Legal
Privacy policy
Last updated: 11 October 2026
This page explains what personal data AutoArchive holds about you, why, and the choices you have. It covers your account, the vehicles and documents you add, data we receive from DVSA, and automated processing we run on your uploads.
Publication blocker
AUTOARCHIVE LTD is the intended operator and data controller, subject to incorporation and official name availability. Company number: pending. Registered office: pending. Registered in England and Wales. Do not publish this page until those details are confirmed and the shared mailboxes below have been tested.
Who this policy covers
AutoArchive is a service for recording and organising vehicle history: personal vehicles and, for fleet workspace members, shared vehicles owned or managed by that workspace. The initial paid service is intended for the United Kingdom. Account holders must be at least 18. Access for people aged 16 or 17 is deferred pending a Children's Code assessment. Fleet plans are for business and professional use only.
Data we collect
- Account details: your email address, and authentication records (including sign-in via Google, where you choose it).
- Workspace membership: which personal or fleet workspaces you belong to and your role in each.
- Vehicle records you add: registration, make, model, mileage, tax and service information you enter yourself.
- MOT history for a registration you look up, sourced from the DVSA MOT History API and shown as DVSA records it.
- Documents you upload (photos and files such as invoices, MOT certificates and service records), stored in private, per-account storage.
- Data automatically extracted from your documents by AI processing, including a confidence level, and any corrections you make to that extracted data.
- Reminder and notification preferences, and the reminder and confirmation emails sent to you.
- Workspace activity and audit records — who did what, and when — for actions like deleting a vehicle, document or account.
- Billing and subscription records where you have a paid plan. Payments are currently processed in Stripe's test mode only; no live payments are taken.
- Basic analytics, monitoring and security logs used to keep the service reliable and secure (for example, error reports and rate-limit records).
- Waitlist sign-ups: your name and email address, and for fleets your company name and number of vehicles, plus a record of when you consented to emails. See Waitlist below.
- Beta test applications, if you apply to test our app: your name, email address (for Android, the Google account used on the Play Store), phone make and model, operating system version, how you heard about us, any notes you add and your agreements to take part. Only AutoArchive administrators can see them; we use them only to run the test and contact you about it, and delete them 90 days after the test ends.
Waitlist
If you join our waitlist, we collect your name and email address and, if you run a fleet, your company name and number of vehicles. We also record that you gave consent and when.
We use this only to email you about AutoArchive: when new features launch, founding-member offers and product updates. We do not share or sell waitlist data.
Our lawful basis is your consent, given by ticking the box on the sign-up form. You can withdraw it at any time using the unsubscribe link in any email, or by emailing privacy@autoarchive.uk, and we will stop emailing you.
We delete waitlist details 12 months after you sign up, or sooner if you unsubscribe or ask us to. If you create an AutoArchive account, your account is then covered by the rest of this policy.
Emails and advertising
AutoArchive does not carry advertising at initial launch and does not load an advertising SDK. Authentication, security, billing and reminders you request are service messages; they are not marketing. The only marketing email we send is to people who join the waitlist and tick the unticked consent box. Every marketing email includes an easy way to unsubscribe.
Why we process this data
To provide your vehicle archive (storing and organising documents and vehicle data you choose to add), to run the automated extraction and reminder features you use, to keep your account secure, to operate workspace sharing and roles for fleets, and to run billing where you are on a paid plan.
Lawful basis
We use your data to provide the service under our contract with you. We rely on our legitimate interests to protect the service and prevent fraud, and on legal obligations to keep billing records where required. We send waitlist and marketing emails only with your consent, which you can withdraw at any time.
Automated processing and AI
When you upload a document, AutoArchive runs automated extraction to read values such as dates, mileage and amounts, together with a confidence score. Extracted values are shown to you for confirmation and you can correct them at any time; your correction is kept alongside the original extraction. See the AI disclosure page for detail on what this does and does not do.
AI Assistant and connected AI apps
If you use the AI Assistant, a summary of vehicles in your active workspace and your question are sent through the Lovable AI Gateway to an OpenAI model to answer it. Check its answers against your saved records; the assistant can make mistakes.
If you choose to connect a third-party AI app using our MCP/OAuth connector, that app can request read-only access to vehicle history you authorise. Access requires your consent and can be revoked. The third-party app's own privacy terms apply to data it receives. We do not give it access merely because you use the assistant.
Who can see your data
Your personal vehicles and documents are visible only to you. In a fleet workspace, members can see the vehicles, documents and activity of that workspace according to their role (viewer, member or admin); AutoArchive access controls (row-level security) enforce this at the database level. AutoArchive staff do not browse individual accounts except to investigate a support request you have raised, or a security or legal obligation.
Where your data is stored
Account, vehicle and document data is stored with our cloud database and storage provider (Supabase/Lovable Cloud). Uploaded files are held in private storage, isolated per account, and only ever served to you through short-lived signed links.
Who processes data for us
Lovable/Supabase provides hosting, authentication, private storage and the Lovable AI Gateway. An OpenAI model is used via the gateway for AI processing. Stripe handles payments; Google provides optional sign-in; the Lovable-managed email delivery provider sends service messages; and Lovable error reporting receives technical fault data. DVSA supplies MOT history as a data source rather than processing data on our behalf.
Processing summary
| Purpose | Data | Lawful basis | Retention |
|---|---|---|---|
| Account and archive | Email, vehicles, files and records | Contract | While your account is active; see retention policy |
| Waitlist and marketing emails | Name, email, fleet company and vehicle count, consent record | Consent | 12 months from sign-up, or sooner if you unsubscribe |
| Document extraction and AI Assistant | Uploaded files or your question and workspace vehicle summary | Contract, when you use these features | Saved results until deletion; gateway processing retention pending verification |
| MCP/OAuth connection | Authorised vehicle history and connection records | Consent for connection; contract for service | Until revoked or account deletion; third-party retention varies |
| Billing and service emails | Subscription records, email address, delivery records | Contract and legal obligation | As required for financial records; email log limits pending verification |
| Security and error reporting | Technical logs, access and error data | Legitimate interests | Intended maximum 12 months, not yet fully verified |
International transfers
Some providers may process data outside the UK. The destinations and safeguards for each provider have not yet been confirmed.
Publication blocker
Confirm each provider's processing locations and any international-transfer safeguards before publishing this policy.
Publication blocker
The intended active-system deletion targets and 12-month security/audit maximum are not yet fully enforced for storage failures and every log source. The maximum backup lifetime is also unverified. See the retention & deletion policy.
How long we keep data
We keep your archive while your account is active. Deleting a document or vehicle removes its active records; account deletion normally removes active records immediately, with a target of no more than 30 days where further cleanup is needed. Necessary billing records may be kept for legal reasons, security and audit evidence has an intended 12-month maximum, and deleted data may remain in rotating backups until they expire. Some limits and the backup lifetime are still unverified. See our retention & deletion policy for the detail and current publication warnings.
Your rights
You can ask to access or correct your personal data, erase it, restrict its use, receive a portable copy, or object to processing where applicable. Email privacy@autoarchive.uk to exercise these rights. We aim to respond within one month. This address remains pending operational verification.
Complaints to the ICO
If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO).
Your choices and rights
- You can review and correct any extracted document data at any time.
- You can change your reminder and email preferences in Settings.
- You can export a PDF vehicle report from your account.
- You can permanently delete your account and its data from Settings — see the retention & deletion policy.
Contact
Questions about this policy or your data can be sent to privacy@autoarchive.uk. This address remains pending operational verification. General contact: contact@autoarchive.uk. See Support & contact for other routes.
