Privacy Policy
Last Updated: August 2026
1. Introduction and Data Controller
This Privacy Policy describes how 3C NET PVT Ltd. (Company Registration No. 16204011) (“Company,” “we,” “us,” or “our”), operating as TowMyCar.uk, collects, uses, processes, and protects your personal information when you use our platform, website, and mobile applications (collectively, the “Platform”).
We are committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (GDPR), the Data Protection Act 2018, and all other applicable data protection laws.
- Data Controller: 3C NET PVT Ltd.
- Contact: support@towmycar.uk
2. Information We Collect
We collect and process various categories of personal data necessary for providing our services:
2.1 Personal Information
- Identity Data: Full name, date of birth, government-issued identification numbers
- Contact Data: Email address, phone number, postal address
- Account Data: Username, password, account preferences, and security settings
2.2 Service-Related Data
- Vehicle Information: Registration number, make, model, year, condition details
- Location Data: Pickup and destination addresses
- Service Details: Type of service requested, service history, preferences
2.3 Financial Information
- Payment Data: Payment card details, billing address, transaction history
- Financial Records: Commission payments, refunds, dispute records
2.4 Technical Information
- Device Data: IP address, device identifiers, operating system, browser type
- Usage Data: Pages visited, time spent, features used, search queries
- Communication Data: Email correspondence and automated notifications, SMS messages for service updates, booking confirmations, and emergency communications, WhatsApp messages exchanged between customers, drivers, and support staff, chat logs from all communication channels, customer service interaction records across all platforms, communication preferences and delivery status information
2.5 Marketing and Communication Data
Communication preferences, marketing consent status, email engagement metrics
3. Legal Basis for Processing Under GDPR
We process your personal data based on the following lawful bases under Article 6 of the General Data Protection Regulation:
3.1 Contract Performance — Article 6(1)(b) GDPR
“Processing is necessary for the performance of a contract to which the data subject is party”
We rely on this legal basis for:
- Creating and managing user accounts (customers and service providers)
- Facilitating towing and roadside assistance service bookings
- Processing payments, refunds, and commission calculations
- Coordinating service delivery between customers and service providers
- Providing customer support related to active services
- Managing disputes and complaints related to service contracts
3.2 Legal Obligation — Article 6(1)(c) GDPR
“Processing is necessary for compliance with a legal obligation to which the controller is subject”
We process personal data to comply with:
- Financial Regulations: HM Revenue & Customs (HMRC) requirements for tax reporting and record-keeping
- Anti-Money Laundering (AML): The Money Laundering, Terrorist Financing and Transfer of Funds Regulations 2017
- Data Protection Laws: GDPR and Data Protection Act 2018 compliance obligations
- Company Law: Companies House filing requirements under the Companies Act 2006
- Consumer Protection: Consumer Rights Act 2015 and related regulations
- Employment Law: For service provider verification and due diligence
- Law Enforcement: Responding to lawful requests from police, courts, and regulatory authorities
3.3 Legitimate Interests — Article 6(1)(f) GDPR
“Processing is necessary for the purposes of the legitimate interests pursued by the controller”
We have conducted Legitimate Interest Assessments (LIAs) for the following processing activities:
3.3.1 Platform Security and Fraud Prevention
- Our Interest: Protecting our platform, users, and business from fraud and security threats
- Necessity: Essential for maintaining trust and operational integrity
- Balancing Test: User safety and platform security outweigh minimal privacy impact
- Safeguards: Data minimization, encryption, and limited access controls
3.3.2 Business Analytics and Improvement
- Our Interest: Understanding user behavior to improve services and develop new features
- Necessity: Required for competitive business operations and user experience enhancement
- Balancing Test: Business improvement benefits balanced against user privacy through anonymization
- Safeguards: IP anonymization, aggregated data analysis, and opt-out mechanisms
3.3.3 Customer Service and Communication
- Our Interest: Providing effective customer support and service communications
- Necessity: Essential for resolving issues and maintaining customer relationships
- Balancing Test: Customer service quality justifies necessary communication processing
- Safeguards: Purpose limitation and retention controls
3.3.4 Marketing to Existing Customers
- Our Interest: Informing existing customers about relevant services and updates
- Necessity: Reasonable expectation within existing customer relationship
- Balancing Test: Relevant service information balanced against easy opt-out options
- Safeguards: Clear unsubscribe mechanisms and preference management
3.4 Consent — Article 6(1)(a) GDPR
“The data subject has given consent to the processing of his or her personal data”
We obtain explicit consent for:
- Marketing to Non-Customers: Newsletter subscriptions and promotional communications
- Optional Analytics: Advanced tracking and personalization features
- Third-Party Integrations: Social media connections and external service integrations
- Research Participation: Customer surveys and market research activities
Consent Management: All consent is freely given, specific, informed, and unambiguous. Users can withdraw consent at any time without detriment. Withdrawal is as easy as giving consent. We maintain records of consent and withdrawal.
3.5 Special Category Data
We do not routinely process special category personal data (sensitive data such as health, race, religion, etc.). In exceptional circumstances where such data is disclosed during service provision, the legal basis is Article 9(2)(f) — necessary for legal claims establishment, exercise, or defense. Such data is subject to immediate data minimization, restricted access, and enhanced security, and is deleted immediately after resolution unless legally required.
4. How We Use Your Information
4.1 Service Provision
- Facilitating connections between customers and service providers
- Processing and managing service bookings
- Coordinating service delivery and logistics
- Handling payments, refunds, and commission calculations
4.2 Account Management
- Creating and maintaining user accounts
- Identity verification and authentication
- Account security and fraud prevention
- Customer support and dispute resolution
4.3 Communication
- Service-related notifications and updates via email, SMS, and WhatsApp
- Emergency communication during service delivery through multiple channels including WhatsApp, SMS, and voice calls
- Real-time coordination between customers and drivers via WhatsApp Business API and SMS
- Customer support correspondence through email, WhatsApp chat, and SMS
- Automated service status updates and booking confirmations via SMS and WhatsApp
- Legal notices and policy updates
4.4 Platform Improvement
- Analyzing usage patterns and user behavior
- Improving platform functionality and user experience
- Developing new features and services
- Performance monitoring and optimization
4.5 Marketing (with consent)
- Sending promotional materials and newsletters
- Personalized service recommendations
- Market research and customer feedback collection
5. Cookies and Similar Technologies
Our use of cookies is governed by GDPR, the Privacy and Electronic Communications Regulations (PECR) 2003, and ICO guidance. For full details on how we use cookies, please see our Cookies Policy.
6. Data Sharing and Third Parties
6.1 Service Providers
Independent contractors providing towing and roadside assistance services. Only information necessary for service delivery is shared. Service providers are bound by confidentiality obligations.
6.2 Technology Partners
- Payment Processors: Stripe for secure payment processing
- Cloud Services: AWS, Google Cloud for data hosting and processing
- Analytics Providers: Google Analytics for platform analytics
- Communication Services: Email service providers, SMS gateways, and WhatsApp Business API for multi-channel customer engagement
6.3 Legal and Regulatory Authorities
- Law enforcement agencies (when legally required)
- Regulatory bodies and government authorities
- Courts and legal representatives (in legal proceedings)
- Insurance companies (for claims and investigations)
6.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new entity, subject to the same privacy protections.
7. International Data Transfers
We may transfer your personal data outside the European Economic Area (EEA) to cloud service providers, payment processors, and technology vendors operating globally. All international transfers are protected by Standard Contractual Clauses (SCCs), adequacy decisions where applicable, additional security measures and encryption, and regular compliance monitoring and audits.
8. Data Retention and Deletion
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, in accordance with our legitimate business needs and legal obligations.
8.1 Retention Schedule
- Active Accounts: Retained while account remains active plus 30 days for account reactivation
- Deleted Accounts: Core identity data retained for 6 months post-deletion for legal compliance
- Service Bookings & Payment Records: 6 months from service completion
- Customer Service & Chat Records: 3 months from last interaction
- Marketing Preferences: Until consent withdrawal plus 30 days
- Log Files: 12 months from creation
8.2 Data Deletion
Regular automated reviews identify data eligible for deletion. Upon valid erasure requests, we will delete data immediately where legally permissible, using industry-standard data destruction methods. Where deletion is not legally permissible, data is anonymized.
9. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of Access (Article 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure (Article 17): Request deletion of your personal data when no longer necessary or where processing is unlawful.
- Right to Restrict Processing (Article 18): Request limitation of processing in certain circumstances.
- Right to Data Portability (Article 20): Request transfer of your data to another provider in a structured, machine-readable format.
- Right to Object (Article 21): Object to processing based on legitimate interests, including direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, email support@towmycar.uk with your request and proof of identity. We will respond within 30 calendar days.
10. Data Security
We implement comprehensive security measures including end-to-end encryption for data transmission, advanced encryption for data storage, multi-factor authentication, regular security audits, access controls, staff data protection training, and a documented incident response procedure. In the event of a data breach, we will notify the ICO within 72 hours where required and inform affected individuals without undue delay.
11. Children's Privacy
Our Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take immediate steps to delete it and terminate the account.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in applicable laws, our data processing practices, or new services. We will notify registered users of material changes by email and via prominent notices on our Platform. Your continued use of our Platform after policy updates constitutes acceptance of the revised terms.
13. Contact Information
- General Inquiries: support@towmycar.uk — Subject: “Privacy Policy Inquiry”
- Data Protection Officer: dpo@towmycar.uk — Subject: “Data Protection Request”
We aim to respond to all privacy-related inquiries within 30 days.
14. Supervisory Authority
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if you believe your data protection rights have been violated:
- Website: ico.org.uk
- Phone: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
