Privacy Notice
Last updated: June 2026 · Version 2026-07-01
1. Controller
BYPASSHIRE LIMITED ("we", "us", "our") is the data controller responsible for your personal data. Pixmion is a trading name of BYPASSHIRE LIMITED. Company number 15981770, registered at Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE.
We are not required to appoint a Data Protection Officer under UK GDPR.
If you have any questions about this privacy notice or how we handle your data, please contact us at [email protected].
2. What We Collect
We collect the following categories of personal data:
- Account data — your name and email address. If you register with an email and password, we also store your password in a securely hashed form (we never store it in plain text). If you sign in with Google, your name and email address are provided to us by Google.
- Acceptance records — when you accept these policies we record which version you accepted, the date and time, your IP address, and your browser/device information, as evidence of your agreement.
- Vehicle registration numbers — the registrations you search for when using our service.
- Search and report history — a record of your past searches and the reports generated for you.
- Payment data — processed securely by Stripe. We do not store your card details; Stripe handles all payment information directly.
- Analytics and session replay data — collected only with your consent through Google Analytics 4 and Fullstory. This may include pages visited, session duration, navigation paths, clicks, taps, browser and device information, approximate location, and replay-style interaction data showing how the Pixmion interface was used. We configure sensitive fields to be masked or excluded, and we do not intentionally send names, email addresses, vehicle registration numbers, card details, or Stripe Checkout URLs to Fullstory custom events.
- Technical data — your IP address, browser type, and device information collected automatically via server logs.
3. Legal Basis (Article 6 UK GDPR)
We process your personal data on the following legal bases:
| Purpose | Lawful Basis |
|---|---|
| Account creation & generating vehicle history reports | Contract performance (Art. 6(1)(b)) |
| Security, fraud prevention & service improvement | Legitimate interests (Art. 6(1)(f)) — our legitimate interest in protecting our platform and users from fraudulent activity, maintaining the security and integrity of our systems, and improving service quality based on aggregated usage patterns |
| Retaining payment records for tax compliance (HMRC) | Legal obligation (Art. 6(1)(c)) |
| Recording your acceptance of our Terms & Privacy Notice | Legitimate interests (Art. 6(1)(f)) — keeping proof that you agreed |
| Analytics and session replay cookies or similar technologies (Google Analytics 4 and Fullstory) | Consent (Art. 6(1)(a)) |
| Marketing emails & newsletters | Consent (Art. 6(1)(a) & PECR Reg. 22) |
Providing your personal data is a contractual requirement necessary to use our service. We cannot create your account or generate vehicle history reports without it. There is no statutory obligation to provide your data.
We do not use automated decision-making, including profiling, that produces legal effects or similarly significantly affects you.
4. How We Use Your Data
We use your personal data for the following purposes:
- To provide vehicle history reports based on the registration numbers you search.
- To process payments securely via Stripe.
- To maintain your account and store your report history for future access.
- To improve our service through consent-based analytics and session replay, including understanding where users get stuck in checkout, registration, dashboard, pricing, and vehicle-check flows.
- To communicate important service updates and changes to our terms or policies.
5. Data Sharing
We share your data with the following third parties, only as necessary to provide our service:
- DVLA — vehicle registration lookups are performed via the official DVLA API to retrieve vehicle details and tax status.
- DVSA — MOT history data is retrieved via the official DVSA MOT History API, including test dates, results, mileage readings, advisories, and failure reasons.
- UKVD / third-party vehicle data providers — we query licensed data providers for vehicle history data including finance, write-off, and stolen vehicle checks.
- Stripe — payment processing. Stripe acts as an independent data controller for payment data.
- Google — if you choose to sign in with Google, your name and email address are received from Google. Additionally, pseudonymised usage data is shared with Google Analytics 4 when you have consented to analytics cookies.
- Fullstory — session replay and product analytics. Fullstory processes pseudonymous user and session identifiers, device and browser metadata, page paths, clicks, taps, UI interaction events, and consented custom event data on our behalf. We use this to understand where users get stuck and improve Pixmion. We configure sensitive fields to be masked or excluded, and we do not intentionally send names, email addresses, vehicle registration numbers, card details, or Stripe Checkout URLs to Fullstory custom events.
- OpenAI — vehicle registration data, MOT history, and background check results are sent to OpenAI's API to generate the AI-powered plain-English analysis in your report. OpenAI processes this data on our behalf as a data processor under a data processing agreement. No personal data (name, email, payment details) is sent to OpenAI — only vehicle-related data.
- Brevo (France, EU) — processes transactional emails (e.g. welcome emails, password resets, purchase confirmations, and account notifications) on our behalf as a data processor. Brevo receives your name and email address for this purpose.
- Trustpilot (Denmark, EU) — after a purchase, your email address is shared with Trustpilot via a blind carbon copy (BCC) on your purchase confirmation email. Trustpilot uses this to send you a review invitation on our behalf. Trustpilot acts as a data processor for this purpose and retains BCC email data for up to 30 days. You are under no obligation to leave a review.
- SendGrid (Twilio) — may be used as a backup transactional email provider. If activated, SendGrid would act as a data processor on our behalf and may receive your name and email address. This disclosure is included for transparency.
- Hosting provider — our application is hosted on UK-based secure cloud infrastructure. No personal data is transferred outside the UK for hosting purposes. The hosting provider processes data on our behalf as a data processor under a data processing agreement.
We do not sell your personal data to any third party.
6. Data Retention
- Reports — stored in your account until you delete them or request account deletion.
- Account data — retained for as long as your account is active, or until you request deletion. Upon receiving a deletion request, we will erase your personal data within 30 days, unless a longer retention period is required by law.
- Payment records — retained for 6 years as required by UK tax law (HMRC requirements).
- Google Analytics 4 data — retained per Google's configured retention settings (14 months).
- Fullstory session replay and analytics data — retained according to the retention period configured in our Fullstory account, then deleted or anonymised according to Fullstory's retention and deletion process. We use this criterion rather than a fixed period because the operational account setting controls the exact retention window.
- Server logs — automatically deleted after 20 days.
- Acceptance records — stored for as long as your account exists and deleted if your account is deleted, because the acceptance records are linked to your account in the application database.
7. Your Rights (UK GDPR)
Under the UK General Data Protection Regulation, you have the following rights:
- Right of access — you can request a copy of the personal data we hold about you (Subject Access Request).
- Right to rectification — you can ask us to correct any inaccurate or incomplete data.
- Right to erasure — you can request that we delete your personal data ("right to be forgotten"), subject to legal retention requirements.
- Right to restriction of processing — you can ask us to limit how we use your data in certain circumstances.
- Right to data portability — you can request your data in a structured, commonly used, machine-readable format.
- Right to object — you can object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
- Right to complain — you can complain to us about how we handle your personal data by contacting [email protected]. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. You can write to: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, or call the helpline on 0303 123 1113.
To exercise any of these rights, contact us at [email protected].
Direct marketing: You have an absolute right to object to the processing of your personal data for direct marketing purposes at any time. To exercise this right, contact us at [email protected] or use the unsubscribe link in any marketing email.
8. Cookies
We use cookies and similar technologies to operate our site and, with your consent, to analyse usage via Google Analytics 4 and understand replay-style interactions via Fullstory session replay. You can manage your cookie preferences at any time using the "Cookie preferences" link in our footer.
For full details on the cookies we use, please see our Cookie Policy.
9. International Transfers
Some of our third-party service providers are based outside the UK:
- Google (United States) — transfers are protected primarily under the UK Extension to the EU-U.S. Data Privacy Framework (the 'UK-US Data Bridge'). Where additional safeguards are required, they are supplemented by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses.
- Fullstory (United States / international processing where applicable) — session replay and product analytics data may be processed outside the UK. Where this happens, transfers are protected using appropriate safeguards under UK GDPR Chapter V, such as an adequacy regulation, the UK Extension to the EU-U.S. Data Privacy Framework, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to EU Standard Contractual Clauses where applicable.
- Stripe (United States) — transfers are protected primarily under the UK Extension to the EU-U.S. Data Privacy Framework (the 'UK-US Data Bridge'). Where additional safeguards are required, they are supplemented by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses.
- OpenAI (United States) — vehicle data is sent to OpenAI for AI-powered report generation. Transfers are protected by the UK International Data Transfer Agreement (IDTA) and OpenAI's data processing agreement. Only vehicle-related data is transferred — no personal data.
- Brevo (France, EU) — transactional email data (name and email address) is processed by Brevo within the EU. The UK has an adequacy decision covering the EU/EEA, so no additional transfer mechanism is required.
- Trustpilot (Denmark, EU) — your email address is shared with Trustpilot for review invitation purposes. The UK has an adequacy decision covering the EU/EEA, so no additional transfer mechanism is required.
- SendGrid (Twilio) (United States) — if activated as a backup email provider, transfers would be protected primarily under the UK Extension to the EU-U.S. Data Privacy Framework (the 'UK-US Data Bridge'). Where additional safeguards are required, they are supplemented by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU Standard Contractual Clauses. This disclosure is included for transparency.
Adequate safeguards are in place for all international transfers in accordance with UK GDPR Chapter V.
10. Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures, including:
- Encryption in transit via TLS/HTTPS for all connections.
- Secure cloud hosting with regular security patching.
- Access controls and authentication to limit data access to authorised personnel.
- Regular security reviews of our systems and processes.
11. Changes to This Notice
We may update this privacy notice from time to time. If we make material changes, we will notify registered users by email. The "Last updated" date at the top of this page will always reflect the most recent revision.
12. Contact
If you have any questions about this privacy notice or wish to exercise your data rights, please contact us at [email protected].
See also our Terms of Service and Data Sources page for related information.