WHY KNOTT HIRE
Privacy Policy

Onward 2 Upward Ltd T/A Why Knott Hire
Last updated: 21 June 2026

1. Who We Are

Data Controller:
Onward 2 Upward Ltd trading as Why Knott Hire
56 Woodland Avenue, Pencoed, Bridgend, CF35 6UP
Company registration: 12707392
ICO registration number: ZB575356

Contact for data protection queries:
Email: info@whyknotthire.co.uk · Phone: 07983 896389

We are a motorhome hire company based in Bridgend, South Wales. This policy explains how we collect, use, store and protect your personal data when you make a booking, use our online booking system, interact with our AI chat assistant, or otherwise engage with our services.

2. What Data We Collect and Why

2.1 Booking and Customer Data

When you make a booking, we collect:

DataPurposeLawful Basis
Full name and surnameTo identify you and create your bookingContract
Email addressTo send booking confirmations, receipts, reminders and documentsContract
Phone/mobile numberTo contact you about your bookingContract
Home addressRequired for our hire terms and for legal documentsContract
Date of birthTo verify you meet our minimum age requirement (25 years)Contract / Legal obligation
Party size and compositionTo ensure vehicle suitability and safety complianceContract
Booking dates, vehicle choice, extras selectedTo fulfil your hireContract
Collection and return time preferencesTo arrange your hireContract
Additional driver names and detailsTo name drivers on the rental agreement and verify entitlementContract / Legal obligation

2.2 Driving Licence and Identity Data

We are legally required to verify that all drivers meet our hire requirements. We collect:

DataPurposeLawful Basis
Driving licence (front and back photograph)To verify licence validity, category and identityLegal obligation / Contract
DVLA check code (share code)To electronically verify entitlement, penalty points and disqualifications via DVLA Access to Driver Data (ADD)Legal obligation
Proof of address documents (photographs)To verify residency and identityContract / Legal obligation
DVLA licence check resultTo confirm eligibility to hireLegal obligation
Last 8 digits of driving licence numberTo cross-reference the DVLA checkLegal obligation

DVLA ADD: Where we use the DVLA's Access to Driver Data API, we are a registered Controller. Data obtained from the DVLA is used solely to verify driver eligibility. It is not shared with third parties and is retained only for the duration required below.

2.3 Payment Data

DataPurposeLawful Basis
Payment card details (tokenised)To process deposit, balance (including monthly Pay Monthly instalments where chosen), and security deposit paymentsContract
Transaction IDs and payment statusTo maintain accurate financial recordsContract / Legal obligation
Payment history per bookingFor invoicing, receipts and VAT recordsLegal obligation

We do not store your full card number. Card data is tokenised by Opayo (Elavon Financial Services Ltd) and we only retain the token and transaction reference. Opayo is PCI DSS compliant. Where you choose to pay by monthly instalments (Pay Monthly), Opayo securely retains a card token so we can take each agreed instalment automatically under your Continuous Payment Authority, until the plan is complete, cancelled by you, or cancelled with your card issuer.

2.4 Communications Data

DataPurposeLawful Basis
Email correspondenceTo communicate about your bookingContract
AI chat conversation contentTo provide customer supportLegitimate interests
WhatsApp messages (where used)To communicate about your bookingLegitimate interests / Contract
Email open & click trackingOur emails may contain a small invisible image and tracked links that tell us, in aggregate, whether emails were opened and which links were clicked, so we can improve our communications. We do not use this to build individual profiles.Legitimate interests
Notification delivery recordsWe keep a record of which notifications we attempted to send you and on which channel (email, WhatsApp or push) and whether they succeeded, so we can diagnose delivery problems. No message content is stored in these records.Legitimate interests / Contract

2.5 Technical and Usage Data

DataPurposeLawful Basis
IP address (server logs)Security, fraud prevention, system integrityLegitimate interests
Booking system usage dataTo operate and improve the booking systemLegitimate interests
First-party analytics events (pages and vehicles viewed, searches, booking-funnel steps)To understand how the booking site is used so we can improve it. We always record this anonymously and in aggregate (a temporary per-visit identifier only, no personal data); we only link a visit to a returning device or to your booking if you accept analytics.Legitimate interests (anonymous aggregate) / Consent (identified)

3. How We Use Your Data

We use your personal data to:

We do not use your data for automated decision-making that has legal or similarly significant effects, except for licence eligibility checks (which you can request a human review of at any time).

4. Data Sharing and Third-Party Processors

We share your data only where necessary with trusted third parties acting as data processors on our behalf. All processors are bound by data processing agreements.

ProcessorPurposeLocationSafeguards
Supabase Inc.Database storage of booking records, uploaded documents and conversation historyUK (London region)UK-region project; SOC 2 Type II; SCCs/IDTA cover any support access from outside the UK
Vercel Inc.Hosting of booking system and serverless functions; cookieless Web Analytics (aggregated, anonymised usage statistics, only with your consent)UK (London region)Functions pinned to London (lhr1); ISO 27001; SCCs/IDTA
Cloudflare, Inc.Content delivery network (CDN), DNS and security (DDoS protection, web application firewall and TLS encryption) for our public website. Processes visitors' connection data (such as IP address) to route, cache and protect page requests. Our booking system and customer portal are served directly and are not routed through Cloudflare's cache.US (global edge network; UK visitors are normally served from the London edge)UK IDTA / EU SCCs; EU–US Data Privacy Framework; ISO 27001; strictly-necessary security processing only — no advertising or tracking
Opayo / Elavon Financial Services LtdPayment processing and card tokenisationUK / EUPCI DSS Level 1; FCA regulated
IONOS SEEmail delivery (SMTP)EU (Germany)GDPR-compliant EU processor
Anthropic PBCAI chat assistant (Claude) — processes message contentUSSCCs; data not used for model training per enterprise terms
Google (Google Ireland Ltd / Google LLC)Google Analytics — anonymised website‑usage statistics; and Google Ads — measuring whether an advertisement led to a booking. This includes “Enhanced Conversions”, where a one‑way hashed (irreversible) form of your email address and name is shared with Google solely to match a booking to an ad click. All of this happens only with your consent.EU / USConsent Mode v2 (advertising & analytics storage stay off unless you accept); customer data hashed (SHA‑256) in your browser before it is sent; SCCs / EU–US Data Privacy Framework
Microsoft (Microsoft Ireland Operations Ltd / Microsoft Corporation)Microsoft Clarity — anonymised session replay and heatmaps showing how visitors move through the booking site so we can improve it; on-page text and anything you type are automatically masked. This happens only with your consent.EU / USLoaded only if you accept analytics cookies; text & form inputs masked by default; not used for advertising and not sold; SCCs / EU–US Data Privacy Framework
RAC Motoring ServicesVehicle on Hire (VE103) application for European travelUKNecessary for legal document processing
DVLADriving licence verification via Access to Driver DataUKUK Government; DVLA ADD agreement
Meta Platforms / WhatsAppWhatsApp messaging (where used)US / EUSCCs; Meta DPA
Xero (Xero Limited)Accounting & VAT invoicing — booking reference, customer name/address and invoice amounts are recorded for our bookkeeping (the refundable security deposit is never sent)EU / USData processing agreement; SCCs; ISO 27001
Prodigi (print-on-demand)Printing & posting a physical gift card — recipient name & address (only when a hard-copy gift voucher is purchased)UK / EUUsed solely to print & post the card; data processing agreement

We do not sell your personal data to any third party. We do not share your data with any other organisation without your explicit consent, except where required by law.

5. Where Your Data Is Held and International Transfers

Your booking and customer data is hosted in the United Kingdom. Our database and uploaded documents (Supabase) and our application servers (Vercel) are configured to the UK (London) region, and our payment processor (Opayo / Elavon) and email provider (IONOS) operate in the UK / EU.

The principal transfer of data outside the UK is the content of AI chat messages, which is processed by Anthropic (United States) to generate replies. In addition, some of our processors are US-headquartered companies whose technical support staff may, exceptionally, access data from outside the UK. Where any personal data is transferred outside the UK, we ensure adequate safeguards are in place, including UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs), and transfers only to processors certified under appropriate frameworks (e.g. the UK–US Data Bridge where applicable).

Our public website (whyknotthire.co.uk) is delivered and protected through Cloudflare's content-delivery and security network. Cloudflare is a US-headquartered provider that operates a global network of edge servers; visitors in the UK are normally served from its London edge, and it processes visitors' connection data (such as IP addresses) only to deliver, cache and secure the website. Our booking system and customer portal (bookings.whyknotthire.co.uk) are served directly and are not routed through Cloudflare's cache, so your booking and customer data continues to be hosted in the UK as described above.

6. Document and File Storage

Photographs of driving licences and proof of address documents are uploaded by customers through the customer portal. These files are stored in a private, access-controlled storage bucket. Files are not publicly accessible, are only accessible to our administrative staff via authenticated access, and are deleted in accordance with our retention schedule (see Section 7).

7. How Long We Keep Your Data

Data CategoryRetention PeriodReason
Booking records (name, contact, dates, vehicle, payment status)7 years from date of hireHMRC financial records requirement
VAT invoices and payment records7 yearsLegal obligation (HMRC)
Driving licence photos and proof of address60 days from return dateTo resolve any post-hire disputes
DVLA licence check results60 days from return datePost-hire dispute resolution
Rental Agreement PDFs7 yearsLegal obligation
AI chat transcripts90 daysCustomer service quality; deleted on rolling basis
WhatsApp conversation threads30 daysCustomer service purposes
Email correspondence3 yearsCustomer service and dispute resolution
Expired/unpaid bookings (no deposit within 48 hours)30 days then deletedOperational necessity
Contact details kept for marketingUntil you unsubscribeOnly where you have opted into our mailing list

After the relevant retention period, data is securely deleted from all systems.

We only retain your personal data for marketing if you have opted into our mailing list. Once a booking's mandatory 7-year financial-record period (HMRC) has elapsed, the personal data held against it is automatically erased unless you remain subscribed to our mailing list — we then keep only a non-identifying record (booking reference, dates and amounts) for statistics. You can unsubscribe at any time, after which we stop using your details for marketing.

8. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

To exercise any of these rights, contact us at info@whyknotthire.co.uk or write to us at the address above. We will respond within 30 days. We may need to verify your identity before processing your request.

8.1 How to request deletion of your data

You can ask us to delete the personal data we hold about you — whether you use the Why Knott Hire website, customer portal, or our mobile app (published by Onward 2 Upward Ltd trading as Why Knott Hire).

To request deletion, do either of the following:

We may ask you to verify your identity, and we will action your request within 30 days.

What is deleted: your booking and contact details (name, email, phone, address, date of birth), uploaded driving-licence and proof-of-address documents, condition/handover photos, app-notification (push) tokens, and any usage-analytics records associated with you.

What we must keep, and for how long: records we are legally required to retain — chiefly financial and payment transaction records, which we must keep for 7 years to meet HMRC and accounting obligations. These are securely deleted once that period ends. Card numbers are never stored by us (payments are handled by our payment processor).

9. AI Chat Assistant

Our website and customer portal include an AI-powered chat assistant built using Anthropic's Claude. Please be aware:

10. Security

In the event of a personal data breach that poses a risk to your rights, we will notify the ICO within 72 hours and, where required, notify you directly.

11. Cookies

Our booking system uses essential session cookies to maintain your session while making a booking — these are always on and need no consent. With your consent, we also use Google Analytics cookies to understand how visitors use the booking site so we can improve it. You choose whether to allow analytics cookies via the banner shown when you arrive — Google Consent Mode v2 keeps analytics switched off unless you accept, and you can change your mind at any time. We also use Vercel Web Analytics, which is cookieless and collects only aggregated, anonymised usage statistics (such as page views, referrer, device type and country) — it is loaded only if you accept analytics, so choosing “Essential only” turns it off as well. With your consent, we also use Microsoft Clarity, which records anonymised, masked session replays and heatmaps so we can see where the booking site can be improved (it sets two first-party cookies and automatically hides on-page text and anything you type); like our analytics cookies it loads only if you accept, and choosing “Essential only” keeps it off. With your consent, we also use Google Ads cookies to measure whether an advertisement led to a booking and, where applicable, for remarketing; like our analytics cookies, these are set only if you accept via the banner, and choosing “Essential only” keeps them switched off. We do not set any advertising or cross-site tracking cookies without your consent.

Our public website is served through Cloudflare for security and performance. Cloudflare does not set advertising or tracking cookies; it only uses a strictly-necessary security cookie if it needs to verify that a request is genuine (for example to mitigate malicious or automated traffic), which requires no consent.

The customer portal (bookings.whyknotthire.co.uk) uses session cookies to keep you logged in, and authentication tokens stored locally in your browser to maintain your admin/customer session.

12. Children's Data

Our services are not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data about a child, please contact us immediately.

13. Changes to This Policy

We may update this policy from time to time to reflect changes in our services or legal requirements. We will post the updated policy on our website and, where changes are significant, notify you by email.

14. How to Complain

If you are unhappy with how we have handled your personal data, please contact us first at info@whyknotthire.co.uk.

If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): Website ico.org.uk · Helpline 0303 123 1113 · Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.

If you are located in the European Union or EEA, you also have the right to lodge a complaint with the data protection supervisory authority in your country of residence. A list of EU/EEA authorities is available at edpb.europa.eu.

Affiliate links

In our trip guides and your booking portal we may show links to Pitchup.com to help you find a campsite for your trip. Using them is entirely optional, and we do not share your personal data with Pitchup. We currently earn no commission from these links; if that changes we will update this notice.


This privacy policy was last reviewed on 29 June 2026 and covers the Why Knott Hire online booking system, customer portal, AI chat assistant, payment processing, and document management systems operated by Onward 2 Upward Ltd. The June 2026 review added our accounting (Xero) and gift-card print (Prodigi) processors, added cookieless Vercel Web Analytics (used only with your consent), and tightened public access to booking data so personal details are no longer readable without verification. The 17 June 2026 update disclosed our use of Google Ads conversion measurement, including Enhanced Conversions — a consent-gated feature that shares a one-way hashed form of your email address and name with Google to attribute bookings to ad clicks. The 18 June 2026 update added Microsoft Clarity — a consent-gated tool providing anonymised session replay and heatmaps, with on-page text and anything you type automatically masked. The 21 June 2026 update added Cloudflare as our website content-delivery, DNS and security provider (the booking system and customer portal are served directly and are not routed through Cloudflare's cache, so booking and customer data remains hosted in the UK). The 29 June 2026 update disclosed three consent-and-transparency items: our own first-party analytics (recorded anonymously and in aggregate by default, and linked to your visit or booking only if you accept analytics), aggregate email open & click tracking (a small invisible image and tracked links that tell us only whether emails were opened and which links were clicked, never to build individual profiles), and notification delivery records (which notifications we attempted and whether they succeeded, with no message content stored).