Privacy Policy

Last updated: April 2026

1. Who We Are

Data Controller: AllCarsUK
Address: Leicester, Leicestershire, LE4 2AT, United Kingdom
Email: allcarsmarketuk@gmail.com
Website: allcarsuk.co.uk

AllCarsUK ("we", "our", "us") is a UK-based car marketplace. This policy explains how we collect, use, and protect your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Information We Collect

Account information: Name, email address, and optionally phone number, location, and profile photo.

Social login: If you log in via Google or Facebook, we receive your name, email, and profile photo from that provider. We do not store your social login tokens.

Listing data: Vehicle details, photos, pricing, and location you provide when creating a car listing.

Messages: Messages exchanged between users through our messaging system.

Usage data: Pages visited, cars viewed, search queries, and device information for platform improvement.

Authentication events: Login history retained for 90 days for security audit purposes.

Referral data: If you join via a referral link, we record which user referred you and track referral credits earned. This links your account to the referrer's account.

Push notification subscriptions: If you opt in to browser push notifications, we store a device subscription token linked to your account to deliver notifications you have requested.

Share activity: When you share a listing via WhatsApp, Facebook, Twitter, or a copy link, we record the channel and a daily-rotated hash of your IP address. The hash is not reversible to your IP and is used solely for anonymous analytics on which channels drive traffic.

Dealer verification documents: If you apply for a verified dealer account, we collect business registration documents (which may include director names and business addresses). These are reviewed by our team and deleted once verification is complete or rejected.

3. How We Use Your Information

We process your personal data for the following purposes:

  • To provide and maintain the AllCarsUK platform (contractual necessity)
  • To create and manage your account
  • To display your listings to potential buyers
  • To facilitate communication between buyers and sellers
  • To send search alerts and price drop notifications you have opted into
  • To verify phone numbers for seller trust badges
  • To process payments via Stripe (we do not store payment card data)
  • To operate the referral programme and award listing credits (legitimate interest)
  • To deliver push notifications you have explicitly opted into (consent)
  • To measure anonymous share analytics for platform improvement (legitimate interest)
  • To verify dealer identity and business credentials (legitimate interest / contractual necessity)
  • To detect and prevent fraud, abuse, and security issues (legitimate interest)
  • To comply with legal obligations (legal basis)

4. Information Sharing

We do not sell your personal information. Limited sharing occurs in these cases:

  • Public profile: Your name, avatar, and car listings are visible to other users.
  • Messaging: Messages are visible to the other participant in a conversation.
  • Stripe: Payment processing. Stripe's privacy policy applies to payment data.
  • Vonage: Phone number for SMS OTP verification only.
  • Browser push services: Push notification tokens are delivered via the browser vendor's push infrastructure (Google FCM for Chrome, Mozilla for Firefox). No message content is stored by these services.
  • Legal requirements: If required by law or to protect the safety of users.

5. Data Security

We use HTTPS encryption, bcrypt password hashing, CSRF protection, and account lockout after failed login attempts. Access to personal data is restricted to authorised administrators only.

6. Cookies

We use essential cookies only. See our Cookie Policy for full details.

7. Your Rights Under UK GDPR

You have the following rights:

Right How to Exercise
Right of access (Art. 15) Download your data
Right to erasure (Art. 17) Profile Settings → Delete Account, or request via email
Right to portability (Art. 20) Download your data as JSON
Right to rectification (Art. 16) Profile Settings → Edit your profile
Right to restrict processing (Art. 18) Contact allcarsmarketuk@gmail.com
Right to object (Art. 21) Profile Settings → Notification preferences

8. Data Retention

We retain your data for as long as your account is active. On deletion:

  • Account details, listings, messages, and favourites are removed
  • Reviews are anonymised ("Deleted User") to maintain marketplace integrity
  • Auth event logs are purged after 90 days
  • Payment records are retained by Stripe per their legal obligations

9. International Transfers

AllCarsUK is based in the UK. Some third-party services (Stripe, Vonage) may process data outside the UK under appropriate safeguards (Standard Contractual Clauses or adequacy decisions).

10. Children's Privacy

AllCarsUK is not intended for users under the age of 18. We do not knowingly collect data from children.

11. Changes to This Policy

We may update this policy. We will notify registered users of significant changes via email. Continued use after changes constitutes acceptance.

12. Complaints

If you are unhappy with how we handle your data, you can contact us at allcarsmarketuk@gmail.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

Add car
Add car
Add car
Add 2 more to compare