Privacy Notice
Version 2026-09-02 · POPIA-oriented operational draft
Who is responsible
VinTrust is the responsible party for consumer accounts and its own platform operations. For an enterprise workspace, the named customer may be the responsible party and VinTrust its operator, as defined in the applicable data-processing agreement.
Information we process
We process account and organisation details, VINs and vehicle attributes, inspection images and metadata, verification findings, audit events, payment references, support records, consent records and data-subject requests. GPS is processed only when captured for an inspection. Card details are handled by the payment gateway and are not stored by VinTrust.
Why and legal basis
We use information to perform the requested service, secure accounts, prevent fraud, maintain evidence and audit trails, meet contractual and legal duties, improve validated models using approved datasets, and support legitimate operational interests. Where consent is the appropriate basis, it is recorded and may be withdrawn without affecting earlier lawful processing.
External recipients
Information may be processed by hosting, AI analysis, communications, payment and explicitly configured vehicle-data providers. VIN transmission to a vehicle-data provider occurs only for an initiated verification and the provider state is disclosed as verified, not verified or unavailable. Enterprise customers control their authorised users and roles.
International processing
Some operators may process information outside South Africa. VinTrust and enterprise customers must ensure an appropriate POPIA section 72 basis and contractual safeguards before enabling such processing.
Retention
Consumer and enterprise retention follows the configured policy, evidential need and legal obligations. An organisation’s default period is displayed in its administration console. Deletion may be restricted where records are required for a dispute, fraud investigation, statutory duty or signed-report integrity.
Security
VinTrust uses role and tenant controls, separation of duties, access logging, server-side gateway verification and cryptographic report-integrity records. No system is risk-free; suspected compromises should be reported immediately through the support or enterprise contact channel.
Your rights
Subject to POPIA, you may request access, correction, deletion, objection, portability where available, or withdrawal of consent. Authenticated users can submit and track requests and export their own data in Settings. Identity verification may be required before fulfilment.
Automated analysis
VinTrust uses automated image and data analysis, but reports are screening evidence rather than autonomous legal determinations. Material adverse or high-impact decisions must receive qualified human review and an opportunity for escalation.
Complaints
Contact VinTrust’s designated Information Officer using the contact in your organisation agreement or support channel. You may also complain to South Africa’s Information Regulator. This notice will be updated when formal contact particulars and operator schedules are approved.
This draft implements clear product disclosures and request controls; formal legal approval, operator agreements, retention schedules and Information Officer particulars remain required.
Read the Terms of Service →