Privacy Policy
Last updated: 05/04/2026
1. Data controller
The data controller for this website is:
MG COMPANY DAYA LTD
Registration number: 16707902
Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: contact@historycar.co.uk
MG COMPANY DAYA LTD ("we", "us", "our") is committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Data we collect
We collect and process the following personal data when you use our service:
- Email address — to deliver your vehicle history report and communicate about your account.
- Vehicle identification data (VIN or registration number) — to generate the requested report.
- Payment information — processed securely by our payment partner Stripe. We do not store your card details on our servers.
- IP address and browser data — collected automatically for security, fraud prevention, and service improvement.
- Cookies — strictly technical cookies necessary for the functioning of the service (see Section 9).
3. Purpose and legal basis
We process your data for the following purposes, in accordance with Article 6 of the UK GDPR:
| Purpose | Legal basis |
|---|---|
| Generating and delivering vehicle history reports | Performance of a contract (Art. 6(1)(b)) |
| Processing payments | Performance of a contract (Art. 6(1)(b)) |
| Customer support and communication | Legitimate interest (Art. 6(1)(f)) |
| Fraud prevention and security | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
4. Data sharing
We share your data only with the following third-party service providers, strictly for the purposes described above:
- Stripe, Inc. — payment processing. Stripe is certified PCI DSS Level 1 and processes payments securely.
- DVSA MOT History API — to retrieve official MOT and vehicle history data for UK-registered vehicles.
- Google Gemini AI — to enhance report analysis and provide intelligent summaries.
- Vercel Inc. — website hosting and infrastructure.
We do not sell, rent, or trade your personal data to any third party for marketing or advertising purposes.
5. Data retention
Your personal data is retained for the following periods:
- Account and report data: up to 2 years from the date of your last activity, for customer support and service improvement.
- Payment records: retained as required by applicable tax and accounting legislation.
- Technical logs (IP, browser): up to 12 months.
You may request the deletion of your data at any time by contacting us at contact@historycar.co.uk. We will process your request within 30 days.
6. Your rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of access — obtain a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — request deletion of your data where there is no compelling reason for continued processing.
- Right to restriction of processing — request that we limit how we use your data.
- Right to data portability — receive your data in a structured, commonly used, machine-readable format.
- Right to object — object to processing based on legitimate interests.
7. How to exercise your rights
To exercise any of the rights listed above, please contact us by email at contact@historycar.co.uk.
Please include sufficient information to identify your account (e.g. the email address used to purchase a report). We will respond to your request within 30 days of receipt.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
8. Data security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- SSL/TLS encryption for all data in transit
- Encrypted data storage at rest
- Regular security audits and updates
- Access controls limiting data access to authorised personnel only
9. Cookies
This website uses only strictly necessary (technical) cookies required for the proper functioning of the service. These include session cookies and authentication tokens.
We do not use tracking cookies, advertising cookies, or any third-party analytics cookies. No cookie consent banner is required as we only use essential cookies in accordance with the Privacy and Electronic Communications Regulations (PECR).
10. International data transfers
Some of our service providers are based outside the United Kingdom:
- Vercel Inc. (United States) — website hosting
- Stripe Inc. (United States) — payment processing
Where data is transferred outside the UK, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the ICO, and/or the transfer is to a country recognised as providing an adequate level of data protection.
11. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.
12. Contact us
If you have any questions or concerns about this privacy policy or our data practices, please contact us:
MG COMPANY DAYA LTD
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: contact@historycar.co.uk