Introduction
Welcome to Ovurr (“we”, “our”, “us”). We’re committed to protecting your privacy and being transparent about how we collect, use, and protect your personal information.
This Privacy Policy explains how we handle your data when you use our website at ovurr.com and our mobile applications (collectively, the “Services”). By using Ovurr, you agree to the collection and use of information in accordance with this policy.
Ovurr is operated from the United Kingdom and complies with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Information We Collect
1. Information You Provide Directly
Account Information: When you create an Ovurr account, we collect:
- Email address
- Name (optional)
Vehicle Search Data: When you check a vehicle, we may store:
- Vehicle registration numbers you search for
- Dates and times of your searches
- Vehicles you save to your garage
Payment Information: If you subscribe to a premium plan:
- Billing information is processed securely by Stripe
- We never store your full credit card details
- We store your Stripe customer ID for subscription management
Communications: If you contact us for support:
- Your email correspondence
- Support ticket information
- Feedback you provide
2. Information We Collect Automatically
Usage Data: We automatically collect:
- Pages you visit on our website
- Features you use (vehicle checker, matchmaker, inspection checklist)
- Time spent on different sections
- Device type (mobile, desktop, tablet)
- Browser type and version
- Operating system
- IP address (anonymised after 24 hours)
- Referring website
3. Information From Third-Party Sources
Vehicle Data: We collect vehicle information from official UK government sources:
- DVLA (Driver and Vehicle Licensing Agency) - vehicle specifications, tax status
- DVSA (Driver and Vehicle Standards Agency) - MOT history and test results
- OneAuto API - vehicle valuations and market data
This information is publicly available and not considered personal data.
How We Use Your Information
1. To Provide Our Services
- Process your vehicle searches and display results
- Maintain your account and garage
- Provide customer support
- Send you service-related emails (password resets, account notifications)
2. To Improve Our Services
- Analyse how users interact with Ovurr
- Identify and fix technical issues
- Develop new features based on usage patterns
3. To Communicate With You
- Send you important updates about our Services
- Respond to your questions and support requests
- Send marketing emails (only if you’ve opted in - you can unsubscribe anytime)
4. To Process Payments
- Manage your subscription
- Process refunds if requested
- Prevent fraudulent transactions
5. For Legal Compliance
- Comply with legal obligations
- Enforce our Terms & Conditions
- Protect against harmful or illegal activity
Legal Basis for Processing (UK GDPR)
Consent: Marketing communications (you can withdraw consent anytime) and non-essential cookies and analytics.
Contract: Creating and managing your account, providing the vehicle checking service, processing subscription payments.
Legitimate Interests: Improving our Services and user experience, preventing fraud and abuse, internal analytics and research.
Legal Obligation: Compliance with tax and financial regulations, responding to lawful requests from authorities.
Data Retention
- Account Data: Retained while your account is active. Deleted within 30 days of account closure.
- Vehicle Search History: Retained for 2 years. Anonymised after 1 year.
- Payment Records: Retained for 7 years (UK tax law requirement).
- Analytics Data: Retained by Google Analytics for 26 months.
- Support Communications: Retained for 3 years.
You can request deletion of your data at any time (subject to legal retention requirements).
Data Security
We take reasonable measures to protect your personal information:
- HTTPS encryption for all data transmission
- Encrypted storage of sensitive data
- Regular security audits and updates
- Firewall protection and access controls
- Limited employee access (need-to-know basis)
- Stripe is PCI-DSS Level 1 compliant
- Firebase/Google Cloud has ISO 27001, SOC 2 certifications
While we use industry-standard security measures, no method of transmission over the internet is 100% secure.
Your Rights Under UK GDPR
- Right to Access - Request a copy of all personal data we hold about you.
- Right to Rectification - Request correction of inaccurate or incomplete data.
- Right to Erasure - Request deletion of your personal data.
- Right to Restrict Processing - Request that we limit how we use your data.
- Right to Data Portability - Receive your data in a structured, machine-readable format.
- Right to Object - Object to processing for direct marketing or legitimate interests.
- Right to Withdraw Consent - Withdraw consent at any time.
- Right to Complain - Lodge a complaint with the UK Information Commissioner’s Office (ICO).
How to exercise your rights: Email us at privacy@ovurr.com. We’ll respond within 30 days.
Children’s Privacy
Ovurr is not intended for users under 16 years of age. We do not knowingly collect personal information from children under 16. If you’re a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@ovurr.com.
International Data Transfers
Your data is primarily stored and processed within the United Kingdom and European Economic Area (EEA). Some of our service providers may transfer data outside the UK/EEA. When this happens, we ensure adequate safeguards are in place (Standard Contractual Clauses) and transfers comply with UK GDPR requirements.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we’ll update the “Last Updated” date. For significant changes, we’ll notify you via email or a prominent notice on our website.
Contact Us
Email: privacy@ovurr.com
Subject Line: “Privacy Inquiry - [Your Topic]”
Response Time: We aim to respond within 5 business days.
Security Vulnerabilities: security@ovurr.com
Complaints to the ICO
If you’re unhappy with how we’ve handled your personal data, you have the right to complain to the UK Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Phone: 0303 123 1113
Website: ico.org.uk/make-a-complaint
Summary (TL;DR)
What we collect: Your email when you sign up, vehicle registrations you search (anonymised in analytics), and how you use our website.
How we use it: Provide the vehicle checking service, improve Ovurr, send important account emails, process payments via Stripe.
Who we share with: Stripe (payments), Google (analytics, hosting), OneAuto (vehicle data). We never sell your data.
Your rights: Access your data, delete your account, opt out of analytics cookies, complain to the ICO.
Contact: privacy@ovurr.com