Mobile App Measurement and Attribution

Updated July 29, 2026. This section applies specifically to the current Android application associated with this website. If it conflicts with an older general statement elsewhere on this page, this section controls for the Android application.

The Android application uses Firebase Analytics as its only analytics SDK. Firebase Analytics automatically assigns a pseudonymous app-instance identifier and may collect the Android advertising identifier when it is available, approximate location derived from a masked IP address, app lifecycle and interaction events, and app/device metadata. We use this information for analytics and for advertising or marketing measurement, including measuring app-install and app-campaign performance. We do not use these identifiers to collect the values entered into a search form.

Google states that Firebase Analytics data is encrypted in transit. Google and its subprocessors process Firebase Analytics data as service providers under the applicable Firebase and Google Analytics terms. Advertising identifiers can be reset or limited through Android privacy settings.

First-party attribution safeguards

The application includes a first-party attribution architecture operated by Legitime Domains d.o.o. Activation is controlled separately for each application and release. When installation registration is enabled, the application sends only its exact package name and Firebase app-instance identifier over HTTPS to the trusted first-party attribution service. The service stores the identifier encrypted at rest, keeps a keyed fingerprint and token hash, and returns a stable opaque token.

The raw app-instance identifier is never placed in website URLs, affiliate URLs, logs, or partner pages. Only the opaque token may be forwarded for attribution when that feature is separately enabled. Neither Firebase Analytics nor the first-party attribution service receives VINs, license plates, names, email addresses, phone numbers, postal addresses, search-form values, cookies, complete affiliate URLs, or partner-page contents from this Android implementation.

The application does not create a user account. Privacy questions or requests can be submitted through the contact information already provided in this policy.

Search submissions and partner processing

When you submit a search, the VIN or license-plate details required by the selected route are transmitted over HTTPS to the partner used by that exact route so the requested search can be performed. The current partner policies for this site are: Bumper.com privacy policy.

For transparency, the Android app treats these user-submitted values as collected and shared with the applicable independent partner. We do not rely on a user-initiated-transfer exception for this disclosure. We also treat the submission as non-ephemeral because we do not control, and have not received affirmative proof of, immediate deletion by every recipient. Partner processing and retention are governed by the applicable partner privacy policy.

The search values are separate from Firebase Analytics and the first-party attribution service: neither receives the values entered into these search forms. The raw Firebase app-instance identifier is never forwarded to a search partner.