Privacy Policy

What we collect, why we are allowed to, who else touches it, and the rights you have. Written to be read, not to be skipped.

Last updated: 17 August 2026

1. Who we are

Vintify is a UK business operating from the United Kingdom, and is the trading name used throughout these pages. Our full registered business details are published here before any paid subscription opens, and are available on request at any time at hello@getvintify.com.

We are the data controller for the personal data described in this policy, except where we say otherwise in “Your buyers’ data”.

For anything about your data, email hello@getvintify.com. We answer data protection requests within one month, as the law requires.

2. What we collect

We collect only what the service needs to work:

  • Account details — your name, email address, and an encrypted password (or a Google sign-in, if you use one).
  • Billing details — your plan, subscription status and payment history. Card numbers are handled entirely by Stripe and never reach us.
  • Your Vinted trading data — your sales, purchases, listings, messages and the buyer information attached to your orders, read from your own Vinted account.
  • What you type into Vintify — costs, SKUs, notes, expenses, goals and settings.
  • Technical data — IP address, browser type and timestamps, recorded when you use the app so we can keep it secure and diagnose faults.

3. What we never collect

We never ask for, receive or store your Vinted password. The extension works with the session already signed in on your own computer, and your Vinted credentials never leave your browser.

We never receive your card number, expiry date or security code. Payments go directly to Stripe.

We do not buy personal data from anyone, and we do not sell yours to anyone.

4. Why we are allowed to use it

Data protection law requires us to have a lawful basis for each purpose. Ours are:

  • To provide the service you have paid for — syncing your Vinted data, calculating profit, producing tax estimates: performance of our contract with you (UK GDPR Article 6(1)(b)).
  • To take payment and prevent fraud: performance of our contract, and our legitimate interests in being paid and not being defrauded (Article 6(1)(b) and (f)).
  • To keep the service secure and diagnose faults: our legitimate interests in running a secure, working product (Article 6(1)(f)).
  • To send you service messages — a failed payment, a change to these terms, a security notice: performance of our contract, and our legal obligations (Article 6(1)(b) and (c)).
  • To send you marketing about Vintify: your consent, which you can withdraw at any time (Article 6(1)(a)). We do not add you to marketing without asking.
  • To keep accounting and tax records: our legal obligations (Article 6(1)(c)).

5. Your buyers’ data

Your Vinted orders contain personal data about other people — your buyers’ usernames, names, towns and delivery details. This part matters and most tools skip it.

For that data, you are the controller and we are your processor. In plain terms: it is your data about your customers, we only hold it to provide the service to you, and we act on your instructions.

As your processor we commit to the following, which together satisfy Article 28 of the UK GDPR and form part of our agreement with you:

  • We process buyers’ data only to provide Vintify to you, and only on your documented instructions — using the service is that instruction.
  • Everyone with access is bound by confidentiality.
  • We keep appropriate security measures, described below.
  • We engage only the sub-processors listed below, under written terms no weaker than these, and we will tell you before we add or replace one so you can object.
  • We help you respond if a buyer exercises their rights, and we help you meet your own breach-notification and impact-assessment duties.
  • On request we delete or return buyers’ data when your account ends, and we make available what you need to show we are meeting these obligations.
  • We tell you without undue delay if we become aware of a personal data breach affecting it.

6. Who else processes it

We use a small number of providers to run Vintify. Each one only receives what it needs, and each is bound by contract to protect it:

  • Supabase — database and authentication. Your data is held in the EU (Stockholm).
  • Railway — application hosting.
  • Stripe — payments. Stripe is the controller of its own payment data and processes it under its own policy.
  • Sentry — error monitoring. We strip authentication headers before anything is sent.
  • Cloudinary — image hosting for listing photos you upload.
  • OpenAI — only when you use an AI feature, and only the listing text involved. It is not used to train their models.

7. Where your data goes

Your database sits in the European Economic Area. Some of our providers — Stripe, Sentry, OpenAI — are based in the United States or process data there.

Where data leaves the UK or EEA we rely on the safeguards the law requires: the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, or an adequacy decision covering that country. You can ask us for details of the safeguard used for any provider.

8. How long we keep it

We keep your account and trading data for as long as your account is open, because the whole point of the product is the history.

When you close your account we delete it within 30 days, apart from anything we are legally required to keep — invoices and payment records, which we keep for six years to satisfy HMRC.

Technical logs are kept for up to 90 days. Error reports are kept for up to 90 days.

9. Your rights

Under UK and EU data protection law you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything that is wrong.
  • Delete your data — we will, unless we are legally required to keep it.
  • Restrict what we do with it, or object to processing based on legitimate interests.
  • Send your data to you or another provider in a portable format. Much of this you can do yourself: Vintify exports to CSV and PDF from inside the app.
  • Withdraw consent to marketing at any time, without affecting anything done before.

10. If you are unhappy

Please tell us first at hello@getvintify.com — we would rather put it right.

You also have the right to complain to the Information Commissioner’s Office, the UK data protection regulator: ico.org.uk, or 0303 123 1113. If you are in the EU, you may complain to your own country’s supervisory authority instead.

11. How we protect it

Everything travels over encrypted connections. Passwords are hashed by our authentication provider and never visible to us. Any Vinted tokens we hold are encrypted at rest.

Every query in the application is scoped to the account that made it, so one customer’s data cannot be returned to another.

Access to production systems is limited to those who need it. If a breach ever affects your rights and freedoms, we will tell the ICO within 72 hours and tell you without undue delay, as the law requires.

No system is perfectly secure, and we will not pretend otherwise. What we can promise is that we will tell you quickly and honestly if something goes wrong.

12. Cookies

We use only the cookies and local storage the app needs to work — keeping you signed in, and remembering your preferences. These are strictly necessary, so under the Privacy and Electronic Communications Regulations they do not require consent.

We do not use advertising cookies and we do not track you across other websites. If we ever add analytics that are not strictly necessary, we will ask for your consent first.

13. Automated decisions

We do not make decisions with legal or similarly significant effects about you by automated means alone.

Vintify does automate things on your behalf — suggesting prices, drafting listing text, responding to offers under rules you set. Those act on your instructions and within limits you control, and you can turn each of them off.

14. Children

Vintify is for people aged 18 and over. We do not knowingly collect data about children. If you believe a child has given us personal data, tell us at hello@getvintify.com and we will delete it.

15. Changes to this policy

If we make a change that materially affects how we use your data, we will email you at least 30 days beforehand.

Minor clarifications take effect when published. The date at the top always shows the current version.

Questions about this policy? Email hello@getvintify.com or use the contact form.