Skip to content

Complimentary concierge delivery on every airport booking this season.

Privacy Policy

What we collect when you book a vehicle, why we need it, and the controls you have over it.

Last updated 14 July 2026 Read the policy

Olivia Motors Mobility Ltd is the data controller for the personal information described in this policy. We collect only what a rental genuinely requires — identity, licence, payment and vehicle data — and we do not sell personal information to anyone. This policy explains each category, the legal grounds we rely on, and how to exercise your rights.

1. Information we collect

When you create an account we collect your name, email address, phone number, date of birth and country of residence. When you book we additionally collect your driving licence number and expiry, a document image for verification, your billing address and a tokenised reference to your payment card. We never store the full card number or security code on our systems.

During a rental we collect vehicle telematics: odometer readings, fuel or battery level, charge and refuelling events, and approximate location where the vehicle is reported stolen, crosses a border without consent, or triggers a roadside assistance call. We do not track continuous location for routine rentals and we do not use telematics for marketing.

We also collect service data: photographs from the guided condition report, support messages, call recordings where you are told at the start of the call, reviews you publish, and device and browser information from our website and apps.

  • Identity & contact — name, email, phone, date of birth, address
  • Licence & verification — licence number, expiry, document image, IDP where required
  • Payment — tokenised card reference, billing address, invoices and receipts
  • Rental & vehicle — booking history, condition photos, mileage, fuel and charge events

2. How we use it

The primary use is delivering the rental you booked: confirming your reservation, verifying that you are legally entitled to drive, preparing the vehicle, issuing digital keys, taking payment, and handling returns, damage claims and refunds.

We use aggregated rental data to plan fleet distribution, forecast demand at each branch and set pricing. This analysis operates on de-identified records; individual bookings are not used to set an individual's price, and we do not practise personalised surge pricing.

With your consent we send product news, member offers and destination guides. Every message includes a one-click unsubscribe, and withdrawing consent never affects your ability to book. Transactional messages — confirmations, key issuance, invoices, safety recalls — are sent regardless because they are part of the contract.

4. Cookies & tracking

Strictly necessary cookies keep you signed in, hold your booking in progress and protect the checkout against fraud. They cannot be switched off because the site does not function without them, and they are exempt from consent requirements.

Analytics cookies measure which pages lead to completed bookings and where people abandon the flow. We use a self-hosted, IP-truncated analytics stack and set these cookies only after you accept them. Marketing cookies, used for measuring advertising campaigns, are off by default and require explicit opt-in.

You can change your choices at any time from the cookie link in the footer. We honour Global Privacy Control signals sent by your browser as an opt-out of analytics and marketing cookies.

5. Sharing & third parties

We share personal information with processors who act only on our written instructions: our payment provider for card authorisation and refunds, our licence verification partner for document checks, our insurer and its approved bodyshops when a claim is opened, and our roadside assistance network when you request help.

We disclose information to public authorities where we are legally required to — for example, naming the driver responsible for a speeding offence or a toll violation, or responding to a valid court order. We tell you when we do this unless the law prevents us.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. If Olivia Motors is acquired, personal information transfers with the business under the same protections, and we notify you at least 30 days before any change of controller.

6. International transfers

Our primary data centres are in New Zealand and Australia. Data for rentals collected in New Zealand is processed locally in Auckland, and data for rentals collected in nearby Pacific branches is processed in Canberra, so that records stay close to the branch that needs them.

Where a transfer leaves the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, supported by a documented transfer risk assessment and encryption in transit and at rest.

You can request a copy of the safeguards applied to a specific transfer by writing to our Data Protection Officer at the address in section 10.

7. Data retention

Booking and invoice records are kept for seven years after the rental ends, to meet tax and accounting obligations in the countries where we operate. Condition report photographs are kept for 24 months, or until a related claim is finally resolved if that is later.

Licence images are deleted 90 days after the rental unless you have asked us to keep them on file for faster future bookings. Support conversations are kept for 24 months; call recordings for 6 months. Marketing consent records are kept for as long as the consent is active plus two years, so that we can evidence it.

When you close your account we delete or irreversibly anonymise everything not covered by a legal retention obligation within 30 days. Anonymised, aggregate statistics may be retained indefinitely because they can no longer identify you.

8. Your rights

Depending on where you live, you have the right to access a copy of your personal information, to correct inaccuracies, to request erasure, to restrict or object to certain processing, to withdraw consent, and to receive your data in a portable machine-readable format.

Most of these are self-service: export and deletion are available in your account privacy settings and complete without a support ticket. For anything else, write to privacy@oliviamotors.com. We respond within one month and never charge a fee for a first request.

If you are unhappy with our response you may complain to your supervisory authority — the Information Commissioner's Office in the UK, or your national data protection authority in the EEA. We would appreciate the chance to resolve it first.

  • Download a full export of your account and booking history
  • Correct your name, licence details or contact information
  • Delete your account and everything not held for tax purposes
  • Turn marketing email, SMS and non-essential cookies on or off

9. Security

All traffic to oliviamotors.com uses TLS 1.3, and data at rest is encrypted with AES-256. Licence images and condition photographs are held in a separate, restricted store with per-object access logging. Card data never touches our servers — it is tokenised by our PCI DSS Level 1 payment provider.

Access to customer records follows least privilege, is granted by role, requires hardware security keys for staff sign-in, and is reviewed quarterly. We run annual third-party penetration tests, maintain a coordinated vulnerability disclosure programme, and are certified to ISO/IEC 27001.

If a breach is likely to result in a risk to your rights, we notify the relevant supervisory authority within 72 hours and tell affected customers directly, with a plain-language description of what happened and what to do.

10. Contact us

The data controller is Olivia Motors Mobility Ltd, 40 Pentonville Road, London N1 9HF, United Kingdom, registered with the Information Commissioner's Office under reference ZA774120.

Our Data Protection Officer can be reached at privacy@oliviamotors.com or by post at the same address, marked for the attention of the DPO. Our EU representative for GDPR purposes is based in Dublin and contactable at the same address.

We review this policy at least annually. Material changes are announced by email and in the product at least 30 days before they take effect, and the previous version stays available on request.

Privacy enquiries

Talk to our Data Protection Officer

Access, correction and erasure requests are acknowledged within two working days and completed within one month.

Contact us

Are you sure?

This cannot be undone.