Legal
Privacy Policy
Last updated: 28 May 2026
SpareCarPart Ltd ("SpareCarPart", "we", "us") takes your privacy seriously. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
SpareCarPart Ltd ("SpareCarPart", "we", "us") is a UK-based marketplace that connects vehicle owners with independent breaker yards and parts suppliers. We are the data controller for personal data you provide to us through the website, mobile experience and customer support channels.
Company details
SpareCarPart Ltd
T1 Dudley Court North, The Waterfront, Brierley Hill, DY5 1XP, United Kingdom
Email: info@sparecarpart.com
If you have any questions about this policy or how we handle your data, contact us at privacy@sparecarpart.com.
2. What we collect, and why
We collect only what we need to introduce you to suppliers, fulfil orders and run a safe marketplace. In plain English:
| Category | Examples | Why we collect it |
|---|---|---|
| Account | Name, email, hashed password, phone, postcode | Create your account, send quote responses, recover access |
| Vehicle | Registration, make, model, year, parts requested | Match the right part to your vehicle and route requests to suppliers who stock it |
| Transactional | Quotes, order status, delivery and warranty events | Fulfil the contract, support warranty claims, meet UK tax and consumer-protection law |
| Communications | Messages with suppliers and support, complaints | Resolve disputes, improve service, hold suppliers to our standards |
| Payments | Stripe charge/refund metadata (no full card numbers stored by us) | Take payment securely via Stripe and reconcile refunds |
| Technical | IP address, browser/device, cookies | Run the site, prevent fraud and — only with consent — analytics & marketing (see Cookie Policy) |
3. Lawful bases for processing
We process your personal data under the following lawful bases as set out in Article 6 of the UK GDPR:
- Contract — to provide the marketplace, send quote requests and process orders.
- Legitimate interests — to operate, secure and improve the service and prevent fraud.
- Legal obligation — to meet tax, accounting and consumer-protection duties.
- Consent — for marketing emails and non-essential cookies. You can withdraw consent at any time.
4. How we share data
We share the minimum data needed to fulfil your request:
- With suppliers, so they can quote and dispatch the part you asked for.
- With service providers (hosting, payments, email, analytics) acting as data processors on our instructions.
- With authorities where required by law or to protect our rights or users.
We never sell your personal data.
5. How long we keep it
We keep data only as long as we need it. Specific retention windows:
- Account data — while active and up to 6 years after closure (UK tax & consumer-protection rules).
- Order & quote records — 6 years from the order date.
- Marketing preferences — until you withdraw consent.
- Smart Finder / AI photos — uploaded images are processed in-memory and discarded within 24 hours. Photos you explicitly attach to a part request are kept for the request lifetime + 90 days.
- Server & security logs — 90 days for application logs, 12 months for security audit logs.
- Rate-limit / IP records — 24 hours rolling.
6. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, port and object to processing of your personal data, and to withdraw consent. To exercise any of these rights, email our privacy team at privacy@sparecarpart.com. We will respond within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
California residents: use our Do Not Sell or Share My Personal Information page to opt out of sale/sharing under the CCPA/CPRA.
6a. Data Protection contact
We do not appoint a statutory Data Protection Officer (we are not required to under Article 37 UK GDPR) but you can reach our privacy lead for any data-protection question:
Privacy team
Email: privacy@sparecarpart.com
Post: Privacy team, SpareCarPart Ltd, T1 Dudley Court North, The Waterfront, Brierley Hill, DY5 1XP, United Kingdom
We aim to acknowledge subject access requests within 3 working days and respond in full within 30 calendar days.
6b. AI photo & image processing
Our Smart Finder, AI Part Finder and AI Health Check accept photos you upload from your device. Here is exactly what happens with that image:
- On-device resizing — the image is downscaled and recompressed in your browser before upload (max 1600px, JPEG quality 0.82) so the smallest possible file leaves your device.
- Transit — uploaded over TLS 1.2+ to our edge server.
- Inference — forwarded to the Lovable AI Gateway (Gemini family) solely to identify the part. The image is not used to train any third-party model.
- Retention — discarded within 24 hours unless you explicitly attach it to a part request (in which case it lives with that request + 90 days).
- No biometric processing — we instruct the model to identify parts, not people. We don't run face detection or biometric analysis.
- No sale or sharing — photos are never sold or shared with advertisers, data brokers or analytics vendors.
Lawful basis: legitimate interest (running the requested AI feature) where you upload anonymously; contract where the photo is part of a request you submit.
6c. Delete my account & data
You can ask us to permanently delete your account and the personal data tied to it at any time. Once verified, we action requests within 30 days.
What gets removed:
- Your account profile (name, email, phone, password hash, saved addresses).
- Saved vehicles, garage list, watchlists and notification preferences.
- Marketing contact record and email/SMS consent flags.
- Photos you uploaded to part requests (request images + any AI Smart Finder photos still in cache).
- Direct messages between you and suppliers, and your supplier reviews tied to this account.
- Device push subscriptions and any browser-side data (cookies, localStorage) on your next visit.
What we have to keep (and why):
- Order, invoice and quote records — kept for 6 years to meet UK tax (HMRC) and consumer-protection law. These are detached from your account and pseudonymised where possible.
- Fraud / abuse flags — minimal identifiers (e.g. hashed email, IP) may be retained to stop a banned account being re-created.
- Security audit logs — kept for up to 12 months, then deleted automatically.
We may need to verify your identity (e.g. by replying from the account's registered email) before we act on the request.
7. Security
We use industry-standard safeguards including TLS encryption in transit, encryption at rest for personal data (database storage and backups), role-based access control, audit logging, and regular security reviews.
Multi-factor authentication. Supplier accounts can enrol time-based one-time-password (TOTP) MFA from Supplier security settings — recommended for everyone handling customer orders, and required for staff accounts.
No system is 100% secure — if we ever suspect a breach affecting you, we will notify you and the ICO as required by law.
8. Your choices and controls
You're in control of what we send you and what we measure:
- Marketing emails — opt in or out at any time from Your account → Communication preferences. We default to opted-out; we only email you when you tick the box.
- Cookies & tracking — toggle analytics and marketing cookies on Cookie preferences. Strictly-necessary cookies stay on because the site needs them to run.
- Transactional emails — quote replies, order updates and security alerts are always sent because they're part of the service you asked for.
9. Processors and sub-processors
We use the following third parties to run the Service. Each acts as a data processor on our written instructions under a Data Processing Agreement. A more detailed register is available on request.
| Processor | Purpose | Location |
|---|---|---|
| Lovable Cloud (Supabase) | Database, auth, file storage | EU / UK |
| Cloudflare | Edge hosting, security | Global edge (UK PoP) |
| Stripe | Card payments | EU / US (IDTA) |
| Lovable AI Gateway | AI Chat, Part Finder, Health Check (prompt + image inference) | EU / US (IDTA) |
| DVLA, DVSA | Vehicle & MOT lookups | UK |
| Parts catalogue partners | Reference part listings | EU / US |
| Google Fonts | Web fonts (IP visible during font fetch) | Global CDN |
We do not currently use any analytics, advertising, retargeting, A/B-testing or session-replay vendors. If we add one, we will update this list, refresh the cookie banner, and ask for fresh consent before it loads in your browser.
10. International transfers
Some of our processors operate outside the UK. Where they do, we rely on UK adequacy regulations or the ICO's International Data Transfer Agreement to ensure your data remains protected to UK standards.
11. Changes to this policy
We may update this policy from time to time. Material changes will be flagged on the site or by email at least 14 days before they take effect.