Enter your details to check order status
Legal
This policy explains how TintRebel ("we," "us," "our") collects, uses, discloses, and safeguards your information when you visit tintrebel.com, interact with our Facebook Page, communicate with us via Facebook Messenger, or make a purchase.
Last updated: March 28, 2026
When you interact with our website, you may voluntarily provide:
When you browse our website, we automatically collect:
When you interact with our Facebook Page or send us messages via Facebook Messenger, we collect:
We use the information we collect for the following purposes:
Order Fulfillment
Process payments, cut your custom tint, ship orders, send confirmations and tracking updates
Customer Service
Respond to inquiries via email, Facebook Messenger, and comments. We use AI-assisted tools to provide faster, more accurate responses
Account Management
Maintain your account, order history, saved vehicles, and loyalty points
Product Customization
Use your vehicle data (year, make, model) to ensure accurate tint fitment
Marketing
Send promotional emails, abandoned cart reminders, and product updates (only with consent)
Site Improvement
Analyze usage patterns to improve our website, products, and user experience
Fraud Prevention
Detect and prevent fraudulent transactions and unauthorized access
Legal Compliance
Meet tax, accounting, and regulatory obligations
We do NOT sell, rent, or trade your personal information to third parties. Ever.
We share your data only with the following categories of service providers, and only to the extent necessary:
Stripe
Payment processingData shared: Name, email, billing address, payment method details
View their privacy policyUPS / USPS
Order shipping & deliveryData shared: Name, shipping address, phone number
Google Analytics
Website analyticsData shared: IP address (anonymized), device/browser data, page views
View their privacy policyMeta / Facebook
Messenger customer service & Page managementData shared: Message responses sent via Messenger API, comment replies via Graph API
View their privacy policyGoogle (Gemini AI)
AI-powered customer service responsesData shared: Message content (no personally identifiable information is stored by the AI provider)
View their privacy policyEmail Service Provider
Transactional & marketing emailsData shared: Email address, first name, order details
We may also disclose your information:
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Account data | Until you delete your account |
| Order & transaction records | 7 years (tax/legal requirements) |
| Payment card details | Not stored - handled by Stripe |
| Shipping addresses | Until you delete your account |
| Abandoned cart emails | 90 days if no purchase made |
| Product reviews | Indefinitely (or until you request removal) |
| Facebook Messenger conversations | 14 days (auto-deleted) |
| Facebook comment replies | Until post is deleted |
| Analytics data | 26 months (Google Analytics default) |
| Server logs | 90 days |
| Marketing consent records | Until consent is withdrawn |
When data is no longer needed, we securely delete or anonymize it.
We implement industry-standard security measures to protect your personal information:
While we take all reasonable precautions, no method of internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security but will notify affected users promptly in the event of a data breach.
Cookies are small text files placed on your device when you visit a website. They help the site remember your preferences and actions.
| Category | Purpose | Required? |
|---|---|---|
| Essential | Shopping cart, authentication session, checkout state | Yes |
| Functional | Saved vehicle selection, user preferences, recently viewed | No |
| Analytics | Google Analytics - page views, traffic sources, user behavior (anonymized IP) | No |
| Marketing | Facebook Pixel, ad conversion tracking (if applicable) | No |
| Payment | Stripe session cookies for secure payment processing | Yes |
We also use browser local storage (similar to cookies) to persist your shopping cart, saved vehicle selection, and authentication state across sessions. This data remains on your device and is not transmitted to third parties.
You can control or delete cookies through your browser settings. Disabling essential cookies may prevent you from using our shopping cart and checkout. Most browsers allow you to:
Depending on your location, you may have the following rights regarding your personal data:
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
We have not sold personal information of any consumer in the preceding 12 months. We do not have actual knowledge that we sell or share the personal information of minors under 16 years of age.
If you reside in a state with comprehensive privacy legislation (VCDPA, CPA, CTDPA, UCPA, etc.), you may have similar rights to access, correct, delete, and opt out of targeted advertising. Contact us to exercise these rights.
To submit a privacy request, you may:
We will verify your identity before processing any request. We aim to respond within 30 days (45 days for complex requests, with notice). You may designate an authorized agent to make a request on your behalf.
We may send promotional emails about new products, special offers, or other information we think you may find interesting. We will only send marketing emails if you have opted in (e.g., by checking a box at checkout or subscribing to our newsletter).
If you enter your email address during checkout but do not complete your purchase, we may send you a reminder email. These are considered transactional in nature but you can opt out by contacting us. Abandoned cart email data is automatically deleted after 90 days if no purchase is made.
We do not currently send SMS marketing messages. If we implement SMS communications in the future, it will be strictly opt-in with clear consent and easy opt-out.
TintRebel operates an AI-powered customer service system through our Facebook Page (facebook.com/tintrebel). This section specifically explains how we handle data when you interact with us on Facebook.
When you send a message to our Facebook Page via Messenger, or comment on one of our posts, our automated system may respond using artificial intelligence. This system is designed to:
Through the Facebook Graph API, we access the following data with your consent:
We do NOT access your Facebook friends list, photos, timeline, private profile information, or any data beyond what is listed above.
Your messages are processed by Google Gemini AI to generate relevant responses. When your message is sent to the AI:
You have full control over your Facebook interactions with us:
Please note that Facebook (Meta Platforms, Inc.) has its own privacy policy governing how they collect and use your data on their platform. Our privacy policy covers only the data we access and process through our Facebook Page integration. For information about Facebook's data practices, please visit Facebook's Privacy Policy.
Some browsers include a "Do Not Track" (DNT) feature that signals to websites that you do not want your online activity tracked. There is currently no uniform standard for responding to DNT signals.
We respect your privacy preferences. If you enable DNT in your browser, we will not use non-essential tracking cookies. Essential cookies required for cart and checkout functionality will still be used.
Our website and services are not directed to individuals under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete it promptly.
If you believe a child has provided us with personal information, please contact us at [email protected].
TintRebel is based in the United States and our services are directed to US customers. If you access our website from outside the US, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located.
By using our website, you consent to the transfer of your information to the United States, which may have different data protection laws than your country of residence. We will take reasonable steps to ensure your data is treated securely and in accordance with this policy.
Our website may contain links to third-party sites (e.g., social media profiles, payment processors, shipping trackers). We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies before providing any personal information.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes:
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: