Hirer data and how long it is kept

What is stored when a hirer checks in, who holds it, the schedule on which it is deleted, and what holds it back.

When a hirer checks in they share some personal information. This is what is stored, who holds it, and how long it is kept. The full detail is in the privacy notice.

Who holds what

  • Your firm is the controller of the booking data. You decide why it is collected and you hold the record of the hire. You are the hirer's first point of contact for anything about their data.
  • KeyProof Ltd is the processor. It runs the check-in and stores the record on your behalf and on your instructions, and does not use the booking data for its own purposes. Company number 17333773, ICO reference ZC195906.

ID and selfie go through Stripe Identity

The hirer's photo ID and live selfie are handled by Stripe Identity. KeyProof does not receive or store the ID images or the selfie: it keeps only the reference for the check and the pass or fail result. A facial image is sensitive biometric data, so that check runs on the hirer's explicit consent, given at the moment they verify.

How long it is kept

Retention runs on scheduled code, not on a promise to remember:

  • The DVLA check code is erased from KeyProof's systems 30 days after signing. The DVLA expires it sooner than that anyway.
  • A non-GB licence's declared identifiers (the licence number and its dates) are erased on the same 30-day clock, so a foreign licence is never held longer than a GB one. What stays is the fact of what was checked: the origin, the country, and the declared entitlement answer.
  • The whole booking record, including the condition photos and the signature, is deleted 24 months after the hire ended. It is kept that long because it is evidence you may need, for example if a dispute or a fine arrives long after the car came back.
  • Your own private notes on a hirer are removed once no checked-in booking for that person remains.

The evidence hold

Deleting a record in the middle of an argument would erase the evidence at the worst possible moment. So a booking is held back from deletion while any of these is true:

  • You have flagged a dispute on it.
  • An insurance claim on it is open or submitted.
  • A fine on it is received or transferred, meaning liability is not yet resolved.

The hold has no fixed length. It is read live from those three things, so it lifts by itself the moment you clear the dispute or the claim or fine reaches its end: settled or rejected, recharged, paid by the firm, or cancelled. Nobody has to remember to lift it, and nothing is kept a day longer than the argument it belongs to.

The same rule applies if you ask for a record to be deleted early. A held hire is refused with a plain message telling you what is holding it, so clear or settle that first.

Hirer rights

Hirers have the usual rights over their personal data: to see what is held, to have mistakes corrected, and to ask for deletion, among others. Because your firm is the controller, the hirer starts with you; KeyProof, as processor, supports you in responding. The privacy notice explains the detail.

Still stuck? We answer from a real inbox, not a bot.