Last updated: October 6, 2026 · effective from September 30, 2026
The controller of the data of the license server and of the purchase pages is Giovanni Rosa Salva, Venice (Italy), developer of VintPro+ and, on the Chrome Web Store, also of VintPro and VintPro Scout: it is the same name as in the trader profile of the developer account. For any privacy question, to exercise your rights or to ask for deletion, write to supporto@vintpro.it: the controller answers directly. No data protection officer (DPO) has been appointed.
This policy covers only:
cfodjbcgakjdafnmdijaahaekpehjbpd on the Chrome Web Store), in every published version, including the optional Raspberry Pi scripts shipped in its pi/ folder;vintpro-license-server.vintpro.workers.dev) and the emails it sends;It does not cover VintPro and VintPro Scout, which are different extensions with their own Privacy Policy, nor what Vinted, Telegram, Discord and Stripe do with data under their own rules.
Who does what. We run the license server: for that data we are the controller (§3.2). Everything else the extension does on your device, on your instructions: that data never reaches us and we cannot see it.
Read from Vinted with your session, on the www.vinted.* sites listed in the extension, on Vinted's messaging service api.vinted.* (reached from the open Vinted tab, as the website itself does, not through an extension permission) and on the photo storage *.vinted.net. None of these reads starts before your yes (§4), except the public data of your profile (number, username, how many reviews, followers and listings), needed to check the session and to link the license.
| Category | Whose | What |
|---|---|---|
| Account | Yours | Number and username; review count and rating of your profile; listings (title, price, photos, description, brand, size, condition, category); views and favourites over time; any restriction on the account |
| Orders | Yours and your counterparts' | Sale orders and also purchase orders: item, price, date, shipping status, address of the item photo and the username of the counterpart, that is the buyer or the seller |
| Money | Yours | Available and pending Vinted balance; yearly totals for the DAC7 thresholds |
| Offers | Of whoever makes you an offer | Username, item, offered price, the buyer's review count and rating |
| Messages | Your buyers' and yours | At every round the engine reads the text of the order and offer chats it checks (the first 25 conversations plus those of open orders), to know where each order stands, who wrote last and not to send the same message twice. It keeps only the text of the last message of each chat (up to 300 characters), with the username, for the /domande command |
| List of conversations | Your counterparts' | Only when you use "🧹 Pulizia conversazioni" (conversation clean-up): the full list of conversations, with the counterpart's username and a preview of the last message (60 characters), to suggest which ones to delete. It deletes only the ones you confirm |
| Favourites | Of people who like your items | Username and number, item |
| Reviews | Of people who review you | Username, address of the profile picture, text, rating |
| Per-customer history | Your buyers' | Computed on your device from your sales: how many purchases, total, average, first and last purchase (Customers page, exports, sale alert on the bot) |
| Session credentials | Yours | The anti-CSRF token of the Vinted page (from the headers of the page's own requests, from its metadata or from its HTML) and the anon_id cookie, read to sign the requests to Vinted. The token stays in the Vinted page (attribute data-vpp-csrf); neither is stored in the extension's space or sent outside Vinted |
Entered by you in the panel or in the bot:
What it never extracts, stores or sends: your Vinted password (it uses the session already open), the shipping addresses, phone numbers and emails of buyers and sellers, card, account or IBAN details, your browsing history, on Vinted or elsewhere, the content of sites other than Vinted. Vinted's responses may contain more fields than those listed above (for example the details of an order): they pass through the extension's memory while it works, but they are not extracted, stored or sent.
| Data | Where it comes from |
|---|---|
| Email address | You type it (trial, key recovery) or give it to Stripe when you buy |
| License key, plan, status, expiry | Created by the server |
| Number and username of the linked Vinted account | Sent by the extension, which reads them from the open Vinted tab |
| Extension version, random installation identifier and engine-turn token | Sent by the extension |
| Country and network (ASN number and provider name) of each access | Derived by Cloudflare from the IP address of the request. The IP address is not stored in readable form |
| Pseudonymised fingerprint of the email and of the IP address (HMAC-SHA256 with a secret key of the server, truncated): it does not contain the address in readable form, but it is still personal data | Only when you request the trial or a key recovery |
| Stripe identifiers (checkout session, customer, subscription, payment, charge, invoice) | From Stripe, after the purchase |
| Date of first and last access, number of accesses | Recorded by the server |
| In our Stripe account, not on the server: name, email, country and billing address you give Stripe, card brand, last 4 digits and expiry, amounts, dates, refunds and disputes | Collected by Stripe when you pay. Never the full card number or its security code |
When the extension calls the server:
Without a saved key the extension does not call the server, except for the trial and the recovery you ask for. Before the trial and before linking, the panel tells you what will reach the server and for how long it is kept, and asks you to confirm.
The same information, with the category names of the Chrome Web Store privacy form:
| Category | Collected | What, why, where and to whom |
|---|---|---|
| Personally identifiable information | Yes | Your email and the number and username of your Vinted account, to the license server (license, §5 and §7); the Vinted usernames of buyers, sellers, people who like your items and reviewers, in your browser and, in alerts, to your Telegram bot and your Discord webhook (§8); number and @username of anyone writing to your bot from another account |
| Authentication information | Yes | License key, installation identifier and turn token, to the license server; your bot token, which travels only to Telegram; the anti-CSRF token and the anon_id cookie of the Vinted page, read to sign the requests to Vinted and never stored in the extension or sent elsewhere (§3.1). Never the Vinted password |
| Financial and payment information | Yes | Your sales and purchases on Vinted, offer prices, balance and DAC7 totals: in your browser and, in alerts and reports, to your bot and your webhook. The license payment is collected by Stripe (§3.2). Never card numbers or IBANs |
| Health information | No | No health data |
| Personal communications | Yes | The messages of order and offer chats (read in the browser, only the last one of each chat is kept) and their text to your Telegram bot with /domande, with the replies you write from the bot; the text of reviews. Never to Discord, never to a server of ours |
| Location | Yes | Only on the license server: country and network of each access, derived by Cloudflare (§3.2). The extension does not read your location |
| Web history | No | No list of the pages you visit, on Vinted or elsewhere |
| User activity | Yes | Only on the license server: first and last access, number of accesses and the engine turn renewed every 4 minutes while it is on, that is when the engine works (§3.2). No record of clicks, keystrokes or movements |
| Website content | Yes | Listings, photos, reviews and orders read on Vinted (§3.1): in your browser and, in alerts, reports and PDFs, to your bot and your webhook |
Right after installation, VintPro+ opens the panel on the "🚦 First start" section. At the top there is "📋 First of all: your data": it says what the extension reads from Vinted, where it stays, what leaves and to whom, what it does in your name and how to withdraw your yes, with the link to this page, and it has two buttons, "I agree" and "I do not agree".
| Purpose | Data | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Running what you switch on: account import, repost and restock, messages to people who like your items and to buyers, offers, orders, storage, reports, bot | §3.1 | None on our side: we do not receive it, the software handles it on your device on your instructions. You decide how to use it: if you sell as a business you are its controller, if you sell privately you stay within personal use |
| Delivering, resending and checking the license, tying it to a single Vinted account, keeping one engine on at a time, delivering the key by hand if the email does not go out | Email, key, Vinted account, installation, token, Stripe identifiers | Performance of a contract (Art. 6.1.b) |
| Preventing a key from being shared or abused: access log, rejected attempts, notices to support | Key, Vinted account, country, network, dates | Legitimate interest in enforcing the license (Art. 6.1.f) |
| Stopping email floods | Fingerprints of the email and of the IP address | Legitimate interest in the security of the service (Art. 6.1.f) |
| Recognising refunds and payment disputes (chargebacks) | Stripe identifiers tied to the key, license email | Performance of a contract and legitimate interest in defending against a dispute (Art. 6.1.b and 6.1.f) |
| Keeping the books and meeting the tax obligations of license sales | Email, name and billing details, amounts, dates, Stripe identifiers | Legal obligation (Art. 6.1.c; Article 2220 of the Italian Civil Code and Article 22 of Presidential Decree 600/1973) |
| Answering when you write to us | Your email and what you write | Performance of a contract or pre-contractual steps (Art. 6.1.b) |
| Complying with another legal obligation, for example a request from an authority | Only the data requested | Legal obligation (Art. 6.1.c) |
What is required, and what happens without it. Email and Vinted account are needed for the trial and the license: without them the license is not activated and the engine does not start. Your yes of §4 is needed for the extension to read your account: without it, it does not read it. A Vinted tab open on your account is needed for the engine to work. A Telegram bot of your own is needed to switch the engine on, because the first start checks that alerts reach you: without it you can use the panel but the engine stays off. The Discord webhook is optional: without it, alerts only go to Telegram.
You can object to processing based on legitimate interest (Art. 21 GDPR) by writing to supporto@vintpro.it.
The extension's permissions, and what they are for:
| Permission | What it is for |
|---|---|
storage, unlimitedStorage | Keeping the data of §7.1 in your browser |
alarms | Letting the engine work at regular intervals |
tabs, scripting | Finding the open Vinted tab and loading into it the scripts that talk to Vinted |
downloads | Writing the daily backup into the Downloads folder and deleting its own older backups, and no other file |
Sites www.vinted.* and *.vinted.net | Working on your Vinted account and downloading the photos of your listings |
api.telegram.org, discord.com/api/webhooks, discordapp.com/api/webhooks | Only your bot and your webhook |
vintpro-license-server.vintpro.workers.dev | The license server |
api.vinted.* (no permission: the open Vinted tab reaches it) | Vinted's messaging service: the list of conversations and their deletion |
No other site. No remotely downloaded code: all the code the extension runs is in the published package.
In the extension's own space (chrome.storage.local) of your Chrome profile, on your device:
| Data | How long |
|---|---|
| Settings (with the bot token, chat id and webhook, in plain text); license (key, trial email, linked account); date and version of your yes of §4; account archive (listings, item details, history of views and favourites, storage); history of sale and purchase orders with the counterparts' usernames; list of who has already received a message | Until you uninstall the extension or delete them |
| Favourites received | 95 days, at most 2000 |
| Engine log | The last 400 lines |
| Last message of each chat, for /domande | Replaced at every new read |
| Offers waiting for your decision in the bot | The last 20 |
| Alerts not yet delivered to Telegram or Discord | 24 hours, at most 30 |
| Queue actions | Successful ones 48 hours; failed ones until you delete them |
| Internal copy of the backup | 2 days |
After the first account import, once a day — even with the engine off — the extension saves the file Downloads/VintPro-Backups/vintpro-backup-YYYY-MM-DD.json. It contains the account archive, the texts of the automatic messages, sales with buyers' usernames, the storage and the settings, including the bot token, chat id and webhook, in plain text. It does not contain the license key.
The extension deletes its own files older than 2 days, and only while it is installed: after uninstalling, the files remain, and you delete them. Backups and exports you make by hand stay wherever you save them. On a Raspberry Pi, the optional script pi/vintpro-usb-backup.sh copies these files to a USB stick and keeps the last 2 days.
The server runs on Cloudflare Workers, with the Cloudflare D1 database in Western Europe. Every day at 03:30 UTC an automatic clean-up deletes whatever has expired.
| Data | How long |
|---|---|
| Paid license: key, email, plan, status, Vinted account number, Stripe identifiers | While the license is active; after it ends (cancellation, refund, revocation) at most 10 years, for accounting obligations and to defend the rights under the contract, then the automatic clean-up deletes it |
| Trial license: key, email, Vinted account number | 12 months from the request, then the automatic clean-up deletes it |
| Number of the Vinted account that had a trial or a license, with the key | As long as VintPro+ exists, so as not to grant a second trial to the same account |
| Access log: key, account number and username, country, network, first and last access, number of accesses | 12 months from the last access |
| Rejected attempts (another account with the same key, a second engine on): key, account number and username, country and network, also of the other side if two installations contend for the engine | 90 days |
| Engine turn: installation, token, account number, country and network of whoever holds it | Deleted within a day of its expiry; a turn that is not renewed expires after 10 minutes |
| Brakes: pseudonymised fingerprints of the email and of the IP address (trial and key recovery); the license key, the Vinted account number and the network, in readable form, for the brakes on attempts and notices | 2 days |
| Subscription invoice payments: Stripe identifiers tied to the key | 540 days from the payment, the window in which a payment can be disputed |
| Stripe events that arrive before the license (Stripe identifiers only) | 30 days |
| Failed deliveries: email and key, when the email with the key does not go out | 90 days, to deliver it by hand |
| Server technical logs: masked email and last 4 characters of the key, never the whole key | At most 7 days, then Cloudflare deletes them |
| Accounting records of license sales (in our Stripe account and in the books) | 10 years, as the law requires (Article 2220 of the Italian Civil Code) |
| Emails you write to us and suspicious-key notices, in the support mailbox | The time needed to handle the request or the notice, and at most 24 months from the last message, then we delete them |
What the engine sends to your bot or your webhook stays in your chat or channel, and on the servers of Telegram or Discord, until you delete it, under the rules of those services. The extension does not delete it.
| Who | Why | What they receive | Where |
|---|---|---|---|
| Cloudflare, Inc. | Hosts the license server (processor) | The data of §3.2. It sees the IP address of each request, from which it derives country and network | Database in Western Europe; worldwide network; US company |
| Resend (Plus Five Five, Inc.) | Sends the key emails and the notices to support (processor) | Your email, the key and the text of the email; in notices, account number and username, country and network | United States |
| Aruba S.p.A. | Hosts the support mailbox, supporto@vintpro.it (processor) | The emails you write to us and the suspicious-key notices (account number and username, country and network) | Italy |
| Netlify, Inc. | Hosts the vintpro.it website, where the purchase starts (processor) | The IP address and technical data of website visitors (server logs). No cookies, no analytics | United States |
| Stripe (Stripe Payments Europe, Ltd. and Stripe, Inc.) | Takes the payment on this website's links, never inside the extension: for the payment it processes data on our behalf (processor); for fraud prevention and its own legal obligations it processes it as an independent controller | The data you give Stripe when paying. It passes the server your email and identifiers; in our Stripe account we see the data of §3.2, never the full card number | European Union and United States |
| Telegram — your bot | Delivering to your chat what the engine sends you and what you ask for | Commands and replies; alerts and morning and evening reports; usernames of buyers, of people who like your items and of reviewers; items, prices, offers with the review count of whoever makes them, sales with the customer's purchase history, balance and DAC7 totals; the text of buyers' messages (up to 160 characters) and the replies you write from the bot; review texts and the reviewer's profile picture; photos of your listings; PDFs of customers, sales and labels; number and @username of anyone writing to your bot from another account. The bot token is part of the address of every call | Telegram's servers, also outside the European Union |
| Discord — only if you set a webhook | Delivering the engine's alerts to your channel | Alerts and reports: offers to decide by hand (buyer, item, price, and how many reviews the buyer has if it is below your threshold), sales with the buyer's username, orders to ship, usernames of people who like your items, DAC7 thresholds, faults, number and @username of anyone writing to your bot from another account. Never the text of chats | United States |
| Vinted | It is the service you work on: the extension uses your session, on www.vinted.* and on the messaging service api.vinted.* | The requests the extension makes for you: reads of your account and the actions of §6 — messages, answers to offers and counter-offers, price and title edits, drafts and photos, publishing, deleting listings, public replies to reviews, deleting conversations | Vinted's servers |
Nobody else. We do not sell, rent or hand over data to advertisers, data brokers or information resellers. We disclose it to an authority only if the law requires it. Telegram and Discord are your choice: the extension sends the data directly from your device to your bot and your webhook, and no server of ours sees it pass. Their rules: Telegram, Discord, Stripe, Cloudflare, Resend, Netlify, Vinted.
Transfers outside the European Union. Cloudflare, Resend, Stripe and Netlify may process data in the United States. All four are certified under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission), and their data processing agreements also contain the standard contractual clauses approved by the Commission (Art. 46 GDPR): Cloudflare, Resend, Stripe, Netlify. We send you a copy of the safeguards if you ask at supporto@vintpro.it. Aruba processes data in Italy. For Telegram and Discord the safeguards of those services apply, which you choose.
discord.com/api/webhooks or discordapp.com/api/webhooks addresses; the panel shows the key masked.pi/ scripts: the launcher starts Chromium with two options that lower the browser's protections, so that it runs without a screen: --password-store=basic, which stores the profile's cookies and passwords, Vinted session included, without the system keyring; and --remote-debugging-port=9223, a local control port through which any program running on the Pi can drive the browser signed in to Vinted. Use that Pi only for VintPro+, with a user of your own, and do not expose it to the network. The instructions at the top of the scripts say to keep the alarm token in ~/.vintpro-allarme.env with permissions 600 (readable only by your user): the scripts do not check it, so do it yourself.You have the right of access, rectification, erasure, restriction, portability and objection (Articles 15–22 GDPR), and the right to withdraw the consent of §4 whenever you want, without affecting what was done before. Write to supporto@vintpro.it from the license email, or quoting the last 4 characters of the key: to protect your data we may ask you to prove the license is yours. We answer within one month. You may also lodge a complaint with the Italian Data Protection Authority (Garante) or with the authority of the country where you live.
How to delete, piece by piece:
chrome://extensions and Chrome deletes all its space. Before that, if you like, you can withdraw your consent and empty the log and sales from the panel; to stop sending data to Telegram or Discord, empty the two fields and save.Downloads/VintPro-Backups folder, and the copies on the USB stick if you use the Raspberry Pi script.VintPro+ is meant for adults. We do not knowingly collect data from anyone under 18: if you think a minor has given us their data, write to us and we will delete it.
We publish every change on this page, with the new date at the top. If VintPro+ starts collecting new data or sending it to new recipients, the version that does so tells you in the panel and asks you again for the yes of "📋 First of all: your data" (§4) before doing it; substantial changes are also sent to the license email. Previous versions are available on request.
VintPro+ is not affiliated with, sponsored or endorsed by Vinted. Vinted is a trademark of Vinted SE.