Welcome to Honk. We are committed to protecting your privacy and personal data in accordance with the
General Data Protection Regulation (GDPR) as applicable in Ireland (EU GDPR) and Northern Ireland (UK GDPR),
along with relevant ePrivacy and cookie regulations.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our platform.
By using Honk, you agree to the practices described in this policy.
This policy applies to all users, whether you are browsing, registered, or actively using our services.
1. Personal Data We Collect
We collect the following types of personal data:
Information You Provide Directly:
First Name and Last Name – collected during account registration
Email Address – required for account creation, verification, and communication
Phone Number – optional, provided when creating or managing vehicle listings
Location Information – city or region, used to show relevant listings
Listing Details – vehicle information, descriptions, and images you upload
Messages – communications between buyers and sellers through our messaging system
Information Collected Automatically:
IP Address – logged for security, fraud prevention, and rate limiting
Browser and Device Information – user agent, device type, operating system
Usage Data – pages visited, time spent, interactions with listings
Cookies and Session Data – see Section 4 for details
2. How We Use Your Personal Data
We process your personal data for the following purposes:
Account Creation and Authentication – to create and manage your user account
Email Verification – to verify your email address and prevent fraudulent accounts
Platform Functionality – to enable you to create listings, browse vehicles, and use our services
Communication Between Users – to facilitate messaging between buyers and sellers
Payment Processing – to process subscription fees and listing boosts (handled by Stripe)
Security and Fraud Prevention – to detect and prevent unauthorized access, spam, and abuse
Legal Compliance – to comply with legal obligations and respond to lawful requests
Platform Improvement – to analyze usage patterns and improve our services
Customer Support – to respond to your inquiries and provide assistance
3. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
Performance of a Contract – processing necessary to provide our services to you (e.g., account creation, listings, messaging)
Legitimate Interests – fraud prevention, security monitoring, platform improvement, and analytics (balanced against your rights)
Legal Obligation – compliance with laws, regulations, and court orders
Consent – where you have explicitly agreed to specific processing activities (e.g., marketing communications)
You have the right to withdraw consent at any time where we rely on consent as the legal basis for processing.
4. Cookies and Tracking Technologies
We use cookies and similar technologies to provide and improve our services. Cookies are small text files stored on your device.
Types of Cookies We Use:
Essential Cookies – required for core functionality (session management, authentication, security)
Security Cookies – CSRF protection, account lockout tracking, rate limiting
Functional Cookies – remember your preferences (location, language settings)
Analytics Cookies – understand how users interact with the platform (if enabled)
Managing Cookies:
You can manage or disable cookies through your browser settings. However, disabling essential cookies may prevent you from using certain features of the platform.
Most browsers allow you to block third-party cookies while keeping first-party cookies enabled.
5. Data Storage and Security
We take the security of your personal data seriously and implement appropriate technical and organizational measures to protect it:
Encryption – sensitive data (phone numbers, locations) are encrypted at rest using industry-standard encryption (Fernet AES-128)
Secure Transmission – all data transmitted between your browser and our servers is encrypted using HTTPS/TLS
Access Controls – strict access controls limit who can access personal data
Password Security – passwords are hashed using Django's PBKDF2 algorithm with SHA256
Rate Limiting – protection against brute-force attacks and automated abuse
Account Lockout – automatic lockout after multiple failed login attempts
Regular Updates – we keep our systems and dependencies up to date with security patches
Data Storage Location: Your data is stored on secure servers. We use reputable hosting providers with strong security practices.
Important: While we implement industry best practices, no method of transmission or storage is 100% secure.
We cannot guarantee absolute security, but we continuously monitor and improve our security measures.
6. Payments and Third-Party Services
Payment Processing (Stripe):
Honk does NOT store or process payment card details. All payment transactions are handled securely by
Stripe, a PCI-DSS compliant payment processor.
When you make a payment, you are redirected to Stripe's secure checkout page. Stripe acts as an independent data controller
for payment information. Their privacy policy is available at:
https://stripe.com/privacy
Other Third-Party Services:
We may use the following third-party services to operate our platform:
Email Service Providers – to send verification emails, notifications, and communications
Cloud Hosting Providers – to host our application and database
Analytics Services – to understand user behavior and improve our services (if enabled)
Error Monitoring – to detect and fix technical issues (Sentry, configured to not send personally identifiable information)
These third parties only access data necessary to perform their services and are contractually obligated to protect your data.
7. Data Sharing and Disclosure
We do not sell your personal data to third parties.
We may share your personal data only in the following circumstances:
Between Platform Users – your name and contact information may be visible to users you interact with (e.g., when messaging about a listing)
Service Providers – with third-party providers who help us operate the platform (as described in Section 6)
Legal Compliance – when required by law, court order, or government request
Protection of Rights – to protect our rights, property, safety, or the rights of users and the public
Business Transfers – in the event of a merger, acquisition, or sale of assets (users will be notified)
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law.
Retention Periods:
Active Accounts – retained while your account is active and for a reasonable period thereafter
Deleted Accounts – personal data is deleted within 30 days of account deletion, except where retention is legally required
Inactive Listings – expired or deleted listings may be removed after a reasonable period
Messages – retained while your account is active or as needed for dispute resolution
Transaction Records – payment and subscription records retained for 7 years to comply with accounting and tax obligations
Security Logs – IP addresses and access logs retained for up to 90 days for security and fraud prevention
Criteria for Retention: We determine retention periods based on legal requirements, business needs, dispute resolution,
and the nature of the data collected.
9. Your Rights Under GDPR
Under the GDPR (both EU and UK versions), you have the following rights regarding your personal data:
Right to Access – you can request a copy of the personal data we hold about you
Right to Rectification – you can request correction of inaccurate or incomplete data
Right to Erasure ("Right to be Forgotten") – you can request deletion of your personal data in certain circumstances
Right to Restrict Processing – you can request that we limit how we use your data
Right to Data Portability – you can request your data in a structured, machine-readable format
Right to Object – you can object to processing based on legitimate interests or for direct marketing
Right to Withdraw Consent – where processing is based on consent, you can withdraw it at any time
Right to Lodge a Complaint – you can file a complaint with a supervisory authority if you believe your rights have been violated
How to Exercise Your Rights:
To exercise any of these rights, please contact us using the details in Section 10. We will respond to your request within 30 days.
Northern Ireland (UK GDPR): Information Commissioner's Office (ICO) – ico.org.uk
10. Contact Information
If you have any questions about this Privacy Policy, wish to exercise your rights, or have concerns about how we handle your personal data,
please contact us: