Privacy Policy

How CarVerity.ai collects, uses and protects your personal information.

Last updated: December 2024

1. Who we are (Data Controller)

CarVerity.ai is operated by CarVerity Ltd. Under UK GDPR, we are responsible for deciding how your personal data is collected, used and protected.

Data Controller:

CarVerity Ltd (trading as CarVerity.ai)

Email: privacy@carverity.ai

2. Information we collect

We collect the following categories of information when you use CarVerity.ai:

A. Account information

Name, email address, password hash, authentication tokens, and account creation or update dates.

B. Usage information

Registrations you search, reports you generate, whether a score was generated, how you interact with the website, and emails you request.

C. Payment information

Payments are processed securely by Stripe. We do not store your full card details. We may receive payment status, the last four digits of your card, billing email, and transaction references.

D. Technical data

IP address, browser type and version, device type and operating system, time zone, pages accessed, error logs, and authentication or session cookies.

E. Vehicle data

We retrieve publicly available vehicle data based on the registration you enter, including DVSA MOT history, MOT outcomes, advisories and defects, DVLA vehicle enquiry data, and mileage records.

F. Support enquiries

If you contact us, we may store the contents of your message, email address, relevant registration numbers, and information needed to resolve your issue.

3. Where we get data from

To generate reliability reports, we query data from:

  • DVSA (MOT history)
  • DVLA (vehicle enquiry data where available)
  • Our own aggregated repair-cost and claim-pattern datasets

We do not control the accuracy of these external data sources and use them only to generate your reliability report. A copy of retrieved vehicle data may be stored so you can revisit previous reports.

4. How we use your information

Provide the service

Generate reliability reports, save and retrieve past reports, deliver purchased bundles, and process payments securely.

Manage your account

Authenticate you, reset passwords, and keep records of purchased checks or bundles.

Communicate with you

Email report copies, receipts, service notices, and respond to support requests.

Improve our service

Monitor performance, improve scoring models, identify bugs, and prevent misuse or fraud.

5. Legal bases for processing

Under UK GDPR, we rely on the following legal bases:

  • Contract: To provide the service you requested, such as creating an account, generating a report, or processing payments.
  • Legitimate interests: To maintain site security, prevent fraud, improve scoring models, and analyse usage trends.
  • Legal obligation: For record-keeping relating to payments and accounting.
  • Consent: If you ever opt into marketing communications.

6. How AI is used

CarVerity.ai does not use AI to calculate reliability scores.

All scores come from a deterministic scoring engine based on MOT outcomes, advisory patterns, defect trends, age and mileage alignment, and repair-cost risk indicators.

AI is only used to produce a readable written summary, created after the score has been generated. We do not send your name, email, or full report history to the AI model. Vehicle data may be briefly processed to generate the summary, but it is not stored by the AI provider and is not used to train models.

7. Cookies and similar technologies

We use minimal essential cookies to operate the site, including:

  • Authentication cookies (Supabase)
  • Session cookies
  • Security and fraud-prevention cookies
  • Stripe checkout cookies when making a purchase

We do not use analytics, marketing or advertising cookies at this time. Your browser allows you to control or block cookies if you choose.

8. International transfers

Some of our service providers are located outside the UK, for example in the United States.

When we transfer your data internationally, we rely on the UK addendum to the EU Standard Contractual Clauses or other UK-GDPR-approved safeguards. These ensure your data remains protected to UK standards.

9. Sharing your data

We do not sell your personal data.

We may share limited data with trusted service providers:

Supabase

Database, authentication, storage

Stripe

Payment processing, fraud prevention

Resend

Transactional email delivery

Vercel

Website hosting

OpenAI

AI summaries only (no personal data)

DVSA & DVLA

Public vehicle data sources

All providers are contractually required to protect your data.

10. How we store and protect data

We store data securely using Supabase and our hosting providers. We protect your data through:

  • Encrypted connections (HTTPS/TLS)
  • Password hashing
  • Access controls and authentication
  • Server-side security and monitoring
  • Regular updates and vulnerability checks

11. Data retention

We keep your account and report history for as long as your account is active with us, or we need it for legal or accounting purposes.

If you request account deletion, we delete your account details, saved reports, and report history. We may retain minimal payment-related information as required by financial regulations.

12. Your rights under UK GDPR

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your data ("right to be forgotten")
  • Object to certain types of processing
  • Restrict how we use your data
  • Request portability of your data
  • Withdraw consent at any time

To exercise these rights, contact us at privacy@carverity.ai.

13. Children's privacy

CarVerity.ai is not intended for individuals under 16. We do not knowingly collect or allow account creation by anyone under this age. If we become aware that a child has created an account, we will delete it.

14. Changes to this policy

We may update this Privacy Policy periodically. The "Last updated" date at the top of this page shows the latest version. Where appropriate or required by law, we will highlight the changes.

15. How to contact us

If you have any questions about this Privacy Policy or how we process your personal data, please contact us:

Email: privacy@carverity.ai

You can also use support@carverity.ai for general support.

16. Your right to complain

You can raise a concern with the Information Commissioner's Office (ICO) if you believe we have handled your data unlawfully.

Website: ico.org.uk

Telephone: 0303 123 1113

Address: ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would appreciate the chance to resolve your concerns before you contact the ICO.

CarVerity.ai