Privacy Policy

Superhero Panda Ltd — Last Updated: 22 June 2026

1. Introduction

Welcome to BIB. We are committed to protecting your privacy and handling your personal data transparently and securely.

This Privacy Policy explains how Superhero Panda Ltd ("we", "us", "our") collects, uses, stores, and protects your personal information when you use BIB - our vehicle history and intelligence service (the "Service").

Data Controller:
Superhero Panda Ltd
Registered in England and Wales - Company Number: 16790496
Registered Office: First Floor, Stanbridge Buildings, Stanbridge Road, Leighton Buzzard LU7 4QQ
Email: privacy@superheropanda.com

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Superhero Panda Ltd is the Data Controller.

2. Information We Collect

2.1 Information You Provide Directly

  • Account details (name, email address) when you register
  • Vehicle registration numbers (VRMs) you enter when searching for vehicle history
  • Payment information processed via Stripe when purchasing Bib credits

2.2 Information We Collect Automatically

  • Device information (IP address, browser type, operating system)
  • Usage data (pages viewed, features used, time spent on our Service)
  • Cookies and similar tracking technologies (see Section 10)

2.3 Information From Third Parties

DVSA MOT History API: When you search for a vehicle, we retrieve that vehicle's MOT test history from the Driver and Vehicle Standards Agency (DVSA) via their official API. This data includes the vehicle's make, model, colour, engine size, recorded mileage at each test, and test results including any defects or advisories noted by the examiner. This data is sourced from official government records and is retrieved at the point of your search. We do not access DVLA registered keeper records - BIB does not know who owns or has owned a vehicle.

3. Legal Basis for Processing

Consent: When you explicitly agree to processing activities (e.g., marketing communications).

Contractual Necessity: To provide you with the Service - for example, processing a BIB lookup when you spend a credit.

Legitimate Interests: To improve our Service, conduct analytics, prevent fraud, and ensure security.

Legal Obligation: To comply with legal and regulatory requirements including tax and financial record-keeping.

4. How We Use Your Information

  • Create and maintain your account
  • Process vehicle lookups you initiate and deliver results
  • Manage your Bib credit balance
  • Process payments via Stripe and issue transaction confirmations
  • Store your lookup history so previously searched vehicles can be re-accessed without spending additional credits
  • Provide customer support
  • Send important service and account notifications
  • Prevent fraud and abuse of the credit system
  • Improve BIB's intelligence and analysis features

5. AI and Automated Processing

BIB uses automated analysis to generate vehicle intelligence from MOT history data. This includes classifying advisory items, identifying patterns across test history, scoring reliability, and comparing a vehicle against peer-group benchmarks. This analysis is performed entirely on data retrieved from DVSA records and does not involve profiling of individual users.

You have the right to be informed when automated processing is used and to request human review of any decision that significantly affects you.

6. Data Sharing and Disclosure

6.1 Your Lookup Data

Vehicle lookup results generated for your account are not shared with other users or third parties. Your lookup history is visible only to you and to authorised Superhero Panda staff for support and fraud prevention purposes.

6.2 Service Providers

We share data with trusted third-party service providers who assist us in operating the Service:

  • Firebase (Google) - cloud infrastructure, user authentication, and data storage
  • Stripe - payment processing for Bib credit purchases
  • DVSA - source of MOT history data (data retrieved on request, not provided by us to DVSA)
  • Vercel - website hosting and delivery

All service providers are contractually bound to protect your data and use it only for specified purposes.

6.3 Legal Requirements

We may disclose your information when required by law, regulation, legal process, or governmental request, or to enforce our Terms of Service, protect our rights or safety, or prevent fraud.

6.4 Business Transfers

If Superhero Panda is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.

7. International Data Transfers

Your data is primarily stored and processed within the United Kingdom and the European Economic Area. Firebase and Vercel infrastructure may process data in other regions. Where data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place including Standard Contractual Clauses approved by the ICO.

8. Data Retention

  • Account data: retained while your account is active
  • Lookup history and credit balance: retained while your account is active and for 12 months after closure
  • Payment records: retained for 7 years to meet HMRC requirements
  • Inactive accounts: if you do not log in for 24 months, we will contact you before deletion

You can request deletion of your data at any time (subject to legal obligations). See Section 9 for your rights.

9. Your Rights Under UK GDPR

Right to Access - request a copy of the personal data we hold about you

Right to Rectification - correct inaccurate or incomplete data

Right to Erasure - request deletion of your personal data in certain circumstances

Right to Restrict Processing - limit how we use your data in certain circumstances

Right to Data Portability - receive your data in a structured, machine-readable format

Right to Object - object to processing based on legitimate interests or for direct marketing

Right to Withdraw Consent - withdraw consent at any time without affecting prior processing

Right to Lodge a Complaint - complain to the ICO if you believe your rights have been violated

How to Exercise Your Rights

Email: privacy@superheropanda.com
Address: First Floor, Stanbridge Buildings, Stanbridge Road, Leighton Buzzard LU7 4QQ

We will respond within one month. In complex cases we may extend this by two months and will inform you of any delay.

10. Cookies and Tracking Technologies

Essential cookies - required for the Service to function (authentication, security, session management)

Performance cookies - help us understand how you use the Service (analytics, error reporting)

Functional cookies - remember your preferences and settings

You can control cookies through your browser settings. Disabling certain cookies may affect functionality.

11. Security

We implement industry-standard security measures including encryption in transit (TLS/SSL) and at rest, secure authentication and access controls, regular security audits, and incident response procedures.

If you suspect a security breach, contact us immediately at security@superheropanda.com.

12. Data Breach Notification

If we experience a data breach posing a risk to your rights and freedoms, we will notify the ICO within 72 hours, notify affected individuals without undue delay, and take immediate steps to contain and remedy the breach.

13. Children's Privacy

BIB is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, contact us at privacy@superheropanda.com.

14. BIB Vehicle Data - Additional Detail

14.1 Vehicle Registration Numbers

A VRM identifies a vehicle. BIB does not access DVLA registered keeper records and does not store or display keeper identity information. VRMs you enter are processed solely to retrieve publicly available MOT history from the DVSA API.

14.2 DVSA Data

MOT history data is sourced from the DVSA MOT History API - official government data. Superhero Panda Ltd does not create or control this data; we retrieve and present it. The accuracy and completeness of MOT history data depends on DVSA records.

14.3 Lookup History

BIB records which vehicles you have previously looked up so that you can re-access results without spending additional credits. This lookup history is associated with your account and is not shared with other users or third parties.

14.4 Payments

Bib credit purchases are processed by Stripe. Stripe handles payment card data directly - Superhero Panda Ltd does not store card numbers, CVV codes, or full payment credentials. We retain records of transactions (amount, date, credits purchased) for 7 years for accounting purposes.

15. Updates to This Policy

We may update this Privacy Policy to reflect changes in our data practices or legal requirements. When we make significant changes, we will update the "Last Updated" date and notify you via email or prominent notice. Continued use after changes constitutes acceptance.

16. Contact Us

Data protection enquiries:
Email: privacy@superheropanda.com
General enquiries:
Email: support@superheropanda.com

Complaints to the ICO

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Phone: 0303 123 1113
Website: ico.org.uk/make-a-complaint