RVPRVPRepaired Vehicle Parts

Privacy Policy

One Orange Day LLC (“RVP”) runs a marketplace for recertified collision components. To issue a certificate we have to record which part went on which vehicle — which means we handle VINs. This policy explains what we collect, why, who it reaches, and what you can ask us to do about it.

Effective August 18, 2026 · Version 2026.1 · Issued by One Orange Day LLC
We treat a VIN as personal information. A VIN identifies a specific vehicle and can reasonably be linked to its owner, so we handle it under this policy even where a given law might not require us to. We do not sell personal information and we do not share it for cross-context behavioural advertising.

1. Who this covers

This policy covers rvpparts.com and the services on it. Most people who use this site do so on behalf of a collision repair facility or an insurance carrier. Vehicle owners generally interact with us in one place — the public certificate verification page — and can do so without an account.

2. What we collect

Account and contact information. Name, work email, phone number, job role, and the facility or carrier you belong to. We use passwordless sign-in links, so we do not store passwords.

Facility information. Business name, address, phone, and identifiers such as a CCC ID, together with approval status and its history.

Repair transaction information. The VIN, vehicle description, repair order number, claim number, and carrier associated with an order; the serialized unit sold; and the certificate and coverage record produced at settlement.

Photographs. Recertification photographs of a component, and job photographs a shop submits through a link we send. Please do not include people, licence plates, or documents unrelated to the part in these photographs.

Payment information. Card payments are processed by Stripe. We receive a confirmation and limited details such as the last four digits and card brand. We never receive or store your full card number.

Technical information. IP address, browser and device type, pages requested, and timestamps, collected in server logs to operate and secure the site.

Business directory information. We maintain a directory of collision repair facilities compiled from public and commercial sources, which may include a facility that has never contacted us. It holds business contact details, not personal consumer data. See section 9 for removal.

3. Why we use it

  • to operate accounts, approve facilities, and take and fulfil orders;
  • to issue certificates and bind coverage to the correct vehicle;
  • to administer warranty claims and verify whether a claim falls within coverage;
  • to show a carrier the certified parts used on that carrier’s own claims;
  • to provide support, send transactional messages, and request job photographs;
  • to detect fraud, misuse, and security incidents;
  • to meet legal, tax, and recordkeeping obligations;
  • to improve the service and understand how recertified components perform.

Where consent is the basis for a message — for example marketing email — you can withdraw it at any time without affecting transactional messages about your orders.

4. What is published on the verification page

Certificate verification is public by design: a QR code on a physical part has to resolve for anyone holding the vehicle. That page is deliberately limited. It shows the part, the recertification record, the installing facility, the coverage window, and only the last eight characters of the VIN.

It does not show pricing, claim numbers, full VINs, or personal contact information. Verification links are unguessable tokens and are not indexed for search.

5. Who we share it with

Carriers. Where an order names a carrier, that carrier can see the certified parts and orders associated with its own claims. Carriers cannot see other carriers’ claims or another facility’s unrelated business.

Facilities. A facility sees its own orders, certificates, and coverage records.

Service providers. We use vendors to run the service, and they may process information only on our instructions:

  • Vercel — application hosting and logging
  • Supabase — database, authentication, and file storage
  • Stripe — payment processing
  • email and SMS providers — sign-in links, order notifications, photo requests

Legal and corporate. We may disclose information to comply with law or valid legal process, to enforce our terms, to protect rights and safety, or in connection with a merger, financing, or sale of assets — in which case this policy continues to apply until you are told otherwise.

We do not sell personal information, and we have not sold or shared personal information for cross-context behavioural advertising in the preceding twelve months.

6. De-identified and aggregated data

We analyse repair, recertification, and claim outcomes to understand how recertified components perform, to price coverage, and to report on programme results. We may create and use de-identified and aggregated data for those purposes and share it with carriers, partners, and the public — for example, failure rates by part type or replacement-avoidance totals.

De-identified data excludes VINs, claim numbers, personal contact information, and anything else that identifies a vehicle, an individual, or a specific facility. We maintain that data in de-identified form, will not attempt to re-identify it, and will bind recipients to the same limits.

7. How long we keep it

Certificates, coverage records, and the recertification record behind them are kept for the life of the coverage and afterwards as a permanent record of what was sold and warranted — a certificate has to remain verifiable. Order and payment records are kept as long as tax and accounting rules require. Account information is kept while the account is active and for a reasonable period after. Server logs are kept for a short operational period. Where a record is no longer needed in identifiable form, we de-identify or delete it.

8. Your privacy rights

Depending on where you live — including California, Virginia, Colorado, Connecticut, Utah, and Texas — you may have the right to:

  • know what personal information we hold about you and why;
  • get a copy of it, in a portable format;
  • correct it if it is inaccurate;
  • delete it, subject to the exceptions below;
  • opt out of sale, sharing, or targeted advertising — none of which we do;
  • not be discriminated against for exercising any of these rights.

To make a request, email privacy@rvpparts.com. We will verify your request, usually by confirming control of an email address on file or, for a vehicle-related request, by asking for information that matches the record. An authorised agent may act for you with written permission.

Limits on deletion. We may keep information needed to maintain a certificate or coverage record, to complete a transaction, to administer or defend a warranty claim, to detect fraud, or to comply with law. If we decline a request, we will tell you why. If we deny a request and you disagree, you may appeal by replying to our decision; we will respond within the period the applicable law allows.

9. Facility directory removal

If your facility appears in our directory and you want it removed, email privacy@rvpparts.com from a company address, or use the address at the foot of this page. We will remove the listing, and we will keep a minimal suppression record so it is not re-added by a later import.

10. Security

Access is restricted by role and enforced in the database itself, not only in the application. Traffic is encrypted in transit and data is encrypted at rest by our hosting providers. Sign-in uses one-time links rather than stored passwords. No system is perfectly secure, and we do not claim otherwise. If a breach affects your information, we will notify you and any regulator as the law requires.

11. Cookies

We use cookies and similar storage that are strictly necessary — keeping you signed in and holding your cart. We do not use advertising or cross-site tracking cookies. Blocking necessary cookies will stop sign-in and checkout from working.

12. Children

This is a business service and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.

13. Where information is processed

We operate in the United States, and information is processed and stored there. If you use the service from elsewhere, you understand your information will be transferred to and handled in the United States, where privacy laws may differ from those in your country.

14. Changes to this policy

If we change this policy materially, we will post the revised version here and update the effective date before the change takes effect. Continuing to use the service after that means you accept the revised policy.

15. Contact

Privacy questions and rights requests: privacy@rvpparts.com, or write to One Orange Day LLC, [MAILING ADDRESS — TO BE COMPLETED]. See also our Terms of Service and Limited Warranty.


Questions about this document: legal@rvpparts.com. Written notice may be sent to One Orange Day LLC, [MAILING ADDRESS — TO BE COMPLETED].