Privacy Policy
How CarVerity.ai collects, uses and protects your personal information.
Last updated: December 2024
1. Who we are (Data Controller)
CarVerity.ai is operated by CarVerity Ltd. Under UK GDPR, we are responsible for deciding how your personal data is collected, used and protected.
Data Controller:
CarVerity Ltd (trading as CarVerity.ai)
Email: privacy@carverity.ai
2. Information we collect
We collect the following categories of information when you use CarVerity.ai:
A. Account information
Name, email address, password hash, authentication tokens, and account creation or update dates.
B. Usage information
Registrations you search, reports you generate, whether a score was generated, how you interact with the website, and emails you request.
C. Payment information
Payments are processed securely by Stripe. We do not store your full card details. We may receive payment status, the last four digits of your card, billing email, and transaction references.
D. Technical data
IP address, browser type and version, device type and operating system, time zone, pages accessed, error logs, and authentication or session cookies.
E. Vehicle data
We retrieve publicly available vehicle data based on the registration you enter, including DVSA MOT history, MOT outcomes, advisories and defects, DVLA vehicle enquiry data, and mileage records.
F. Support enquiries
If you contact us, we may store the contents of your message, email address, relevant registration numbers, and information needed to resolve your issue.
3. Where we get data from
To generate reliability reports, we query data from:
- DVSA (MOT history)
- DVLA (vehicle enquiry data where available)
- Our own aggregated repair-cost and claim-pattern datasets
We do not control the accuracy of these external data sources and use them only to generate your reliability report. A copy of retrieved vehicle data may be stored so you can revisit previous reports.
4. How we use your information
Provide the service
Generate reliability reports, save and retrieve past reports, deliver purchased bundles, and process payments securely.
Manage your account
Authenticate you, reset passwords, and keep records of purchased checks or bundles.
Communicate with you
Email report copies, receipts, service notices, and respond to support requests.
Improve our service
Monitor performance, improve scoring models, identify bugs, and prevent misuse or fraud.
5. Legal bases for processing
Under UK GDPR, we rely on the following legal bases:
- Contract: To provide the service you requested, such as creating an account, generating a report, or processing payments.
- Legitimate interests: To maintain site security, prevent fraud, improve scoring models, and analyse usage trends.
- Legal obligation: For record-keeping relating to payments and accounting.
- Consent: If you ever opt into marketing communications.
6. How AI is used
CarVerity.ai does not use AI to calculate reliability scores.
All scores come from a deterministic scoring engine based on MOT outcomes, advisory patterns, defect trends, age and mileage alignment, and repair-cost risk indicators.
AI is only used to produce a readable written summary, created after the score has been generated. We do not send your name, email, or full report history to the AI model. Vehicle data may be briefly processed to generate the summary, but it is not stored by the AI provider and is not used to train models.
7. Cookies and similar technologies
We use minimal essential cookies to operate the site, including:
- Authentication cookies (Supabase)
- Session cookies
- Security and fraud-prevention cookies
- Stripe checkout cookies when making a purchase
We do not use analytics, marketing or advertising cookies at this time. Your browser allows you to control or block cookies if you choose.
8. International transfers
Some of our service providers are located outside the UK, for example in the United States.
When we transfer your data internationally, we rely on the UK addendum to the EU Standard Contractual Clauses or other UK-GDPR-approved safeguards. These ensure your data remains protected to UK standards.
9. Sharing your data
We do not sell your personal data.
We may share limited data with trusted service providers:
Supabase
Database, authentication, storage
Stripe
Payment processing, fraud prevention
Resend
Transactional email delivery
Vercel
Website hosting
OpenAI
AI summaries only (no personal data)
DVSA & DVLA
Public vehicle data sources
All providers are contractually required to protect your data.
10. How we store and protect data
We store data securely using Supabase and our hosting providers. We protect your data through:
- Encrypted connections (HTTPS/TLS)
- Password hashing
- Access controls and authentication
- Server-side security and monitoring
- Regular updates and vulnerability checks
11. Data retention
We keep your account and report history for as long as your account is active with us, or we need it for legal or accounting purposes.
If you request account deletion, we delete your account details, saved reports, and report history. We may retain minimal payment-related information as required by financial regulations.
12. Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data ("right to be forgotten")
- Object to certain types of processing
- Restrict how we use your data
- Request portability of your data
- Withdraw consent at any time
To exercise these rights, contact us at privacy@carverity.ai.
13. Children's privacy
CarVerity.ai is not intended for individuals under 16. We do not knowingly collect or allow account creation by anyone under this age. If we become aware that a child has created an account, we will delete it.
14. Changes to this policy
We may update this Privacy Policy periodically. The "Last updated" date at the top of this page shows the latest version. Where appropriate or required by law, we will highlight the changes.
15. How to contact us
If you have any questions about this Privacy Policy or how we process your personal data, please contact us:
Email: privacy@carverity.ai
You can also use support@carverity.ai for general support.
16. Your right to complain
You can raise a concern with the Information Commissioner's Office (ICO) if you believe we have handled your data unlawfully.
Website: ico.org.uk
Telephone: 0303 123 1113
Address: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would appreciate the chance to resolve your concerns before you contact the ICO.