Effective August 25, 2026
Privacy
This page describes the data Wynn's Fluid Finder actually collects and uses. It is a description of the current application, not a substitute for counsel.
Who operates this app
Wynn's Fluid Finder is operated by [Legal operator name]. Mail: [Mailing address]. Questions go through Support.
The app is a dealership workplace tool for invited users. It is not directed at children and there is no public sign-up.
Account data
An administrator creates the account. The profile stored for a user includes email, display name, phone number, optional address, account status, and dealership membership or Wynn's staff role.
Sign-in and cookies
Sign-in uses email and password, then a phone verification on each new session unless a trusted-browser record is in effect. Session cookies are HTTP-only with SameSite=lax:
wynns_session— signed-in session, 14 dayswynns_auth_challenge— phone-check challenge, 10 minuteswynns_trust_browser— optional trusted browser, 30 dayswynns_acting_dealer— Wynn's staff “working as” a dealership, 12 hours
A trusted-browser record stores a hashed token, a short label, the browser user-agent, and a hashed IP. The raw trust secret is not stored.
Firebase Authentication sends the phone verification. That step uses reCAPTCHA.
VIN scans
A scan stores the VIN, year, make, model, transmission, dealership, a result summary, and the full scan result so the same VIN can be reopened without calling the vehicle-data source again. When Wynn's staff scan while working as a store, that is recorded on the history row.
Vehicle attributes and manufacturer fluid data come from an OEM vehicle-data service called with the VIN. The 17-character VIN format (excluding I, O, and Q) is applied in this app; this app does not call a public NHTSA decode API.
VIN photos
On a touch device you can capture or choose a VIN photo. The image is sent to the app server, which sends it to Google Gemini to read the VIN. You review the number before a scan. The photo is not written to Cloud Storage.
An audit record of the extraction keeps the VIN, a confidence value, image size and type, and which model produced the read. It does not keep the image.
Other data this app stores
Product catalog images that administrators upload are stored in Firebase Storage. Security-sensitive actions write audit events (actor, dealership when relevant, outcome, and a small metadata payload).
When account email is configured, password-setup and recovery messages are sent over Google Workspace SMTP to the address on the account.
Who can see a scan
Scan history is scoped to the user and dealership. Authorized dealership admins, assigned Wynn's staff, and global administrators can access a store's history according to their role. Scan results are not sold.
How long data is kept
Session and trust-browser cookies expire as listed above. Scan history and audit records persist. When a dealership is archived, its scan history, audit trail, and catalog overrides are kept. List screens load a bounded number of recent scans; that limit is a query cap, not a deletion schedule.
This app does not include a self-serve “delete my data” flow, and it does not publish a retention time-to-live for scan or audit records. To ask about an account or a record, contact an administrator at your dealership.
