Privacy Notice
Last updated: 30 March 2026
This Privacy Notice explains how AutoAudit collects, uses and protects personal data when you use autoaudit.uk.
AutoAudit is committed to handling personal data responsibly and in line with applicable UK data protection law, including the UK GDPR and the Data Protection Act 2018.
1. Who We Are
AutoAudit is a UK-focused online used vehicle research service.
For privacy questions or data requests, contact us at support@autoaudit.uk.
For the purposes of data protection law, AutoAudit is the data controller of the personal data described in this notice.
2. Personal Data We Collect
a) Data you provide directly
- email address, if you create an account or contact us
- vehicle registration numbers you enter
- optional details you provide, such as mileage or asking price
- support messages and correspondence
b) Account and authentication data
- account identifiers
- login and authentication records
- basic account metadata
c) Payment and transaction data
Payments are handled by Stripe. We do not store full payment card details. We may receive transaction-related information such as:
- payment status
- transaction reference IDs
- purchase history
- limited billing-related metadata
d) Technical and usage data
- IP address
- browser and device information
- app and page usage information
- logs used for security, debugging and performance monitoring
3. How We Use Personal Data
We use personal data to:
- generate and deliver vehicle reports
- provide paid features and process purchases
- create and manage user accounts
- save reports for account holders
- respond to support requests and enquiries
- maintain platform security and prevent abuse
- debug, improve and develop the service
- comply with legal and financial obligations
4. Lawful Bases for Processing
Under UK GDPR, we rely on one or more of the following lawful bases:
Contract
Where processing is necessary to provide the service you ask us to provide, including generating reports, creating accounts and supplying paid content.
Legitimate interests
Where processing is reasonably necessary for our legitimate interests, including operating the platform, preventing fraud and misuse, troubleshooting issues, improving our services, and defending legal claims.
Legal obligation
Where we must process or retain data to comply with legal, tax, accounting, regulatory, or law-enforcement obligations.
5. Third-Party Processors and Services
We use third-party providers to help us operate AutoAudit. These may include:
- Supabase for authentication and database services
- Stripe for payment processing
- Vercel for hosting and application infrastructure
- DVSA and vehicle data providers for MOT, enrichment, valuation or history-related data
These providers may process personal data on our behalf or as separate controllers depending on the context of the service they provide.
6. Data Sharing
We do not sell your personal data.
We may share personal data where necessary:
- with service providers that help us operate AutoAudit
- to process payments and manage transactions
- to comply with legal obligations
- to establish, exercise or defend legal claims
- in connection with a business sale, merger, or restructuring
7. Data Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this notice.
Typical retention periods are:
- account data: while your account remains active and for a reasonable period afterwards where needed for security, backup or compliance purposes
- saved reports: typically up to 30 days, unless a longer period is required for technical, legal or support reasons
- transaction and payment records: retained for as long as reasonably necessary for accounting, tax and legal compliance
- support communications: retained for as long as reasonably necessary to deal with the issue and maintain records
8. Security
We use reasonable technical and organisational measures to help protect personal data, including secure hosting, access controls and encrypted connections where appropriate.
However, no method of storage or transmission is completely secure, so we cannot guarantee absolute security.
9. International Transfers
Some of our service providers may process data outside the UK. Where this happens, we take steps intended to ensure appropriate safeguards are in place in line with applicable data protection law.
10. Your Rights
Depending on the circumstances, you may have the right to:
- request access to your personal data
- request correction of inaccurate personal data
- request erasure of your personal data
- request restriction of processing
- object to certain processing
- request transfer of your data
- withdraw consent where processing is based on consent
To exercise your rights, email support@autoaudit.uk.
11. Complaints
If you are unhappy with how we handle your personal data, we would appreciate the chance to address your concerns first.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator.
12. Cookies and Similar Technologies
We may use essential cookies and similar technologies necessary for the operation, security and performance of the site.
If we introduce non-essential analytics or marketing cookies, we will provide appropriate notice and controls where required.
13. Changes to This Privacy Notice
We may update this Privacy Notice from time to time. The latest version will always appear on this page with the revised date.
14. Contact
For privacy questions or data requests, contact support@autoaudit.uk.
