Privacy Policy
How GoodToKnow collects, uses, and protects personal data on goodtoknow.net.
Last updated: 29 June 2026
1. Who We Are
GoodToKnow OÜ ("the Company," "we," "us," or "our"), registered in Estonia and located at Roseni 10, Floor 5, 10111 Tallinn, Estonia, operates goodtoknow.net. Our core service is a B2B API that reconciles fragmented vehicle records from national and regional registries into a single verified history report, together with residual value estimates and risk scores. Clients are typically motor insurers pricing used-car policies and vehicle marketplace operators performing pre-listing due diligence. If you have any questions about this policy, contact us at [email protected].
2. Information We Collect
Our primary data flows are business-to-business: we process vehicle identification numbers (VINs) and associated registry metadata submitted by API clients, not end-consumer personal profiles. However, the following categories of personal data may be collected through the website and supporting services:
- Identity and contact data you submit directly: name, job title, company name, business email address, and telephone number when you register for API access or contact our team.
- API account data: login credentials, organisation details, and billing contact information created when you activate an account.
- Communication content: messages, support tickets, and email correspondence with our team.
- Technical and usage data collected automatically: IP address, browser type, operating system, referring URL, pages visited, session timestamps, and API call logs (endpoint, response time, error codes, not payload content).
- Analytics data: aggregate behavioural signals collected via first-party analytics tools to understand how visitors use the site.
VIN lookup payloads submitted through the API are processed solely to return the requested vehicle history and risk output. We do not use vehicle registry data to build consumer profiles, and we do not use VIN payloads submitted by clients to train machine-learning models without explicit written agreement.
3. How We Use Information
We use the information described above for the following purposes:
- Provisioning and operating the API service: authenticating API clients, routing requests to registry data sources, returning scored results, and managing rate limits and billing.
- Account management: creating and maintaining API accounts, sending transactional messages such as credential resets and usage alerts.
- Service improvement: analysing aggregate usage patterns to improve query accuracy, data coverage, and response performance; no individual behavioural profiling is involved.
- Communication: responding to sales enquiries, support requests, and developer documentation feedback.
- Legal and security obligations: detecting abuse, satisfying audit or regulatory requests, and enforcing our Terms of Service.
We do not sell personal information to third parties.
4. Sharing
We share personal data only with service providers acting as processors on our behalf under written data-processing agreements (for example, infrastructure hosting providers and business email systems). We share data with competent authorities where required by Estonian law or another applicable legal obligation. We do not transfer personal data to third parties for their own marketing purposes.
5. Retention and Security
We retain account and contact data for the duration of the commercial relationship and for up to three years thereafter, or for a longer period if required by a legal or contractual obligation. API call logs (excluding payload content) are retained for up to 13 months for service monitoring and billing reconciliation purposes, then deleted or anonymised.
We apply technical and organisational safeguards proportionate to the sensitivity of the data, including encrypted transit (TLS), access controls, and regular security reviews. No method of transmission or storage is entirely without risk; we cannot guarantee absolute security.
6. Your Rights
Subject to applicable Estonian and EU data-protection law, you may have rights to access, correct, delete, or restrict the use of your personal data, and to object to certain processing or withdraw consent where processing is based on consent. To make a request, email [email protected]. We aim to respond within 30 days. If you are not satisfied with our response you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).
7. International Data Transfers
GoodToKnow OÜ is based in Estonia (EU). Where we use infrastructure or service providers located outside the European Economic Area, we apply appropriate safeguards such as Standard Contractual Clauses to ensure that international transfers of personal data meet the requirements of applicable EU data-protection law.
8. Cookies
We use cookies and similar technologies on goodtoknow.net. See our Cookie Policy for full details, including how to manage your preferences.
9. Changes and Contact
We may update this policy from time to time. Material changes will be reflected by a new "Last updated" date above. We encourage you to review this page periodically.
GoodToKnow OÜRoseni 10, Floor 5
10111 Tallinn, Estonia
Email: [email protected]
Phone: +372 614 2280