Privacy Policy
Effective Date: 06.03.2025
1. Introduction
This Privacy Policy explains how EpicVIN.uk (“we”, “our”, “us”) collects, uses, discloses, and protects your personal data when you access or use our website (the “Site”) and our related services (the “Services”). This Policy is an integral part of our Terms and Conditions and is designed to ensure compliance with applicable data protection laws, including the UK Data Protection Act 2018 and the General Data Protection Regulation (GDPR).
By accessing or using our Site and Services, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy. If you do not agree with our practices, please do not use our Services.
2. Who We Are
EpicVIN.uk is a vehicle history reporting service operated by EpicVIN.uk. We act as the data controller for the personal data that you provide to us.
Contact Information:
For any questions, concerns, or complaints regarding our data processing practices or this Privacy Policy, please contact us using the details above.
3. Information We Collect
We collect personal data in a manner consistent with industry practices. The types of personal data we may collect include:
3.1 Personal Identification Information
- Name
- Email address
- Telephone number
- Other contact details provided during registration or communication with us
3.2 Vehicle-Related Information
- Vehicle Identification Number (VIN)
- Registration number
- Data provided by you when requesting a vehicle history report or using our free vehicle check (pre-check)
3.3 Technical Data
- IP address
- Browser type and version
- Device information (e.g. device model, operating system)
- Network information (e.g. Internet service provider)
- Cookies and similar tracking technologies data
3.4 Usage Data
- Pages visited on our Site
- Time spent on the Site
- Referring URLs
- Interaction with website features and content
3.5 Location Data
- Geographical location information, if you enable location services on your device
3.6 Payment Information
- Transaction details
- Payment method details as provided by third-party payment processors (note: we do not store sensitive payment card details)
This information is collected either directly from you or automatically through your interactions with our Site and Services.
4. How We Collect Your Data
We collect your personal data by several methods, including:
4.1. Direct Interactions
- Account Registration: When you create an account by providing your name, email, and other relevant details.
- Service Use: When you request a vehicle history report, enter a VIN or registration number for a free pre-check, or purchase our Services.
- Communication: When you contact us via email, complete forms, or provide feedback.
4.2. Automated Technologies
- Cookies and Tracking Technologies: We use cookies, web beacons, and similar technologies to collect technical data, usage data, and preferences.
- Log Files: These record information automatically about your device and interactions with the Site.
4.3. Third-Party Sources
- Service Providers: Data provided by third-party payment processors, analytics providers, and CRM systems that help us deliver and improve our Services.
5. Purposes and Legal Basis for Processing
We process your personal data for several purposes, which include:
5.1. Provision and Improvement of Services
- Operating the Site: To enable you to use our Services, manage your account, and provide vehicle history reports.
- Customer Support: To address your queries, provide support, and resolve issues.
- Service Enhancement: To analyse user behaviour, improve our offerings, and ensure the quality and security of our Services.
5.2. Account Management and Transaction Processing
- Registration and Billing: To create and manage your account, process your transactions, and communicate with you about your account status.
- Marketing and Communication: To send you updates, newsletters, and promotional communications (only where you have provided your consent).
5.3. Compliance and Security
- Legal Obligations: To comply with applicable laws, regulations, and legal processes.
- Security: To monitor and secure our Site against fraudulent or malicious activities.
5.4. Legal Basis for Processing
Our processing of your personal data is based on:
- Consent: Where you have provided consent (e.g. marketing communications).
- Contractual Necessity: To perform the contract for providing our Services.
- Legitimate Interests: For the purposes of improving our Services, ensuring security, and managing our business operations.
- Legal Obligation: To comply with statutory or regulatory requirements.
6. How We Share Your Data
We may share your personal data with third parties in the following circumstances:
6.1. Service Providers and Partners
We share data with third-party service providers who perform functions on our behalf, including:
- Payment Processors: To process transactions securely.
- Analytics Providers: To analyse usage patterns and improve our Services.
- CRM Systems: To manage customer relationships.
- Hosting and IT Service Providers: To ensure the proper functioning and security of our Site.
6.2. Business Partners
In some cases, data may be shared with trusted business partners for the purpose of delivering our Services. These partners are contractually obligated to protect your data and only use it for specified purposes.
6.3. Legal and Regulatory Requirements
We may disclose your personal data if required by law, regulation, or legal process, including:
- Law Enforcement Authorities: To comply with legal obligations or protect our rights.
- Regulatory Bodies: In response to lawful requests for information.
6.4. Aggregated and Anonymised Data
We may also share aggregated or anonymised data that does not identify you personally for research, statistical, or business purposes.
7. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) or the United Kingdom, including the United States. In such cases, we ensure that:
- Appropriate Safeguards: We use standard contractual clauses or other legal mechanisms to ensure that your data is protected in accordance with UK and EU data protection standards.
- Advanced Security Measures: We utilise state-of-the-art security technologies and best practices to protect your data during international transfers and while in storage.
- Compliance with Laws: All transfers are conducted in compliance with applicable data protection laws and regulations.
8. Cookies and Similar Technologies
We use cookies and similar tracking technologies to improve your experience on our Site. This section explains how we use these technologies and your choices regarding them.
8.1. What Are Cookies?
Cookies are small text files stored on your device that enable us to remember your preferences, analyse usage, and personalise content.
8.2. How We Use Cookies
We use cookies for the following purposes:
- Essential Cookies: To enable core Site functionality, such as user logins and shopping carts.
- Performance Cookies: To collect information about how you use our Site, which helps us improve our Services.
- Functional Cookies: To remember your preferences and provide a more personalised experience.
- Marketing Cookies: To deliver advertisements that are relevant to you (subject to your consent).
8.3. Managing Cookies
You can control and manage cookies via your browser settings. Please note that disabling cookies may affect the functionality and performance of our Site.
For further details, please review our dedicated Cookie Policy.
9. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with legal obligations. The retention period may vary depending on:
- The type of data and its sensitivity.
- The purposes for which it was collected.
- Applicable legal and regulatory requirements.
Once your data is no longer needed, we will securely delete or anonymise it.
10. Your Data Protection Rights
Under the GDPR and the UK Data Protection Act 2018, you have the following rights regarding your personal data:
10.1. Right to Access
You have the right to request access to your personal data and obtain a copy of it.
10.2. Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to have it corrected or updated.
10.3. Right to Erasure
You may request the deletion of your personal data under certain circumstances (the “right to be forgotten”), subject to legal or contractual restrictions.
10.4. Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain situations.
10.5. Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transfer it to another controller.
10.6. Right to Object
You may object to the processing of your personal data on grounds relating to your particular situation, including for direct marketing purposes.
10.7. Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing prior to withdrawal.
To exercise any of these rights, please contact us at info@epicvin.uk. We will respond to your request within the timeframes required by applicable law.
11. Security of Your Data
We take the security of your personal data seriously. To protect your data, we have implemented a variety of technical and organisational measures, including:
- Encryption: To secure data during transmission and storage.
- Access Controls: To restrict access to personal data only to authorised personnel.
- Regular Security Assessments: To identify and mitigate potential vulnerabilities.
- Incident Response Procedures: To respond promptly in the event of a data breach.
Despite our efforts, no method of electronic storage or transmission is completely secure. You are encouraged to take reasonable steps to protect your own information.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When we make changes:
- We will update the “Effective Date” at the top of this Policy.
- We may notify you by email or by prominently posting a notice on our Site.
- Continued use of our Site and Services after the changes have been made constitutes your acceptance of the updated Privacy Policy.
We encourage you to review this Privacy Policy periodically.
13. Additional Information for Commercial Users
If you are using our Services on behalf of a legal entity or for business purposes (“Commercial User”), please note:
- EpicVIN.uk and the Commercial User act as independent data controllers.
- Each party is responsible for complying with applicable data protection laws concerning its respective processing activities.
- Additional terms may apply to Commercial Users, which will be provided separately.
14. Feedback and Enquiries
We welcome your feedback regarding our privacy practices. If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us at:
Email: info@epicvin.uk
By using our Site and Services, you acknowledge that you have read, understood, and agreed to the terms of this Privacy Policy and consent to the collection and use of your personal data as described herein.