1. What We Collect
Data stored on your device only
The following data is stored in Chrome's local extension storage and is never transmitted to our servers:
| Data | Purpose | Retention |
|---|---|---|
| Filter settings (countries, cities, max shipping, min rating, age filter) | Remember your filter preferences | Until you reset them or uninstall the extension |
| Item cache (seller country/city, shipping price, rating, listing age) | Avoid re-fetching the same item page | 7 days, then auto-expired |
Data synced across your devices via Chrome
The following data is stored in Chrome's sync storage, which Chrome may synchronise across devices on the same Google account:
| Data | Purpose | Retention |
|---|---|---|
| Installation ID (unique installation identifier) | Identify your installation for license management | Until you uninstall the extension |
| License tier and status | Know whether Pro features are active | Until you uninstall |
| Trial eligibility data | Track your 3-day free trial | Until you uninstall |
Data transmitted to our backend
When you first use the extension, your Installation ID is sent to our server to register your free trial. On subsequent launches, it is sent to validate your license status.
| Data | When sent | Why |
|---|---|---|
| Installation ID | On first launch and periodic revalidation | Trial registration and license validation |
| License key (if entered) | When you activate a Pro license | License activation |
License purchase records (D1 database)
When you purchase a Pro license through Creem, our payment processor notifies us via a webhook. We store the following in our database:
| Data | Source | Purpose |
|---|---|---|
| Creem customer ID | Creem webhook | Link your Creem account to your license |
| License key | Creem webhook | Validate your Pro status |
| Subscription ID | Creem webhook | Track subscription lifecycle (renewals, cancellations) |
| Product type (monthly / lifetime) | Creem webhook | Determine license terms |
| License status | Creem webhook + ongoing updates | Know if your license is active, expired, or cancelled |
| Installation ID | Extension (passed at checkout) | Link your license to your extension installation |
We do not receive or store your name, email address, billing address, or payment card details. These are handled exclusively by Creem under their own privacy policy.
The rk_id cookie
When you register for a free trial, our backend sets a cookie named rk_id on the backend domain.
It is:
- HttpOnly and Secure — not accessible to page scripts
- Required for cross-origin requests from the extension
Its sole purpose is to restore your prior registration if you reinstall the extension. It is never used for tracking or advertising.
2. What We Don't Collect
- Your Vinted username, email, or account details
- Your Vinted session cookies or authentication tokens (the extension causes your browser to include these in requests on your behalf, but we never receive or store them)
- The items you viewed, searched for, or purchased on Vinted
- Your name, email address, or billing information
- Your IP address (we do not log it in our application; Cloudflare, our infrastructure provider, may process it per their own privacy policy)
- Any data from websites other than the supported Vinted domains
We do not use, sell, or transfer your data for advertising or marketing purposes.
3. How the Extension Accesses Vinted Pages
To show seller location, shipping cost, and other details on Vinted catalog pages, the extension fetches individual item pages directly from Vinted using your existing logged-in session. This is equivalent to your browser visiting those pages on your behalf.
- The extension reads only publicly visible information from each item page (seller location, shipping price, rating, listing age)
- None of this information is transmitted to our servers
- All parsed data is cached locally on your device for up to 7 days
4. Permissions We Use
| Permission | Why |
|---|---|
storage |
Save filter settings and item cache on your device |
tabs |
Send status notifications (rate limit warnings, login prompts) to open Vinted tabs |
alarms |
Schedule background license checks without keeping the service worker alive continuously |
| Host permissions on Vinted domains | Fetch item pages on supported Vinted websites |
| Host permission on our backend domain | License validation and trial registration |
5. Third-Party Services
Cloudflare Workers and D1
Our backend runs on Cloudflare Workers, and our license database runs on Cloudflare D1. Your Installation ID and license records are stored and processed on Cloudflare's infrastructure. Cloudflare acts as a data sub-processor under their Data Processing Addendum. Data may be processed in the United States or other countries where Cloudflare operates. Cloudflare participates in the EU–U.S. Data Privacy Framework.
Google Chrome Sync
Data stored in Chrome's sync storage (Installation ID, license tier, and trial eligibility data) may be synchronised to Google's servers as part of Chrome's built-in sync feature, subject to Google's privacy policy.
Creem
License purchases are processed by Creem, our payment and license management provider. When you purchase a license, Creem processes your payment and sends us a webhook confirming the transaction. We receive only the data listed in Section 1. Creem's privacy policy governs how they handle your payment and billing data.
6. Legal Basis for Processing (GDPR)
| Processing activity | Legal basis |
|---|---|
| Trial registration (generating and storing Installation ID) | Performance of a contract — Art. 6(1)(b) |
| License validation (sending Installation ID to backend) | Performance of a contract — Art. 6(1)(b) |
| Storing license purchase records in D1 | Performance of a contract — Art. 6(1)(b) |
| Local caching of Vinted item data | Legitimate interest of the user (improving browsing experience) — Art. 6(1)(f) |
7. Data Retention
| Data | Retention |
|---|---|
| Item cache | 7 days (auto-expired), deleted on uninstall |
| Filter settings | Until you reset them or uninstall the extension |
| Chrome sync data (Installation ID, license tier, trial eligibility data) | Until you uninstall the extension |
rk_id cookie |
400 days, or until you clear browser cookies |
| License records in D1 (customer ID, license key, subscription ID) | Until you request deletion. We may retain records for up to 7 years for accounting and legal compliance purposes if a purchase was made. |
8. Your Rights (GDPR / EEA)
If you are located in the European Economic Area, you have the right to:
- Access — request a copy of personal data we hold about you
- Erasure — request deletion of your Installation ID and associated license records from our database
- Rectification — request correction of inaccurate data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — where processing is based on consent (currently not applicable)
To exercise any of these rights, contact us at the address below. We will respond within 30 days. Note that deleting an active license record will deactivate your Pro license.
To delete your local data immediately: uninstall the extension. All data in Chrome's local and sync storage is removed on uninstall. If you disable rather than uninstall the extension, locally stored data persists until you uninstall.
9. International Data Transfers
Your Installation ID and license records are processed on Cloudflare's infrastructure, which may be located outside the European Economic Area, including in the United States. These transfers are covered by Cloudflare's Standard Contractual Clauses and their participation in the EU–U.S. Data Privacy Framework.
10. Children's Privacy
The extension is not directed at children under 16 and we do not knowingly collect data from children. Vinted itself requires users to be at least 18 years old.
11. Changes to This Policy
We will update the "Last updated" date at the top of this page when we make material changes. Significant changes will also be noted in the Chrome Web Store update description.
12. Chrome Web Store User Data Policy
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
13. Contact
For privacy questions, data access requests, or erasure requests:
Email: rackoon.support@gmail.com
We aim to respond within 30 days.