Privacy Policy
Last updated: February 3, 2025
1. Introduction
RecallRover ("Service") is operated by UpfrontOps, LLC ("we," "us," or "our"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and how we protect it. By using RecallRover, you agree to the practices described in this policy.
2. Information We Collect
We collect only the information necessary to deliver your recall report:
- Vehicle Identification Number (VIN): The 17-character VIN you enter to generate your recall report.
- Email address: Used to deliver your report and purchase confirmation.
- Payment information: Credit card or other payment details processed securely by Stripe. We do not store your full card number on our servers.
- Usage data: We collect anonymized analytics data (pages visited, device type, browser) through cookies and analytics services to improve the Service.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Report generation: Your VIN is sent to the NHTSA public API to retrieve recall data, which is then processed into your report.
- Report delivery: Your email address is used to send you your recall report and purchase receipt.
- Payment processing: Your payment details are used solely to complete your one-time purchase.
- Service improvement: Anonymized usage data helps us understand how customers use RecallRover and improve the experience.
- Bot protection: We use Google reCAPTCHA to prevent automated abuse. reCAPTCHA may collect hardware and software information for analysis.
4. Third-Party Services
We share your information with the following third parties only as needed to operate the Service:
- Stripe: Processes your payment securely. Stripe's handling of your payment data is governed by the Stripe Privacy Policy.
- NHTSA: We send your VIN to the National Highway Traffic Safety Administration's public API to retrieve recall data. NHTSA is a U.S. government agency; their data is publicly available.
- Resend: We use Resend to deliver your report and receipt via email. Resend processes your email address on our behalf. See the Resend Privacy Policy.
- Anthropic (Claude): We use the Claude AI API to generate plain-language recall summaries. Only recall data (not your email or payment info) is sent to this service.
- Google reCAPTCHA: Used for bot protection. Subject to the Google Privacy Policy.
- Hotjar: Used for anonymized analytics and heatmaps to improve our website. Sensitive fields are suppressed from recording. See the Hotjar Privacy Policy.
- Google Analytics: Used to understand website traffic and usage patterns. See the Google Privacy Policy.
We do not sell, rent, or share your personal information with advertisers, insurers, data brokers, or any other third parties beyond those listed above.
5. Data Retention
We retain your data as follows:
- VIN and report data: Stored in our database to enable report delivery and customer support. Retained for as long as needed to provide the Service.
- Email address: Retained for report delivery and customer support purposes. We do not use your email for marketing unless you explicitly opt in.
- Payment records: Transaction records are retained as required by applicable tax and accounting laws. Full card details are held only by Stripe.
6. Data Security
We take reasonable measures to protect your information, including:
- All data transmitted between your browser and our servers is encrypted via HTTPS/TLS.
- Payment processing is handled entirely by Stripe, a PCI DSS Level 1 certified provider.
- Our infrastructure runs on Cloudflare, which provides DDoS protection, Web Application Firewall, and other security features.
- Sensitive form fields are excluded from analytics recording using PII suppression.
No method of electronic storage or transmission is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Cookies and Tracking
RecallRover uses cookies and similar technologies for:
- Essential cookies: Required for payment processing and bot protection (Stripe, reCAPTCHA).
- Analytics cookies: Google Analytics and Hotjar use cookies to understand how visitors interact with our site. These cookies collect anonymized data.
You can control cookies through your browser settings. Disabling cookies may affect the functionality of the Service.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate personal information.
- Deletion: Request deletion of your personal information, subject to legal retention requirements.
- Opt out: Opt out of analytics tracking by using browser settings or tools like the Google Analytics Opt-out Browser Add-on.
To exercise any of these rights, contact us at support@recallrover.com. We will respond within 30 days.
9. Children's Privacy
RecallRover is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the Service after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at support@recallrover.com.