Privacy Policy
Last updated: January 2025
1. Introduction
This Privacy Policy applies to [Company Name] Ltd ("we", "us", "our") and explains how we collect, use, and protect your personal data.
We are committed to protecting your privacy in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What We Collect
We collect the following types of information:
Information you provide:
- Email address (for paid reports)
- Payment details (processed via Stripe/Apple Pay/Google Pay)
- Vehicle registration or VIN that you search
Automatically collected:
- IP address
- Browser type and version
- Analytics data (e.g., via Google Analytics)
We may log searches without identifying details for performance monitoring and abuse prevention purposes.
3. How We Use Your Data
We use your personal data for the following purposes:
- To process and deliver vehicle reports and payments
- To email receipts or invoices
- To improve our site and services through analytics
- To detect and prevent fraud or misuse
- To comply with legal obligations
4. Legal Basis
We process your data based on the following legal grounds:
- Performance of a contract – when you purchase a report
- Legitimate interest – for security, analytics, and preventing abuse
- Consent – where you opt in to marketing communications (none by default)
5. Sharing Your Data
We only share data with trusted processors:
- Payment providers (Stripe, Apple Pay, Google Pay)
- Analytics providers (e.g., Google Analytics)
- Cloud hosting and email services used to run the platform
We never sell your personal data.
6. International Transfers
All data is stored in the UK or European Economic Area (EEA) where possible.
If data is transferred outside the UK/EEA, it will be under approved safeguard mechanisms to ensure your data remains protected.
7. Data Retention
We retain data for the following periods:
- Reports stored for 30 days after purchase
- Transaction records kept for up to 6 years for tax and legal compliance
- Free checks and anonymous data logs may be retained up to 90 days for abuse prevention
8. Your Rights
Under UK GDPR, you have the following rights:
- Request a copy of your data (access)
- Correct inaccurate data (rectification)
- Request deletion of your data (erasure)
- Object to processing or restrict it
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk
9. Security
We take the security of your data seriously and implement the following measures:
- Encrypted connections (HTTPS) for all data transmission
- Regular server monitoring and access control
- No permanent storage of full payment card numbers (handled by PCI-compliant providers)
10. Contact
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
📧 Email: [Privacy Contact Email]
📮 Address: [Company Address]