V2.0 LIVERinevo v2.0 "Firing Pin" is now the Main Engine— 500k+ live Korean catalog, zero IP-bans & sub-minute delta webhooks.
What's New in v2.0
BACK TO HOMEPAGE
PRIVACY FRAMEWORK ZERO AI TRAINING ON USER DATA

Privacy Policy

LAST UPDATED: SEPTEMBER 4, 2026 • VERSION 2.1 • GLOBAL COMPLIANCE (GDPR, CCPA, PIPA)

Welcome to Rinevo. We take transparency and personal data protection seriously.

This Privacy Policy explains how Rinevo (“Company,” “we,” “our,” or “us”) collects, processes, stores, and protects personal and technical information when you interact with www.rinevoapi.com, our developer API gateway, vehicle search indexes, developer testing sandboxes, and administrative applications.

1. Who We Are

Operator: Rinevo Data Services operates the high-performance www.rinevoapi.com data aggregation platform.

Core Mission: Providing developer-friendly REST endpoints, real-time vehicle index queries, and automated Korean-to-English automotive specification translation for international automotive enterprises and software engineers.

Data Protection Contact: [email protected]

2. What Rinevo Does

Rinevo is an automated data indexing and API integration platform. We aggregate publicly accessible automotive market registry data, standardize technical specifications, options arrays, and inspection records, and transform regional terminology into structured English JSON payloads for enterprise consumers.

No Vehicle Sales or Brokering: We are a pure technology and data infrastructure provider. We do not sell vehicles, broker auto sales, or hold physical car inventory.

3. Information We Collect

What We Do NOT Collect (Trust Principles)

  • No Credit Card Numbers Stored: All billing is processed via external PCI-DSS Level 1 compliant processors; we never store or see your raw card numbers.
  • No Biometric or Sensitive Personal Data: We never collect medical, biometric, racial, religious, or political data.
  • No Address Books or Contact Harvesting: Our services never request access to your device contact lists or mobile files.
  • No End-User Tracking Across Unrelated Sites: We do not participate in third-party cross-site data broker networks.

A. Data You Submit & API Interactions

When you query our API endpoints or interactive sandbox, we process search parameters (e.g., brand, model, vehicle registration plate numbers, or chassis VIN identifiers) solely to return the corresponding structured vehicle records.

B. Account & Authentication Metadata

If you register for an account or authenticate via Google OAuth, we receive your verified email address, full name, profile avatar URL (if provided by Google), and assign a cryptographic API Key and internal user identifier.

C. Technical & Operational Server Logs

To enforce subscription rate limits, prevent denial-of-service (DoS) attacks, and maintain server reliability, our edge reverse proxies automatically log:

  • Client IP address and geographic country code
  • HTTP request method, target path, and HTTP status code
  • Request duration, payload size, and user-agent header string
  • API key bearer prefix (for quota accounting)

4. How We Use Information & AI Disclosures

We utilize collected information exclusively for:

  • Delivering requested vehicle specifications, images, and option translations.
  • Monitoring platform uptime, throughput quotas, and error rates.
  • Defending against automated bot abuse, credential stuffing, and cyber threats.
  • Complying with statutory accounting and tax regulations.

Mandatory AI & Machine Learning Disclosures (2025–2026 Standards)

  • Zero AI Training on User Data: Customer search queries, API calls, VIN lookups, and account data are NOT used to train, retrain, fine-tune, or improve public AI models (including OpenAI, Google Gemini, or Anthropic models).
  • Translation Engine Processing:Automotive options (e.g., 통풍시트 → Ventilated Seats) are translated using deterministic dictionaries and cloud NLP services under enterprise zero-data-retention terms.
  • Probabilistic Output Disclaimer: Machine-translated vehicle options, insurance accident claim categories, and color keys are generated automatically and may contain minor linguistic variations. Always verify vehicle equipment against source photos.

5. Cookies & Tracking Technologies

We use cookies and local storage tokens strictly to maintain authenticated sessions, record legal consents, and collect aggregate usage metrics. We do not deploy third-party advertising or retargeting cookies.

Cookie / Storage KeyPurposeDurationHow to Opt Out
rinevo_terms_acceptedRemembers acceptance of Terms of Service & Privacy PolicyPersistent (Local)Clear browser localStorage
rinevo_auth_tokenSecure session token for admin dashboard accessSession / 7 DaysLog out of the dashboard or clear cookies
_ga, _ga_*Google Analytics — anonymous aggregate visitor volume metricsUp to 14 MonthsGA Opt-Out Plugin

6. Third-Party Sub-Processors & Infrastructure

To host and protect our platform, we engage trusted third-party service providers (“Sub-processors”) bound by stringent Data Processing Agreements (DPAs):

ProviderService RoleLocationPrivacy Link
Cloudflare, Inc.DNS routing, DDoS mitigation, and edge SSL cachingGlobal Edge NetworkCloudflare Privacy
Hetzner / VPS CloudBackend data processing workers, PostgreSQL database, and Redis cacheGermany / EU / USHetzner DPA
Google LLCGoogle OAuth authentication & anonymous aggregate analyticsUnited States / GlobalGoogle Privacy

7. Data Retention Schedules

We adhere to strict data minimization principles. We do not maintain indefinite log storage:

  • API Request Logs & IP Access Records: Retained in rotating log files for exactly 30 days for diagnostic and DDoS security analysis, after which they are permanently purged.
  • Aggregated Analytics Data: Retained in Google Analytics for 14 months (standard non-personally identifiable retention ceiling).
  • Account & API Key Records: Retained for the active duration of your subscription account. Upon account deletion requests, all associated API keys and credentials are deleted within 14 calendar days.
  • Public Vehicle Catalog Data: Aggregated vehicle specifications are refreshed continuously as listings become active or sold across regional markets.

8. Your Legal Rights (GDPR & CCPA/CPRA)

Depending on your geographic residency, you possess enforceable data protection rights:

  • Right to Access: Request copies of your personal registration details and billing history.
  • Right to Rectification: Request correction of inaccurate account metadata.
  • Right to Erasure (“Right to be Forgotten”): Request immediate deletion of your account and API keys.
  • Right to Restrict or Object: Restrict processing under Article 18 & 21 of the GDPR.
  • Right to Data Portability: Obtain your account details in structured, machine-readable JSON format.
  • Right to Opt-Out of Sale/Share: We do not sell personal data under California CCPA/CPRA.

To exercise any of these rights, email us at: [email protected]

We verify requests through your registered account email and respond within 30 calendar days with zero fee.

9. International Data Transfers

Because our API servers and data processing clusters operate across high-speed nodes located in the European Union, United States, and East Asia, your API requests may transit across international borders.

All cross-border data transmissions are encrypted via industry-standard TLS 1.3 cryptographic protocols, and sub-processor transfers comply with the European Commission Standard Contractual Clauses (SCCs).

10. Children's Privacy Protection

Rinevo is a commercial developer API and enterprise vehicle analytics suite intended exclusively for businesses and adult developers aged 18 and older. We do not knowingly market to or solicit personal data from children under 16 (in the EEA) or under 13 (in the United States, under COPPA).

If you believe a minor has registered an account, contact us immediately at [email protected] for permanent removal.

11. Security Architecture

We implement multi-layered physical and software security safeguards to protect all user and system data:

  • TLS 1.3 Encryption: All API calls and web traffic are strictly enforced over HTTPS with HSTS headers.
  • Cryptographic Key Hashing: API secrets and user tokens are stored using salted cryptographic hash functions.
  • Automated Rate Limiting: In-memory Redis sliding-window counters protect against brute-force and credential abuse.
  • Breach Notification Commitment: In the unlikely event of a verified data breach impacting user accounts, we commit to notifying affected users and supervisory authorities within 72 hours of confirmation.

12. Policy Changes & Updates

We may revise this Privacy Policy periodically to reflect technological improvements, security audits, or legal mandates. Material changes will be accompanied by an updated “Last Updated” date at the top of this page.

Your continued use of our developer APIs or website after changes are posted constitutes your affirmative acceptance of the modified Privacy Policy.

13. Contact & Inquiries

For privacy inquiries, Data Protection Officer (DPO) questions, or regulatory requests:

14. Regional Compliance Supplements

A. EEA / UK GDPR Statutory Supplement

Under Article 6 of the General Data Protection Regulation (GDPR), our legal bases for processing personal data include:

  • Contract Performance (Art. 6(1)(b)): Executing API transactions, providing vehicle datasets, and provisioning developer credentials.
  • Legitimate Interests (Art. 6(1)(f)): Maintaining server perimeter security, defending against automated bot attacks, and optimizing API response latency.
  • Legal Obligations (Art. 6(1)(c)): Retaining transaction and tax invoicing logs.

EEA/UK residents have the right to lodge a formal complaint with their national supervisory data protection authority.

B. California Consumer Privacy Act (CCPA / CPRA)

In compliance with California Civil Code § 1798.100 et seq., Rinevo confirms:

  • Zero Sale or Sharing of Personal Information: We have not sold or shared any consumer personal data in the preceding 12 months for cross-context behavioral advertising.
  • Non-Discrimination: We do not discriminate against users who exercise statutory privacy rights.
  • Right to Opt-Out: Because we do not sell or monetize personal data, no “Do Not Sell My Info” opt-out transaction is necessary.

C. South Korea Personal Information Protection Act (PIPA)

Public vehicle specifications (chassis VINs, model names, registration numbers, inspection charts) indexed from Korean automotive marketplaces (such as Encar) constitute public commercial vehicle registry metadata and do not include the personal identification details of private Korean registered vehicle owners.