Who helps us run KeyProof.
These are the third-party services (our sub-processors) that help us operate the site and the product. We keep this list current and, once we take on operators, we give notice before we add or change one.
What we use today
KeyProof’s product now handles hirer check-in details, condition photos and operator account data, alongside the enquiries you send us through a form. These providers help us receive and look after it:
- Vercel hosts the website and the product, and delivers form submissions to us. Vercel Blob storage holds condition photos and operator-uploaded vehicle documents in a private store, and operator logos in a separate public store. A US company, and one of those whose transfer terms we have read: see international transfers below. A second, encrypted copy of each condition photo is kept at Cloudflare R2, so the private store is not the only place that imagery exists.
- Neon is our product database: operator accounts, vehicles, bookings and the hirer check-in details attached to them, alongside enquiries and the founders’ HQ (the private admin area). Stored in a UK/EU region.
- Cloudflare R2 is where our encrypted database backups are sent, and where an encrypted copy of every condition photograph is kept. Every backup is encrypted on our side before it is uploaded, and we hold the key, so the store only ever receives ciphertext it cannot read. Each photograph copy carries its own separate key, which we hold and never send to Cloudflare. That key is deleted with the record when it is erased, but a copy of it survives inside our weekly encrypted database backups, kept in this same store for 35 days and then removed; from then on nobody can read the photograph copy, including us, and the store removes the unreadable bytes no later than 830 days after the copy was written. Stored in Western Europe. The weekly export runs, so this store holds a copy, and what it receives is ciphertext.
- Resend sends our transactional email. A US company, and one of those whose transfer terms we have read: see international transfers below.
- Zoho hosts our business email inboxes, on its EU servers. A UK to EEA transfer is covered by the UK’s adequacy regulations, so no further mechanism is needed for where the inboxes sit.
- Notion holds our own internal operating and product documentation, and a copy of the enquiry details a firm sends us through the founding form (the contact’s name, phone or email, firm and message), so we can follow it up. Hirer check-in data is never stored there. A US company, and one we have not yet read the transfer terms for: see international transfers below.
- Clerk provides secure login for operators and for us as the founders. It does not hold hirer check-in data. A US company, and one of those whose transfer terms we have read: see international transfers below.
- Stripe covers several separate parts of the service:
- Identity checks: document capture and a live-selfie match, on Stripe’s own hosted pages. We keep the session reference, the outcome and the timestamps, not the raw identity document. Where an operator is authorised to confirm that the same person is collecting the car, the verified selfie is passed through our servers to show it to them and is not stored by us.
- The hirer verification fee, through Stripe’s hosted checkout.
- Operator subscription and setup billing, and the billing portal.
- Stripe Connect onboarding, and deposit holds and card hire payments taken on the operator’s own connected Stripe account, including release, capture and refund. That money never reaches KeyProof and we take no platform fee on it.
- DVLA Vehicle Enquiry Service can confirm a vehicle’s tax status from the registration an operator enters. It receives the operator’s vehicle-registration number only, not any hirer personal data. UK government service. We do not use it: the DVLA closed VES registration to new applicants, so our registration lookups run on the DVSA service listed below instead, and nothing reaches VES today. If that ever changes, we will update this page before it starts receiving anything.
- DVSA MOT History returns the MOT tests a vehicle has on record, including the mileage the tester wrote down at each one, from the registration an operator enters. Like the DVLA service above, it receives the operator’s vehicle-registration number only, which is public vehicle data, and not any hirer personal data. UK government service.
- getAddress.io returns matching addresses when a hirer looks up their postcode during check-in, so they can pick their address instead of typing it out. Only the postcode they enter is sent, and only if they use the address finder: never a name, ID, licence or any other detail. UK.
- Upstash provides rate limiting that protects our forms and hirer links from abuse. To do that it processes short-lived IP addresses and request identifiers, which expire automatically a short time after the request. It holds no booking record and no hirer file.
- Sentry reports errors, so a fault is found by an alert rather than by somebody opening the page. When a request fails it can capture technical details about it, such as the page and the IP address. It is switched on and receiving error telemetry: it is configured not to send personal data by default, and hirer link tokens are scrubbed from a report before it leaves. A US company, and one of those whose transfer terms we have read: see international transfers below.
- Discord receives our internal operational alerts, so we as the founders hear that an event happened (a new enquiry, a failed automation job) as it happens. Those notifications are event names, counts and firm-level system state only: no hirer personal data, and no enquirer names, phone numbers or email addresses. A US company. No personal data reaches it, so there is no transfer of personal data here to cover.
- Companies House is used when a firm signs itself up, to check the company number given is real and active, and to compare the name of the person signing up against the officers on the public register. It receives that company number and that name. No hirer data reaches it, and it is a UK government service. Self-serve signup is not open yet, so nothing reaches it today.
- Browser push services (Apple, Google, Mozilla and Microsoft) deliver the phone alerts an operator can switch on inside their own dashboard. The content of each alert is end-to-end encrypted to that operator’s device: the push service only routes an opaque, encrypted message to an endpoint the operator’s own browser chose, and cannot read it. It carries operator-facing booking alerts, never a hirer file in readable form, and runs only for an operator who has turned push on.
- Vercel Web Analytics measures page traffic without cookies and without profiling anyone.
The paper behind this list
Every provider named above operates under its own published data processing agreement, and each of those agreements forms part of the account terms we accepted when the account was opened, so it binds without a separate signature. That is worth saying in plain words rather than leaving it to be assumed: these are the providers’ standard published terms, we did not negotiate them, and we do not hold a countersigned copy of any of them. What we do hold is a dated internal register recording where each agreement is published and when we last checked it, which we re-check once a year and whenever a provider changes its terms.
One exception, because a list like this is only worth reading if the exceptions are on it. getAddress.io publishes no standalone data processing agreement, so what stands behind it is its published terms of service. We have recorded that rather than papered over it. What it receives is a postcode somebody typed: never a name, a licence, or a hire record.
International transfers
Several of these providers are based outside the UK. Below are the transfer terms we have read in the provider’s own agreement, with the date we last checked. We name a mechanism only where we have read it.
- Vercel: the UK International Data Transfer Addendum, and the 2021 standard contractual clauses. Its agreement covers the paid plan we are on. Checked 17 August 2026.
- Stripe: the EEA standard contractual clauses, controller to controller and controller to processor, the UK International Data Transfer Addendum, and Data Privacy Framework self-certification. Checked 17 August 2026.
- Clerk: the standard contractual clauses, the UK Addendum approved by the Information Commissioner, and Data Privacy Framework self-certification including the UK Extension. Checked 17 August 2026.
- Sentry: Data Privacy Framework self-certification, with the standard contractual clauses and the UK Addendum standing behind it. Checked 17 August 2026.
- Resend: the EU standard contractual clauses controller to processor, the UK Addendum, the Swiss modifications, and the Data Privacy Framework with its UK Extension. Checked 13 August 2026.
- Cloudflare: the EU standard contractual clauses, the UK Addendum, and Data Privacy Framework self-certification. Checked 17 August 2026. It receives ciphertext only, so this covers a transfer of data nobody at Cloudflare can read.
Four are outstanding, and we would rather say so than let the list above imply otherwise. We have recorded where Neon, Notion, Upstash and Zoho publish their agreements, and have not yet read the transfer clauses inside them, so no mechanism is claimed for those four here. Of the four, Neon holds our database in a UK or EU region and Zoho keeps our inboxes on EU servers, so neither relies on a transfer out of the UK and the EEA for where the data sits; Upstash holds rate-limit counters rather than records. The one carrying personal data to the US is Notion, which holds the contact details a firm sends us through the founding form, and never any hirer check-in data. We keep the most sensitive data in a UK or EU region wherever we can.
Built, and switched on
We describe what each provider can process above, rather than only what has run so far, so this page does not understate anything. Stripe is switched on, including the identity check. Card hire payments and deposit holds are switched on too, but they run on an operator’s own connected Stripe account, so for any one firm they start once that firm has connected one. Sentry is switched on as well, and receives error telemetry configured to exclude personal data by default, as described in its entry above.
The DVLA licence share code and the e-signature are handled by our own application rather than a dedicated third-party checking provider, though they still run on the infrastructure listed above. We do not send a hirer’s share code to the DVLA; the operator checks it themselves on the DVLA service. If we add a new provider it goes on this list, with the paper behind it recorded as described above, before it processes anyone’s data.
Changes and notice
We review these providers and their agreements at least once a year and at renewal. Once we have operators, we notify them before adding or replacing a sub-processor, and they can object. For who we are and how to reach us, see our privacy notice, or email privacy@keyproof.co.uk.