Privacy Policy
LAST UPDATED: SEPTEMBER 4, 2026 • VERSION 2.1 • GLOBAL COMPLIANCE (GDPR, CCPA, PIPA)
Welcome to Rinevo. We take transparency and personal data protection seriously.
This Privacy Policy explains how Rinevo (“Company,” “we,” “our,” or “us”) collects, processes, stores, and protects personal and technical information when you interact with www.rinevoapi.com, our developer API gateway, vehicle search indexes, developer testing sandboxes, and administrative applications.
1. Who We Are
Operator: Rinevo Data Services operates the high-performance www.rinevoapi.com data aggregation platform.
Core Mission: Providing developer-friendly REST endpoints, real-time vehicle index queries, and automated Korean-to-English automotive specification translation for international automotive enterprises and software engineers.
Data Protection Contact: [email protected]
2. What Rinevo Does
Rinevo is an automated data indexing and API integration platform. We aggregate publicly accessible automotive market registry data, standardize technical specifications, options arrays, and inspection records, and transform regional terminology into structured English JSON payloads for enterprise consumers.
No Vehicle Sales or Brokering: We are a pure technology and data infrastructure provider. We do not sell vehicles, broker auto sales, or hold physical car inventory.
3. Information We Collect
What We Do NOT Collect (Trust Principles)
- No Credit Card Numbers Stored: All billing is processed via external PCI-DSS Level 1 compliant processors; we never store or see your raw card numbers.
- No Biometric or Sensitive Personal Data: We never collect medical, biometric, racial, religious, or political data.
- No Address Books or Contact Harvesting: Our services never request access to your device contact lists or mobile files.
- No End-User Tracking Across Unrelated Sites: We do not participate in third-party cross-site data broker networks.
A. Data You Submit & API Interactions
When you query our API endpoints or interactive sandbox, we process search parameters (e.g., brand, model, vehicle registration plate numbers, or chassis VIN identifiers) solely to return the corresponding structured vehicle records.
B. Account & Authentication Metadata
If you register for an account or authenticate via Google OAuth, we receive your verified email address, full name, profile avatar URL (if provided by Google), and assign a cryptographic API Key and internal user identifier.
C. Technical & Operational Server Logs
To enforce subscription rate limits, prevent denial-of-service (DoS) attacks, and maintain server reliability, our edge reverse proxies automatically log:
- Client IP address and geographic country code
- HTTP request method, target path, and HTTP status code
- Request duration, payload size, and user-agent header string
- API key bearer prefix (for quota accounting)
4. How We Use Information & AI Disclosures
We utilize collected information exclusively for:
- Delivering requested vehicle specifications, images, and option translations.
- Monitoring platform uptime, throughput quotas, and error rates.
- Defending against automated bot abuse, credential stuffing, and cyber threats.
- Complying with statutory accounting and tax regulations.
Mandatory AI & Machine Learning Disclosures (2025–2026 Standards)
- Zero AI Training on User Data: Customer search queries, API calls, VIN lookups, and account data are NOT used to train, retrain, fine-tune, or improve public AI models (including OpenAI, Google Gemini, or Anthropic models).
- Translation Engine Processing:Automotive options (e.g., 통풍시트 → Ventilated Seats) are translated using deterministic dictionaries and cloud NLP services under enterprise zero-data-retention terms.
- Probabilistic Output Disclaimer: Machine-translated vehicle options, insurance accident claim categories, and color keys are generated automatically and may contain minor linguistic variations. Always verify vehicle equipment against source photos.
6. Third-Party Sub-Processors & Infrastructure
To host and protect our platform, we engage trusted third-party service providers (“Sub-processors”) bound by stringent Data Processing Agreements (DPAs):
| Provider | Service Role | Location | Privacy Link |
|---|---|---|---|
| Cloudflare, Inc. | DNS routing, DDoS mitigation, and edge SSL caching | Global Edge Network | Cloudflare Privacy |
| Hetzner / VPS Cloud | Backend data processing workers, PostgreSQL database, and Redis cache | Germany / EU / US | Hetzner DPA |
| Google LLC | Google OAuth authentication & anonymous aggregate analytics | United States / Global | Google Privacy |
7. Data Retention Schedules
We adhere to strict data minimization principles. We do not maintain indefinite log storage:
- API Request Logs & IP Access Records: Retained in rotating log files for exactly 30 days for diagnostic and DDoS security analysis, after which they are permanently purged.
- Aggregated Analytics Data: Retained in Google Analytics for 14 months (standard non-personally identifiable retention ceiling).
- Account & API Key Records: Retained for the active duration of your subscription account. Upon account deletion requests, all associated API keys and credentials are deleted within 14 calendar days.
- Public Vehicle Catalog Data: Aggregated vehicle specifications are refreshed continuously as listings become active or sold across regional markets.
8. Your Legal Rights (GDPR & CCPA/CPRA)
Depending on your geographic residency, you possess enforceable data protection rights:
- Right to Access: Request copies of your personal registration details and billing history.
- Right to Rectification: Request correction of inaccurate account metadata.
- Right to Erasure (“Right to be Forgotten”): Request immediate deletion of your account and API keys.
- Right to Restrict or Object: Restrict processing under Article 18 & 21 of the GDPR.
- Right to Data Portability: Obtain your account details in structured, machine-readable JSON format.
- Right to Opt-Out of Sale/Share: We do not sell personal data under California CCPA/CPRA.
To exercise any of these rights, email us at: [email protected]
We verify requests through your registered account email and respond within 30 calendar days with zero fee.
9. International Data Transfers
Because our API servers and data processing clusters operate across high-speed nodes located in the European Union, United States, and East Asia, your API requests may transit across international borders.
All cross-border data transmissions are encrypted via industry-standard TLS 1.3 cryptographic protocols, and sub-processor transfers comply with the European Commission Standard Contractual Clauses (SCCs).
10. Children's Privacy Protection
Rinevo is a commercial developer API and enterprise vehicle analytics suite intended exclusively for businesses and adult developers aged 18 and older. We do not knowingly market to or solicit personal data from children under 16 (in the EEA) or under 13 (in the United States, under COPPA).
If you believe a minor has registered an account, contact us immediately at [email protected] for permanent removal.
11. Security Architecture
We implement multi-layered physical and software security safeguards to protect all user and system data:
- TLS 1.3 Encryption: All API calls and web traffic are strictly enforced over HTTPS with HSTS headers.
- Cryptographic Key Hashing: API secrets and user tokens are stored using salted cryptographic hash functions.
- Automated Rate Limiting: In-memory Redis sliding-window counters protect against brute-force and credential abuse.
- Breach Notification Commitment: In the unlikely event of a verified data breach impacting user accounts, we commit to notifying affected users and supervisory authorities within 72 hours of confirmation.
12. Policy Changes & Updates
We may revise this Privacy Policy periodically to reflect technological improvements, security audits, or legal mandates. Material changes will be accompanied by an updated “Last Updated” date at the top of this page.
Your continued use of our developer APIs or website after changes are posted constitutes your affirmative acceptance of the modified Privacy Policy.
13. Contact & Inquiries
For privacy inquiries, Data Protection Officer (DPO) questions, or regulatory requests:
- Privacy Desk Email: [email protected]
- Official Domain: www.rinevoapi.com
- Telegram Community: https://t.me/+N8ta-M6u5phlMmQy
14. Regional Compliance Supplements
A. EEA / UK GDPR Statutory Supplement
Under Article 6 of the General Data Protection Regulation (GDPR), our legal bases for processing personal data include:
- Contract Performance (Art. 6(1)(b)): Executing API transactions, providing vehicle datasets, and provisioning developer credentials.
- Legitimate Interests (Art. 6(1)(f)): Maintaining server perimeter security, defending against automated bot attacks, and optimizing API response latency.
- Legal Obligations (Art. 6(1)(c)): Retaining transaction and tax invoicing logs.
EEA/UK residents have the right to lodge a formal complaint with their national supervisory data protection authority.
B. California Consumer Privacy Act (CCPA / CPRA)
In compliance with California Civil Code § 1798.100 et seq., Rinevo confirms:
- Zero Sale or Sharing of Personal Information: We have not sold or shared any consumer personal data in the preceding 12 months for cross-context behavioral advertising.
- Non-Discrimination: We do not discriminate against users who exercise statutory privacy rights.
- Right to Opt-Out: Because we do not sell or monetize personal data, no “Do Not Sell My Info” opt-out transaction is necessary.
C. South Korea Personal Information Protection Act (PIPA)
Public vehicle specifications (chassis VINs, model names, registration numbers, inspection charts) indexed from Korean automotive marketplaces (such as Encar) constitute public commercial vehicle registry metadata and do not include the personal identification details of private Korean registered vehicle owners.
