Privacy / effective August 23, 2026
Your worksheet stays local. VIN lookup uses NHTSA.
Calculator entries
This version performs calculations in your browser. HitchMargin does not require an account and does not send calculator entries to an application database.
VIN and vehicle identity lookup
When you choose to decode a VIN, your browser sends it to HitchMargin in an encrypted HTTPS request body. HitchMargin forwards it to the U.S. Department of Transportation's NHTSA vPIC service to return manufacturer-reported identity information. The VIN is not placed in the page URL, is not written to a HitchMargin application database, is not returned in full, and is cleared from the form after a successful decode.
Cloudflare, which hosts HitchMargin, and DOT/NHTSA may process network and request data under their own policies and operational logs. Do not use the VIN lookup if you do not want the full VIN sent to those services. The year/make/model selector does not require a VIN.
When HitchMargin provides a link to a manufacturer rating tool or source, the VIN is not automatically forwarded. The manufacturer receives data only if you choose to follow that link and enter information on its site.
Share links
When you choose “Copy share link,” the weights you entered are placed in the page URL. Anyone who receives that link can read those values. Do not put a VIN, name, address, or other personal information into fields or shared links.
Analytics and advertising
HitchMargin uses Cloudflare Web Analytics to understand aggregate page traffic and real-user performance, including Core Web Vitals. Its reports can show page paths, referring sites, countries, device types, browsers, operating systems, navigation types, and performance timings. See Cloudflare's descriptions of the data's origin and collection and available dimensions.
Cloudflare states that Web Analytics does not use cookies or local storage to collect usage metrics and does not fingerprint individuals for analytics. It also does not log URL query strings. That exclusion keeps the weight values in a HitchMargin share link's query string out of Web Analytics. The lightweight analytics beacon sends measurements to Cloudflare's endpoint at cloudflareinsights.com/cdn-cgi/rum. See Cloudflare's Web Analytics FAQ.
HitchMargin does not use advertising pixels, affiliate tracking, custom analytics events, visitor accounts, or an application database for these measurements.
Hosting and security
Cloudflare delivers and protects HitchMargin. It may process network details such as an IP address, request headers, and security signals, and may set strictly necessary security cookies such as __cf_bm when bot protection is active. That cookie supports Cloudflare's bot controls; it is not a HitchMargin account identifier or an advertising profile. See Cloudflare's cookie documentation.
External sources
Links to manufacturers, NHTSA, and other third-party sites are governed by those sites’ privacy policies. HitchMargin does not control their data handling. See the U.S. DOT privacy policy and the Cloudflare privacy policy.
Contact
Questions about this notice or HitchMargin can be sent to support@hitchmargin.com. Email sent to that address is routed by Cloudflare Email Routing to an owner-controlled Google inbox. Cloudflare and Google may process the message, sender address, and delivery data under their respective privacy policies. Do not send VINs, payment details, identity documents, or other sensitive records by email.