Privacy Policy
Last updated: 16 April 2026
1. Who we are
odo.ie is operated by Sprout Media Limited, a company registered in Ireland with its registered office at 26 Upper Pembroke Street, Dublin, D02 X361. Sprout Media Limited is the data controller for the personal data processed through odo.ie.
For any data protection or privacy query, you can contact us through the website or write to us at the postal address above. We have not appointed a Data Protection Officer as we are not required to do so under Article 37 GDPR, but the directors of Sprout Media Limited handle all privacy matters directly.
2. The data we collect
We collect only what is necessary to provide the service, and we collect it directly from you — we do not buy, rent, or receive your personal data from any third-party source.
- Account data: email address, display name (optional), postal address (optional)
- Authentication data: hashed password (bcrypt) or magic-link tokens, session tokens, and IP address at sign-in time (for security)
- Vehicle data: registration, make, model, colour, fuel type, year, odometer readings, VIN (optional)
- Service data: service type, date, odometer, cost, garage name, notes, uploaded receipt photos (optional)
- Fuel & logbook data: fill-up volumes, prices, locations, trip origins/destinations, distances, purpose
- Renewal data: NCT, motor tax, and insurance renewal dates and amounts
- Contact-form messages: name, email, subject, and message content when you write to us
We do not collect payment-card details (we do not yet take payments), PPS numbers, driving licence information, biometric data, or any data from your vehicle's onboard systems.
3. Why we process your data and our legal basis
Under Article 6 GDPR we rely on the following legal bases:
- Performance of a contract (Art 6(1)(b)) — creating and securing your account, storing the vehicle, service, fuel and logbook records you enter, sending the service and renewal reminders that are the core of the product, and providing the export/print tools you use.
- Consent (Art 6(1)(a)) — any optional marketing emails and any non-essential analytics or advertising cookies we may introduce in future. You can withdraw this consent at any time through the cookie icon in the bottom-left of every page, or from your notification settings. Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
- Legitimate interest (Art 6(1)(f)) — responding to your contact-form messages, protecting the service against fraud and abuse, and keeping minimal security logs. We have assessed that these interests are not overridden by your rights and freedoms.
- Legal obligation (Art 6(1)(c)) — responding to lawful requests from Irish authorities, and retaining limited records where tax or company law requires it.
We do not sell, rent, or share your personal data for advertising, and we do not use your data to build marketing profiles.
4. How long we keep your data
We keep data only for as long as we need it, on the following basis:
- Account and vehicle data: until you delete your account. Deletion is permanent and propagates within 24 hours.
- Encrypted database backups: retained for up to 30 days on a rolling basis, after which they are overwritten. Deleted records remain in backups until they age out.
- Authentication tokens: access tokens expire after 15 minutes; refresh tokens after 30 days of inactivity.
- Security and access logs: up to 90 days, then automatically purged.
- Contact-form messages: up to 2 years, to allow us to follow up on any related query or dispute.
You can export all your data (JSON or CSV) at any time from Settings, and you can delete your account at any time from Settings → Account.
5. Who we share your data with
We use a small number of carefully chosen data processors who host our infrastructure. Each is bound by a written Data Processing Agreement and processes your data only on our instructions:
- Neon Inc. — PostgreSQL database hosting in the EU-West (Ireland / Frankfurt) region. All vehicle, service, fuel and logbook data lives here.
- Netlify, Inc. — application hosting and serverless functions that power the site.
- Resend (Drop Labs, Inc.) — email delivery for magic links, welcome emails, reminders and contact-form receipts.
- Bunny.net — image CDN for the vehicle photos you upload.
- OpenStreetMap Foundation — map tiles on the NCT centres map. No personal data is sent to OSM; tile requests carry only the map area you are viewing.
We do not share your data with any other third party except where required by law (for example a valid request from An Garda Síochána or the Revenue Commissioners).
6. International transfers
Your primary database is hosted inside the EU (Ireland / Frankfurt), so your day-to-day vehicle and service data does not leave the EEA. Some of our processors (Netlify, Resend, Bunny.net) are US-based and may process limited personal data (your email address, IP address, or request metadata) in the United States. We rely on the EU–US Data Privacy Framework where the provider is certified, and on the European Commission's Standard Contractual Clauses (SCCs) as a fallback safeguard. You can request a copy of the relevant transfer mechanism by contacting us.
7. Security
All data is encrypted in transit (TLS 1.2+) and at rest. Passwords are hashed with bcrypt and never stored in plain text. Authentication tokens are cryptographically signed and time-limited. Access to production systems is restricted to named administrators using multi-factor authentication. We have procedures in place to notify the Data Protection Commission and affected users within 72 hours of becoming aware of a notifiable personal data breach.
8. Your rights under GDPR
You have the following rights in relation to your personal data:
- Access — request a copy of the data we hold about you. Use the Export feature in Settings, or write to us.
- Rectification — correct any inaccurate data. You can edit almost everything directly in the app.
- Erasure (“right to be forgotten”) — delete your account from Settings → Account, or ask us to erase it.
- Restriction — ask us to pause processing while a query is resolved.
- Portability — receive your data in a structured, machine-readable format (JSON or CSV) via the Export feature.
- Objection — object to processing based on legitimate interest, including disabling email reminders in notification settings.
- Withdraw consent — where consent is our legal basis, you can withdraw it at any time without affecting processing carried out before withdrawal.
- Not be subject to automated decision-making — see section 9.
We aim to respond to any rights request within one month, as required by Article 12(3) GDPR.
9. Automated decision-making and profiling
We do not carry out automated decision-making that produces legal or similarly significant effects on you, and we do not build marketing or behavioural profiles. Our reminder logic is a deterministic calculation based on dates and mileage you enter — it is informational only and does not make decisions about you.
10. Children
odo.ie is a tool for vehicle owners in Ireland and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has created an account, please contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top of the page always reflects the most recent change. If we make a material change that affects how your personal data is processed, we will notify you by email before the change takes effect.
12. Complaints — your right to lodge a complaint with the DPC
If you believe we have handled your personal data in a way that breaches GDPR or the Data Protection Act 2018, we would appreciate the chance to put things right — please contact us first. You also have the right at any time to lodge a complaint with the Irish supervisory authority:
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28
Phone: +353 (0)761 104 800 / +353 (0)57 868 4800
Website: www.dataprotection.ie
13. Contact
For any privacy-related query, use our contact form or write to Sprout Media Limited, 26 Upper Pembroke Street, Dublin, D02 X361.