Privacy Policy

How we collect, use, and protect your data

Last Updated: February 2026

1. Who We Are

This website, cargarages.co.uk, is operated by Craig Davies, trading as CarGarages.co.uk ("we", "us", "our"). We are the data controller for the personal data processed through this website. Our address is 1 New Houses, Penybryn, Hengoed, CF82 7FR. You can contact us at support@cargarages.co.uk or through our contact page.

2. What Data We Collect

We collect different types of personal data depending on how you use the website:

Account Data

When you register an account, we collect your email address and store a secure hash of your password. We also record your user type (e.g. driver or business owner).

Business Owner Data

If you claim or add a business listing, we collect information you provide including your name, role, business details, contact information, and any gallery images you upload.

Vehicle Data

If you use our MOT reminder service, we collect your vehicle registration number, make, model, and MOT/tax/insurance expiry dates. This data is used solely to send you timely reminders.

Payment Data

For premium listing purchases, we store transaction IDs, payment amounts, and plan types. We do not store your credit or debit card details. All card processing is handled securely by our payment providers (Stripe and PayPal).

Usage Data

We collect anonymised usage data including garage page views, click-through actions, pages visited, and garages saved to favourites. This helps us improve the service and provide analytics to business owners.

3. How We Use Your Data & Lawful Basis

Under UK GDPR, we must have a lawful basis for processing your personal data. The table below sets out each purpose and the legal basis we rely on:

PurposeLawful Basis
Managing your account and authenticationContract performance
Processing business listing claims and premium upgradesContract performance
Processing payments for premium listingsContract performance
Sending MOT, tax, and insurance remindersContract performance (you request this service)
Sending marketing emails about features or updatesConsent (opt-in)
Email open and click trackingLegitimate interest (measuring email effectiveness)
Showing garages near your location (IP geolocation)Legitimate interest (core site functionality)
Providing business owners with anonymised listing analyticsLegitimate interest (service improvement)
Improving the website based on aggregated usage dataLegitimate interest (service improvement)
Retaining payment records for tax complianceLegal obligation (UK tax regulations)

Where we rely on legitimate interest, we have assessed that the processing is necessary for our purposes and that your rights and interests do not override those purposes. You have the right to object to processing based on legitimate interest at any time.

4. Email Tracking

Some of our emails include a small invisible image (a tracking pixel) that tells us whether the email was opened, and links that let us know if they were clicked. We use this data to measure the effectiveness of our communications and to improve future emails. You can prevent open tracking by disabling image loading in your email client.

5. Cookies & Local Storage

We use a limited number of cookies and browser local storage entries:

  • Authentication cookies (essential) — these keep you signed in and are required for the site to function. No consent is needed for essential cookies under UK GDPR.
  • Analytics cookies (coming soon) — these will help us understand traffic patterns. When implemented, these will require your consent.
  • Local storage — we store recently viewed garages and temporary favourites data in your browser's local storage for convenience. This data never leaves your device.

For full details, see our Cookie Policy.

6. Third-Party Services

We share data with the following third-party services as necessary to operate the website:

  • Cloud database & authentication provider — stores your account data and manages sign-in sessions. Data is hosted in the EU.
  • Stripe & PayPal — payment processing for premium listings. Your card details are handled directly by these providers and are never stored on our servers.
  • Email delivery provider — used to send transactional emails (e.g. MOT reminders, account notifications) and marketing campaigns.
  • Geolocation service — your IP address is used to determine your approximate location so we can show garages near you. Your IP address is not stored by us.
  • Postcode lookup service — used for location-based searches. No personal data is shared.
  • Google — used to source business data and reviews displayed on garage listings.
  • DVSA — the Driver and Vehicle Standards Agency's public API is used to look up vehicle MOT history for our MOT reminder service.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide services to you. Specifically:

  • Account data: retained until you delete your account or request erasure.
  • Vehicle data: retained while your MOT reminder is active. You can delete vehicles from your dashboard at any time.
  • Payment records: retained for 7 years to comply with UK tax and accounting regulations.
  • Usage and analytics data: retained in anonymised form indefinitely.
  • Contact form messages: retained for up to 2 years.

8. International Data Transfers

Some of our third-party service providers are based outside the United Kingdom. Where your data is transferred outside the UK, we ensure that appropriate safeguards are in place:

  • European Union: Our cloud database is hosted in the EU, which the UK Government has recognised as providing adequate data protection.
  • United States: Some service providers (including our payment processors) may process data in the US. These transfers are protected by appropriate safeguards such as Standard Contractual Clauses (SCCs) or the provider's participation in recognised data protection frameworks.

9. Data Security

We take the security of your personal data seriously. We use industry-standard measures to protect your information, including encrypted connections (HTTPS) across the entire website, securely hashed passwords (your password is never stored in plain text), access controls restricting who can view personal data, and regular review of our security practices. While no method of transmission over the internet is completely secure, we take reasonable steps to protect your personal data from unauthorised access, alteration, or destruction.

10. Automated Decision-Making

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.

11. Your Rights (UK GDPR)

Under the UK General Data Protection Regulation (UK GDPR), you have the following rights:

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — ask us to correct inaccurate or incomplete data.
  • Right to erasure — ask us to delete your personal data ("right to be forgotten").
  • Right to data portability — request your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent — where we rely on consent, you can withdraw it at any time.

To exercise any of these rights, please contact us via our contact page. We will respond to your request within one month.

Right to complain: If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection. You can contact the ICO at ico.org.uk/make-a-complaint or by telephone on 0303 123 1113.

12. Marketing & Unsubscribe

We will only send you marketing emails if you have given us explicit consent or if you are an existing customer and the emails relate to similar services. Every marketing email we send includes an unsubscribe link at the bottom.

You can also unsubscribe at any time by contacting us. Please note that unsubscribing from marketing emails will not affect transactional emails (such as MOT reminders or account notifications).

13. Children

Our website is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

14. Changes to This Policy

We may update this privacy policy from time to time. Any changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this page periodically for the latest information on our privacy practices.

15. Contact for Data Requests

For any data protection enquiries, subject access requests, or to exercise your rights under UK GDPR, please use our contact form and select "General Enquiry" as the subject. We aim to respond to all data requests within one calendar month.

Related Policies

Return to homepage