remarketing to people who visited the site(a) consent to marketing cookies; withdrawable at any time
Technical and security dataServer logs, error reports with request context, bot-protection tokens on formsKeeping the Service running and secure(f) legitimate interest; (c) where security law requires

We do not process special categories of personal data and do not knowingly process data of children under 16.

4. Where the data comes from

  • from you, when you register, subscribe, use the dashboard, call the API or contact support;
  • automatically, from your browser or API client (request metadata, IP address, cookies);
  • from Stripe, which tells us the outcome of payments and your billing details;
  • from a team owner who invites you (your email address).

We do not buy personal data and do not enrich your profile from third-party sources.

5. Automated decisions

Quotas, rate limits and abuse suspensions are applied by fixed rules (for example, a set number of distinct query signatures per hour) without human review. A suspension is temporary, affects API access only, and can be reviewed by contacting us. We do not make decisions producing legal or similarly significant effects based solely on automated processing, and we do not profile users.

6. Recipients and processors

We share personal data only with providers that process it on our instructions under Article 28 contracts, and with authorities when the law requires it. Current processors:

ProviderRoleDataLocation and transfer basis
Cloud hosting providerApplication hosting and databaseAll data aboveUnited States; EU–U.S. Data Privacy Framework and Standard Contractual Clauses. Provider name available on request
Stripe Payments Europe Ltd / Stripe Inc.Payments, invoices, billing portalBilling details, payment method (we never see card numbers)Ireland and United States; DPF and SCCs
Cloudflare Inc.Bot protection on forms (Turnstile), private object storage for data snapshots, edge networkIP address and browser signals; snapshot storage holds no personal dataUnited States and global edge; DPF and SCCs
Google Ireland Ltd (Tag Manager, Analytics 4, Google Ads conversion tags and remarketing)Product and marketing analytics, conversion measurement, remarketing audiencesAnalytics data (section 3); a hashed user id when logged in; no plain names or email addresses are sent to GoogleIreland and United States; DPF and SCCs; IP anonymisation enabled
Functional Software Inc. (Sentry)Error monitoringTechnical error reports, which may include a user id and request pathUnited States; DPF and SCCs
Crisp IM SASSupport chatName, email, company, plan and the messages you sendFrance (EU)
Amazon Web Services EMEA SARL (Amazon SES)Sending verification, alert, digest and billing emailsEmail address, name, email content, delivery and bounce eventsEU region; Amazon Web Services Inc. as sub-processor under the DPF and SCCs
Resend Inc.Sending one-to-one product emails from news.vehdb.com and receiving replies to themEmail address, name, email content, delivery events, suppression (opt-out) listUnited States; DPF and SCCs
Meta Platforms Ireland Ltd (Meta Pixel and Conversions API)Advertising conversion measurement and audience buildingPseudonymous browser identifiers, page and event data, hashed email for matching where consentedIreland and United States; DPF and SCCs. Loaded only with your consent to marketing cookies

Where a provider is outside the European Economic Area we rely on an adequacy decision (including the EU–U.S. Data Privacy Framework for certified U.S. companies) or on the European Commission's Standard Contractual Clauses with supplementary measures. Copies of the transfer safeguards are available on request. We update this list when a processor changes; material changes are announced as described in section 13.

We do not sell personal data. Sharing with Google and Meta is limited to the pseudonymous conversion measurement and audience matching described above, under their advertising data-processing terms, and only where you have consented to marketing cookies.

7. Retention

DataKept for
Account, team, preferences, lists, saved searches, search historyLife of the account; deleted within 30 days of account deletion
Invoices, payment records, VAT data7 years after the financial year, as required by Estonian accounting law
API and MCP request logs13 months, to enforce monthly quotas, investigate abuse and answer billing disputes; aggregated counters without personal data are kept longer
OAuth tokens and clientsUntil they expire, are revoked or the account is deleted
Support conversations3 years after the last message
Analytics and marketing dataPer platform settings: 14 months for Google Analytics user-level data; Google Ads and Meta audiences expire after at most 180 days without new activity
Error reports90 days
Server and security logs30 days, longer only while a security incident is investigated
Marketing attribution fieldsLife of the account

Backups are retained for up to 30 days and are overwritten on rotation; data deleted from the live system disappears from backups on that schedule.

8. If you build on the API for your own users

When your product calls the VehDB API or MCP server, we receive the request metadata described in section 3 from your systems. We do not receive your end users' identities unless you put them in requests, which you should not do. For that request metadata we act as an independent controller for metering and security, and you remain the controller of your own users' data. Do not send us personal data of your users; if your use case requires it, contact us first so a data processing agreement can be put in place.

9. Security

Passwords are stored as one-way hashes. API tokens are stored hashed and shown once. All traffic is encrypted in transit (TLS), and data at rest is encrypted by our hosting and storage providers. Access to production systems is limited to named staff with multi-factor authentication. Payment card data never touches our systems. If a breach affecting your data occurs, we will notify the supervisory authority within 72 hours where required and inform you without undue delay when the breach is likely to result in a high risk to you.

10. Cookies and similar technologies

TypeExamplesPurposeYour choice
Strictly necessarySession cookie, CSRF token, “remember me”, bot-protection tokenLogin, form security, keeping you signed inRequired; blocking them breaks the Service
Analytics and measurementGoogle Analytics cookies set through Google Tag ManagerAggregate usage and conversion measurementBlockable in your browser or through the consent controls where shown; the Service works without them
MarketingGoogle Ads and Meta Pixel cookies set through Google Tag ManagerMeasuring ad conversions and building remarketing audiencesSet only with your consent where the law requires it; withdrawable through the consent controls or your browser
SupportCrisp chat session cookieKeeping your chat conversation togetherSet only when the chat widget loads
Local storageDashboard preferences, comparison shortlistRemembering your choices on this deviceClearable in your browser

We honour browser Global Privacy Control signals for analytics where the law requires it.

11. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate data; you can edit most of it in your profile and billing settings;
  • erase your data; you can delete your account yourself from your profile, which removes everything except records we must keep by law;
  • restrict processing while a dispute about accuracy or lawfulness is resolved;
  • portability: receive your account data, lists and saved searches in a machine-readable format;
  • object to processing based on legitimate interest, including marketing attribution and consent-free analytics, and to any direct marketing at any time — the unsubscribe link in any product email opts you out with one click;
  • withdraw consent where processing is based on it, without affecting processing before withdrawal;
  • lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee, Tatari 39, 10134 Tallinn) or the supervisory authority of your country of residence.

To exercise a right, email info@vehdb.com from your account address, or from another address with enough detail for us to verify you. We respond within one month, extendable by two months for complex requests, and we do not charge for requests unless they are manifestly unfounded or excessive.

12. Users outside the EU

Residents of the United Kingdom have equivalent rights under the UK GDPR; the Information Commissioner's Office is the relevant authority. Residents of California and other U.S. states with privacy laws may exercise access, deletion, correction and opt-out rights through the same contact. Marketing pixels that could count as “sharing” for cross-context behavioural advertising under those laws load only with consent, and you can opt out through the consent controls or by emailing us. Residents of Canada may contact the Office of the Privacy Commissioner. We apply this policy to everyone regardless of location.

13. Changes to this policy

We announce material changes by email or in the dashboard before they take effect and record the date at the top of this page. Earlier versions are available on request.

14. Contact

Privacy questions and requests: info@vehdb.com
Savas OÜ, Sepapaja tn 6, Tallinn, Harju, Estonia 15551