Your information
Privacy notice
This notice explains how REVU MOTO LTD uses personal information supplied through our motorbike-valuation wizard and related enquiries.
Who controls your information
REVU MOTO LTD, trading as REVU MOTO, is the controller of the personal information described in this notice. REVU MOTO LTD is registered in England and Wales under company number 16046819. Our registered office is 30 Cleeve Road, Basingstoke, Hampshire, United Kingdom, RG24 9RZ. The registered office is not necessarily a customer visiting address; any customer visit must be arranged in advance.
For privacy questions or to exercise your rights, WhatsApp REVU MOTO on +44 7405 756426 or write to the registered office above.
What we collect
The current four-screen valuation form collects what you want to do; the motorbike's UK registration or, without a standard UK registration, its make, model and year; mileage and unit; overall condition and optional notes; photographs or your choice to add them later; your price expectation, another offer or part-exchange target where relevant; your name, email address, optional phone number and preferred contact route; enquiry source; and the declarations you make. You may also add an optional variant or manual make, model and year for a UK-registered motorbike. If you choose the optional official lookup, we may retain the relevant DVSA vehicle and MOT snapshot, its source and retrieval time, your confirmation or correction, and which identity fields differed from your answers.
If the valuation progresses, we may ask for further information through the secure portal or an agreed contact route. That may include keeper and V5C position, selling authority and ownership evidence, provenance or theft history, modifications, detailed mechanical and cosmetic condition, service, MOT and recall information, outstanding-finance and settlement information, timing, the motorbike's location and proposed inspection, collection or handover arrangements. Do not send another person's personal information or any document, account, login or bank details unless REVU MOTO has provided an approved process for the specific check.
Fields marked as required are needed to identify and value the motorbike, confirm that you have authority to sell it, give us a usable way to respond and prepare secure valuation-portal access. A valid email address is required for the valuation so the receipt can issue private tracking instructions; creating a portal account remains optional. If you do not provide the required fields, you can ask a general question but we may not be able to complete a valuation. Fields marked optional help us make the first review more useful but are not required.
Do not upload or send a V5C copy or document reference, driving licence, bank details, finance login, finance account number, full finance agreement or another identity document through the public wizard. A V5C identifies the registered keeper; it is not proof of ownership. We verify identity and selling authority separately if a purchase progresses.
If someone else is the registered keeper or owner, describe only your relationship and authority to sell. Do not enter that person's name, contact details or identity-document information in the public form.
If you create a valuation-portal account, we also collect the email address you use for the account. We store a one-way password derivation with a unique random salt, rather than your readable password, together with account dates, failed sign-in counts, temporary lockout information and one-way digests of active session and security tokens. The portal shows a limited customer view of valuations linked to that account. A private valuation claim code is shown to the submitting browser once; only its one-way digest, issue date, expiry and use state are stored.
If you request a customer password reset, we store the account identifier, a one-way digest of the random reset token, its request and one-hour expiry times, use or invalidation state, and bounded email-delivery information such as status, provider message ID and error code. We do not store the raw reset token in D1. Resend receives it inside the account-security email link and may retain that message under its configured provider-retention period; the token then arrives in the link fragment and is held briefly in the account page’s memory.
After submission, we may also issue one-click portal handoffs. The submitting browser can receive a short-lived receipt token, and an unlinked valuation’s transactional emails can each receive an independent one-use email token. The handoff tables store only a one-way digest of each random token, the valuation or email notification it belongs to, its issue and expiry times, and whether and by which account it was consumed. If you respond to a published offer in the portal, we collect your choice—interested, question or not proceeding—an optional message of up to 500 characters and the response time. We also retain the customer-visible offer amount, bounded REVU MOTO offer message and publication time that your response concerned, so a later replacement offer cannot change the meaning of your recorded choice. A one-way digest of a random request identifier prevents duplicate responses. A new portal response counts as substantive valuation activity for the retention period described below; retrying the same response does not extend it again.
If a valuation is linked to your signed-in customer account and still open, you may add motorbike photographs later through that secure account. The service accepts no more than eight photographs and 50 MB across one valuation, with a 10 MB limit for each stored file. Supported JPEG, PNG and WebP originals over that limit may be resized in your browser before upload. Files that do not need or support browser resizing can retain embedded camera metadata, such as capture time, device details or location; remove location metadata before upload if you do not want it included. We record the file type, byte size, upload time, private random storage location and one-way SHA-256 digests of the upload request key and file content. Those digests let an interrupted request be retried without storing the raw retry key or keeping a second copy of the same file. A genuinely new successful portal photograph is substantive valuation activity for the retention period below; replaying the same upload is not.
For each new portal response, we also create a separate staff-alert record containing the random response and valuation identifiers, delivery and attempt state and relevant times. A send-eligible record acts as the alert anchor while that response remains unreviewed; later alert records are marked superseded and do not send another email while that anchor is active. Every response still remains visible and actionable in the private admin portal. Reviewing the anchor lets a later response become the next alert even if an older coalesced response remains unreviewed. A terminal, dead-letter, uncertain or coalesced alert record does not act as an anchor. This coalescing limits unnecessary provider disclosures without hiding portal work.
Where a response-alert send is attempted, its record may also contain a bounded provider message ID and the exact frozen outbound alert. The fixed generic message says that one or more replies need review and contains only the valuation reference, the anchor's response/alert time and secure admin-portal link, with fixed REVU MOTO sender and recipient addresses. It does not copy your response category, optional message, motorbike label, email address or telephone number. Its provider idempotency key contains the random anchor-response identifier so an explicitly rejected attempt can be retried safely.
A separate non-personal counter limits response-alert provider attempts across all valuations to 20 per UTC date. When that budget is full, the provider is not called and no attempt is added; a new send-eligible alert remains pending and can be attempted after the UTC date changes. This reserves the rest of the shared Free-plan email allowance for customer receipts, progress messages, password resets and other customer-critical mail.
For transactional valuation email, we keep the kind and customer-visible status of the update, any published offer amount and bounded REVU MOTO offer message, attempt and retry times, provider message ID, delivery state and allowlisted signed delivery-event identifiers. To retry safely without sending a different or duplicate message, the valuation record also keeps the exact outbound provider request, its first-attempt time and a pseudonymous correlation tag; that request contains the destination address, sender and Reply-To, subject and rendered email content. For a valuation not already linked to an account, the rendered portal link includes the raw one-use email handoff token in its URL fragment. The frozen request is deleted with the valuation record under the retention policy below. If an address bounces, complains or is suppressed by the provider, we retain a keyed, non-reversible representation of the normalized address and the suppression reason so the service does not keep sending to it. We do not retain the provider's raw webhook body in our database.
Why we use it and our lawful bases
- To identify and value the motorbike, respond to you and discuss a possible purchase or part exchange. We do this because you have asked us to take steps before a possible contract.
- When you request it, to retrieve official vehicle and MOT information, help you complete the valuation and compare the returned facts with your answers. This supports the pre-contract steps you requested and our legitimate interest in making the valuation information more accurate.
- To assess condition, provenance, selling authority, outstanding finance and collection requirements before a transaction. This supports those pre-contract steps and our legitimate interest in buying motorbikes responsibly.
- To protect the form, prevent duplicate, abusive or fraudulent submissions, organise genuine enquiries and keep service records. We rely on our legitimate interests in operating a secure and effective acquisition service, balanced against your rights.
- To create and secure an account you request, provide customer password recovery, link a valuation using a private code or short-lived one-click handoff, let you track its progress, add later motorbike photographs, record the response you choose to send about an offer, show it to our buying team and send the team a privacy-minimal operational alert that a new response needs review. This supports the pre-contract steps you requested and our legitimate interests in providing a secure and responsive customer service.
- To send transactional receipt, progress and offer emails about the valuation you requested, record delivery or failure and stop sending to addresses that bounce, complain or are suppressed. This supports those pre-contract steps and our legitimate interests in providing a reliable service and protecting email reputation. These messages are not general stock or news marketing.
- To keep purchase, payment, accounting and legal records where we buy a motorbike. We rely on applicable legal obligations and our legitimate interests in documenting the transaction and handling legal claims.
We do not add contact details collected through this wizard to a general stock or news marketing list. Any future marketing sign-up will be separate, optional and specific to the communication channel, and will include a simple way to unsubscribe.
Optional official vehicle and MOT information
You enter the registration yourself. For a UK registration, the wizard may offer a clearly labelled “Find my motorbike” button when REVU MOTO's official lookup is available. We send the registration to the Driver and Vehicle Standards Agency (DVSA) MOT History API only after you press that button. We do not run the lookup when the page loads, while you type or merely because you move to another step, and we do not put the registration in the page URL or send it as an analytics event.
DVSA may return the registration, make, model, manufacture or first-use dates, year, engine capacity, colour, fuel type, MOT status, test dates and results, expiry or first-test due date, recorded mileages, recent defects and advisories, and an outstanding-recall indicator where available. Official records may be missing, delayed or incomplete. The wizard shows the returned motorbike, source and retrieval time and asks you to confirm it, correct your answers or reject it. The manual fields stay available, and an unavailable or unsuccessful lookup does not stop you completing the valuation manually.
If you submit after confirming or correcting a result, REVU MOTO's server checks that the returned snapshot was signed by this service and still relates to the submitted registration. We then retain the relevant official snapshot, source and retrieval time, your decision, and any recorded match or difference with the valuation. The temporary signed lookup token is not stored in a browser draft or retained in the valuation submission. Seller-entered answers remain identified separately and require human review.
The DVSA result is not a market valuation or proof of ownership, registered-keeper authority, mileage accuracy, finance status, theft or recovery history, insurance write-off history, service history, exact trim or options, present physical condition or roadworthiness. It does not replace the V5C, approved provenance and finance checks, identity and selling-authority checks or a physical inspection if the valuation progresses.
DVSA MOT History information is public-sector information. Contains public sector information licensed under the Open Government Licence v3.0. Learn more in the official MOT History API documentation.
Do not upload identity, V5C, finance or bank documents through this public wizard. If the valuation progresses, REVU MOTO may ask you to present appropriate records through an approved process.
Prioritisation and human review
The wizard uses rule-based scoring to organise valuation enquiries. For the current four-screen form, it considers information such as whether the request is for part-exchange, the reported overall condition, photographs, how complete the seller-entered motorbike and contact details are, optional condition notes and, when you used the optional lookup, whether relevant seller and official identity or mileage fields matched or need review. This may affect the order in which enquiries are reviewed.
The score does not calculate a valuation, automatically accept or reject a motorbike, or make a binding decision. We do not make solely automated decisions that have a legal or similarly significant effect on you. A person reviews the supplied information before REVU MOTO makes an offer or declines to proceed. You may ask us to explain the information used, correct it or object to this prioritisation by contacting us.
Valuation portal accounts
You can create an optional account to view valuations linked to it. The valuation form requires an email address so its receipt can prepare private tracking access, but an email match by itself never grants access. After a successful submission, the receipt may post a high-entropy one-click handoff directly to the secure portal; that receipt token is not put in the page address, email or browser storage and becomes unusable after 30 minutes. If the valuation is still unlinked, a transactional email may instead carry its own one-use token in the link fragment. The account page removes that fragment immediately, before making a request, and posts the token from memory to the same portal origin to create temporary secure cookies. The portal can consume either kind only after you create an account or sign in, and only when the account email stored by the service matches the contact email stored with that valuation. Otherwise, or if the handoff expires, you must supply both the valuation reference and the separate seven-day private claim code shown after submission.
Customer pages expose a deliberately limited view: reference, submitted and updated dates, a customer-safe progress status and timeline, selected motorbike facts, whether photographs were received, any published offer, the response history you sent and secure valuation messages sent to you by the REVU MOTO team. While a valuation remains open, the page may also let its linked customer add photographs within the limits described above; every upload is rechecked against the signed-in account and valuation at the time it is sent. Team messages show a fixed “REVU MOTO team” sender rather than an administrator's account identity. Customer pages do not expose internal scores, review flags, notification ledgers, storage keys, file digests, admin identity or activity, or the complete internal submission. Admin accounts are separately authorised and cannot be created through customer registration.
You may respond to a published offer by telling us that you are interested, have a question or do not wish to proceed, and may add a message of up to 500 characters. This sends every response to the REVU MOTO admin portal. A send-eligible response may also anchor a fixed-team-inbox alert saying generically that one or more replies need review, with only the valuation reference, response/alert time and secure admin link. Later replies do not send another alert while that anchor remains unreviewed, but they remain visible in the portal. Reviewing the anchor lets a later reply create the next alert even if an older coalesced reply is still unreviewed; terminal, dead-letter, uncertain and coalesced rows do not suppress it. The alert withholds your response category, message, motorbike label and contact details. The separate 20-attempt UTC-day budget may delay a new alert until the next UTC date without delaying or hiding your portal response. Your response does not automatically change the valuation status, accept an offer, sell the motorbike or create a binding contract. An authorised person reviews it and follows up through the normal valuation process.
An authorised REVU MOTO administrator may send you a secure valuation message of up to 1,200 characters. Each team message is added to the valuation's secure update history as an immutable record; it cannot be silently edited or deleted while the valuation remains active. The portal keeps the message text, time and internal author account for audit and access control, while the customer view exposes only the text, time and fixed team sender. The general valuation event history receives only the message identifier and intended audience, not a second copy of the message text. A newer team message may replace an earlier unsent email nudge, but every team message remains visible in the secure portal. This update history does not create a general customer messaging channel: customer offer responses remain available only where the portal explicitly offers the response controls described above.
Customer passwords must be at least 8 characters. REVU MOTO cannot retrieve your password. If you forget it, you can request an email containing a random link that works once and expires after one hour. The request page gives the same response whether or not a customer account exists. The link token is carried only in the URL fragment, removed from the address before the account page makes a request and checked against its stored one-way digest. Successfully using the link confirms control of the email address stored for that customer account, changes the password, invalidates any other reset link and revokes all existing sessions. It does not by itself link or reveal a valuation. Automated reset does not apply to administrator accounts; administrator recovery remains a controlled manual process using the separate MFA safeguards. Never send us your password, a reset link or an admin setup code.
Transactional valuation and account emails
When customer email is enabled, REVU MOTO may send a receipt and later updates when a valuation enters review, contact begins, an offer is published or the valuation closes. Each message contains your email address as its destination, the valuation reference, a limited motorbike description, the customer-visible status, any published offer and bounded offer message from REVU MOTO, and a link to the secure portal. If the team adds a secure portal message, the email service receives a separate generic “message waiting” nudge with the destination, limited motorbike description, valuation reference and secure portal link, but not the team message text or internal administrator identity. While the valuation is unlinked, a customer email link contains a random one-use handoff token in its fragment so you can create an account or sign in on another device; after linking, the fragment contains only the valuation reference so the authenticated portal can open that owned record. A reference alone grants no access. Customer email does not contain your complete submitted details, photographs or private storage locations, internal score or flags, your password, a portal session token, manual claim code or a portal response message.
If you ask to reset a customer password, REVU MOTO may use the same email service to send the account address a separate security message containing a one-hour, one-use reset link. That message does not contain your password, valuation submission, photographs, valuation claim code or portal session. Possession and successful use of the link verifies control of the stored customer-account inbox for recovery; it does not grant valuation access.
After you post a portal response, the same service may send REVU MOTO's fixed monitored inbox a separate operational alert anchored to one unreviewed send-eligible response. Its generic review-needed copy, reference, response/alert time and admin link tell the authorised team which valuation to open; your response category, optional message, motorbike label and contact details stay in the private portal and are not copied into that alert. Further replies stay in the portal without another email while that anchor remains unreviewed. Reviewing the anchor allows a later reply to create the next alert; older coalesced replies do not block it.
These customer-facing service and account-security messages, team-message nudges and the internal operational alert are not marketing emails. We do not use email-open or link-click information for this service. Provider-level open and click tracking must remain disabled. For valuation updates and team-message nudges, we record whether the provider accepted, delivered, delayed, failed, bounced, received a complaint about or suppressed a message. For a password-reset request, the local reset record is limited to its bounded send status, provider message ID, HTTP status and safe error code. For a response-alert row, the local record distinguishes accepted, explicit failure, dead letter, uncertain delivery, supersession after prior admin review and quota-protecting coalescence behind an active unreviewed anchor; provider acceptance is not proof that a person read the alert or reviewed every reply. The UTC-day budget record contains only the date, provider-attempt count and update time, not customer or valuation information.
Who receives your information
Authorised REVU MOTO staff may use the information for the valuation and any resulting transaction. If you press “Find my motorbike”, we send only the registration needed for that request to DVSA and receive the official vehicle and MOT information described above; we do not send your name, contact details, photographs, price expectation or condition answers to DVSA for this lookup. DVSA operates the official MOT History service under Department for Transport public functions rather than solely on REVU MOTO's instructions; see the MOT History API privacy notice.
We also use service providers acting on our instructions where needed to operate the service:
- Cloudflare for website and API hosting and, where enabled for the production valuation service, security services such as Turnstile, durable database storage, private photograph storage and direct staff-notification email;
- Resend, where the shared email service is enabled, to send the internal new-valuation notification and privacy-minimal new-response staff alert described below, send the customer-safe transactional valuation updates and customer-requested password-reset messages described above, and report or return relevant delivery, delay, failure, bounce, complaint and suppression information;
- approved workflow-automation and customer-relationship-management providers used to route and manage a valuation;
- other approved email, SMS or WhatsApp services used to send valuation-related messages; and
- professional advisers, insurers, finance companies, provenance-check providers, law-enforcement bodies or regulators where necessary for a proposed purchase, legal claim, fraud prevention or legal obligation.
Providers may process only the information needed for their service and must protect it under their contract or applicable law. We do not sell valuation information to data brokers.
Every securely stored valuation enters REVU MOTO's private admin portal queue, where an authorised REVU MOTO administrator can review the submitted details and update its progress. REVU MOTO then attempts a separate automatic notification in order through its configured lead webhook, the optional fixed Cloudflare email route and, when the complete shared email service is enabled and neither earlier route succeeds, Resend. The webhook receives the complete submitted details and private stored-photo metadata. The Cloudflare and Resend internal emails contain the complete submitted details, assessment and a photograph receipt summary, but do not attach raw photograph files or disclose private R2 object keys. Resend sends that internal notification only to REVU MOTO's fixed monitored valuation mailbox; your valid email address may be placed in its Reply-To header so the authorised recipient can respond to you.
Resend therefore receives several deliberately different kinds of message. The internal new-valuation notification contains the written information you submitted through the current form, including your contact details and preference, sale or part-exchange intent, motorbike identity and mileage, overall condition and optional notes, price or comparison information, any part-exchange target, the service's assessment and submission context, and a photograph receipt summary. Information collected later is sent to Resend only if it is included in a separate approved email flow. Separate customer valuation messages contain only the limited payload described in “Transactional valuation and account emails” and, while a valuation is unlinked, the random one-use handoff token embedded in the portal-link fragment. A team-message nudge contains the destination address, limited motorbike description, valuation reference and secure portal link, but not the message waiting in the portal or internal administrator identity. A portal-response staff alert goes only to REVU MOTO's fixed monitored inbox and says generically that one or more replies need review; it contains only the valuation reference, anchor response/alert time and admin link, not your response category, optional message, motorbike label or contact details. Its idempotency key contains the random anchor-response identifier. Later replies are not sent to Resend while that send-eligible anchor remains unreviewed; their alert rows are superseded while every reply remains in the portal. Reviewing the anchor lets a later response create the next alert even if an older coalesced reply remains unreviewed, and terminal, dead-letter, uncertain or coalesced rows are not anchors. The separate global budget sends no more than 20 response-alert provider attempts on one UTC date; overflow remains local and pending for a later UTC date. Resend may also receive standard technical delivery information such as message and event identifiers, timestamps, destination and delivery outcome. None of these messages contains raw photograph bytes, private R2 object keys, passwords, portal session material or a manual claim code. REVU MOTO verifies Resend's signed customer-delivery webhooks before using them and does not copy their raw bodies into the valuation database.
Saving a valuation reference or preparing a WhatsApp message does not itself send a separate message. If secure storage cannot be confirmed, the receipt asks you to copy the complete submission summary, open the displayed WhatsApp fallback to REVU MOTO at +44 7405 756426, paste the summary and press send so the team receives it.
International transfers
Some technology or messaging providers may process information outside the United Kingdom. Where UK law requires a transfer safeguard, we use an applicable UK adequacy regulation or an approved contractual transfer mechanism, such as the UK International Data Transfer Agreement or UK Addendum, together with a transfer-risk assessment and appropriate security measures.
Before any Resend email flow is activated, REVU MOTO must record Resend's current processing locations and subprocessors, execute the applicable data-processing terms, and document the lawful UK transfer safeguard and transfer-risk assessment where required. We do not treat a provider account or successful test message as completing that review.
Photographs and document safety
Motorbike photographs are used for private valuation and are not published as stock advertising from this form or your valuation account. Private storage uses non-public object locations and random identifiers. You may send supported JPEG, PNG, WebP, HEIC or HEIF images in the initial form or, for an open linked valuation, later from the signed-in account. Supported photographs may be converted in your browser before sending, which commonly removes embedded location metadata, but conversion is not guaranteed for every device or format and you should not rely on it to hide personal information.
Do not include paperwork, faces, house numbers, unrelated vehicle registrations or other personal information in a photograph. If sensitive paperwork is submitted by mistake, contact us promptly and identify the valuation reference so we can investigate and remove it where appropriate.
How long we keep information
If no purchase takes place, our production retention policy is to delete the valuation enquiry, any official lookup evidence retained with it, its private photographs, customer offer responses, team-to-customer portal messages, response-alert records and local customer-email notification/event records no later than 12 calendar months after our last substantive valuation contact, including a genuinely new photograph added through the customer account, from active valuation storage and connected customer systems. An idempotent retry of the same photograph does not extend the period again. Equivalent deletion or anonymisation must cover provider-held CRM, workflow, messaging and email copies, including the staff response alert and team-message nudge. We may keep specific information longer where it is reasonably needed for a documented legal claim, fraud investigation or legal obligation. After deletion, we may retain a minimal pseudonymous record showing that the deletion process ran, without retaining the valuation submission itself.
If REVU MOTO buys the motorbike, relevant purchase, authority, provenance, payment and accounting records are retained for the statutory period that applies to the record, normally six years from the end of the relevant company financial year. A longer period may apply while a legal claim, regulatory matter or other legal requirement remains open. The online valuation must not be opened for production enquiries until the last-contact schedule, connected-system deletion and purchased-record retention transition have been implemented and tested.
Customer and admin account records are kept while the account is active and needed to provide or secure the service, then deleted or anonymised when they are no longer required, subject to fraud, legal-claim and legal-obligation exceptions. Customer sessions expire after no more than seven days and admin sessions after no more than eight hours; sign-out, password change, account disabling or security action may end them sooner. Customer password-reset links expire after one hour, and used, invalidated or expired reset records are removed after a short security-audit window. Private claim codes expire after seven days. Receipt handoff tokens become unusable after 30 minutes; each email handoff has its own lifetime of no more than seven days and does not depend on the original manual claim remaining valid. The handoff and reset tables retain only non-reversible token digests and bounded lifecycle metadata. A raw email-handoff token also remains within the exact frozen customer-email provider request until that request is deleted with the valuation under the policy below. A raw password-reset token is not stored in D1 but remains in the provider-held reset message until that message is deleted under the configured email-provider retention period. Temporary authentication rate-limit records are used only to prevent abuse and are periodically removed.
A keyed, non-reversible email-address suppression entry may be retained after the related valuation is deleted for as long as reasonably necessary to honour a bounce, complaint or provider suppression and prevent unwanted repeat sending. It does not contain the readable address. REVU MOTO must also configure and test an appropriate minimum retention/deletion period for customer message content and delivery metadata kept by the email provider.
Browser storage and security
The optional “Save my progress” control uses session storage in the current browser tab only when you choose it. The current saved-draft format may include your sale or part-exchange intent and target, registration type and registration, seller-entered make, model, year or variant, mileage and unit, overall condition and optional notes, whether photographs will follow, and the selected price or comparison answers. It does not include official lookup values unless you change an editable value yourself, and it never includes the official snapshot or signed token, hidden MOT or recall result, submission identifiers or source metadata, your name, phone number, email address, preferred contact route, photographs or declarations. Older draft formats are removed rather than restored. You can switch saving off or use “Clear saved answers” at any time.
The draft is removed after an acknowledged automatic hand-off, when you clear it, and normally when the browser tab or browser session ends. It remains available after an unconfirmed hand-off so you can return to your answers. A browser's session-restore feature may retain it; closing the tab clears the active draft in normal browser use. Cloudflare Turnstile may process IP address, browser and interaction signals to distinguish genuine users from automated abuse. When Turnstile is enabled, JavaScript is required for online submission; if JavaScript is unavailable, use the separate WhatsApp contact route shown on the valuation page. The wizard does not use advertising cookies or add its form data to advertising profiles.
The valuation and admin portals use a strictly necessary, host-only secure session cookie named __Host-revu_session. It is HttpOnly, so portal scripts cannot read it, and it is sent only over HTTPS with SameSite=Lax protection. The server stores only a digest of the random session token. A separate anti-forgery token is rotated after a portal page reload, kept in page memory and required for changes.
If you use a one-click handoff, the portal temporarily sets two more strictly necessary host-only cookies: __Host-revu_claim_handoff holds the random handoff token and __Host-revu_claim_reference holds the valuation reference. Both are HttpOnly, Secure and SameSite=Lax, last no more than 30 minutes and are cleared after successful consumption. A receipt token is posted directly to the portal. An email token arrives only in the link fragment, which is not sent with the page request; the account script immediately removes the fragment, then posts the token from memory to the same portal origin to arm these cookies. It is not placed in a query string, referrer, local storage or session storage. Portal scripts do not save customer or admin records, passwords, claim codes or security tokens in local storage or session storage.
Photographs selected in the customer account, their local previews and the random keys used for safe upload retry exist only for the life of that page. The page explicitly clears them when you remove them, switch valuation, sign out, or when the browser signals that the page is being left or reloaded; closing the page also releases its memory. They are not added to local storage or session storage.
A customer password-reset token also arrives only in a link fragment. The account script strictly validates and removes that fragment before its first network request, keeps the token only in page memory and sends it to the same-origin reset endpoint only when you submit a new password. It is not copied into a query string, cookie, referrer, local storage or session storage.
Your rights
Depending on the circumstances, you may ask for access to your personal information, correction, deletion, restriction, portability, or object to processing based on legitimate interests, including valuation prioritisation. These rights are not absolute, and we will explain if a legal exception applies. You also have an unconditional right to object to use of your information for direct marketing.
WhatsApp REVU MOTO on +44 7405 756426 or write to our registered office. You may also complain to the UK Information Commissioner's Office through ico.org.uk.
Changes to this notice
We will publish material changes on this page and update the effective date. Each submitted valuation records the privacy-notice version that applied when it was received.