1. Scope
Affix Plate Pass (“the extension”) helps users check whether a UK vehicle appears road-legal on live MOT and Vehicle Excise Duty records, then requests AffixIO proofs of that outcome. This policy explains what data is processed for that single purpose.
Related pages: Plate Pass product page, Security, Compliance.
2. Data we process
Vehicle registration lookups
When you run a check, the extension processes the UK registration mark (VRM) you enter, select, or confirm from a listing page. Related MOT expiry, tax status, and summary vehicle attributes returned by the lookup may also be processed so AffixIO can issue circuit proofs.
Website content on matched listing sites
On supported vehicle listing and GOV.UK pages, a content script may read visible page text only to detect UK registration marks and show an optional Plate Pass chip. That detection runs locally in your browser. A registration is sent to AffixIO only when you start a check.
Local extension storage
The extension stores on your device:
- Settings (detection toggles, optional AffixIO API base URL, optional API key)
- Recent check history (VRM, MOT and tax summary, AffixIO proof identifiers and digests)
You can clear recent checks from the extension popup.
Optional AffixIO API key
If you paste an AffixIO API key in Options, it is stored in Chrome sync or local storage on your devices and sent only to api.affix-io.com (or the API base you configure) when proving circuits. Leave the key blank to use the AffixIO Plate Pass proxy instead.
What we do not collect for Plate Pass
- Your name, email, or account profile through the extension itself
- Payment card details
- Health data
- Full browsing history
- Keystrokes, mouse tracking, or advertising analytics inside the extension
3. How we use data
Data is used only to:
- Perform the MOT and tax road-legal lookup you requested
- Issue AffixIO proofs on circuits such as
motor_inspection_valid,attested_range, andaudit_proof - Show results and recent checks inside the extension
- Operate, secure, and rate-limit AffixIO services that back those requests
We do not sell Plate Pass user data. We do not use it to determine creditworthiness or for lending. We do not use it for unrelated advertising profiles.
4. Where data is sent
Network calls for Plate Pass go to AffixIO hosts:
- https://www.affix-io.com (Plate Pass proxy and site)
- https://api.affix-io.com (prove, verify, and related API paths)
Lookups may consult official or open vehicle data sources (for example DVLA or GOV.UK-backed records) through AffixIO’s Plate Pass backend so the extension can return live MOT and tax status. AffixIO’s verification design aims for binary eligibility outcomes and proof metadata rather than retaining personal identity dossiers on the default verify path.
5. Legal basis
For UK GDPR purposes, processing for Plate Pass is based on:
- Your request to perform a vehicle status check and receive a proof (contract or steps at your request before a contract, and/or legitimate interests in providing the tool you installed)
- Legitimate interests in securing the service, preventing abuse, and keeping an audit trail of proof issuance
Where an optional API key is used, processing is necessary to authenticate your AffixIO API requests.
6. Retention
- On your device: settings and recent checks remain until you clear them, uninstall the extension, or Chrome clears extension storage.
- On AffixIO: proof metadata and operational logs may be retained as needed to operate attestation, Merkle audit, security, and rate limiting. AffixIO is built so the default verify path is designed not to retain personal source records. See Compliance.
7. Security
Transport uses HTTPS. Optional API keys should be treated as secrets. Prefer AffixIO hub keys with least privilege. Production AffixIO attestation uses ML-DSA-65. Report security issues via Security or hello@affix-io.com.
8. Your rights
Depending on applicable law, you may have rights to access, rectify, erase, restrict, or object to certain processing, and to complain to the UK Information Commissioner’s Office. For Plate Pass requests email hello@affix-io.com. You can also clear local extension history yourself and revoke an API key in hub.affix-io.com.
9. Children
Plate Pass is not directed at children under 16. Do not use it to submit personal data relating to children.
10. Changes
We may update this policy as the extension or AffixIO services change. The “Last updated” date at the top will change when we do. Material changes may also be noted on the Plate Pass page.
11. Contact
AffixIO · United Kingdom
Email: hello@affix-io.com
Product: https://www.affix-io.com/plate-pass/
This policy URL: https://www.affix-io.com/plate-pass/privacy/