Legal

Browser Extension Privacy Policy

Our Vinted Token Copier extension reads one cookie — your own Vinted token — and copies it to your clipboard. It has no network access, so nothing is collected, stored or sent anywhere. This is the detail.

Last updated 6 September 2026

Introduction

This Policy covers one thing: the Resell Reserve Vinted Token Copier, our browser extension. Everything else we run — our Discord, this website, the Reframe photo app — is covered by our main Privacy Policy.

The short version is that the extension collects nothing. It has no network access of any kind, there is no server behind it, and it has nowhere to send anything. What follows sets out exactly what it touches and what becomes of it.

1. What the extension accesses

The extension reads one cookie, named refresh_token_web, and only on Vinted domains. That cookie holds your Vinted session's refresh token — the same value your browser's own developer tools show you under Application, then Cookies.

It is read when you open the extension's popup, so that it can be displayed to you and copied to your clipboard when you click Copy token.

The extension does not read any other cookie, does not create, alter or delete cookies, and cannot see any website other than Vinted.

2. What happens to it

Nothing leaves your device. Specifically:

  • It is not sent anywhere. The extension makes no network requests of any kind. There is no server, no analytics, no error reporting and no remote code
  • It is not stored. The extension writes nothing to disk, to browser storage or to a database. Closing the popup discards it
  • It is not shared or sold. No third party is involved, because nothing is transmitted
  • We never receive it. Installing this extension gives Resell Reserve no copy of your token and no visibility of your Vinted account

The only place your token goes is your clipboard, when you ask for it.

3. Permissions, and why they exist

Cookies

To read the refresh_token_web cookie so that it can be shown to you.

Vinted domains

Chrome only returns cookies for domains an extension holds permission for. Vinted runs a separate domain for each country, and your cookie exists only on the one you signed in to, which is why several are listed.

No other permission is requested. The extension runs no code on the pages you visit, so your browsing is never visible to it.

4. Your responsibility for the token

A refresh token grants access to your Vinted account. Once it is on your clipboard, where it goes next is up to you — only paste it into a tool you have chosen and trust.

Treat anyone who asks you for it as a scammer. Resell Reserve staff will never ask you for your token: not in a ticket, not in a direct message, not anywhere.

If you think your token has been exposed, change your Vinted password. That invalidates the token immediately, and you can then take a fresh one.

5. Children

The extension is not directed at children, and it collects no data from anyone.

6. Changes to this Policy

If this Policy changes, the updated version will be published at this address and the date above will change with it. Because the extension collects nothing, any change to this Policy would mean a change to what the extension does — and that requires a new version to pass Chrome Web Store review before it can reach you.

7. Contact

Questions about this Policy: support@resellreserve.co.uk, or open a ticket in our Discord server.

Resell Reserve is not affiliated with, endorsed by or connected to Vinted. "Vinted" is a trademark of its respective owner.