How we handle personal data.
This notice explains how KeyProof handles personal data across three things: people who visit this website or send us an enquiry, car-hire firms who hold a KeyProof operator account, and hirers whose details a firm collects through the KeyProof product. Our role, and your rights, differ between them, so we set each one out below.
Who we are
KeyProof is a verification tool for independent car-hire firms, operated by KeyProof Ltd (registered in England & Wales, company no. 17333773, registered office 66 Paul Street, London, EC2A 4NA). We are registered with the ICO, reference ZC195906. For any privacy question, or to exercise your rights below, contact us at privacy@keyproof.co.uk.
Our two roles: controller and processor
For some data we are the controller: we decide why and how it is used. This covers our own operator accounts, website enquiries and the contact form, the free handover-checklist signup and its consent record, and basic site security and analytics. This notice is our controller notice for all of that.
For the hirer personal data that a car-hire firm collects through the KeyProof product, we are the processor. Each firm is the controller of its own hirers and decides why the data is collected; we process it only on that firm’s instructions, under an agreement that meets Article 28 of the UK GDPR. If a firm sent you a check-in link, see the hirer section below, and contact that firm to exercise your rights over your booking record.
Website visitors and enquiries
If you fill in a form on this site, we collect what you put into it: typically your name, your phone number, and, depending on the form, your hire firm’s name, a rough fleet size, an email address, an Instagram or WhatsApp handle, and your message. We use these details to reply to you and answer your enquiry. Our lawful basis is legitimate interest (UK GDPR Article 6(1)(f)): you have asked us to get in touch, so a reply is expected. We will not use your details for marketing without asking you separately first.
Your enquiry is saved in our own database as well as emailed to us. That is so an outage at our email provider cannot lose your message before anyone has read it. We keep it for up to 12 months from the day you send it, and scheduled code deletes it after that rather than us having to remember. If you would like it removed sooner, email privacy@keyproof.co.uk and we will delete it.
We also keep basic security and performance information about visits to the site. There are no advertising cookies here, and our analytics is privacy-friendly and cookieless: we use Vercel Web Analytics, which measures page traffic without cookies and without building a profile of you. We keep our own aggregate count of page views, by day and by page, with no cookies and nothing that identifies you. Our lawful basis for keeping the site secure and working is legitimate interest.
When you submit a form, we also record where you came from: the page you first landed on, the website that linked you to us (the site name only, never the full address you came from), and any campaign tag in the link you clicked. This tells us which of our pages and channels actually bring enquiries. It is stored alongside your enquiry and kept for as long as we keep that enquiry. It uses no cookies and no third party: your browser holds it only for the length of that visit and forgets it when you close the tab, so it cannot follow you between visits or across other websites. Our lawful basis is legitimate interest. If you would rather we did not keep it, say so when you get in touch and we will remove it from your record.
Hire firms we approach
We also keep a sales record of hire firms we have approached, whether or not they ever contacted us: the firm’s name, a business phone number, the name of the person we spoke to, and a short note of each call. We are the controller for this and our lawful basis is legitimate interest (Article 6(1)(f)): we are a new company introducing a business tool to other businesses. Scheduled code deletes a firm’s record 24 months after the last contact, and deletes the individual call notes on the same clock.
One thing is deliberately kept for longer. If you tell us you are not interested or ask us not to contact you again, we keep that record without a time limit, because it is the only thing stopping somebody calling you again in two years having never heard of you. It holds the refusal and the contact details it applies to, and nothing else is done with it. If you would rather we deleted everything including the refusal, email privacy@keyproof.co.uk and we will, though we then have no way to recognise you if your firm comes up on a list again.
The free handover-checklist signup
If you request the handover checklist, we collect your email address, plus a record of the consent you gave: the wording you agreed to, the date and time, and the IP address and browser details of the device you used, kept as evidence of that consent. We use your email to send you the checklist and, because you ticked the box agreeing to it, to send occasional practical guides for hire operators. Our lawful basis is your consent, and, for the direct marketing emails, we rely on your consent under the Privacy and Electronic Communications Regulations (PECR).
You can withdraw consent at any time, by replying “unsubscribe” to any email or by emailing privacy@keyproof.co.uk, and we will stop straight away. When you unsubscribe we delete your details outright: we do not keep a suppression record of your address. Either way, scheduled code deletes your details 12 months after you signed up, whether or not we have emailed you since.
Operator accounts
If your firm holds a KeyProof operator account, we process the account details needed to run it: the account holder’s name and email, login credentials handled by our authentication provider, and the records your firm creates in the product (bookings, fleet, calendar, payments and fines information, and check-in records). For the account itself we are the controller and our lawful basis is performance of our contract with your firm (Article 6(1)(b)). For the hirer data inside those records we act as your firm’s processor, as described below. The commercial and data-protection terms of the service sit in the separate operator agreement your firm signs with us.
Hirer check-in records (we process these for the hire firm)
If a hire firm sends you a KeyProof check-in link, you complete a short check before and at the end of the hire. The firm is the controller of this data; KeyProof processes it on the firm’s behalf and on its instructions. Depending on the check, this can include your name, date of birth and address (you must be 18 or over), phone number, an optional email, your driving-licence details (a DVLA share code for a Great Britain licence, or the licence details you type in if it was issued elsewhere, since no equivalent check exists outside Great Britain), an e-signed copy of the firm’s own hire agreement, and the condition photos of the vehicle.
Photo ID and the live selfie run through Stripe Identity. KeyProof does not receive or store your raw ID images: we store the Stripe Identity session reference, the pass or fail result, and three yes-or-no flags recording whether the name, date of birth and address you typed agreed with the document (never the document’s details themselves). Your DVLA share code is stored so the hire firm can check it manually against the DVLA’s own service. When you e-sign, we keep a snapshot of the signed agreement and a cryptographic hash of it so the record can be shown to be unaltered.
That is what we store. It is not all we use. Where an identity check has passed, we read the name, date of birth and address that Stripe took off your document back from Stripe at the moment a page is produced, and show those in place of the details you typed at check-in. That happens in three places: the hire record the firm prints, the liability pack described below, and the read-only copy a firm can share with its insurer, on which the date of birth and address are withheld and the name is not. The firm’s own handover screen reads them the same way. None of it is written to our database. When your check passes, or when the firm first opens your booking afterwards, the same details are read once more to compare them with what you typed, and only whether each one agreed is kept. If Stripe can no longer answer, or no check completed, the page says so in those words and falls back to the details you typed.
A facial image is biometric, special-category data. Where identity verification is used, it is handled through Stripe Identity under your explicit consent, given at the point of verification, which is the firm’s condition under Article 9(2)(a) for processing it. Where the firm confirms the same person is collecting the vehicle, KeyProof fetches the selfie from Stripe for that one view and does not store it: it is a same-person check only.
The identity check itself is automated: Stripe Identity’s software checks that the document is genuine and compares your photo ID with your live selfie, and KeyProof stores the pass or fail result. A failed check is not a decision about your hire: you can retry, and after two failed attempts the link gives you the hire firm’s phone number so a person takes over. The decision to hand over the vehicle always sits with a human at the hire firm, never with the software, and the firm can complete a hire without the automated check, which is recorded when it happens. If you want to contest a result or ask for a human review, contact the hire firm as the controller; you also have the right to complain to the ICO (ico.org.uk).
Hirer deposit holds and hire payments run on the hire firm’s own Stripe account. KeyProof Ltd never holds your deposit money.
Two things a firm can do with your record reach outside the firm, and neither is obvious from the check-in, so we set both out here.
The first is a traffic fine or penalty charge that arrives for the vehicle after your hire. The firm can use the record to transfer liability to you, which means telling the issuing authority (a council, a police force, or another enforcement body) that the car was on hire to you at the time, and giving them your name, your date of birth, your address, the contact details you supplied, and what the record holds about the licence and the hire. Where additional drivers were recorded on the booking, their names go with it, and their licence numbers where those are still held. Where an identity check ran, the name, date of birth and address are the ones read off your document rather than the ones you typed, because the authority matches them against the licence. KeyProof assembles that pack out of the record and the firm sends it: we never submit anything to an authority ourselves, and we never decide who is liable.
The second is the charge that can follow. A firm can send you a link to pay a recharged fine by card: a page on this site with a one-off code in the address, showing what the charge is for. It carries none of your identity details, and the payment runs on the firm’s own Stripe account in the same way a deposit or a hire charge does, so KeyProof Ltd never holds that money either.
Retention here runs on scheduled code, not promises: your DVLA share code is erased from our systems 30 days after signing (the code itself expires at the DVLA sooner). If you checked in with a licence issued outside Great Britain, where there is no share code, the same 30-day sweep erases the licence number, its dates, its categories and any international permit number on the same clock. What is kept after that is the record of the check rather than the licence: that a non-GB licence was used, the country it came from, whether you told us you live here or were visiting and the date you gave for that, and whether the firm was entitled to hire to you on it. The firm has to be able to show what it checked and on what basis, which is the same reason the booking record itself is kept for as long as it is. The booking record, including photos and your signature, is deleted in full 24 months after the hire ends, whatever state the firm left it in, because until then it is evidence the firm may need for an insurance claim or dispute. There is one exception, and it is the reason the record exists at all: if the hire firm has flagged a dispute, or an insurance claim or a traffic fine on your hire is still open, the record is held beyond 24 months until that matter is settled, and deleted once it is. We cannot destroy evidence while it is still being argued over. The additional-driver details on a booking follow the same clocks as the lead hirer's: a driving licence number is erased at 30 days, the rest at 24 months. When we erase a booking that ran an identity check, we also ask Stripe to erase the documents and the selfie held on their side, so our deletion does not stop at our own database.
Backups are the part a notice usually leaves out, so here it is. When your record is deleted it goes from the live system as promised above, photographs included. An encrypted copy of each of your photographs is also held off-site. The store holding it never has the key. The key is deleted with your record, and the only place a copy of that key survives is inside our encrypted database backups, which are kept for 35 days and then removed; from then on nobody can read the copy, including us, and the store removes the unreadable bytes no later than 830 days after the copy was written.
There is one case where your record is deleted sooner than 24 months. Where the hire firm created its own KeyProof account online and then let its free trial end without ever paying, we lock that account and delete the hirer records on it 30 days later, rather than keeping them for the usual two years. A firm that walked away is not going to need the evidence, and we would rather not sit on your documents on an account nobody is watching. The exception above still applies and it is the same exception: if a dispute has been flagged, or an insurance claim or a traffic fine on your hire is still open, that record is kept until the matter is settled and deleted once it is. We do not destroy evidence while it is still being argued over, whatever the firm did about its subscription.
If your hire led to an insurance claim, the firm can keep its own record of that claim (which insurer, the excess, what was claimed and what was paid back) after the booking record itself has been deleted, because a claim can run for years after the hire. That record is the firm’s financial paperwork and holds nothing that identifies you: the firm’s own working note on the claim is erased at the moment the booking record is, and scheduled code re-checks that no claim is left holding one.
A hire firm can also keep two private lists of its own inside KeyProof, and we process both as that firm’s processor, on its instructions. The first is a do-not-rent list: a name, a phone number, and the firm’s own note of why it will not hire to that person. It is private to that one firm, is never shared with other firms or pooled into any industry database, and when a phone number matches, KeyProof only shows the firm a warning: it never blocks a booking or decides anything about you. The second is a private note or flag a firm can keep against a hirer’s phone number. The firm decides what goes in both and can delete an entry at any time, so a request to correct or remove one goes to that firm. A do-not-rent entry has no fixed end date, because the firm’s reason for keeping it does not expire, but scheduled code erases the written reason after 24 months, on the same clock that destroys the booking record it came from. A private note is deleted once the hirer has no check-in record left with that firm.
To exercise your rights over a booking record, an entry on a firm’s do-not-rent list, or a note it keeps about you, contact the hire firm you dealt with, or email privacy@keyproof.co.uk and we will pass the request to them and assist.
Who we share data with
We use a small number of trusted providers who act as our processors, or as sub-processors for the hirer data we handle on a firm’s behalf. They handle data only to provide their service to us and do not use it for their own purposes. The maintained register is our sub-processors page, which sets out for each one what it can see, where it processes and the transfer basis, and it is the list a firm’s operator agreement points at. The summary here names the same companies:
- Vercel: website and product hosting, plus file storage (Blob) for condition photos and vehicle documents in a private store, and operator logos in a separate public store. A second, encrypted copy of each condition photo is kept at Cloudflare R2.
- Neon: our Postgres database, including operator, vehicle and booking records.
- Cloudflare R2: where our encrypted database backups are sent, which means a copy of everything Neon holds, including hirer check-in records. It also holds an encrypted copy of every condition photograph, each one under its own separate key that we keep and destroy when we erase the record the photograph belongs to. Every backup is encrypted by us before it is uploaded and we keep the key, so the store only ever receives ciphertext it cannot read. Stored in Western Europe. The export runs weekly, so a copy of your record is there, and what the store receives is ciphertext.
- Clerk: operator and founder account authentication. Not hirer check-in data.
- Stripe: identity checks (Stripe Identity), the hirer verification fee, operator subscription billing, and deposit holds and card hire payments on the operator’s own connected account (Connect). Stripe is switched on: an identity check runs as part of the check-in link. Deposit holds and hire payments run on the firm’s own connected Stripe account, so they start for a firm once it has connected one.
- Resend and Zoho: sending and handling email.
- Notion: our own internal operating and product documentation, and a copy of the enquiry details you send us through the founding form (your name, phone or email, firm and message) so we can follow it up. Hirer check-in data is never stored there.
- Upstash: rate limiting to protect the service, which processes short-lived IP addresses and request identifiers.
- DVLA Vehicle Enquiry Service: vehicle MOT and tax checks from a registration number. We do not currently use this service (no key is set, so nothing reaches it today); when enabled it would receive only a vehicle registration. We do not send a hirer’s licence share code to the DVLA; the operator checks that themselves.
- DVSA MOT History: the MOT tests a vehicle has on record, from the registration an operator enters. Vehicle data only, no hirer personal data.
- getAddress.io: address suggestions from a postcode, so you can pick your address at check-in instead of typing it. It receives only the postcode you enter, and only if you use the address finder. UK.
- Sentry: error monitoring, and it is switched on. When a request fails it receives technical details about the failure, such as the page and the IP address. It is configured not to send personal data by default, and hirer link tokens are scrubbed from a report before it leaves. A US company; the transfer terms we have read are set out on the sub-processors page.
- Discord: carries our own operational alerts, so we hear as it happens that something needs looking at. Those messages are event names, counts and firm-level system state: never a hirer detail, and never an enquirer’s name, phone number or email address. A US company, and no personal data reaches it.
- Companies House: checks that a company number given by a firm signing itself up is real and active, and compares the name of the person signing up against the officers on the public register. It receives that company number and that name, and no hirer data. UK government service, and self-serve signup is not open yet, so nothing reaches it today.
- Browser push services (Apple, Google, Mozilla and Microsoft): deliver the phone alerts an operator can switch on in their own dashboard. The content is encrypted to that operator’s device, so the service routes an opaque message to an address the operator’s browser chose and cannot read it. Operator alerts only, never a hirer file in readable form.
- Vercel Web Analytics: cookieless site analytics.
Two kinds of recipient sit outside that processor list, and in both cases the hire firm decides and the hire firm sends. If your hire leads to an insurance claim, the firm can share a read-only copy of your hire record with its insurer or claims handler, through a secure link that expires after seven days. If it leads to a traffic fine or a penalty charge, the firm can name you to the issuing authority, as set out in the hirer section above.
We do not sell your personal data or share it with anyone else for their own marketing.
Where data is processed and international transfers
Some of these providers are based in, or process data in, the United States. Where personal data is transferred outside the UK, we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, with the ICO International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, as the fallback safeguard. Our database region is kept in the UK or EU.
Cookies
This site does not use advertising or tracking cookies, and analytics is cookieless, so there is no consent banner. The only cookies we set are strictly-necessary session cookies used by our authentication provider (Clerk) on the signed-in areas of the product, at /fleet, /pipeline and /record, to keep you logged in securely. These are exempt from the consent requirement because they are essential to a service you have asked for.
Your rights
For the data we control, you can ask us to show you what we hold, correct it, delete it, restrict or object to how we use it, and request a copy in a portable format where that applies. Because we rely on legitimate interest for enquiries and site security, you have the right to object, and we will stop unless we have a compelling reason not to. Where we rely on consent, you can withdraw it at any time. Just ask, and we will sort it. For hirer booking records, where we are the processor, please contact the hire firm you dealt with, and we will support them in responding.
Complaints to the ICO
If you are unhappy with how we handle your data, you can complain to the UK’s data-protection regulator, the Information Commissioner’s Office. You can reach the ICO at ico.org.uk/concerns, by phone on 0303 123 1113, or by post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the chance to put things right first, so please do contact us as well.
Changes
This is our current privacy notice. If we change how we handle your data, we will update this page and always show the latest version here.