Privacy Policy
Responsible entity
Good Store LLC
Registration and Tax ID 406325098, Georgia
46 Dodashvili Street, Tbilisi, Georgia
+995 595 115 562
What this notice covers
This notice describes how Good Store LLC handles information when you use the free vehicle identity check on cartraceai.com. It is written to be read, not to be survived.
We process personal data under the Law of Georgia on Personal Data Protection. Where you are in the European Economic Area, we also apply the General Data Protection Regulation.
This version also covers how we return a completed check through a refresh-safe result page and, only when you choose “Save in this browser”, how we keep recent checks in the same browser profile. Saving is optional. If you do not save, you still receive the check you requested and no saved-check collection is created.
What we store
For every check we store an opaque public identifier, a keyed one-way hash of the VIN, the input type, your chosen language and the outcome. The hash cannot be reversed to recover the VIN.
The application database does not store your full IP address or browser user-agent string. To limit abuse it stores only a keyed one-way hash of a truncated network range. Our web servers separately record the network address, browser user-agent, and request and security metadata in access and security logs; the logs rotate weekly and four archived rotations are retained.
After a completed check, the refresh-safe result keeps the normalized VIN temporarily only inside an authenticated, encrypted result cookie bound to that exact search and guest session. Result continuity creates no additional database copy of the VIN.
Only when you explicitly save a check do we create an immutable saved snapshot. It contains the normalized VIN encrypted with a versioned encryption key, a masked VIN, allowlisted vehicle identity facts, the result status, and references and policy versions that prove the exact search, source and retained evidence. It does not contain a plaintext VIN or raw provider response.
The saved-check access record contains only a purpose-separated HMAC-SHA-256 digest of the random browser capability, its key version, read scope, issue and expiry times, and any revocation time. We do not store the raw capability in PostgreSQL, a URL, a log or analytics.
We do not ask for or store your name, email address, postal address, telephone number or payment information. There are no user accounts and no email or cross-device recovery for saved checks.
Why we are allowed to do this
Providing the check you asked for: we process the VIN because you asked us to perform the check. Without the identifier there is no service to provide. The short result-continuity step is used only to return that same completed check safely after the redirect and on refresh.
Saving a check at your request: if you actively choose “Save in this browser”, we process the encrypted snapshot and browser capability only to provide that optional same-browser feature. Saving is not required for the free check. Declining or leaving the confirmation creates no saved collection and does not reduce the core service.
Preventing abuse: we rely on our legitimate interest in keeping the service available and in not passing automated traffic on to the public data source we depend on. This is why a truncated network range is hashed and counted.
Keeping records of what we did: we rely on our legitimate interest in being able to investigate faults and demonstrate that the service behaved correctly.
We do not treat the save action as consent to advertising, analytics, profiling or any unrelated use. We use neither result cookie nor saved-check capability for those purposes.
Cookies and browser storage
We set __Host-cartrace_session after you submit a check. It links your submission to its result and protects the form against cross-site request forgery. It has Path=/, is host-only, Secure, HttpOnly and SameSite=Lax, and expires after no more than 24 hours.
When refresh-safe results are enabled, a completed check returns a private 303 redirect and sets __Secure-cartrace_free_result. It contains an authenticated encrypted VIN envelope bound to the exact search and guest session. It is scoped to the exact result path, is Secure, HttpOnly and SameSite=Lax, has no Domain attribute, and expires after no more than 1 800 seconds, or 30 minutes. The result identifier alone does not grant access.
Only after a successful explicit save do we set or renew __Host-cartrace_recent_checks. It contains a versioned random browser-collection capability; PostgreSQL stores only its HMAC-SHA-256 digest. It has Path=/, is host-only, Secure, HttpOnly and SameSite=Lax, has no Domain attribute, and expires no later than 2 592 000 seconds, or 30 days. Merely opening an empty recent-checks page sets no cookie and creates no stored collection.
The cookies described above support checking, saving when you choose to do so, and continuing the report offer for the same vehicle. We use no third-party tracking or analytics cookies, localStorage, sessionStorage or IndexedDB. Another person using the same browser profile may open saved checks and see the reminder; on a shared device, dismiss the reminder and do not save checks unless you accept that access.
Continuing the offer for your checked vehicle
When a free VIN check returns vehicle identity data and reminders are enabled, we set the __Host-cartrace_checked_vehicle cookie to continue the paid-report offer for that vehicle on other pages of this site. It contains an encrypted VIN and search reference bound to your guest session. It has Path=/, Secure, HttpOnly and SameSite=Lax, no Domain attribute, and expires after no more than 1 800 seconds, or 30 minutes.
The reminder displays a masked VIN. Dismissing it clears the matching cookie; creating an order for the same vehicle also clears it. Ordinary page navigation does not extend its lifetime. Reopening your own result may start a new 30-minute period. This feature does not store an additional VIN in the database or save a Recent Check. It sends no data to advertising networks and uses no third-party tracking, analytics events, localStorage, sessionStorage or IndexedDB. Another person using the same browser profile may also see the reminder.
How long we keep information
Check records are deleted 30 days after they are created. Records of calls made to the vehicle data source, and the vehicle data returned, are deleted 180 days after the call.
The encrypted result cookie expires after no more than 1 800 seconds. An unsaved result creates no recoverable VIN in the application database.
A saved snapshot and access grant last no more than 30 days and never beyond the earliest retained search, checked provider request, original source request or normalized cache deadline on which the result depends. Expired or invalidated evidence, or loss of current licensing or data rights, makes the saved result unavailable sooner.
“Remove” immediately revokes access to one saved result. “Clear all” immediately revokes every grant for that browser collection and expires its capability cookie. These actions remove browser access now; they do not promise immediate physical deletion of the immutable encrypted snapshot. Inaccessible ciphertext remains only until its already fixed source-bounded deadline, then the existing retention deletion of required evidence removes the snapshot and grants by database cascade.
Abuse-prevention counters expire after 15 minutes. Sessions expire after 24 hours at the latest and are then deleted. Deletion is carried out automatically by a scheduled process running under a restricted database identity; it is not a manual promise.
Who else receives information
To decode a VIN we send it to the vehicle product information catalog operated by the United States National Highway Traffic Safety Administration, NHTSA. This is a public government service; we hold no account with it.
This is a transfer of data outside Georgia and the European Economic Area. It happens only because it is necessary to perform the specific check you asked for, and it is limited to the VIN itself. We send no information about you with it.
Result refresh, saving and opening a saved check reuse retained source-backed evidence. They do not call NHTSA again, add a provider, create another recipient or introduce another international transfer.
We use no analytics provider, advertising network, content delivery network or embedded third-party content. Nobody else receives anything.
Your rights and saved-check controls
You may ask us for a copy of the data we hold about you, to correct it, to delete it, to restrict how we use it, or to object to our use of it. You may also ask to receive it in a portable form.
The exact browser capability lets that browser profile list masked VINs and open the full saved result. It is not an account and cannot be recovered by email or on another device. Another person using the same browser profile may have the same access.
You can use “Remove” or “Clear all” without contacting us. Access is revoked immediately, while any inaccessible encrypted snapshot is physically removed later by the bounded retention cascade described above.
There is an important practical limit. We deliberately avoid direct account identifiers. Without the browser capability or enough information to lawfully identify the relevant record, we may be unable to connect a request to a particular check or inaccessible snapshot. Where we cannot identify the record, we cannot act on a request about it, and we will tell you so.
To make a request, write to Good Store LLC, 46 Dodashvili Street, Tbilisi, Georgia, or call +995 595 115 562. We will respond within one month.
If you are not satisfied, you may complain to the Personal Data Protection Service of Georgia. If you are in the European Economic Area, you may complain to your local supervisory authority.
Automated decision-making
We carry out no automated decision-making or profiling that produces legal or similarly significant effects. The check returns manufacturer specification data and tells you which sources answered; it does not score you or the vehicle.
Changes and language
The version identifier and effective date of this notice are shown at the top of the page. When we change it materially, we publish a new version identifier and a new effective date.
This notice is published in Georgian, English, Russian, Kazakh, Armenian and Azerbaijani. If the versions differ, the Georgian version prevails.