Privacy Policy

Last updated: August 24, 2026

1. Scope

SC01Guide.com is operated by Vermel Ventures LLC, a California limited liability company. This policy covers the SC01Guide.com website, account services, vehicle reports, and the SC01 Guide mobile app.

We collect the information needed to run VIN lookups, provide reports, manage accounts and purchases, prevent abuse, support users, and operate the service. We do not sell personal information or use it for third-party targeted advertising.

2. Accounts and sign-in

When you create or use an account, we collect your email address and account identifier. We store your available report quantities, purchase history, report history, and the VINs connected to your account activity. A one-time sign-in code expires after 10 minutes. A signed-in session normally expires after 30 days.

We use this information to sign you in, show your research history, provide purchased reports, and respond to support requests.

Only after a one-time sign-in code has been successfully verified and consumed, and only when no account exists for the email address, we may send the email address and network IP address observed by our server to UserCheck to assess new-account abuse. Existing-account sign-ins are not submitted to UserCheck.

For the same eligible new-account attempt, we may first send only the domain portion of the email address to FakeFilter to check for a temporary-email provider. We do not send the full email address or the network IP address to FakeFilter. We cache that domain and verdict for up to seven days for a positive result and up to one day for a negative result.

3. VIN lookups, reports, and searches

When you submit a VIN, we send it to our backend to retrieve or create a vehicle record. We may use NHTSA and other vehicle-data services to obtain available vehicle details. We store decoded vehicle data so the same VIN can be researched again without repeating every external request.

A lookup may be linked to your account when you are signed in. We also record a device identifier, IP address, request time, request outcome, and basic device or browser information for report access, service measurement, fraud prevention, rate limiting, and security. VIN and place searches can form part of your research history. We count each complimentary report against your account, the device you use, and the network address the request came from, so that extra accounts on the same device or connection do not unlock more of them. A request can be refused on that basis, and we record the refusal as a security event.

A successful complimentary report creates a temporary report-access record. Its IP address is removed after 30 days, and an expired access record is deleted within 90 days after expiry.

When the private vehicle research workspace is enabled for your account, we store the canonical public listing links you add, source and listing identifiers, normalized vehicle facts you enter, research stage, notes, and evidence timestamps. For a supported public listing, an administrator may enable private listing import for selected accounts and reviewed sources. An import can collect normalized listing observations, such as displayed vehicle identity, price, mileage, seller, location, and availability facts. We retain those observations and their evidence timestamps with the account. An import can also collect a listing image and retain a sanitized private copy for the research workspace. We process source HTML and original image files only as needed for the import. We do not store raw HTML, source response bodies, or original image files. The private image is re-encoded without the original file metadata and is served only through an authenticated, account-owned route. When separately enabled, Cloudflare's image-recognition service may analyze that sanitized copy to identify a possible VIN. We store the bounded result and whether it agrees with the VIN displayed on the listing, but not the model's raw answer or reasoning. A possible VIN from an image does not change or confirm the VIN saved for the vehicle automatically. Sources configured for manual tracking remain saved links and are not fetched. Imports do not use marketplace passwords or session cookies and do not collect private marketplace messages. Private notes are stored exactly as entered, so do not enter credentials and only enter contact details you intend us to store. Adding or saving a listing does not consume a vehicle report or one of your complimentary reports. A report remains a separate action you choose explicitly.

4. Purchases and payment information

Payments are processed by Stripe. Stripe collects the payment method, billing address, name, email address, and other details needed to process the transaction. We do not receive or store your full card number. We receive transaction identifiers, amount, currency, payment status, and customer details Stripe sends us so we can add purchased reports, issue refunds, prevent fraud, and provide support.

Stripe handles payment data under its own privacy policy.

5. Camera scans and inspections

If you scan a VIN, the app uses the camera to read text from the windshield plate or door-jamb sticker. Recognition happens on your device. The image is not uploaded to us or added to your photo library. Temporary camera files remain in app-controlled storage under the device operating system's storage lifecycle.

When you use an inspection while signed in, we store its VIN, vehicle description, checklist answers and state, custom checklist items, item notes, overall notes, finish or reopen state, and created, updated, and completion timestamps with your account. We also store a client-reported sync device identifier. This lets inspections sync between the website and the SC01 Guide app after a connection is available. Offline changes remain queued on the mobile device and sync after a connection is available. The mobile app keeps a local copy so a temporary connection problem does not erase your work.

For an inspection sync request, we record the request IP observed by our server as security and support evidence. We remove that IP from the inspection sync record after 90 days.

You can delete an individual inspection from your account. We keep a deletion tombstone while the account remains active so an offline or out-of-date device cannot restore the deleted inspection by mistake. Account deletion removes its server-backed inspection records and sync history, including tombstones linked to that account.

To remove inspection data from a previously signed-in device after account deletion, the app creates a random, deletion-only device handle and the server stores only a one-way form of it. The handle cannot authenticate a user or read or modify account or inspection data. At account deletion, the server severs the handle's link to the account and keeps only a deletion receipt for a maximum of 400 days. The device that completes account deletion removes its local inspection records and sync data after the server confirms deletion. On another previously signed-in device's next successful connection, the handle can return only the deletion result so the app can remove that account's local inspection records and sync data. If the device never reconnects, its remaining app storage is subject to the device operating system, app removal, device erasure, and backup settings.

6. Location and maps

With permission, the app can use precise location to show nearby chargers and repair shops or to choose a trip origin. Nearby charger matching can occur on the device. Repair searches and trip planning send the coordinates needed for that request to our services. Trip planning also sends the route points to Mapbox. Typed locations are sent to a mapping service so they can be converted into coordinates.

We do not add precise GPS coordinates to your account history. Our security and operational records may contain a coarse network location inferred from an IP address. You can deny or withdraw location access in iOS Settings and enter a location manually where the feature allows it. Mapbox processes data under its own privacy policy.

7. Device, usage, and diagnostic information

We collect service events such as the feature used, request result, duration, error details, app or browser type, device identifier, IP address, and account identifier when signed in. We use these records to operate the service, understand feature use, diagnose failures, enforce access limits, and investigate abuse. We do not track you across apps or websites owned by other companies.

The SC01 Guide mobile app uses Expo's EAS Update service to check for and download compatible JavaScript and asset updates when the app launches. An update request sends Expo the app platform and operating system, our public Expo project identifier, the update channel, the compatible runtime version, and a random installation token that lets Expo determine whether that installation requested or downloaded an update. When available, the request also includes identifiers for the current, embedded, requested, or recently failed software update. After a fatal launch error, a later request can include a limited description of that prior error. The HTTPS connection also exposes its network IP address to Expo. The random token is not your SC01 Guide account identifier or a hardware identifier.

Expo can provide us with counts of installations that ran an update and failed installs. These are operational update-delivery metrics, not analytics about which SC01 Guide features, VINs, reports, or inspections you use. We do not intentionally add your email address, SC01 Guide account identifier, VINs, reports, inspection content, purchase history, or precise location to EAS Update requests. A failed-launch error description can contain diagnostic context from the failed code path. We do not use EAS Update for advertising or tracking your activity across other companies' apps or websites. See Expo's privacy explanation and privacy policy.

8. Service providers

We share data only as needed with providers that help us deliver the service:

  • Cloudflare for hosting, network security, storage, private listing-image processing, optional image recognition, and service logs
  • Bright Data for authorized retrieval of public vehicle-listing pages when a direct request cannot obtain the listing
  • Stripe for checkout, payments, refunds, and payment fraud controls
  • Resend for one-time sign-in codes and service email
  • FakeFilter for domain-only temporary-email screening on new-account attempts
  • UserCheck for email, domain, and network risk screening on new-account attempts
  • Expo for mobile app update delivery and update adoption and failed-install metrics
  • Mapbox for location search and route planning
  • NHTSA and vehicle-data services for available vehicle information

We may also disclose information when required by law, to protect users or the service, or as part of a business transfer where the recipient must continue to handle the data under applicable law.

9. Retention

We keep account, report, and purchase records while your account is active and as needed to provide the service. Routine operational logs are normally kept for up to 90 days. Security records may be kept for up to 365 days. Transaction, refund, fraud, tax, dispute, or legal records may be kept longer when required for those purposes.

Account deletion removes the live account and email link. Report-lot quantities and ledger events retained for transaction and product audit may remain under an opaque former-account identifier, together with a deletion timestamp so they are not mistaken for orphaned data.

Administrative authorization and account-control audit records may also remain under opaque user identifiers when needed to prevent old privileges from returning, investigate security incidents, and prove who changed account access. Their structured fields do not copy the account email address. The service rejects recognizable email addresses, IP addresses, VINs, credentials, secrets, and pasted payloads from operator-entered audit reasons. Operators are instructed not to enter personal data or secrets in those reasons.

Archiving a vehicle hides it from the active workspace but does not erase its evidence. You can restore an archived vehicle to active research. Deleting the account removes its private vehicle records, listings, normalized observations, notes, and access grant. It also removes account-linked image-recognition evidence. Anonymous daily recognition reservation and execution-start totals may remain so deletion cannot reset a shared service limit. It also makes private listing images inaccessible immediately and queues their physical deletion from private storage. Temporary storage failures are retried automatically. Persistent failures remain recorded for operational recovery.

UserCheck reports that it keeps raw API logs for up to 90 days, after which it anonymizes them for analytics. That provider retention applies to the email address and network IP address UserCheck receives for an eligible new-account check. See UserCheck's privacy policy.

FakeFilter receives only the email domain described above. Its public documentation describes the domain-check endpoint but does not state a provider retention period. See FakeFilter's API documentation.

Provider retention periods are controlled by each provider. Local app data normally remains until you delete it, clear the app's data, or remove the app. After account deletion, a previously signed-in device removes that account's inspection data on its next successful connection as described above.

10. Your choices

You can use public educational pages without an account. You can deny camera or location permission and type a VIN or location instead where supported. You can request access to, correction of, or deletion of your account information through the account controls or by contacting us. We may retain limited records when required for security, fraud, payment disputes, taxes, or other legal obligations.

To ask a privacy question or make a data request, email [email protected]. You can also visit our Support page.

11. Children's privacy

The service is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information so we can review and remove it where required.

12. Policy changes

We may update this policy when the service or our practices change. We will post the revised policy here and change the date at the top. If a change materially affects how we handle personal information, we will provide notice where required.