← Back to The Lane Check

Privacy Policy

Last updated 12 September 2026

Who operates this service

The Lane Check is operated by Vent Pro NYC Inc., 1712 East 22nd Street, New York, NY 11229, United States. “The Lane Check” is a trading name used by that company for this service. Subscription payments are processed by Stripe and appear on your statement as LANECHECK.

Contact: [email protected]

The short version

We hold your email address, a count of the reports you have run, and whether your subscription is paid. We never see your card. We do not sell anything to anyone, and we run no advertising or analytics. You can have all of it deleted by sending one email.

Your account

Running a report requires an account, because the first three reports are free and we have to count them somewhere you cannot edit. An account is created the first time you ask for a sign-in code at an email address.

We store, for each account:

  • Your email address. It is how you sign in, and it is how a Stripe payment is matched to your account.
  • Sign-in records. When you request a code we store a one-way hash of that code and of the one-click link, never the code itself, along with when it was issued and how many times an incorrect code was submitted. These rows expire after ten minutes and are single-use.
  • Your session. Signing in sets one cookie, lc_session. It holds a random value; our database stores only a one-way hash of it, so a copy of our database would not let anyone sign in as you. It is HttpOnly and Secure, lasts 30 days, and is removed when you sign out. It is strictly necessary for the service to work and is not used for tracking.
  • The vehicles you have run. For each report we keep the VIN (or the year, make and model), and the date. This is what enforces the free limit, it is what lets you re-open a report you already ran without spending another credit, and for subscribers it is your history.
  • Subscription state. Whether your plan is free, active, past due or cancelled, plus your Stripe customer and subscription identifiers and the date your current period ends.

What happens to a VIN you enter

A VIN is sent to our server, which queries the National Highway Traffic Safety Administration (NHTSA) public APIs to decode the vehicle and retrieve owner-complaint and recall records for that year, make and model. NHTSA receives the VIN or the year/make/model from our server, not from your browser. Their handling of that request is governed by NHTSA’s own policies.

We keep the VIN against your account as described above. A VIN identifies a vehicle, not a person, and we make no attempt to link one to an owner, a registration or any history record.

Payments

Payments are taken by Stripe. Card numbers are entered on Stripe’s own checkout page and never reach our servers — we cannot see them and do not store them. Stripe tells us, by a signed webhook, the email address used at checkout, your Stripe customer and subscription identifiers, and the status of the subscription. That is what switches your account on. Stripe’s handling of your payment data is governed by Stripe’s privacy policy.

Email

Sign-in codes are delivered by Resend, an email provider, which receives your email address and the contents of that message in order to deliver it. We send sign-in codes and service messages about your account. We do not send marketing email, and there is no mailing list.

Stored on your device

  • The session cookie described above — strictly necessary, not used for tracking.
  • Recent VIN searches — the last six VINs you looked up are kept in your browser’s localStorage so the Recent buttons work. This never leaves your device and you can clear it with the Clear recent VINs button.

There are no advertising cookies, no tracking pixels and no third-party analytics.

Who else is involved

  • Cloudflare — hosts the site, the API and the database, and processes connection information such as your IP address in order to deliver it and to rate-limit abuse. We store a hashed form of your IP address only inside short-lived rate-limiting counters, which expire within the hour.
  • NHTSA — receives the vehicle you look up. Public US government API.
  • Stripe — payments.
  • Resend — delivers sign-in emails.
  • Google Fonts — typefaces are loaded from fonts.googleapis.com and fonts.gstatic.com. Google receives your IP address and browser details as part of serving those files. No VIN, email address or account data is sent to Google.

What we never do

  • We do not sell, rent or share your email address or your search history with anyone.
  • We do not run advertising, behavioural profiling or third-party analytics.
  • We do not use your data to train anything.
  • We do not tell a manufacturer, auction or dealer which vehicles you looked at.

How long we keep it

  • Sign-in codes — ten minutes, then dead; the row is cleared on use.
  • Sessions — 30 days, or immediately when you sign out.
  • Rate-limiting counters — under an hour.
  • Account, report history and subscription state — until you ask us to delete it. We remove accounts that have been inactive for two years.

Your choices

Email [email protected] from the address on the account and we will, within 30 days:

  • send you a copy of everything we hold about you;
  • correct anything that is wrong;
  • delete your account and its history. If you have an active subscription, cancel it first or ask us to, since deletion ends your access.

Depending on where you live you may have these rights under law (for example the GDPR or the CCPA). We apply them to everyone regardless. We do not sell personal information as those laws define it. Our lawful basis for holding your email address and report count is performance of the contract you enter into when you use the service.

Children

This is a tool for motor-vehicle dealers. It is not directed at children and we do not knowingly collect data from anyone under 18.

Where your data is

The database is hosted by Cloudflare in the United States. If you use the service from outside the United States, your information is transferred there.

Security

Sign-in codes and session tokens are stored only as one-way hashes. Everything is served over HTTPS. Payment card data never reaches us. No system is perfect, and we will tell affected users promptly if we ever become aware of a breach that puts their data at risk.

Changes

If we change this policy in a way that materially affects you, we will email account holders before it takes effect. The date at the top always reflects the current version.

Contact

Questions about this policy: [email protected]

Back to The Lane Check Privacy Policy Terms of Use [email protected]