Privacy notice
Last updated 27 September 2026
The short version
When you ask for quotes, we send your name, contact details and postcode to local garages so they can quote you. That is the whole point of the service, and it only happens because you ticked the box to say we could. We don't sell your data to anyone else.
Qostly Shopping (in development)
Qostly Shopping is not live yet. Its public page collects no personal data: there is no account, form or sign-up. The website analytics described below apply to it as to the rest of the public site. Before Shopping shows retailer offers or links, we will update this notice to explain what happens when you follow a link to a retailer, including any cookies the retailer or its affiliate network sets.
Who we are
Qostly is a product of Digital Marvels Limited, which operates this service. For enquiries, email contact@digitalmarvels.tech. Company and legal information.
What we collect, and why
- Your quote request
- Your name, email address, phone number if you give one, your postcode, the service you need, and anything you tell us about your vehicle. We need this to pass your request to garages — without it there is nothing to send.
- Quotes, agreements and approved changes
- We store garages' itemised quote revisions, the quote you accept, the resulting agreement history, change-order decisions and completion or cancellation records. This gives both sides a reliable record of what was authorised. Submitted revisions are not edited in place.
- Secure driver access and evidence photos
- Access credentials are checked against one-way hashes. Queued emails contain the secure access link until notification records are deleted; the link itself expires after 30 minutes. For a price increase, a garage may upload supporting photos. We validate them, remove embedded metadata and keep them in private storage visible only to the driver, that garage and authorised Qostly administrators.
- Garage accounts and authentication
- If you create a garage account, we collect your name and email address. Neon Auth stores the account, password credentials, verification status and session records. Passwords are handled by the authentication service; Qostly does not store them in its application database.
- Garage claims
- A claim records your account, name, role, phone number and any message you provide. We use it to verify that you represent the garage before granting access to its listing or leads.
- Listing corrections
- A correction records your name, email address, role if supplied, and the change you request so an administrator can check and apply it.
- A hashed version of your IP address
- We store a one-way hash, never the address itself. We use it only to stop automated abuse of the request form. We also retain a shortened browser user-agent string. Our hosting and security providers may process network addresses to deliver and protect the service.
- How you found us
- With analytics consent, we retain validated campaign labels (source, medium and campaign) in session storage for up to 24 hours and attach them to a submitted request. Declining or withdrawing analytics stops future attribution and clears that browser campaign record. Previously saved request attribution follows request retention. Do not put personal details in campaign links.
- Optional website analytics
- If you allow analytics, Microsoft Clarity records masked clicks, scrolling, navigation and page interactions on Qostly's public pages. It turns those events into behavioural metrics, heatmaps and session replays so we can find confusing or broken journeys. We also count consent-dependent quote starts, completed steps, validation failures and successful submissions with Vercel Analytics, without form answers or request identifiers. Clarity never runs in driver, garage or administrator workspaces, and we do not send it account or request identifiers.
Our lawful basis
We rely on your consent to share your details with garages. You give it by ticking the box on the request form, and we record when you did. You can withdraw it at any time by emailing us — though if a garage already has your details, you will need to contact them directly as well, because they hold their own copy.
When you ask us to create an account, review a claim or correct a listing, we use the information to provide that requested service, secure the directory and prevent fraudulent access. These forms stay closed until our legal identity and privacy review are complete.
Microsoft Clarity is optional and relies on your consent. It does not load until you choose “Allow analytics”. You can change your choice at any time through Analytics settings in the footer. Declining analytics does not affect Qostly.
Who we share it with
Local garages. We send your request to at most three verified garages in Liverpool who cover the service you need. A directory listing alone does not make a garage eligible to receive your details. Once a garage has your details, it is responsible for them under its own privacy policy. We cannot delete a garage's copy on your behalf.
Our suppliers. We use Neon to host our database (in London), Vercel to run the website, Neon Auth to manage accounts and sessions, Vercel Private Blob to hold change-order evidence, Resend to send request and marketplace email, and the sender configured within Neon Auth for account email, and Cloudflare to protect public forms from bots. They process data on our instructions.
Microsoft Clarity. If you allow analytics, Microsoft processes masked public-page usage data for Qostly. We use it only to improve the site, never for advertising. Read the Microsoft Privacy Statement.
Vercel also collects aggregate public-page visits and performance measurements without our optional funnel events when analytics is declined. Browser analytics do not run in private workspaces. We do not sell your data.
Where it is held, and for how long
Our application database is hosted in London. Other suppliers may process data in other countries; our supplier and transfer arrangements must be reviewed before collection opens. We keep quote requests, access sessions, quote and agreement histories, notification records and private evidence for 24 months from the request date, after which the retention job deletes the database records and associated private files. Abandoned staged evidence uploads are removed after 24 hours. Access links expire after 30 minutes and request sessions after 30 days; their records remain subject to request retention.
We keep account information while the account is active. Claims and corrections are kept while they are needed to verify access, maintain an audit trail and resolve disputes. You can ask us to close an account or erase information that no longer needs to be retained.
Clarity has its own retention periods, separate from Qostly's database retention. See Microsoft's Clarity retention information.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to what we're doing with it. Email contact@digitalmarvels.tech and we will respond within one month.
If you think we've handled your data badly, you can complain to the Information Commissioner's Office at ico.org.uk. We'd rather you told us first so we can put it right.