Privacy policy

Last updated: 21 May 2025

Who we are

PCNTrack is a UK-based fleet compliance automation platform operated as a sole trader business. We are registered with the Information Commissioner's Office (ICO) under the UK Data Protection Act 2018 and UK GDPR. Our data controller registration number is [ICO REGISTRATION NUMBER — add once registered].

Contact us: hello@pcntrack.co.uk

What data we collect and why

We collect and process the following personal data:

Business account dataName, email, business nameContract performanceDuration of your account
Driver dataName, mobile number, vehicle regLegitimate interest (PCN matching)3 years from last PCN, then deleted
PCN recordsPCN reference, amount, issuer, photosContract performance7 years (HMRC compliance)
Payment dataHandled entirely by Stripe — we never see card numbersContract performancePer Stripe's policy
Usage dataLogin times, feature usageLegitimate interest (service improvement)12 months rolling
Error logsTechnical errors, stack traces (via Sentry)Legitimate interest (reliability)90 days rolling

Data retention policy

We retain personal data only for as long as necessary:

When you delete a driver or PCN in the dashboard, it is soft-deleted (hidden from your view immediately) and permanently destroyed within 90 days.

Cookies and tracking

We use the following cookies and tracking technologies:

Supabase sessionEssentialKeeps you logged inSession end
SentryFunctionalCaptures errors to improve reliability90 days
pcntrack_cookie_consentEssentialRemembers your cookie preference1 year

We do not use advertising cookies, social media tracking pixels, or any third-party analytics tools. You can withdraw consent for non-essential cookies at any time by clearing your browser cookies or using the consent banner at the bottom of any page.

Who we share your data with

We use the following sub-processors:

Supabase (EU West — Ireland)Database and authenticationEU standard contractual clauses
StripePayment processingUK adequacy decision
TwilioSMS notificationsStandard contractual clauses
AnthropicAI PCN extraction (photo processing)Standard contractual clauses
SentryError monitoringStandard contractual clauses
VercelHosting and deploymentStandard contractual clauses

We never sell your data. We never share your data with advertisers.

Your rights under UK GDPR

You have the right to:

To exercise any right, email us at hello@pcntrack.co.uk. We will respond within 30 days. You also have the right to complain to the ICO at ico.org.uk.

Data processing agreements

If you use PCNTrack to process personal data on behalf of your business (for example, your drivers' data), we act as a data processor and you act as the data controller. A Data Processing Agreement (DPA) is available at /dpa and is incorporated into our Terms of Service for all customers.

Security

All data is stored in Supabase (EU West, Ireland) with Row Level Security enforced at the database level, ensuring complete multi-tenant isolation. All connections are encrypted in transit (TLS 1.3). Passwords are never stored — we use Supabase Auth with email-based authentication.

Changes to this policy

We will notify you by email of any material changes to this privacy policy at least 30 days before they take effect. The current version is always available at pcntrack.co.uk/privacy.