Review-safe public draft
Privacy Policy
This review-safe draft explains the information categories and privacy boundaries reflected by the current VEHICOTEK storefront and planned account, installer, warranty, contact, and support pathways.
Last updated: July 24, 2026
Scope
This Privacy Policy describes how VEHICOTEK public website experiences may collect, use, disclose, and protect information through the storefront, company pages, product pages, installer pathways, account access routes, warranty and protection routes, and contact workflows.
This page is drafted for the current repository state. Production provider names, retention periods, dedicated contacts, and legally required disclosures must be finalized before relying on this page as legal advice or a final public policy.
Information We Collect
Depending on which public route or account workflow you use, VEHICOTEK may collect the following categories of information:
- Contact information
- Business information
- Authentication metadata
- Installer application data
- Vehicle and warranty information when submitted through approved workflows
- Claim and support communications
- Order and transaction information when commerce workflows exist
- Device, browser, IP, and diagnostics data generated by normal website operation
- Session storage used for homepage intro playback
Automatic Information
Normal website operation may create technical information such as IP address, browser type, device information, request timestamps, diagnostics, security logs, and error information. The committed storefront also uses the session-only browser storage key vehicotek_intro_played to avoid replaying the homepage intro during the same browser session.
How We Use Information
- Present product, installer, warranty, protection, company, contact, and account experiences.
- Route inquiries to the correct product, installer, account, warranty, claim, protection benefit, business, or general support pathway.
- Validate form input and reduce unnecessary sensitive information in general contact messages.
- Prepare installer applications, owner verification, warranty registration, claim preparation, and support workflows where those routes exist.
- Maintain security, debug issues, protect accounts, and improve website reliability.
- Comply with applicable legal, operational, accounting, or dispute obligations when approved systems exist.
Account and Authentication
Owner and installer account routes may use authentication/session endpoints in configured environments. The current storefront treats browser-stored roles, permissions, sessions, and cart counts as development-only state and not as a production authorization boundary.
Installer Application Data
Installer application routes may ask for business name, contact details, service area, capabilities, application status, and supporting business information. Approved backend workflows must govern application review, organization records, invitations, memberships, roles, approval, suspension, and audit records.
Vehicle, Warranty, and Claim Data
Warranty registration, lookup, claim, transfer, and protection benefit pathways may involve vehicle identifiers, installation records, product information, installer context, photos, documents, ownership contact information, and status information. The repository currently separates these public preparation pages from backend warranty and claim implementation.
Orders and Transactions
Future commerce workflows may involve cart, order, pricing, fulfillment, payment, tax, returns, and order-support information. Medusa owns authoritative commerce records, while payment processors own payment-processor transaction state. The F2F-B public pages do not implement cart, checkout, Stripe, or payment processing.
Retention
VEHICOTEK should retain information only as long as necessary for the purposes described in this policy, including account management, installer application review, warranty and claim administration, customer support, security, legal compliance, accounting, and dispute handling. Exact retention periods require legal and operational approval.
Security
VEHICOTEK should use reasonable administrative, technical, and organizational safeguards appropriate to the information and workflow involved. No website can guarantee absolute security, and users should avoid submitting passwords, verification codes, full payment-card numbers, government identifiers, or unnecessary sensitive information through general contact forms.
Choices and Rights
Depending on your location and applicable law, you may have rights to request access, correction, deletion, portability, restriction, objection, or withdrawal of consent. These rights are not identical everywhere and may be subject to verification, exceptions, and retention obligations. Use the Contact page to start a privacy request until a dedicated privacy contact is approved.
Children
VEHICOTEK public pages are designed for automotive product, installer, owner, warranty, and business workflows and are not directed to children. If child-related data handling becomes relevant, the policy and product requirements must be reviewed before implementation.
Cross-Border Processing
Provider locations, hosting regions, support locations, and data transfer mechanisms are not finalized in the committed repository. Cross-border processing disclosures and safeguards must be reviewed before production use.
Third-Party Services
The current storefront references Medusa-backed account and commerce concepts in configured environments. No committed analytics abstraction, tracking script, or marketing cookie provider is present. Future analytics, email, payment, maps, support, hosting, or OMS providers must be documented before production launch.
Changes
VEHICOTEK may update this Privacy Policy as product, account, installer, warranty, support, and commerce systems evolve. The page should show an updated effective date when finalized changes are published.
Contact
Until dedicated privacy contact information is approved, privacy questions should begin through the Contact VEHICOTEK page and should avoid unnecessary sensitive details.
