Privacy Notice

LuxuryCarHire.Club Limited is committed to respecting your privacy and protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Personal data we collect

We collect contact information, driving licence details, payment information, and communications you send to our concierge team. Vehicle hire bookings may also generate vehicle tracking data and condition reports used to ensure vehicle security and maintain service quality.

How we use your information

  • To process, confirm, and fulfil your vehicle hire bookings.
  • To verify driving eligibility and manage security deposits.
  • To manage membership subscriptions and corporate accounts.
  • To send service updates, confirmations, and—infrequently—curated invitations.
  • To comply with licensing, insurance, and accounting obligations.

Lawful basis

We process personal data under the lawful bases of contract, legitimate interests, and consent (for optional marketing). We only retain data for as long as necessary to fulfil the above purposes and meet statutory requirements.

Sharing

Data is shared with insurance providers, vetted service partners, and cloud providers who act under strict contractual controls. We never sell personal data.

Your rights

You may request access, correction, deletion, or restriction of your personal data at any time. Please email privacy@luxurycarhire.club to exercise your rights. If you remain dissatisfied you may complain to the Information Commissioner’s Office (ICO).

Data Retention Periods

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The specific retention periods are set out below:

Data CategoryRetention Period
Booking records7 years (legal/tax requirement)
Payment records7 years (financial regulations)
Contact messages (unlinked to account)90 days
Newsletter subscriber IP addresses30 days
Session data30 days
Account dataRetained until account deletion
Verification tokens24 hours
Audit logs2 years

Third-Party Data Processors

We share personal data with the following third-party processors, each operating under strict data processing agreements compliant with UK GDPR requirements:

ProcessorPurposeLocation
StripePayment processingEU / US
NeonDatabase hostingEU
VercelWebsite hostingGlobal CDN
ResendTransactional emailUS
SentryError monitoringUS
GoogleAnalytics, Search Console, Business ProfileUS
CloudflareSecurity / CDN, Turnstile CAPTCHAGlobal
TwilioSMS, WhatsApp messagingUS
MetaWhatsApp Business, MessengerUS
UpstashRate limiting via RedisEU

Where data is transferred outside the UK, appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions, to ensure your data is protected to UK GDPR standards.

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, LuxuryCarHire.Club Limited will:

  • Notify affected users within 72 hours of becoming aware of the breach.
  • Report the breach to the Information Commissioner's Office (ICO) within 72 hours where the breach is likely to result in a risk to individuals' rights and freedoms, as required under UK GDPR Article 33.
  • Communicate the nature of the breach, the data affected, and recommended protective measures via your registered email address.

We maintain an internal breach register and incident response procedures to ensure timely detection, investigation, and resolution of all data security incidents.

Contact

LuxuryCarHire.Club Limited. Data Protection Officer: privacy@luxurycarhire.club.

Last updated: 2026