Privacy Policy
How YourServiceCentre.com collects, uses and protects your personal data, in compliance with the UK GDPR and the Data Use and Access Act 2025.
๐ Last updated: 14 May 2026YourServiceCentre.com is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over it.
We collect only the data we need to book and deliver your car service: contact details, vehicle information, payment data, and service history. We share it with the specific partner garage doing your service, and with essential providers like Stripe (payments) and Postmark (email). We never sell your data. You can ask us to delete everything at any time by emailing privacy@yourservicecentre.com.
1. Who we are
YourServiceCentre.com is operated by Validus Media Ltd, a company registered in England and Wales.
- Company number: 08013355
- Registered office: 152 Osmondthorpe Lane, Leeds, LS9 9EG, United Kingdom
- Trading name: YourServiceCentre.com (also t/a Unavoidable Marketing)
- Data Protection contact: privacy@yourservicecentre.com
- ICO registration: [Pending registration - will be updated once issued]
Under the UK GDPR and Data Protection Act 2018, we act as the data controller for the personal data you provide to us when you use yourservicecentre.com.
2. What personal data we collect
Identity and contact details
- Full name
- Email address
- Mobile phone number
- Home or collection address (for free collection and delivery)
- Account password (stored as a one-way salted hash, never visible to us)
Vehicle data
- Vehicle registration number (number plate)
- Make, model, year of manufacture, fuel type, engine size, colour
- MOT history and current MOT expiry date
- Tax status
- Service history (services you book through us)
- Current and historical mileage readings
Payment and financial data
- Card details are processed directly by Stripe (our payment processor) - we never see or store full card numbers
- Billing address
- Transaction history (date, amount, what you paid for)
- Care plan subscription status and payment history
Service interaction data
- Bookings you've made (service type, date, garage assigned)
- Messages between you, us, and the garage
- Photos uploaded by the garage during your service (walk-around, advisory items)
- Reviews and ratings you leave
- Customer support tickets and conversations
Technical data
- IP address (for security and fraud prevention)
- Browser type and version
- Device type (desktop, mobile, tablet)
- Pages you visited and when
- Referrer URL (which site you came from)
We do NOT collect any special category data (race, ethnicity, religious beliefs, political opinions, health data, sexual orientation, biometric data, genetic data, or trade union membership). If you provide this voluntarily in a message or support ticket, we won't use it for anything beyond responding to your enquiry.
3. How we collect your data
We collect data in four ways:
1. Information you give us directly
When you enter your registration plate, book a service, create an account, set up a care plan, contact us, or leave a review.
2. Information from government and third-party APIs
When you enter your registration plate, we query:
- DVLA Vehicle Enquiry Service (VES) - to retrieve your vehicle's make, model, fuel type, engine size, colour, tax status, MOT status
- DVSA MOT History API - to retrieve your vehicle's MOT history, mileage readings and advisory items
This is covered in section 5 below.
3. Information collected automatically
When you visit our website, we automatically collect technical data via essential cookies and server logs.
4. Information from our partner garages
When a garage completes your service, they upload mileage readings, photos, work performed, and advisory notes which become part of your service history.
4. Why we use your data (lawful basis)
Under UK GDPR Article 6, we must have a lawful basis for processing your personal data. The basis depends on what we're doing:
| What we do with your data | Lawful basis |
|---|---|
| Process your service booking | Contract - necessary to fulfil our agreement with you |
| Take payment | Contract |
| Manage your care plan subscription | Contract |
| Send booking confirmations, reminders, status updates | Contract |
| Send invoices and receipts | Legal obligation - UK tax and consumer law |
| Retain financial records (6 years) | Legal obligation - HMRC requirements |
| Look up your vehicle via DVLA / DVSA | Contract |
| Share your details with the assigned garage | Contract |
| Send service reminders and renewal nudges | Legitimate interests - keeping you on the road safely and lawfully |
| Send marketing emails (if you've opted in) | Consent - you can withdraw any time |
| Prevent fraud, secure our systems | Legitimate interests - protecting our business and customers |
| Improve our website and services | Legitimate interests - we use aggregated, anonymous data |
| Respond to your enquiries and support requests | Legitimate interests or Contract |
Under the Data (Use and Access) Act 2025, which came into force on 5 February 2026, we also rely on "recognised legitimate interests" where applicable (for example, responding to safeguarding requests or emergency situations).
5. DVLA and DVSA MOT data lookups
When you enter your vehicle registration on our site, we query two UK government APIs to retrieve information about your car. This is essential for us to give you an accurate price and recommend the right service.
What we look up
- DVLA Vehicle Enquiry Service: Make, model, year, fuel type, engine size, colour, CO2 emissions, tax status, MOT status
- DVSA MOT History API: Full MOT test history, mileage readings, pass/fail results, advisory items
What we store
We cache the response data for up to 48 hours in our database to speed up repeat visits and reduce API costs. After that, the data is automatically re-fetched on your next visit.
What we don't get
Neither the DVLA nor DVSA API will tell us:
- The vehicle's owner's name or address
- Insurance details
- Accident history
- Finance/lease status
For privacy reasons, this information is not legally available via API. We ask you directly for your name, address, and contact details.
The DVLA's privacy policy is available at gov.uk/dvla/personal-information-charter. The DVSA's is at gov.uk/dvsa/personal-information-charter.
6. Who we share your data with
We only share your data with the parties we need to in order to deliver our service. We never sell your data to advertisers, data brokers, or anyone else.
Categories of recipients
- Partner garages - the specific garage assigned to your booking (see section 7 below)
- Payment processors - Stripe (registered in Ireland) handles all card payments
- Email service - Postmark (operated by ActiveCampaign, USA - UK-EU adequacy applies) sends transactional emails
- SMS service - Twilio (Ireland) sends booking reminders and status updates
- Cloud hosting - our infrastructure is hosted in UK data centres (Cloudflare R2 and Vercel UK regions)
- Analytics - we use privacy-friendly analytics that don't track you across sites
- Government APIs - DVLA and DVSA (UK)
- Professional advisors - lawyers, accountants, auditors when needed
- Law enforcement - if legally required (court order, criminal investigation)
7. Sharing data with partner garages
When you book a service, we share specific information with the garage assigned to do the work. This is necessary so they can collect, service, and return your vehicle.
What the garage sees
- Your name
- Your mobile phone number
- Your collection address
- Your vehicle registration, make, model, year, mileage
- The service you've booked
- Any specific notes you've added (e.g. "there's an intermittent noise from the front passenger wheel")
- Your previous service history WITH US (so they can recommend the right service)
What the garage does NOT see
- Your email address (we route messages via our platform)
- Your payment card details (Stripe handles this)
- Your home address if different from collection address
- Other bookings you've made with other garages on our platform
- Reviews or feedback you've left about OTHER garages
Each partner garage signs a Data Processing Agreement with us before they go live on the platform. They are bound by UK GDPR to use your data only for the specific service you've booked.
8. How long we keep your data
We don't keep your data longer than we need to. Different data has different retention periods:
| Data type | Retention period | Why |
|---|---|---|
| Account details (name, email, phone) | While account active + 1 year | For final invoices, complaints handling |
| Vehicle data (DVLA/MOT cache) | 48 hours then auto-purged | Performance and cost-saving |
| Service history | 7 years | Industry standard - for warranty claims, vehicle resale value, customer reference |
| Bookings (confirmed) | 7 years | HMRC tax records + warranty |
| Payment / invoice records | 6 years | HMRC legal requirement |
| Care plan subscriptions | 7 years after cancellation | Tax and dispute records |
| Marketing consent records | Until you unsubscribe + 3 years | To prove we had consent |
| Support tickets and messages | 3 years | Complaint handling |
| IP addresses / server logs | 30 days | Security and fraud prevention |
| Cookies (non-essential) | 13 months max | ICO guidance |
When the retention period expires, your data is either permanently deleted or fully anonymised (with no way to link it back to you).
9. How we keep your data secure
We take data protection seriously. Our security measures include:
Technical measures
- Encryption in transit: All data is sent over HTTPS using TLS 1.3
- Encryption at rest: Database data is encrypted using AES-256
- Password hashing: Passwords are hashed with bcrypt (cost factor 12) - we never see your actual password
- Two-factor authentication (2FA): Available on all accounts, mandatory for garage and admin accounts
- Role-based access control: Customers see only their own data, garages see only their assigned jobs, admins see only what's needed for their role
- API authentication: OAuth 2.0 for service-to-service calls
- Regular security updates: All software patched within 14 days of vendor release
- DDoS protection: via Cloudflare
- SQL injection / XSS protection: Parameterised queries, content security policy headers
Organisational measures
- Staff trained on data protection annually
- Background checks on all employees handling customer data
- Signed confidentiality and data protection agreements for all staff and contractors
- Data breach response plan with 72-hour ICO notification procedure
- Annual penetration testing by independent security firms
- Quarterly internal security audits
- Access logs reviewed monthly
10. Your rights under UK GDPR
Under the UK GDPR, you have the following rights regarding your personal data:
1. Right to be informed
That's what this privacy policy is for - to tell you clearly what we do with your data.
2. Right of access (Subject Access Request)
You can request a copy of all the personal data we hold about you. We'll respond within one month, free of charge. Email privacy@yourservicecentre.com.
3. Right to rectification
You can ask us to correct any inaccurate or incomplete data. You can also update most of your details yourself in your account dashboard.
4. Right to erasure ("right to be forgotten")
You can ask us to delete your personal data. Note: we may need to keep some data (like invoice records) for legal reasons, but we'll delete everything else.
5. Right to restrict processing
You can ask us to pause processing your data while a dispute is resolved.
6. Right to data portability
You can request your data in a machine-readable format (we provide JSON export) so you can move it to another service.
7. Right to object
You can object to certain types of processing, especially for marketing and profiling.
8. Rights relating to automated decision-making
You have the right not to be subject to a decision based solely on automated processing that has a significant effect on you. See section 11.
To exercise any of these rights, email privacy@yourservicecentre.com. We'll respond within one month.
11. Automated decision-making
Under the UK GDPR (Article 22A, as updated by the Data Use and Access Act 2025), you have specific rights regarding automated decisions that significantly affect you.
We use automated systems for two things:
Garage assignment
When you book a service, our system automatically assigns the booking to a suitable garage based on distance, capacity, vehicle specialism, and customer ratings. This is a logistics decision with no significant impact on your rights. You can request a different garage at any time before your service date by contacting us.
Service recommendation
Based on your car's age and mileage, we automatically recommend a service type (Interim, Full, or Major). This is a suggestion, not a decision - you choose which service you actually book.
Neither system makes decisions with legal or significant effects on you (such as denying you a service, setting individual pricing differently, or profiling you for marketing). If we ever introduce systems that do, we'll update this policy and seek your explicit consent.
12. International data transfers
Most of your data stays within the UK. Some of our service providers process data in:
- Republic of Ireland (Stripe, Twilio) - EU adequacy decision applies
- USA (Postmark / ActiveCampaign) - covered by the UK extension to the EU-US Data Privacy Framework (DPF)
All transfers comply with UK GDPR Chapter 5. We use Standard Contractual Clauses (SCCs) with providers where adequacy decisions don't apply.
13. Marketing communications
We will only send you marketing emails or SMS if you've explicitly opted in. You can unsubscribe at any time using the link in any marketing email, by replying STOP to any marketing SMS, or by emailing privacy@yourservicecentre.com.
Note: we will always send you transactional messages (booking confirmations, payment receipts, service reminders) even if you've opted out of marketing. These are necessary to fulfil our contract with you.
14. Children's data
Our services are intended for adults aged 18 or over. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us at privacy@yourservicecentre.com and we will delete it.
15. Complaints and how to contact the ICO
If you're not happy with how we've handled your data, please contact us first at privacy@yourservicecentre.com - we'll do our best to resolve it.
You also have the right to lodge a complaint with the UK's data protection regulator:
- Information Commissioner's Office (ICO)
- Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Helpline: 0303 123 1113
- Website: ico.org.uk
16. Changes to this policy
We may update this privacy policy from time to time. The "last updated" date at the top of this page shows when. If we make significant changes (like adding a new category of recipient, or starting a fundamentally new use of your data), we'll email you to let you know before the change takes effect.
17. How to contact us
For any data protection questions or to exercise your rights:
- Email: privacy@yourservicecentre.com
- Post: Data Protection Officer, Validus Media Ltd, 152 Osmondthorpe Lane, Leeds, LS9 9EG
- Phone: 0113 123 4567 (Mon-Sat 8am-7pm)
We aim to respond to all data protection enquiries within 5 working days. For formal requests under UK GDPR (Subject Access Requests, erasure requests, etc.), we respond within one month as required by law.