Legal
Privacy Policy
Last updated: 10 September 2026
SpareCarPart ("we", "us") takes your privacy seriously. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
SpareCarPart ("we", "us") is a UK-based online marketplace that connects vehicle owners with independent breaker yards and parts suppliers. We are the data controller for personal data you provide to us through the website, mobile experience and customer support channels.
If you have any questions about this policy or how we handle your data, contact us at privacy@sparecarpart.com.
2. What we collect, and why
We collect only what we need to introduce you to suppliers, fulfil orders and run a safe marketplace. In plain English:
| Category | Examples | Why we collect it |
|---|---|---|
| Account | Name, email, hashed password, phone, postcode | Create your account, send quote responses, recover access |
| Vehicle | Registration, make, model, year, parts requested | Match the right part to your vehicle and route requests to suppliers who stock it |
| Transactional | Quotes, order status, delivery and warranty events | Fulfil the contract, support warranty claims, meet UK tax and consumer-protection law |
| Communications | Messages with suppliers and support, complaints | Resolve disputes, improve service, hold suppliers to our standards |
| Payments | Stripe charge/refund metadata (no full card numbers stored by us) | Take payment securely via Stripe and reconcile refunds |
| Technical | IP address, browser/device, cookies and consented usage or page-performance measurements | Run and secure the site and - only with consent - analytics & marketing (see Cookie Policy) |
| Nearby directory location | Rounded latitude and longitude after you tap “Use My Current Location” | Sort available automotive listings by distance. The location is sent only for the requested search and is not written to the directory database. |
3. Lawful bases for processing
We process your personal data under the following lawful bases as set out in Article 6 of the UK GDPR:
- Contract - to provide the marketplace, send quote requests and process orders.
- Legitimate interests - to operate, secure and improve the service and prevent fraud.
- Legal obligation - to meet tax, accounting and consumer-protection duties.
- Consent - for marketing emails and non-essential cookies. You can withdraw consent at any time.
- Consent - for optional browser geolocation used by the nearby automotive directory. You can deny permission and enter a postcode instead.
4. How we share data
We share the minimum data needed to fulfil your request:
- With suppliers, so they can quote and dispatch the part you asked for.
- With service providers (hosting, payments, email, analytics) acting as data processors on our instructions.
- With authorities where required by law or to protect our rights or users.
We never sell your personal data.
5. How long we keep it
We keep data only as long as we need it. Specific retention windows:
- Account data - while active and up to 6 years after closure (UK tax & consumer-protection rules).
- Order & quote records - 6 years from the order date.
- Marketing preferences - until you withdraw consent.
- Optional analytics data - collected only after consent. Core Web Vitals records include a metric, rating, coarse page area, navigation type and browser user-agent and are stored in Supabase for operational reporting. Google Analytics only loads after analytics consent and when a Measurement ID is configured; it remains disabled while no ID is configured. No session-recording or replay tool is configured. Withdrawing consent stops future analytics collection; these records are not attached to your customer account.
- Smart Finder / AI photos - uploaded images are processed in-memory and discarded within 24 hours. Photos you explicitly attach to a part request are kept for the request lifetime + 90 days.
- Server & security logs - 90 days for application logs, 12 months for security audit logs.
- Rate-limit / IP records - stored as one-way protection-key hashes and scheduled for deletion once older than 24 hours; cleanup runs every minute, subject to normal scheduler operation and bounded cleanup batches.
- Radio-code lookup audit - stores the brand, result status and a one-way hash of the radio serial, never the returned unlock code. Audit and feedback rows are scheduled for deletion once older than 24 hours; cleanup runs every minute, subject to normal scheduler operation and bounded cleanup batches.
- Nearby directory location - a rounded coordinate is cached in your browser for 30 minutes. It is used transiently by our server to sort results and is not stored in the directory database.
6. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, port and object to processing of your personal data, and to withdraw consent. To exercise any of these rights, email our privacy team at privacy@sparecarpart.com. We will respond within one month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
California residents: use our Do Not Sell or Share My Personal Information page to opt out of sale/sharing under the CCPA/CPRA.
6a. Data Protection contact
We do not appoint a statutory Data Protection Officer (we are not required to under Article 37 UK GDPR) but you can reach our privacy lead for any data-protection question:
Privacy team
Email: privacy@sparecarpart.com
We aim to acknowledge subject access requests within 3 working days and respond in full within 30 calendar days.
6b. AI photo, chat & voice processing
Our Smart Finder, AI Part Finder, AI Health Check and Mech assistant process only the content you deliberately submit. Here is what happens:
- On-device resizing - the image is downscaled and recompressed in your browser before upload (max 1600px, JPEG quality 0.82) so the smallest possible file leaves your device.
- Transit - uploaded over TLS 1.2+ to our edge server.
- Smart Finder inference - routed server-to-server through the configured provider solely to identify the part. When OpenRouter is configured, each request requires an endpoint that OpenRouter marks as no-data-collection and Zero Data Retention (ZDR), so routes OpenRouter identifies as retaining or training on prompt content are excluded. These safeguards depend on OpenRouter's published endpoint-policy classifications. If OpenRouter is not configured, the finder can use Google Gemini with the Paid Service safeguards described below. Public production use remains disabled until the paid service configuration has been confirmed.
- Mech chat inference - text and any part photo attached directly in Mech chat are processed server-to-server by Google Gemini under a Cloud Billing project. Google states that Paid Service prompts and responses are not used to improve its products, but may be logged for a limited period for abuse prevention and legal compliance.
- Mech voice transcription - only after you tap the microphone and grant browser permission, the resulting audio recording is sent through our server to Groq Whisper to turn it into editable text. We do not save the audio to your account. Groq states that inference inputs and outputs are not retained by default, but may be logged for up to 30 days for reliability or abuse monitoring; retained data is processed in US Google Cloud infrastructure.
- AI-provider handling - OpenRouter states that it does not retain prompt or response content unless an account opts into prompt logging. Routed model providers and Google Gemini still process the content to produce the requested result, and retain limited operational metadata such as token counts and latency.
- AI photo retention - Smart Finder photos are discarded within 24 hours unless you explicitly attach one to a part request (in which case it lives with that request + 90 days). Voice-provider retention is described separately above.
- No biometric processing - we instruct the model to identify parts, not people. We don't run face detection or biometric analysis.
- No sale or sharing - photos are never sold or shared with advertisers, data brokers or analytics vendors.
Lawful basis: legitimate interest (running the requested AI feature) where you upload anonymously; contract where the photo is part of a request you submit.
6c. Delete my account & data
You can ask us to permanently delete your account and the personal data tied to it at any time. Once verified, we action requests within 30 days.
What gets removed:
- Your account profile (name, email, phone, password hash, saved addresses).
- Saved vehicles, garage list, watchlists and notification preferences.
- Marketing contact record and email/SMS consent flags.
- Photos you uploaded to part requests (request images + any AI Smart Finder photos still in cache).
- Direct messages between you and suppliers, and your supplier reviews tied to this account.
- Device push subscriptions and any browser-side data (cookies, localStorage) on your next visit.
What we have to keep (and why):
- Order, invoice and quote records - kept for 6 years to meet UK tax (HMRC) and consumer-protection law. These are detached from your account and pseudonymised where possible.
- Fraud / abuse flags - minimal identifiers (e.g. hashed email, IP) may be retained to stop a banned account being re-created.
- Security audit logs - kept for up to 12 months, then deleted automatically.
We may need to verify your identity (e.g. by replying from the account's registered email) before we act on the request.
7. Security
We use industry-standard safeguards including TLS encryption in transit, encryption at rest for personal data (database storage and backups), role-based access control, audit logging, and regular security reviews.
Multi-factor authentication. Supplier accounts can enrol time-based one-time-password (TOTP) MFA from Supplier security settings - recommended for everyone handling customer orders, and required for staff accounts.
No system is 100% secure - if we ever suspect a breach affecting you, we will notify you and the ICO as required by law.
8. Your choices and controls
You're in control of what we send you and what we measure:
- Marketing emails - opt in or out at any time from Your account → Communication preferences. We default to opted-out; we only email you when you tick the box.
- Cookies & tracking - toggle analytics and marketing tools on Cookie preferences. Strictly-necessary cookies stay on because the site needs them to run.
- Transactional emails - quote replies, order updates and security alerts are always sent because they're part of the service you asked for.
9. Processors and browser-side tools
We use the following services to run the Service and optional browser-side tools when you consent. Service providers process data under their applicable data terms and our instructions. A more detailed register is available on request.
| Processor | Purpose | Location |
|---|---|---|
| Lovable Cloud (Supabase) | Database, auth, file storage | EU / UK |
| Vercel | Website hosting, delivery and platform security | Global infrastructure |
| Stripe | Card payments | EU / US (IDTA) |
| Google Gemini | Mech chat and configured Smart Finder photo identification | Global processing under Google's applicable data terms |
| Groq | Optional Mech microphone transcription | United States (Google Cloud; international-transfer safeguards apply) |
| OpenRouter and selected model providers | Privacy-filtered routing for Part Finder, Health Check and image generation | Varies by routed provider |
| DVLA, DVSA | Vehicle & MOT lookups | UK |
| Parts catalogue partners | Reference part listings | EU / US |
| Core Web Vitals / Supabase | Consented first-party page-performance reporting | Supabase project region |
| Google Analytics (when configured) | Optional aggregate usage measurement that is only used after analytics consent and when a Measurement ID is configured | Google service region |
Core Web Vitals and Google Analytics stay off unless you grant analytics consent. Google Analytics also stays off unless a Measurement ID is configured. No session replay, advertising or retargeting vendor is currently configured. We will update this list and ask for fresh consent before adding a new optional use.
10. International transfers
Some of our processors operate outside the UK. Where they do, we rely on UK adequacy regulations or the ICO's International Data Transfer Agreement to ensure your data remains protected to UK standards.
11. Changes to this policy
We may update this policy from time to time. Material changes will be flagged on the site or by email at least 14 days before they take effect.
