Privacy
What we know about you, why we need it, who else sees it, how long we keep it, and what you can tell us to do about it. Written to be read rather than to be defensible.
Last updated 25 September 2026. Version 3.4. What changed
Privacy at a glance
The whole notice, one line per section. Every line is the same sentence the section itself opens with, so nothing here is friendlier than what it summarises.
We keep your request so we can acknowledge it and respond. It does not create an account or authorise access to your website.
Who is responsible for your information
MZ Corp Limited, trading as Carqo, registered in England and Wales under number 17351738.
Everything Carqo is currently running. Sections for things not switched on yet are not shown.
We read a business’s own website to report how well machines can read it. Registrations, phone numbers, email addresses and postcodes found on the pages are removed before anything is stored.
Counts of how many people arrived and what they looked at. No analytics company, no advertising network, no third-party script.
One cookie, and only once you sign in. Nothing that needs your consent, so nothing asks for it.
Marketing goes off on request and stays off. The messages your account needs to work are not marketing and keep coming.
Nobody buys it. A short list of suppliers process it on our instructions, and this is the whole list.
The law, courts and the police
We disclose where the law requires it. It has never happened.
A buyer of the business would take on this notice.
Kept in London. Some of the suppliers that handle it on the way are elsewhere, and this section says which.
Encrypted in transit and at rest, one private store nothing can serve from, and a record of who did what.
Every category has a period, a reason and a job that actually deletes it. Any period not yet decided is named as such.
Eight rights, all free. Where you have an account, two of them are buttons rather than requests.
Complain to us through a form on this site, and to the ICO whether or not you complain to us first.
Carqo is for adults. The paid and contractual parts are for people 18 or over, we do not verify age, and we do not knowingly hold information about a child.
Every version is kept, with what changed and when. We email you before a material change takes effect, not after.
Contacting us about your information
Email admin@carqo.co.uk, or use the forms on this site. A person reads both.
Doing something about it
Every one of these opens a case with a deadline. Write to us and it starts the same clock as a button would.
What does Carqo use about me
Open the one that sounds like you. Everything here is in the full notice below as well.
Using Carqo for your businessA business, and the people in it.
| We use | Why | How long | More |
|---|---|---|---|
| Scanning a business website | To report how well automated systems can read a business’s own website. | Scan results are kept while the site is a live prospect or a customer, and the evidence extracts are capped at 200 characters each. | Read the section |
| Asking Carqo to check your website | To reply to you with what the check found, and to talk to you about it. | Kept while you are a prospect or a customer, and deleted when the enquiry is closed. | Read the section |
Things that happen anywaySecurity, counts and early-access requests.
| We use | Why | How long | More |
|---|---|---|---|
| Early-access enquiries and request emails | To record the early-access request you make, acknowledge it and notify the person handling it. | Up to 24 months, or earlier when the enquiry is closed or you ask for deletion. | Read the section |
| How many people arrived, and roughly where from | So Carqo can tell whether anything it does brings anybody, using counts that identify nobody and store nothing on your device. | The counts are kept as numbers. There is nothing in them that belongs to anybody, so nothing in them expires with a person. | Read the section |
Nothing here is used to build a profile of you for advertising, and nothing is sold. If a row looks wrong, tell us and we will correct it.
Early-access requests
We keep your request so we can acknowledge it and respond. It does not create an account or authorise access to your website.
Your email address is required. Your business website is optional and is stored as information, not fetched or scanned by this form. We record the wording you acknowledged and the applicable privacy version.
Early-access enquiries and request emails
To record the early-access request you make, acknowledge it and notify the person handling it.
- What we use
- email address
- optional business website
- the acknowledgement wording and privacy version
- receipt and repeat-request times
- email delivery state and provider references
- a keyed address hash for duplicate and suppression checks
- Why we are allowed to
- Our legitimate interests. Responding to the request you initiated, keeping it retrievable and preventing duplicate or unwanted messages. This one is optional.
- How long
- Up to 24 months, or earlier when the enquiry is closed or you ask for deletion. Delete the enquiry, queued messages and attempts. Keep a keyed suppression hash to prevent re-enrolment, and minimal provider references until provider deletion is handled.
- Who else sees it
- Cloudflare, Inc., Supabase, Inc., Resend, Inc.
- Is it automated
- No
- What you can do
- Ask for access or deletion through the contact page
- No account, marketing subscription or website-access permission is created
Cloudflare handles the request, Supabase stores the accepted enquiry and delivery jobs, and Resend processes the visitor acknowledgement and internal notification. Messages contain no tracking pixel. An early-access request does not subscribe you to promotional campaigns.
Duplicate requests do not create duplicate acknowledgement emails. A delivery failure leaves the saved request intact and can be reviewed by the authorised operator. A provider accepting a message is not proof that it reached your inbox.
After deletion, a keyed address hash prevents a retry or later repeat submission from enrolling you again. Provider deletion work is tracked separately; local deletion does not claim to delete a copy already held by a mail provider or recipient.
Who is responsible for your information
MZ Corp Limited, trading as Carqo, registered in England and Wales under number 17351738.
The data controller is MZ Corp Limited, a company registered in England and Wales under number 17351738, trading as Carqo. Its registered office is 128 City Road, London, EC1V 2NX.
Everything described here is done by us. Where somebody else decides for themselves what to do with your information, this notice says so and names them.
We have not appointed a Data Protection Officer, because we are not required to. That is a judgement we re-test before any new kind of processing starts rather than a settled fact.
Our ICO registration number is ZC208622.
What this notice covers
Everything Carqo is currently running. Sections for things not switched on yet are not shown.
This notice is generated from a register of what Carqo actually does, rather than written separately and kept in step by hand. A section appears here only once the thing it describes is running.
That is why this page may be shorter than you expect. It describes the Carqo you can use today, not the Carqo we are building.
It does not cover what anybody else does with information after we pass it to them. Where that happens, the section says so and tells you who to ask.
Scanning a business website
We read a business’s own website to report how well machines can read it. Registrations, phone numbers, email addresses and postcodes found on the pages are removed before anything is stored.
Somebody gives us the address of a business website and we read a limited number of its pages, the way a search engine would. We keep what we found and short extracts showing why.
Scanning a business website
To report how well automated systems can read a business’s own website.
- What we use
- the website address given for the scan
- facts the business has published on that website, such as what it offers, prices and locations
- extracts of page text, with registrations, telephone numbers, email addresses and postcodes removed before storage
- Why we are allowed to
- Our legitimate interests. Reporting to a business how machine-readable its own published website is, at its own request, from pages it has published.
- How long
- Scan results are kept while the site is a live prospect or a customer, and the evidence extracts are capped at 200 characters each. Deleted with the site row, which cascades to every scan, finding and vehicle. A person named in a page title cannot be detected by pattern, so the control is how little is kept rather than a filter.
- Who else sees it
- Nobody outside Carqo.
- Is it automated
- No
- What you can do
- Ask us to delete a scan of your website
Asking Carqo to check your website
To reply to you with what the check found, and to talk to you about it.
- What we use
- business name
- your name
- email address
- the website address where you give one
- phone number where you give one
- Why we are allowed to
- Our legitimate interests. Replying to a business that asked for a report about its own website and left its details to receive it. This one is optional.
- How long
- Kept while you are a prospect or a customer, and deleted when the enquiry is closed. Deleted with a statement, on request or when the enquiry closes.
- Who else sees it
- Netlify, Inc., Supabase, Inc.
- Is it automated
- No
- What you can do
- Ask us to delete your details
- Object to it, and we stop
We honour the site’s robots.txt file before every page. A site that asks crawlers to stay away is not read at all, and the scan stops with nothing kept.
We never copy photographs, and we never keep a registration number. Where a plate is on the page we record only that one was there.
A page title could carry somebody’s name and no pattern reliably finds one. The control is how little text we keep, which is 200 characters per finding, rather than a filter we could claim catches everything.
Measuring the site
Counts of how many people arrived and what they looked at. No analytics company, no advertising network, no third-party script.
There is no Google Analytics here, no Meta pixel, no advertising identifier and no third-party script of any kind. Your browser is not asked to contact any company other than ours while you use this site.
We count how many people arrive and roughly where from: whether you came from a search engine, a social network, a link somebody posted, or straight to us. We keep the name of a search engine or a social network and never the name of any other site you came from, because that can say something about you and a search engine cannot.
How many people arrived, and roughly where from
So Carqo can tell whether anything it does brings anybody, using counts that identify nobody and store nothing on your device.
- What we use
- a count per day of arrivals from one of six broad channels, onto one of a couple of dozen page templates
- the name of a public search engine or social network, where that is where you came from, and never any other website
- a campaign label Carqo itself wrote into a link
- nothing that identifies who arrived, and no page address you were on before
- Why we are allowed to
- Our legitimate interests. Knowing whether anything Carqo does brings anybody. The alternative is spending on things nobody can tell apart, and the design was chosen so that this could be answered without asking a visitor to accept anything.
- How long
- The counts are kept as numbers. There is nothing in them that belongs to anybody, so nothing in them expires with a person. There is nothing to delete. No row here names anyone, so no row here can be found by name, and closing an account removes nothing from a count that never knew about it.
- Who else sees it
- Supabase, Inc.
- Is it automated
- No
- What you can do
- Nothing is stored on your device, so there is nothing to clear and nothing to accept
- If your browser sends Do Not Track or Global Privacy Control, nothing is counted. Not every browser offers either setting, and Safari offers neither
- Block the request to /api/arrival and the count simply does not happen. Nothing else on the page depends on it
Cookies
One cookie, and only once you sign in. Nothing that needs your consent, so nothing asks for it.
Signed out, this site sets no cookies at all. That is why you have not been asked to accept any.
Signed in, there is one: the cookie that keeps you signed in. It is strictly necessary for a service you asked for, which is the one category the law does not require consent for, and it carries nothing but a session reference.
If that ever changes we will ask you properly before setting anything that is not strictly necessary, and this page will say so before it happens rather than after.
Emails, and turning them off
Marketing goes off on request and stays off. The messages your account needs to work are not marketing and keep coming.
There are two different things and they are deliberately kept apart, because bundling them is how a business ends up either spamming somebody or leaving them unable to use their account.
| Stops | Keeps coming |
|---|---|
| Launch news and anything promoting Carqo | A reply to something you asked us |
| Anything about a product we would like you to use | A notice we are required to send you |
Every marketing email carries an unsubscribe link and the header that makes your email app’s own unsubscribe button work. When you use either, we record a one-way hash of your address so a later import cannot quietly put you back.
That record deliberately survives deleting your account. If you come back later and want to hear from us, ask and we will lift it.
Who else sees it
Nobody buys it. A short list of suppliers process it on our instructions, and this is the whole list.
We do not sell, rent or trade your details. No advertising network, analytics company or data broker receives anything from this site.
These are the organisations that receive anything, what they do with it, and where.
| Who | What they do | Where |
|---|---|---|
| Cloudflare, Inc. | Runs the website and its forms, carries every request, and turns away attacks. Acts only on our instructions. It is our domain name service, and since 25 September 2026 it also runs this website and the forms on it. What you type into a form, such as an early-access or privacy request, passes through it on the way to our database in London. We have set it up not to keep a copy of what passes through and switched off its logs of the site’s activity. Its machines are worldwide, so where a request is handled depends on where you are. | Wherever you are. Their machines are worldwide |
| Netlify, Inc. | Ran the website until 25 September 2026. Acts only on our instructions. It ran this website until 25 September 2026, when we deleted the site we had there, including any early-access requests made through its form. It no longer receives anything from this site. It is in the United States. | United States |
| Supabase, Inc. | Runs the database everything is stored in. Acts only on our instructions. The database is in London. That is where the record is kept; it is not a claim that nobody at Supabase outside the UK can ever reach it, which is a separate question and an open one. | United Kingdom |
| Resend, Inc. | Sends the emails we send you. Acts only on our instructions. Which Resend region this account uses has not been established. | United States |
| Courts, police and regulators | Where the law requires or permits it. A public body, where the law requires it. This has never happened. | United Kingdom |
This list is held in our own code next to the parts of the application that reach these services, and a test fails the build if the application starts contacting somebody who is not on it. That is the mechanism that stops this table quietly going out of date.
The law, courts and the police
We disclose where the law requires it. It has never happened.
We would disclose information where the law requires it, for example under a court order, or where it is necessary to prevent or detect a crime. That has never happened.
We disclose what the request lawfully reaches and no more, and we tell you unless we are prohibited from doing so.
If Carqo is sold or closes
A buyer of the business would take on this notice.
If the business were sold or merged, your information would transfer with it and the buyer would be bound by this notice until they told you otherwise.
Where your information goes
Kept in London. Some of the suppliers that handle it on the way are elsewhere, and this section says which.
What you give us, and anything you upload, is kept in London. That is a choice rather than a legal requirement: the law would allow us to keep them elsewhere with the right paperwork, and we would rather not need the paperwork for a photograph of somebody’s passport.
Saying only that would be misleading, because things pass through other places on the way. The website you are reading is served by a network with machines all over the world, which also carries the request to it, and the email that reaches you is sent from the United States. What we send each of them is the request or the message, not your account.
The table above says where each supplier processes. Where a supplier is outside the UK, that is a restricted transfer and needs a mechanism the law recognises. Which mechanism is in place for each of them is being confirmed in writing before Carqo carries real customers, and where it is not yet confirmed we say so rather than assert a contract we cannot produce.
We do not say "all your data stays in the UK". It would be easier to write and it would not be true.
How it is kept safe
Encrypted in transit and at rest, one private store nothing can serve from, and a record of who did what.
- The site is served only over an encrypted connection, and your details are encrypted in transit and at rest.
- There are two separate stores for files. One is public and is the only one anything can be served from. The other is private, holds identity documents and unredacted originals, and no address reaches it.
- Forms refuse submissions sent from any other website, and limit how many can be sent from one place.
- A sign-in link is treated as a credential: it is never written to a log, and an error report from your browser has its query string dropped whole rather than scrubbed, because a query string is where a token ends up.
- Actions taken on an account are recorded with the person or system that took them.
No system is perfect. If we suffer a breach that puts you at risk we will tell you, and we will report it to the ICO within 72 hours as the law requires.
How long we keep things
Every category has a period, a reason and a job that actually deletes it. Any period not yet decided is named as such.
A retention period only means something when three things are true: it is stated, it is published, and something runs and deletes. A published period the code does not keep is worse than no period at all, because it is a promise the system contradicts.
The periods below are read out of the same constants the deletion jobs read, so the number you are reading and the number a job acts on are the same number.
| What | How long | From when, and why |
|---|---|---|
| Early-access requests | 24 months at most | Or earlier, when the enquiry is closed or you ask us to delete it |
| Backups | 35 days | An erased record is never restored to live from one |
A record can be held past its period where an open dispute, a legal claim or a request from you would otherwise be destroyed underneath it. That takes a named person and a written reason, and the database refuses a freeze without both.
Restoring a backup would move the system backwards in time. It must not move your privacy backwards in time, so an erasure, a freeze or a document destruction that happened after a backup was taken is reapplied before that system is used again, from a record kept outside the database being restored.
What you can ask us to do
Eight rights, all free. Where you have an account, two of them are buttons rather than requests.
These are free, you do not have to give a reason, and we will not ask for one. We answer within one month.
See what we hold about you
Ask us for a copy of everything we hold about you, and we will send it.
UK GDPR Article 15
Correct something that is wrong
Tell us what is wrong and what it should say, and we will fix it.
UK GDPR Article 16
Delete what we hold about you
Ask us and we delete it. You do not have to give a reason.
UK GDPR Article 17
Pause what we do with it
Ask us to keep your information but stop using it while something is being sorted out.
UK GDPR Article 18
Take it somewhere else
Get the information you gave us in a machine-readable file you can hand to somebody else.
This right covers what you gave us.
UK GDPR Article 20
Object to something we do
Where we rely on our own legitimate interests, you can object and we have to stop unless we can show a compelling reason not to.
UK GDPR Article 21
Stop the marketing
An absolute right, with no balancing and no reason needed. It takes effect at once.
It stops marketing. It does not stop a reply to something you asked us, because that is not marketing.
UK GDPR Article 21(2)
Ask about an automated decision
Ask us to explain a decision, tell us why you think it is wrong, and have a person look at it again.
Nothing on Carqo currently decides something significant about you without a person or a fixed rule in the path. This route exists anyway, because you should be able to contest a decision whether or not the law compels us to let you.
UK GDPR Article 22
Complain about how we handled your information
Open a complaint with us. It gets a reference and a deadline, and you can see where it is up to.
You do not have to come to us first. Going straight to the ICO costs you nothing and affects nothing else.
UK GDPR Article 77 gives you the separate right to complain to the ICO
Where we need to be sure it is you, we ask for the least that will do. We do not ask for identity documents to answer a request about an email address you can already prove you control.
If you are unhappy with us
Complain to us through a form on this site, and to the ICO whether or not you complain to us first.
You can complain to us and we have to take it. There is a form rather than an email address you have to hunt for, and it creates a case with a reference so you can see where it is up to.
You do not have to complain to us first. Going to the regulator instead costs you nothing and affects nothing else. The Information Commissioner's Office regulates data protection in the UK.
- Our ICO registration number is ZC208622
- Helpline 0303 123 1113
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Age
Carqo is for adults. The paid and contractual parts are for people 18 or over, we do not verify age, and we do not knowingly hold information about a child.
We do not ask your age when you create an account and we do not verify it, so we are not going to claim we check. What we do is keep the paid and contractual parts of Carqo to adults, and say plainly that is where the line is.
Carqo is not designed for or directed at children, and nothing here profiles anybody or serves advertising. If you believe we hold information about a child, tell us and we will delete it.
Changes to this notice
Every version is kept, with what changed and when. We email you before a material change takes effect, not after.
When something material changes we update the date at the top and email the people it affects before it takes effect.
Continuing to browse the site is not agreement to a new version, and we do not treat it as such. Where a change needs your agreement we will ask for it.
Changing this notice does not change what you already agreed to. Your consent is stored with the exact wording you were shown on the day.
Contacting us about your information
Email admin@carqo.co.uk, or use the forms on this site. A person reads both.
For anything to do with your information, email admin@carqo.co.uk or use the request forms in your account. A person reads that address.
You can write to us instead: MZ Corp Limited, 128 City Road, London, EC1V 2NX.
We do not publish a telephone number for privacy requests. A request needs a written record with a date on it, because the clock for answering starts the day it arrives, and a phone call leaves neither.