In short
- We are interested in vehicles, not the people who own them.
- We do not receive or hold keeper names or addresses.
- We never see your card details — Stripe handles payment.
- Your report is tied to your code. It isn't published, indexed, or sold.
- We don't use advertising or tracking cookies.
1Who is responsible
ECU DATA is a small, privately run operation based in the United Kingdom, and is the data controller for this service. For anything about your data, contact web@ecu-data.net.
2What we collect
| What | Why | Basis |
|---|---|---|
| The registration you enter | To identify the vehicle and produce the report you asked for. | Performance of our contract with you |
| The vehicle data returned — specification, ECU, tax, MOT and so on | It is the product. We cache it so re-opening a report is instant and doesn't re-query the sources. | Contract; legitimate interests (running the service efficiently) |
| Your access code (stored hashed and encrypted) and which vehicles it has unlocked | So you can get back into what you paid for, and so a credit isn't spent twice on the same vehicle. | Contract |
| Email address, if you give one | To send your receipt and your code. | Contract |
| Payment | Handled entirely by Stripe. We receive confirmation that a payment succeeded and a reference — never your card number. | Contract; legal obligation (tax records) |
| Server logs — IP address, time, page, user agent | Security, abuse prevention, rate limiting and diagnosing faults. | Legitimate interests (keeping the service up and unabused) |
What we don't hold
A vehicle record is not a person. We do not receive the keeper's name, their address, or their contact details from any of our sources, so we cannot hold, disclose or lose them. Where a report shows previous-keeper information it is a count and dates only, never an identity.
3Where the vehicle data comes from
Reports are assembled from public records and third-party data sources, including official government vehicle and MOT records. We pass on what those sources hold. If something about a vehicle is wrong at source, correcting it with us does not correct it at source — and vice versa.
If you believe a report contains information that identifies you personally and should not, contact us and we will look at it.
4Who we share it with
- Stripe — payment processing. They are a controller in their own right for payment data; see their privacy policy.
- Our hosting and infrastructure providers — they process data on our instructions to run the service.
- Data sources — we send them a registration in order to ask about a vehicle.
- Anyone we are legally required to tell, if we are obliged to.
We do not sell your data, and we do not share it for advertising.
5How long we keep it
- Vehicle reports and cached vehicle data — kept while the service operates, so your access remains permanent as promised.
- Codes and purchase records — kept while the code is valid, and for as long as tax and accounting law requires (normally six years).
- Server logs — kept short-term for security and diagnostics, then deleted.
6Cookies
We use only what the site needs to work — for example remembering that you have entered a valid code so you aren't asked for it on every page. No advertising cookies, no third-party analytics or tracking pixels.
7Where your data is held
Our infrastructure and payment provider may process data outside the UK. Where that happens, we rely on the safeguards permitted under UK data protection law, such as adequacy decisions or standard contractual clauses.
8Your rights
Under UK GDPR you have the right to:
- ask what we hold about you, and get a copy;
- have inaccurate personal data corrected;
- ask us to delete personal data, where we have no continuing reason to keep it;
- object to, or ask us to restrict, processing based on legitimate interests;
- receive data you gave us in a portable form;
- withdraw consent, where we relied on consent.
Email web@ecu-data.net and we'll respond within a month. You can also raise a concern with the Information Commissioner's Office.
9Security
Access codes are stored hashed, so the stored value cannot be used to open a report, and separately encrypted at rest so support can retrieve a lost code. Traffic is served over HTTPS. Card details never reach our servers. No system is perfectly secure, but we do not keep data we don't need — which is the most reliable protection there is.
10Changes
If we change this policy we will update the date at the top. Material changes affecting how we use your data will be made clear on the site.