Privacy policy
This policy covers the vint-agent browser extension and the website at https://vintagent.app. We, the people who run vint-agent, are the controller of your personal data: we decide how it is used. To reach us about anything in this policy, email [email protected].
The short version
- We never ask for your Vinted password. The extension works through the Vinted tab you are already logged into, in your browser.
- Your wardrobe, orders, conversations and shipping labels stay in your browser. We only receive parts of them when you save a backup or use an AI feature. If you join the leaderboard, we also receive how many items you sold this week and this month.
- We store your vint-agent account, the Vinted accounts you link, your backups, and the notes, SKUs and locations you add.
- We don’t sell your data, show ads, or use analytics or advertising trackers.
- You can delete backups, unlink a Vinted account or delete your whole account yourself at any time, in the panel’s Settings or on the account page.
What we store on our servers
Our servers run on Convex. This is everything the extension and the website store there.
| Data | What it is | Why | How long |
|---|---|---|---|
| Account | Your email address, your password as a salted hash (PBKDF2-SHA256, 600,000 rounds) if you set one, your plan, and your sign-in sessions. If you use Continue with Google: your Google account id, your name and the link to your Google profile photo as Google sends them (updated each time you sign in with Google), and that Google verified your email address. | To sign you in and apply your plan | Until your account is deleted. A sign-in lasts up to 30 days. |
| Linked Vinted accounts | For each Vinted account you use with vint-agent: its Vinted user id, username, market (for example vinted.fr) and the date you linked it | To keep your backups and notes with the right account, and so one Vinted account belongs to one vint-agent user | Until you unlink it or delete your account |
| Billing | Your Stripe customer id, subscription id, subscription status, renewal date and whether it is set to cancel | To know which plan you paid for | Until your account is deleted |
| Monthly usage | How many times you used each metered feature this month, for example 212 reposts | To apply your plan’s monthly limits | Deleted on the 1st of the next month |
| Backups | A copy of each listing you back up: title, description, brand, price, currency, status, the listing’s details as Vinted returns them, its parcel size, and its photos | So you can restore or relist the listing later | Until you delete the backup, unlink its Vinted account or delete your account |
| Inventory | The SKU and storage location you type for a listing | To show them in Dressing+, Backups and Order+ | Until you clear them, unlink their Vinted account or delete your account |
| Inbox organisation | Per conversation: pinned, archived, a colour mark and your private note. Your mark colours. We don’t store message text. | To show your inbox the way you organised it on every device | Until you clear them, unlink their Vinted account or delete your account |
| Automatic labels | The ids of sales the extension has already made a label for automatically, and when. Not the label, the buyer or the address. | So a label is never made twice, from another tab or device | Until you unlink that Vinted account or delete your account |
| Autopilot replies to favourites | If you switch it on: for each favourite Autopilot answers, the Vinted member id and item id, when a tab took it on, whether the reply went out and how many times it failed. Not the message, the member’s name or anything else about them. | So a member is never contacted twice about the same item, from another tab or device | Until you unlink that Vinted account or delete your account |
| Leaderboard (only if you join) | For each Vinted account you join with: the nickname you pick, how many items you sold this week and this month (counted by the extension from your Vinted orders), the days you opened vint-agent, your streak, your best streak and your best month. Anyone can see the nickname, market, items sold and active days. Not your email, Vinted username or anything about your orders. | To rank you against other sellers who joined, and to award streaks and trophies | Until you leave the leaderboard, unlink that Vinted account or delete your account. Leaving deletes all of it. |
| Suggestions | Text you send from the panel’s More tab, with the extension version | To read your feedback | Until you ask us to delete it or delete your account |
| Affiliate programme | If you are an affiliate: your code and its Stripe promotion code id, the commission on each paid invoice of a subscription that started with your code (the month of that subscription, the rate, the amount, the currency and the date), and the payouts we made to you. If you subscribed with an affiliate’s code: that your subscription started with it, its Stripe subscription id, and the commission it earned. The affiliate sees only when you joined and what they earned, never your email. | To pay affiliates their commission | An affiliate’s records until their account is deleted. When a customer who used a code deletes their account, the link to them is removed and the affiliate keeps the commission records, which then identify no one. |
| Unrecognised order statuses | A status sentence from Vinted that Order+ couldn’t sort, with its market and how often it was seen. It isn’t linked to your account or to an order. | To add the sentence to Order+ | Until we have added it |
| Server logs | Which server function ran, when, and whether it failed. Our code doesn’t write what you store or send into the logs; when something fails, a log line can name your user id. | To find and fix faults | Kept by Convex for a short time. We don’t copy them elsewhere. |
| Support emails | What you write to [email protected], with your email address | To answer you | Until the matter is closed, then up to 12 months in case you write again |
Your private notes and suggestions contain whatever you type into them. Please don’t put a buyer’s personal details there unless you need to.
We don’t keep our own copies of the database outside Convex, so deleted data is gone from our side once the deletion finishes.
What stays in your browser
The extension keeps these in your browser’s extension storage, on your device only. Removing the extension deletes them.
- Your vint-agent sign-in token.
- Your settings, filters, relist settings, saved messages for Notifs+ and the list of favourites you already messaged.
- The running queue and its log.
- Your wardrobe, orders, sales figures for the Dashboard, conversations and offers, read live from Vinted. If you join the leaderboard, only your weekly and monthly count of items sold is sent to us.
- Shipping labels. They include the buyer’s name and address. The extension downloads them from Vinted and makes the PDF in your browser. They are never sent to us.
The website keeps your sign-in token in your browser’s local storage when you sign in on the account page. It sets no cookies of its own and uses no analytics or advertising trackers.
How the extension uses Vinted
The extension adds a panel to Vinted’s pages on Vinted’s own domains. When you start an action, such as a relist or a price change, it sends the request to Vinted from your Vinted tab, as you. Your browser attaches your Vinted session itself.
- We never ask for or store your Vinted password or session cookies. Like Vinted’s own page, the extension reads the page’s security token and Vinted’s anonymous visitor id, only to send them back to Vinted with each request. They are never sent to us.
- Our servers never connect to Vinted.
- Nothing runs on your Vinted account unless you start it in the panel, or switch on an Autopilot automation (replies to new favourites, automatic labels). An automation you switch on runs from any open Vinted tab until you switch it off, and what it does shows in the queue.
- vint-agent isn’t made by, affiliated with or endorsed by Vinted. Vinted’s own privacy policy covers your Vinted account.
AI features
AI features send text to Anthropic, which runs the Claude model, through our server. We don’t store what is sent or what comes back. Anthropic keeps it only for a limited time under its commercial terms and doesn’t use it to train its models.
- Suggested replies send the listing title and the last 20 messages of the conversation, marked as buyer, seller or Vinted.
- AI listings send the details you type, your Vinted market (for example vinted.fr) and, if you add one, a photo of the item.
- Rewritten text on relist (if you switch it on in the relist settings) sends each listing’s title, brand and description.
AI features are only available on plans that include them, and only run when you ask for them.
Image+ isn’t available yet. When it launches, the photos you upload to Image+ will be sent to Google’s Gemini API to make the new image. We will update this policy before then.
Who processes data for us
These companies process data on our behalf, only to run vint-agent, under a data processing agreement with us.
| Company | What they do for us | What they receive |
|---|---|---|
| Convex | Database, sign-in, photo storage and server functions | Everything in “What we store on our servers” |
| Stripe | Payments and the billing portal | Your email address and vint-agent user id. You enter your card on Stripe’s page; we never see it. Stripe is also responsible itself for some payment data, for example to prevent fraud, under its own privacy policy. |
| Resend | Sends password reset emails | Your email address and the reset code |
| Google (only if you use Continue with Google) | Signs you in with your Google account | You sign in on Google’s own page, so Google learns that you signed in to vint-agent. We ask Google only for your name, email address and profile photo. |
| Anthropic | Runs the AI features | The text and photos described under “AI features” |
| Cloudflare | Hosts the website, and forwards email sent to [email protected] to our mailbox | Your IP address and the pages you request; the emails you send us |
| Google Fonts | Serves the fonts on the website and in the panel | Your browser requests the fonts from Google, so Google receives your IP address |
We don’t sell your data, share it with advertisers, or use it to decide creditworthiness or lending.
Chrome Web Store and Google user data
The use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. vint-agent’s use of information received from Google APIs (Continue with Google) adheres to the Google API Services User Data Policy, including the Limited Use requirements. In short:
- We use this data only to provide and improve vint-agent’s single purpose: helping you manage your own Vinted wardrobe.
- We don’t sell it, use it for advertising, or use it to decide creditworthiness.
- We transfer it only to the processors above, to run the features you use, or when the law requires it.
- No person at vint-agent reads it, unless you ask us to (for example in a support request), it is needed for security or to comply with the law, or it has been made anonymous.
Where your data is stored
Our Convex deployment is in the European Union (Ireland). Convex, Stripe, Resend, Google, Anthropic and Cloudflare are based in the United States, so your data can be processed there. When we send personal data outside the European Economic Area or the United Kingdom, we rely on the EU-US Data Privacy Framework (and its UK extension) where the company is certified under it, and otherwise on the European Commission’s Standard Contractual Clauses (with the UK addendum) in our agreement with that company. You can ask us for a copy of these safeguards.
Legal basis
If you are in the European Economic Area or the United Kingdom, we rely on:
- Contract, to provide the account, backups, billing, AI features, Autopilot and the other features you use, and to pay affiliates.
- Consent, for the leaderboard. You join it yourself and can leave at any time; leaving doesn’t affect what was lawful before.
- Legitimate interests, to keep the service secure, to find faults, to add unrecognised order statuses, to read your suggestions and answer your emails, and to load the fonts. You can object to these.
- Legal obligation, to keep billing records for as long as tax and accounting law requires.
Your rights
You can ask us to show you, correct, export or delete your data, to restrict or stop using it, and to object to our use of it based on legitimate interests. Where we rely on consent, you can withdraw it at any time. Email [email protected] from the address on your account. We reply within one month.
You can do some of this yourself:
- Delete a backup and its photos in the panel’s Backups tab.
- Export your backups as CSV in the Backups tab.
- Clear a SKU, location or note by emptying it.
- Cancel your subscription in the billing portal, from the account page.
- Leave the leaderboard in the panel’s Dashboard tab. This deletes your nickname, counts, streak and trophies.
- Unlink a Vinted account at the end of the panel’s Settings. This deletes that account’s backups and their photos, inventory, inbox organisation, automatic label records and leaderboard entry.
- Delete your account at the end of the panel’s Settings or on the account page. You type DELETE to confirm.
- Sign out, and remove the extension to delete what it keeps in your browser.
Deleting your account cancels a paid plan straight away, with no refund for the rest of the period (see “Withdrawal and refunds” in the terms if you are within 14 days of subscribing), then deletes your account and sign-ins, linked Vinted accounts, backups and their photos, inventory, inbox organisation, automatic label records, leaderboard entries, monthly usage and suggestions. If you are an affiliate, it also switches off your code and deletes your referrals, commissions and payouts. If you subscribed with an affiliate’s code, the affiliate keeps the commission records, unlinked from you. It starts at once and usually finishes within minutes. If the subscription can’t be cancelled, nothing is deleted and you are told why. Stripe keeps the payment records, with your email address, for as long as tax and accounting law requires. If you can’t sign in, email [email protected] from the address on your account and we will delete it for you within 30 days.
You can also complain to a data protection authority, in the EU or UK country where you live or work, or where you think the problem happened.
Security
Connections to our servers use HTTPS. Passwords are stored only as a salted hash. The keys for Stripe and Anthropic stay on our server and are never sent to your browser. Each backup, note and SKU can only be read with the account that saved it.
Children
vint-agent is for Vinted sellers. You must be at least 18 to use it. We don’t knowingly collect data from children; if you think a child has given us data, email us and we will delete it.
Changes
If we change this policy, we update the date at the top. If a change affects what we collect or who receives it, we tell you by email or in the panel before it applies.
Contact
Email: [email protected].