Draft — not yet reviewed by a solicitor. This page describes what the software actually stores and does. It is not a substitute for legal advice, and the bracketed details below need filling in with the operator's real company information before this is published as the final policy. Registration with the ICO as a data controller has not yet happened and is a separate step.
Privacy Policy
Draft — last updated 21 September 2026.
Who this covers
WhizzTrack is stock management software sold to car dealerships. Each dealership (the controller) holds its own customers' personal details — names, addresses, phone numbers, emails, and the finance and vehicle details tied to a sale. WhizzTrack (the processor, operated by [operator legal name — to be added]) stores that data on the dealership's behalf and only acts on its instructions. If you bought a car from a dealership using WhizzTrack, your dealership is who to contact about your details — we process them, we do not decide what happens to them.
What is stored
- Vehicle records: registration, VIN, make and model, provenance and history.
- Customer records: name, address, phone, email, and whether they opted into marketing.
- Sale and invoice records: price, deposit, finance, and the paperwork issued for it.
- Uploaded documents and photos tied to a vehicle or sale — V5C, HPI check, service book.
- Staff accounts: name, email, role, and a hashed password. We never store it in the clear.
Why, and on what basis
Sale and invoice records are kept to run the dealership's business and because HMRC requires six years of financial records to be retained — that record cannot be deleted on request while it is still within that window, though a customer's personal details on it can be erased separately (see below). Everything else is processed to perform the contract between the dealership and its customer: booking a viewing, arranging a test drive, or handling a part exchange.
Where it is kept, and who else sees it
Data is stored on a server in the UK. It is never sold, and it is never shown to another dealership — every record belongs to exactly one dealership, enforced by the software itself rather than left to good practice at each screen. A small number of sub-processors handle infrastructure on our behalf:
- Fly.io — hosts the application and its database.
- Anthropic — reads an uploaded HPI check or similar document to fill in a vehicle's details, but only for dealerships where a dealership or operator has switched this on. It is off by default.
- DVLA / DVSA — a dealership using registration lookup sends a vehicle's plate to look up its basic details or MOT history. This is off unless configured.
- Resend — sends the app’s own emails to dealership staff: sign-up verification, password resets, and the MOT reminder digest (vehicle registrations, not customer details). Off unless configured.
- Sentry — receives a report when something in the app crashes, so it can be fixed the same day. Reports are set to carry no IP address, cookies, request headers or bodies, or database contents — only what broke and where. Off unless configured.
- Backup storage — a nightly copy of the database and uploaded documents, encrypted before it leaves our hosting so the storage company holds only ciphertext it cannot read. Kept 30 days. [Operator to name the storage company and the country it stores in.]
- Stripe — takes card payments for a dealership’s WhizzTrack subscription, on its own payment page. It receives the dealership owner’s email and card details. If a dealership connects its own Stripe account to take card deposits, a customer pays that dealership directly on Stripe’s page, and the customer’s email, the car and the amount are passed to the dealership’s account to set the payment up. Off unless configured.
The Data Processing Agreement sets out what this means in the terms UK GDPR uses for it. [Operator to add: registered company name, address, and keep the sub-processor list on both pages current if it changes.]
How long it is kept
Sale and invoice records: six years from the end of the financial year the sale falls in, for HMRC. Because a dealership's year end can be up to a year after a sale, a buyer's personal details are removed automatically seven years after the last sale, appointment or change to their record — the sale itself and its figures stay, with their name taken off it and off its invoices. An enquiry that never led to a viewing is deleted after two years. Everything else stays for as long as the dealership's account is open, unless a customer asks for their personal details to be erased — the dealership can do this for any customer from their own account, which keeps the financial record (price, date, what was sold) but replaces the name, address, phone and email with a note that it was erased at the customer's request. Uploaded documents and photos are removed along with the vehicle record they belong to, on the same terms.
Security
Passwords are hashed, never stored or logged in the clear. Every account belongs to one dealership and one role, and what a car cost or a deal made is hidden from sales and workshop staff. The site is served over HTTPS, and repeated wrong password attempts lock an account temporarily rather than allowing unlimited guesses. Anyone can turn on two-step sign-in with an authenticator app. Who opened, exported or erased each customer’s record is logged for two years. Backups held outside our hosting are encrypted before they leave it.
Your rights
If your details are held by a dealership using WhizzTrack, you can ask that dealership to see what is held about you, correct it, or erase it (subject to the six-year financial retention above). Contact the dealership directly — they hold your record and decide how to act on the request; we carry it out on their instruction.
Contact
[Operator to add: a real contact email or address for privacy queries and ICO registration reference, once registered.]