Legal

Privacy policy

We collect the minimum needed to run your account, generate your checklists and keep the service secure. We never sell your personal data.

Last updated · 12 August 2026

1. Summary and who is responsible

Rhys Morgan trading as VehicleFaults is the data controller for the personal data described here. We collect the minimum needed to run your account, generate reports, take payment and keep the service secure. We do not sell your personal data and we do not use it for third-party advertising.

For any privacy question or request, email team@vehiclefaults.com. Security issues can be reported to team@vehiclefaults.com. Registered business details are available on request.

Where you use the service to record information about your own customers, you are the controller of that data and we act as your processor.

2. What we collect

  • Account data · name, email address, password hash, business name, dealership logo and website, and team membership.
  • Usage and device data · pages viewed, features used, browser and device type, referrer, IP address and approximate country/region.
  • Vehicle and report data · the vehicles you look up (make, model, variant, year, mileage, VIN or registration if entered), checklist answers, notes and photos you add.
  • Billing data · plan, trial dates, currency, invoices and payment status. Card details are handled by our payment processor; we never see or store full card numbers.
  • Integration data · tokens or credentials for a connected stock feed or DMS, and the vehicle records synced from it.
  • Communications · support messages, feedback, and email engagement such as whether a service email was delivered or opened.
  • Free-tool data · details entered into a free report or lead form, including an email address if you give us one.

3. Why we use it and our lawful bases

  • To provide the service, generate checklists and store your reports · performance of our contract with you.
  • To create and manage your account, trial and subscription and to take payment · contract and legal obligation.
  • To keep the service secure, prevent fraud and abuse, and enforce rate limits · legitimate interests.
  • To measure and improve accuracy, performance and product decisions using first-party analytics · legitimate interests.
  • To send service and transactional emails you need to use the product · contract.
  • To send marketing emails about the product · consent, or legitimate interests for existing business customers. You can unsubscribe from any marketing email at any time.
  • To meet accounting, tax and legal obligations, and to establish or defend legal claims · legal obligation and legitimate interests.

4. Who we share it with

We use trusted providers to run the product, each under contract and only for what they need:

  • Cloud hosting, database, authentication and file storage · to run the app and store your data.
  • Edge hosting and content delivery · to serve the website securely and quickly.
  • AI model providers, accessed through our AI gateway · to generate checklists and summaries from the vehicle details you enter.
  • Research and web-data providers (including Perplexity and Firecrawl) · to gather published fault information for the models you look up.
  • Transactional email delivery · to send account, report and billing emails.
  • Payment processing · when paid plans are enabled, to take payment and issue invoices.
  • Connected DMS or stock-feed providers you choose to link, and only at your instruction.

5. AI processing

Vehicle details you enter are sent to AI providers to generate a checklist. We instruct providers not to use your inputs to train their models where that option is available. Prompts do not include your customer's personal data unless you type it into a free-text field · please don't.

AI output is guidance, not a decision about you. We do not use automated decision-making or profiling that has a legal or similarly significant effect on you.

6. Public and shared content

Reports you share, pass certificates you publish, and public verification links are accessible to anyone with the link. Your dealership name, logo and the vehicle details on that report will be visible. You control whether to create or revoke them.

7. International transfers

Some providers operate outside the UK/EEA, including in the United States. Where that happens we rely on approved safeguards such as UK/EU standard contractual clauses with the UK Addendum, or an adequacy decision. You can ask us for details of the safeguards used.

8. How long we keep it

  • Account and report data · while your account is active, then up to 12 months after closure, unless you ask us to delete it sooner.
  • Photos and uploads · deleted with the related check or account, subject to short-lived backups.
  • Billing and tax records · up to 7 years where tax law requires it.
  • Security, rate-limit and error logs · up to 12 months.
  • Analytics · aggregated and retained without direct identifiers.
  • Marketing suppression lists · kept indefinitely so we can honour your unsubscribe.

9. Your rights

You can request access to your data, correction, deletion, restriction of processing, or portability, and you can object to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time, including via the unsubscribe link in any marketing email.

Email team@vehiclefaults.com to exercise any right · we respond within one month. We may ask you to verify your identity. If you are in the UK you can complain to the Information Commissioner's Office (ico.org.uk); in the EEA, to your local supervisory authority.

10. If you are in the United States or Canada

We do not sell or share personal information for cross-context behavioural advertising, and we do not use sensitive personal information for inferring characteristics. US residents may request to know, correct, delete or receive a copy of their personal information, and will not be discriminated against for doing so.

Canadian users can request access to and correction of their personal information under PIPEDA, and may complain to the Office of the Privacy Commissioner of Canada. Use the privacy email above for any of these requests; an authorised agent may act for you with written authority.

11. Security

Data is encrypted in transit, access to production data is restricted and logged, photos are held in private storage with short-lived signed links, database access is scoped per user by row-level security, and passwords are hashed and checked against known-breached password lists.

No system is perfectly secure, so please use a strong, unique password. If a personal data breach is likely to cause a risk to you, we will notify the relevant regulator within 72 hours and tell affected users without undue delay.

12. Children

The service is intended for motor-trade professionals and adult buyers. It is not for anyone under 18 and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.

13. Cookies and changes to this policy

Cookies and browser storage are described in our cookie policy.

We may update this policy; the date at the top shows the latest version, and we will tell you by email or in the app about material changes before they take effect.

Questions about this policy? Email hello@vehiclefaults.com and we'll come back to you.