Privacy Policy
What we collect when you book a vehicle, why we need it, and the controls you have over it.
Olivia Motors Mobility Ltd is the data controller for the personal information described in this policy. We collect only what a rental genuinely requires — identity, licence, payment and vehicle data — and we do not sell personal information to anyone. This policy explains each category, the legal grounds we rely on, and how to exercise your rights.
1. Information we collect
When you create an account we collect your name, email address, phone number, date of birth and country of residence. When you book we additionally collect your driving licence number and expiry, a document image for verification, your billing address and a tokenised reference to your payment card. We never store the full card number or security code on our systems.
During a rental we collect vehicle telematics: odometer readings, fuel or battery level, charge and refuelling events, and approximate location where the vehicle is reported stolen, crosses a border without consent, or triggers a roadside assistance call. We do not track continuous location for routine rentals and we do not use telematics for marketing.
We also collect service data: photographs from the guided condition report, support messages, call recordings where you are told at the start of the call, reviews you publish, and device and browser information from our website and apps.
- Identity & contact — name, email, phone, date of birth, address
- Licence & verification — licence number, expiry, document image, IDP where required
- Payment — tokenised card reference, billing address, invoices and receipts
- Rental & vehicle — booking history, condition photos, mileage, fuel and charge events
2. How we use it
The primary use is delivering the rental you booked: confirming your reservation, verifying that you are legally entitled to drive, preparing the vehicle, issuing digital keys, taking payment, and handling returns, damage claims and refunds.
We use aggregated rental data to plan fleet distribution, forecast demand at each branch and set pricing. This analysis operates on de-identified records; individual bookings are not used to set an individual's price, and we do not practise personalised surge pricing.
With your consent we send product news, member offers and destination guides. Every message includes a one-click unsubscribe, and withdrawing consent never affects your ability to book. Transactional messages — confirmations, key issuance, invoices, safety recalls — are sent regardless because they are part of the contract.
3. Legal basis
Where the UK GDPR or EU GDPR applies, we rely on performance of a contract for everything needed to supply the rental, including identity and licence verification, payment and vehicle handover.
We rely on legal obligation for retaining invoices for tax, responding to police requests for driver identification after a traffic offence, and complying with anti-money-laundering checks on high-value bookings. We rely on legitimate interests for fraud prevention, network and vehicle security, service improvement and defending legal claims — balanced against your rights and documented in our assessments.
We rely on consent for marketing email and SMS, for non-essential cookies, and for storing a licence image beyond the rental period to speed up future bookings. Consent can be withdrawn at any time in your privacy settings.
6. International transfers
Our primary data centres are in New Zealand and Australia. Data for rentals collected in New Zealand is processed locally in Auckland, and data for rentals collected in nearby Pacific branches is processed in Canberra, so that records stay close to the branch that needs them.
Where a transfer leaves the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, supported by a documented transfer risk assessment and encryption in transit and at rest.
You can request a copy of the safeguards applied to a specific transfer by writing to our Data Protection Officer at the address in section 10.
7. Data retention
Booking and invoice records are kept for seven years after the rental ends, to meet tax and accounting obligations in the countries where we operate. Condition report photographs are kept for 24 months, or until a related claim is finally resolved if that is later.
Licence images are deleted 90 days after the rental unless you have asked us to keep them on file for faster future bookings. Support conversations are kept for 24 months; call recordings for 6 months. Marketing consent records are kept for as long as the consent is active plus two years, so that we can evidence it.
When you close your account we delete or irreversibly anonymise everything not covered by a legal retention obligation within 30 days. Anonymised, aggregate statistics may be retained indefinitely because they can no longer identify you.
8. Your rights
Depending on where you live, you have the right to access a copy of your personal information, to correct inaccuracies, to request erasure, to restrict or object to certain processing, to withdraw consent, and to receive your data in a portable machine-readable format.
Most of these are self-service: export and deletion are available in your account privacy settings and complete without a support ticket. For anything else, write to privacy@oliviamotors.com. We respond within one month and never charge a fee for a first request.
If you are unhappy with our response you may complain to your supervisory authority — the Information Commissioner's Office in the UK, or your national data protection authority in the EEA. We would appreciate the chance to resolve it first.
- Download a full export of your account and booking history
- Correct your name, licence details or contact information
- Delete your account and everything not held for tax purposes
- Turn marketing email, SMS and non-essential cookies on or off
9. Security
All traffic to oliviamotors.com uses TLS 1.3, and data at rest is encrypted with AES-256. Licence images and condition photographs are held in a separate, restricted store with per-object access logging. Card data never touches our servers — it is tokenised by our PCI DSS Level 1 payment provider.
Access to customer records follows least privilege, is granted by role, requires hardware security keys for staff sign-in, and is reviewed quarterly. We run annual third-party penetration tests, maintain a coordinated vulnerability disclosure programme, and are certified to ISO/IEC 27001.
If a breach is likely to result in a risk to your rights, we notify the relevant supervisory authority within 72 hours and tell affected customers directly, with a plain-language description of what happened and what to do.
Two-factor authentication is available on every account
10. Contact us
The data controller is Olivia Motors Mobility Ltd, 40 Pentonville Road, London N1 9HF, United Kingdom, registered with the Information Commissioner's Office under reference ZA774120.
Our Data Protection Officer can be reached at privacy@oliviamotors.com or by post at the same address, marked for the attention of the DPO. Our EU representative for GDPR purposes is based in Dublin and contactable at the same address.
We review this policy at least annually. Material changes are announced by email and in the product at least 30 days before they take effect, and the previous version stays available on request.
Privacy enquiries
Talk to our Data Protection Officer
Access, correction and erasure requests are acknowledged within two working days and completed within one month.
Related documents