Rider Vault

← Back to home

Privacy Policy

Version 1.4·Effective Date: 6 April 2026·ridervaultapp.co.uk/privacy
v1.4 — What changed from v1.3: ICO registration number updated to C1907107. Registration confirmed 12 April 2026. All other content unchanged.
Plain English Summary

This is a summary. Full legal detail follows in the numbered sections below.

Rider Vault is a motorcycle management app. We collect and use your data solely to provide you with the service — nothing more.

  • We collect your email address, vehicle registration numbers, bike photos, service history you enter, and (in a future update) GPS mileage data.
  • We use your vehicle registration to look up MOT, VED, and recall data from official government sources.
  • VIN and V5C reference numbers are encrypted on your device before they reach our servers. We hold ciphertext only.
  • We do not sell your data or share it with advertisers or use it for profiling.
  • You can delete your account and all your data from within the app at any time.
  • All data is stored in the United Kingdom.

1. Who We Are

Arroket Intelligence Ltd ('we', 'us', 'our') is the data controller for personal data processed through Rider Vault (the mobile application and any associated service). Registered in England and Wales.

Registered address71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
Company No.17137573
Privacy contactadmin@arroketintelligence.com
ICO registeredC1907107

2. What Data We Collect and Why

We collect only what is necessary to deliver the service. Each category below states what we collect, why, and the lawful basis under UK GDPR.

2.1 Account Credentials

DataPurposeLawful Basis
Email addressAuthentication and service communications (MOT/VED reminders, critical alerts).Art. 6(1)(b) — Performance of contract
PasswordStored as bcrypt hash (cost factor 12) only. Never transmitted or stored in plain text.Art. 6(1)(b) — Performance of contract

2.2 Vehicle Data

DataPurposeLawful Basis
Registration (plate)Used to query DVLA VES and DVSA MOT History APIs for tax status, MOT history, and recall information on behalf of the user.Art. 6(1)(b)
Make, model, year, variantEntered by the user; used to build the bike profile and calculate the health score.Art. 6(1)(b)
Purchase date, current mileageUsed for service interval calculations and health score.Art. 6(1)(b)
VIN / V5C reference numberAES-256 encrypted on-device before transmission. Server holds ciphertext only. Encryption key stored in iOS SecureStore — we cannot decrypt without the device.Art. 6(1)(b)

2.3 Service and Maintenance Records

Service logs entered manually by the user: service type, date, mileage, workshop, and notes. These are not parsed for advertising or profiling. Used solely to generate health scores and reminders.

2.4 Photographs

Optional. If added, photos are stored on your device only using expo-file-system. Photo files never reach our servers. Only a filename reference and bike profile link are stored in our database. EXIF metadata (which may include GPS location) is stripped before the photo is written to device storage.

2.5 GPS / Location Data — Not Yet Active

Not collected in the current version. When GPS mileage tracking is introduced (future update), explicit consent will be required, only derived mileage figures will be stored (not raw GPS coordinates), and consent can be withdrawn from Settings at any time.

2.6 Crash and Error Data (Sentry)

Crash logs collected via Sentry for app reliability. Configured for crash reporting only — not behavioural analytics. Device identifiers are not linked to user accounts. Retained for 90 days. Does not constitute tracking under Apple ATT rules. Lawful basis: Art. 6(1)(f) — Legitimate interests.

3. How We Use Your Data

Delivering the serviceCalculating the health score, checking MOT/VED/recall status via government APIs, generating reminders.
Account managementAuthentication, billing, customer support.
App reliabilityCrash reporting via Sentry. No behavioural analytics.
Legal complianceRetaining records as required by UK law.

We do not use your data for advertising, profiling, behavioural targeting, or any purpose beyond operating the service. We do not sell your data.

4. Data Architecture and Security

Data residencyAll personal data stored in the United Kingdom. Supabase database: London region (AWS eu-west-2). No cross-border transfer outside UK or EEA.
Photo storageOn-device only (expo-file-system). Photo files never reach our servers.
VIN / V5C encryptionAES-256 client-side encryption before any transmission. Server holds ciphertext. Decryption key in iOS SecureStore.
Database isolationSupabase Row Level Security (RLS) enabled on all 12 tables. Each user can access only their own rows. Enforced at database level independent of application controls.
Password storagebcrypt hash, cost factor 12. Plain-text password never stored or transmitted.
Session tokensJWT tokens stored in iOS SecureStore (not AsyncStorage). 15-minute access token expiry; 7-day refresh token with rotation.
Breach notificationUsers notified within 72 hours per UK GDPR Art. 33/34 in the event of a relevant breach.
No ad trackingRider Vault does not use ad networks, cross-app tracking, or behavioural profiling. Apple ATT not triggered.

5. Third-Party Data Processors

All processors have been selected with UK data residency and security in mind.

ProcessorPurposeData and Residency
SupabaseDatabase and authentication hostingUK (AWS eu-west-2). Processes: email, registration numbers, service records. Photos are not transferred.
RailwayAPI server hosting (Fastify backend)Processes registration numbers in transit only; no persistent personal data storage.
SentryCrash reportingMay receive device identifiers. Crash-reporting only; not linked to user accounts.
Apple (App Store)App distribution / TestFlightApple's terms apply to users directly.
DVLA (VES API)Vehicle data query — government APIReceives registration number only. Returns vehicle data. No other account data transmitted to DVLA.
DVSA (MOT History API)MOT history query — government APIReceives registration number only. Returns MOT history. No other account data transmitted to DVSA.

6. Data Retention

Account dataRetained for the life of the account. Deleted within 30 days of account deletion.
Service recordsRetained for the life of the account. Deleted on account deletion.
Crash logs (Sentry)90 days.
DVLA / DVSA API cacheRetained per the terms of the respective government API.
PhotosOn-device only. Removed when the user deletes photos or uninstalls the app.

7. Your Rights

You have the following rights under UK GDPR. To exercise any right, contact admin@arroketintelligence.com or use the in-app controls where indicated. We will respond within 30 days.

Access (SAR)Request a copy of all personal data we hold about you. Email admin@arroketintelligence.com.
RectificationCorrect inaccurate data. Most data is self-serviceable directly within the app.
ErasureDelete your account and all personal data via Settings > Delete Account (two-step confirmation). Also available by email. Data removed within 30 days. Irreversible.
RestrictionRequest that processing be restricted while a dispute is resolved. Contact us by email.
Data portabilityReceive your data in structured JSON or CSV format. Email admin@arroketintelligence.com. In-app export planned post-launch.
ObjectObject to processing based on legitimate interests (e.g. crash analytics). Contact us by email.
Withdraw consentLocation data consent (Phase 9, not yet active): withdrawable from app Settings at any time without affecting prior lawful processing.
Complain to ICOico.org.uk · 0303 123 1113 · Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

8. Government API Attribution

Vehicle and MOT data displayed within the app is sourced from official UK government APIs and is reproduced with permission:

Contains public sector information licensed under the Open Government Licence v3.0.

DVLA Vehicle Enquiry Service · DVSA MOT History API

9. Changes to This Policy

We will notify registered users of material changes via the email address on their account. The current version is always available at ridervaultapp.co.uk/privacy. Continued use of the app after notification constitutes acceptance of the revised policy.

10. Contact Us

Emailadmin@arroketintelligence.com
Privacy-specific queriesadmin@arroketintelligence.com
Registered address71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
Company No.17137573