carrapp
Carr
carrratings
Get app

Privacy Policy

1. Introduction

At Carr App Ltd (“Carr,” “we,” “us,” or “our”), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share your personal information when you use our mobile application (“App”) and website (“Website”). By using our App or Website, you consent to the practices described in this Privacy Policy.

2. Information We Collect

We collect information to provide and improve our services, personalise your experience, and for other purposes as described in this Privacy Policy. The types of information we collect include:

  • Personal Information: When you create an account or use our Services, we may collect your full name, email address, phone number, and vehicle registration number. We collect your phone number for verification purposes during account creation and your vehicle registration number to provide you with relevant services.
  • Payment Information: To access our paid features, you will need to provide payment information through our third-party payment processor, Stripe. This may include your credit or debit card details, or payment methods like Apple Pay or Google Pay. Stripe allows you to securely save your payment details for future use. We do not store your full card details or see sensitive information like card numbers. We can only view basic information about the payment method used for your transactions.
  • Device and Usage Information: We automatically collect information about your device and how you use our App and Website. This includes your IP address, device ID and type, device-specific and app settings, app crashes, advertising IDs (such as Google’s AAID and Apple’s IDFA), browser type, version and language, operating system, time zones, identifiers associated with cookies or other technologies that can uniquely identify your device or browser (e.g., IMEI/UDID and MAC address), information about your wireless and mobile network connection, and information about device sensors such as accelerometer, gyroscope, and compass.
  • Location Information: We may collect your location information if you use the “Petrol Nearby” feature to find petrol stations near you. You can choose whether or not to allow us to access your location information.
  • Cookies and Similar Technologies: We use cookies and similar technologies to collect information about your browsing and usage patterns. This helps us improve our services, personalise your experience, and deliver relevant advertising. For more information, please see our Cookie Policy.

3. How We Use Your Information

We use the information we collect for various purposes, including:

  • To Provide and Improve Services: We use your information to create and manage your account, provide customer support, process transactions, communicate with you about our services, and personalise your experience.
  • To Personalise User Experience: We may use your information to provide you with tailored quotes and recommendations based on your profile and activity on the App.
  • For Marketing and Promotional Purposes: With your consent, we may use your information to send you marketing communications about our products and services. You can opt out of these communications at any time.
  • For Safety and Security: We use your information to prevent, detect, and take action against fraud or other illegal activities, to address ongoing or alleged misconduct, and to protect the safety of our users.
  • For Legal Compliance: We may use and disclose your information to comply with applicable laws, regulations, legal processes, or government requests.

4. Lawful Basis for Processing

We process your personal data based on the following lawful bases:

  • Contractual Necessity: We process your data to fulfill our contractual obligations to you, such as providing the services you request and managing your account.
  • Legal Obligation: We process your data to comply with legal obligations, such as tax laws and regulations.
  • Legitimate Interests: We process your data for our legitimate interests, such as improving our services, preventing fraud, and protecting our legal rights.
  • Consent: We may process your data for marketing purposes or other purposes with your consent. You can withdraw your consent at any time.

5. How We Share Your Information

We may share your information with the following parties:

  • Service Providers and Partners: We share your information with third-party service providers and partners who help us operate and improve our services. These third parties may provide services such as data hosting and maintenance, analytics, customer support, marketing, advertising, payment processing, and security measures.
  • For Legal Reasons: We may disclose your information if required by law, court order, or government regulation, or if we believe it is necessary to protect our rights or the rights of others.
  • Business Transfers: If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction.
  • Aggregated and De-identified Information: We may share aggregated or de-identified information that does not directly identify you with third parties for research, analytics, or other purposes.

6. Data Security

Carr takes the security of your personal data seriously. We have implemented appropriate technical and organisational measures to protect your personal data from unauthorised access, disclosure, alteration, or destruction.
These measures include:

  • Encryption of data in transit and at rest
  • Firewalls and intrusion detection systems
  • Access controls and authentication mechanisms
  • Regular security assessments and audits

However, no method of transmission over the Internet or electronic storage is 100% secure. Therefore, we cannot guarantee the absolute security of your data.

Please note that we do not sell your personal information, including your name, contact information, or any other information that directly identifies you.

7. Data Retention and Deletion

We will retain your personal data for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. This includes retaining data for a reasonable period after you have closed your account to comply with legal obligations, resolve disputes, and enforce our agreements.

You have the right to request the deletion of your personal data. You can do this by deleting your account in the App or by contacting us at data@car-r.com. Please note that we may be required to retain certain information for legal or legitimate business purposes, even after you have requested deletion.

8. Your Rights

Under the UK General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:

  • Right to Access: You have the right to request access to your personal data and to obtain information about how we process it.
  • Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal data.
  • Right to Erasure: You have the right to request that we erase your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected or if you withdraw your consent.
  • Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to have it transmitted to another controller.
  • Right to Object: You have the right to object to the processing of your personal data for direct marketing purposes or on grounds relating to your particular situation.
  • Right Not to be Subject to Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.
  • Right to Withdraw Consent: If you have given your consent to the processing of your personal data, you have the right to withdraw it at any time.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe that we have not complied with data protection laws.

9. Children's Privacy

Carr is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18. If you are under 18, please do not use the App or Services or provide any personal information to us.

10. Push Notifications and App Permissions

10.1 Push Notifications

Carr may send you push notifications through the App to provide updates, reminders, and promotional messages. You can manage your push notification preferences in the App settings.

10.2 App Permissions

When you use the App, you may be asked to grant certain permissions, such as access to your location, camera, contacts, or other features of your device. These permissions are optional, and you can choose whether or not to grant them. However, some features of the App may not function properly if you do not grant the necessary permissions. The legal basis for processing your location data for the “Petrol Nearby” feature is your consent, which you can withdraw at any time through the App settings.

11. Third-Party Services

Carr may offer features or services that are provided by third parties. These third-party services may have their own terms and conditions and privacy policies, which you should review before using them. Carr is not responsible for the practices of these third parties.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make any material changes, we will notify you through the App or by other means. Your continued use of the App or Services after the effective date of the revised Privacy Policy constitutes your acceptance of the changes.

13. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: data@car-r.com

14. Marketing Choices

You can opt out of receiving marketing communications from Carr by following the unsubscribe instructions in our emails or by adjusting your notification preferences in the App settings.

15. ICO UK

For residents of the United Kingdom, the Information Commissioner’s Office (ICO) is the UK’s independent authority set up to uphold information rights in the public interest, promoting openness by public bodies and data privacy for individuals. If you have any concerns about our data processing, you have the right to lodge a complaint with the ICO. You can find their contact details and more information on their website: https://ico.org.uk

16. Data Security

Carr takes the security of your personal data seriously. We have implemented appropriate technical and organisational measures to protect your personal data from unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using industry-standard Secure Socket Layer (“SSL”) technology (SSL encryption version 3) and at rest.
  • Firewalls and intrusion detection systems to monitor and prevent unauthorised access.
  • Strict access controls and authentication mechanisms to limit access to personal data to authorised personnel only.
  • Regular security assessments and audits to identify and address potential vulnerabilities.
  • A differentiated system of access authorisations to ensure that only authorised personnel can access specific types of data.

While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. Therefore, we cannot guarantee the absolute security of your data.

17. Data Breaches

In the event of a data breach that compromises the security of your personal data, Carr will promptly investigate the incident and take appropriate steps to mitigate the potential harm. We will notify you and the relevant supervisory authority (the Information Commissioner’s Office in the UK) of any data breach that poses a high risk to your rights and freedoms, as required by applicable law.

18. Data Protection Officer

Carr has appointed a Data Protection Officer (DPO) to oversee our compliance with data protection laws. If you have any questions or concerns about our data protection practices, you can contact our DPO at:
Email: dpo@car-r.com

19. Direct Marketing

We may use your personal data to send you marketing communications about our products and services that we think may be of interest to you. You will only receive marketing communications from us if you have given your consent or if you have previously used our services and we are promoting similar products or services. You can opt out of receiving marketing communications at any time by clicking the “unsubscribe” link in the email, adjusting your notification preferences in the App settings, or by contacting us at data@car-r.com.

20. Automated Decision-Making and Profiling

Carr does not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.

21. Data Minimisation and Purpose Limitation

Carr is committed to collecting and processing only the minimum amount of personal data necessary to fulfil the purposes outlined in this Privacy Policy. We will not use your personal data for any purpose that is incompatible with the purposes for which it was originally collected, unless we have your consent or are otherwise permitted or required by law.

22. Data Breaches

Carr App Ltd commits to enhancing the privacy and security of the personal data it handles by implementing data anonymization and pseudonymization techniques where appropriate. This process involves modifying personal data so that individuals are not identifiable without the use of additional information, which is kept separately and secured with technical and organizational measures. This practice is part of our broader strategy to ensure data minimization and protect user privacy, especially when using data for testing, research, and analysis purposes. By anonymizing and pseudonymizing data, we aim to reduce the risks associated with data processing while maintaining the utility of the data.

23. Marketing Choices

You have the right to control whether and how Carr uses your personal data for marketing purposes. You can exercise your marketing choices by:

  • Opting out of email marketing: Clicking the “unsubscribe” link in any marketing email you receive from us.
  • Managing push notification preferences: Adjusting your notification settings within the App.
  • Contacting us directly: You can email us at data@car-r.com to update your marketing preferences or request to be removed from our marketing lists.

24. Data Subject Access Requests (DSARs)

You have the right to request access to the personal data we hold about you. This is known as a Data Subject Access Request (DSAR). To make a DSAR, please contact us at data@car-r.com. We will respond to your request within one month and may ask you to verify your identity before providing the information.

25. Obligation to Provide Personal Data

You are not obligated to provide us with your personal data. However, if you choose not to provide certain information, we may not be able to provide you with the full range of our Services. For example, we need your vehicle registration number to process payments for drivable charges and to use the app.

26. Cookies and Tracking Technologies

Carr uses cookies and similar tracking technologies on our website and App to enhance your user experience, analyse usage patterns, and deliver personalised content and advertising. These technologies collect information about your device, browsing behaviour, and interactions with our services. You can manage your cookie preferences through your browser settings or the App’s settings. For more information, please refer to our Cookie Policy.

27. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: data@car-r.com

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection matters.

Our Registration reference is: ZB685879

28. Effective Date

This Privacy Policy is effective as of 15th May 2024. We may update this policy from time to time, and any changes will be posted on this page.

29. International Data Transfers

Your data may be transferred to and processed in countries outside the UK/EEA. We ensure appropriate safeguards are in place to protect your data in accordance with applicable data protection laws.

30. Data Breach Notification

In the event of a data breach, we will notify you and relevant authorities promptly if there is a high risk to your rights and freedoms.