Legal
Privacy Policy
How we collect, use, share and protect your personal data — and the rights you have over it.
Last updated: 6 September 2026 · Version 2026-09-06 · Applies to the Republic of Ireland.
Draft — pending Irish legal review
1. Introduction
CarAlert (“we”, “us”, “our”, the “Service”) is an independent, community-based vehicle-safety and vehicle-utility service for the Republic of Ireland. We are committed to protecting your privacy and handling your personal data responsibly, lawfully, transparently and securely, in accordance with Regulation (EU) 2016/679 (the “GDPR”), the Irish Data Protection Act 2018, the ePrivacy Regulations (S.I. No. 336 of 2011) and other applicable law.
This Privacy Policy explains what personal data we collect, why we collect it, the legal bases on which we rely, who we share it with — including how information is shared within the community so that members can look out for one another — how long we keep it, how we protect it, and the rights you can exercise. Please read it carefully. By creating an account you confirm that you have read and accepted this Policy.
We are independent and are not affiliated with, endorsed by, or acting on behalf of the National Car Testing Service (NCTS), the Road Safety Authority (RSA), the Department of Transport, Motor Tax Online, An Garda Síochána, the National Vehicle and Driver File, or any vehicle-owner register.
2. Who is the data controller?
The data controller responsible for your personal data is Huftek Software Limited, a company established in the Republic of Ireland, of [registered office address — to be confirmed]. You can contact us about privacy at privacy@caralert.ie (address to be confirmed). Where required, our Data Protection Officer / privacy contact can be reached at the same address.
3. Scope and your acceptance
This Policy applies to the CarAlert website and web application, and to all personal data we process about visitors, registered members, vehicle watchers, reporters, people invited to share a vehicle, and those who contact our support team. Because a core purpose of the Service is enabling members of the community to alert one another about issues affecting vehicles, you acknowledge and consent that, when you create an account and use the Service, certain information you provide or generate will be shared with other members of the community as described in Section 7, so that the community can function and members can help each other.
4. The personal data we collect
We collect and process the following categories of personal data:
- Account data: your email address, hashed password, account status, trust level, locale, time zone, your confirmation that you are aged 18 or over, and records of your acceptance of this Policy and our Terms (including the version and timestamp).
- Vehicle data: Irish vehicle registration numbers you add or report, a private nickname you choose, your stated relationship to a vehicle, and any verification evidence you later provide. Registration numbers may constitute personal data in the Irish context and are treated accordingly.
- Report and alert data: the structured category and severity of an issue you report, any short optional note (after automated moderation), an optional coarse or manually entered location (never precise GPS by default), timestamps, and a reference.
- Compliance and reminder data: the NCT and motor-tax dates you enter or confirm, reminder preferences and the history of reminders we have sent you. We never collect or store your Motor Tax PIN, Vehicle Registration Certificate (VRC) number, Vehicle Identification Number (VIN), or any tax-payment or card credentials.
- Community relationships: the watch relationships between you and vehicles you look after or are invited to, and invitations you send or accept.
- Communications and support: messages you send us, support tickets and related correspondence.
- Technical and usage data: IP address, device and browser information, approximate region derived from your IP, and privacy-safe product analytics. We do not put raw registration numbers, notes or precise locations into analytics or third-party telemetry.
- Cookies and similar technologies: strictly necessary cookies for authentication and security, and — only with your consent — optional analytics cookies. See our Cookie Notice.
Where a registration number you enter belongs to a vehicle associated with another person, you are providing us with information that may relate to that person. You must only use the Service for genuine safety and vehicle-utility purposes and not to track, harass, identify or contact any individual.
5. How we use your personal data (purposes)
- To create, secure and administer your account and authenticate you.
- To operate the community alert network: to receive a report about a vehicle, route it to the verified watchers of that vehicle, and deliver it to them by in-account notification and email.
- To provide NCT and motor-tax reminders and to link you to the official services to act on them.
- To manage vehicle claims, shared access, transfers and verification.
- To keep the Service safe: to prevent, detect and investigate abuse, harassment, fraud, plate enumeration, and misuse, and to enforce our Terms and community rules.
- To respond to your support requests and communicate service and security messages.
- To comply with our legal obligations and to establish, exercise or defend legal claims.
- With your separate, opt-in consent only, to send you optional news or marketing (which you can withdraw at any time).
6. Our legal bases for processing
We rely on the following legal bases under Article 6 of the GDPR:
- Performance of a contract (Art. 6(1)(b)): to provide the account and the core Service you sign up for, including delivering community alerts to vehicles you watch and sending the reminders you configure.
- Consent (Art. 6(1)(a)): for optional analytics cookies, optional marketing, and — as you expressly accept when registering — for the sharing of your reports and relevant vehicle information with the appropriate members of the community as described in Section 7. You may withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Legitimate interests (Art. 6(1)(f)): to keep the Service and its users safe, to prevent and investigate abuse and fraud, to secure our systems, and to maintain the integrity of the community network. We balance these interests against your rights and freedoms and only process what is necessary.
- Legal obligation (Art. 6(1)(c)): where we must process data to comply with Irish or EU law.
7. Community sharing — how members help each other
The purpose of CarAlert is to let people look out for each other's vehicles. To make that possible, some information is shared between members — but always in a limited, purpose-bound way, and never as a public directory. Specifically:
- Reports are delivered to the people who watch that vehicle. When you report an issue about a vehicle, the category, severity, time, any moderated note and any coarse location are shared with the verified watchers of that vehicle so they can act on it. This is the community “having your back”.
- The reporter always stays anonymous to the recipient. We do not reveal who made a report. We do not tell the reporter who watches a vehicle, how many people watch it, whether it is registered with us, or whether the report was delivered or read.
- Vehicle owners and watchers are never publicly identified. There is no public feed and no public “who owns this plate?” lookup. Compliance dates are shared only with the people you invite and grant access to.
- County derived from the registration. Irish plates encode the county in which a vehicle was first registered. When we show a county for a registration, that information comes from the plate itself — not from any database of owners or from tracking.
- You control your own sharing. You choose which vehicles to add, who to invite to a shared vehicle, and what access they have. You can leave, revoke access or delete your data as described below.
By accepting this Policy you consent to this community sharing taking place for the purposes described. We do not sell your personal data, and we do not use your safety or compliance data for behavioural advertising.
8. Who else we share data with (processors and recipients)
- Service providers (processors) who host and run the Service on our behalf under written data-processing agreements, including our cloud database and authentication provider (hosted in the European Union), our transactional email provider (when enabled), error-monitoring and privacy-safe analytics providers. They may only process your data on our instructions.
- Professional advisers such as lawyers and auditors, where necessary and under confidentiality.
- Authorities such as An Garda Síochána, the Data Protection Commission, or courts, where we are legally required or permitted to disclose data, or to protect the vital interests, rights or safety of any person.
- Successors in the event of a merger, acquisition or reorganisation, subject to this Policy.
9. International transfers
We aim to store and process personal data within the European Union / European Economic Area. Where any processor processes data outside the EEA, we ensure an adequate level of protection through an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism, together with appropriate supplementary safeguards.
10. How long we keep your data (retention)
- Account and profile: while your account is active; deleted or anonymised after account closure, subject to justified security or legal retention.
- Alerts and reports: kept in your account history for a limited period (for example up to 12 months by default); moderation and safety evidence may be retained separately only where necessary.
- Reminders and compliance cycles: current and recent history (for example up to 24 months), which you can delete unless a narrow audit reason applies.
- Verification evidence: deleted shortly after the relevant decision and appeal window.
- Security, audit and consent records: retained for a defined period as required to prove compliance and protect the Service.
11. How we protect your data (security)
We apply appropriate technical and organisational measures, including encryption in transit, hashed passwords, keyed hashing of registration numbers for lookup so raw plates are not exposed in logs or URLs, strict access controls and row-level security, private and time-limited storage of any evidence, rate limiting and abuse detection, redacted logging, and regular review. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident, including notifying the Data Protection Commission and affected individuals where legally required.
12. Automated processing and moderation
We use automated rules to moderate report notes (for example to remove contact details, links, threats or personal data) and to assess risk and trust in order to prevent abuse. These do not produce legal or similarly significant effects on you without the opportunity for human review; account restrictions and claim decisions support human review and appeal.
13. Your rights
Subject to the conditions and exemptions in the GDPR, you have the right to: access your personal data; rectify inaccurate data; erase data (“right to be forgotten”); restrict or object to processing, including processing based on legitimate interests; data portability; and withdraw consent at any time where processing is based on consent. You can exercise most of these from your account settings, or by contacting us. We will respond within the timeframes required by law, and we will protect the rights and data of other people when we respond.
You also have the right to lodge a complaint with the Irish supervisory authority, the Data Protection Commission (www.dataprotection.ie, 21 Fitzwilliam Square South, Dublin 2, D02 RD28), although we would welcome the chance to address your concern first.
14. Emergency boundary
The Service is not an emergency service and cannot dispatch help. If life or safety is at risk, contact the emergency services on 112 or 999 first.
15. Children
The Service is intended for adults. You must be at least 18 years old to create an account, and you confirm this when you register. We do not knowingly collect data from people under 18.
16. Cookies
We use strictly necessary cookies to keep you signed in and to protect the Service, and — only with your consent — optional analytics cookies. For details and choices, see our Cookie Notice.
17. Changes to this Policy
We may update this Policy from time to time. When we make material changes we will update the version and date at the top and, where appropriate, notify you or ask you to re-accept. Your continued use after an update means you accept the revised Policy.
18. Contact us
If you have any questions about this Policy or how we handle your personal data, contact us at privacy@caralert.ie or write to us at the registered office above (details to be confirmed before launch).
