1. About this Privacy Policy
This Privacy Policy explains how CheckMyRide collects, uses, stores, discloses and otherwise processes personal data when individuals use the CheckMyRide website, create accounts, post or respond to vehicle advertisements, operate dealer profiles, request inspections or valuations, contact customer support, or use any other service made available by CheckMyRide.
CheckMyRide is a vehicle classifieds and related-services platform. Unless expressly stated in a specific transaction, CheckMyRide does not own vehicles advertised by users and is not the buyer or seller in transactions arranged through the platform.
This Policy is designed to reflect the transparency requirements of the Personal Data Protection Act, No. 9 of 2022, as amended. Under Gazette Extraordinary No. 2498/16 dated 22 July 2026, the Act's provisions, other than section 1, are appointed to come into operation on 1 January 2027. CheckMyRide intends to implement the safeguards described in this Policy from the stated effective date.
2. Who is responsible for your personal data
For the purposes of applicable data protection law, the controller is the person or organisation that determines why and how personal data is processed.
Controller / legal entity: CHECK MY RIDE.LK (PVT) LTD
Company registration number: PV 00370876
Incorporated in Sri Lanka: 14 August 2026
Registered address: 115B Dugalawatta, Kumbuka North, Gonapola Junction, Horana, Sri Lanka
Privacy contact: [email protected]
Telephone: +94 71 548 0412
Data Protection Officer / privacy lead: To be confirmed
Where a dealer, private seller, inspector, valuation provider, finance provider, insurer or other third party independently determines how it uses personal data, that party may be a separate controller and will be responsible for its own processing.
3. Scope
This Policy applies to personal data processed through:
- the website checkmyride.lk and any authorised subdomains;
- mobile or web applications operated by CheckMyRide, if launched;
- buyer, seller, dealer, inspector, moderator and administrator accounts;
- vehicle advertisements, dealer pages, enquiries, messaging and saved-vehicle functions;
- inspection booking, valuation, report delivery and related customer-support processes;
- paid listing upgrades, subscriptions, advertising and other payment-enabled services, if activated;
- email, telephone, WhatsApp, social-media and offline interactions with CheckMyRide.
This Policy does not govern a third-party website, payment service, social-media platform, map provider, finance provider, insurer, dealer, seller or inspector acting independently. Their own privacy notices may apply.
4. Key definitions
| Term | Meaning |
|---|---|
Personal data | Information that identifies or can reasonably identify a natural person directly or indirectly, including names, identification numbers, financial data, location data and online identifiers. |
Processing | Any operation performed on personal data, including collection, recording, storage, use, disclosure, transmission, making available, alteration, retrieval, deletion and destruction. |
Controller | A person or entity that determines the purposes and means of processing personal data. |
Processor | A separate person or entity that processes personal data on behalf of a controller. |
Special categories of personal data | More sensitive personal data defined by Sri Lankan law, including data relating to children, health, biometric identification, offences or convictions, and certain other protected attributes. |
Data subject | The identified or identifiable natural person to whom personal data relates. |
5. Personal data we collect
5.1 Account and identity data
- name, username, email address, telephone number and WhatsApp number;
- password in hashed or otherwise protected form;
- profile photograph, preferred language, account role and communication preferences;
- records of registration, login, verification, account status and acceptance of terms, including the version accepted, date and time, and a technical identifier such as IP address where reasonably necessary to evidence electronic acceptance and platform security;
5.2 Seller and dealer verification data
- identity or business-verification information, such as National Identity Card, passport, business-registration certificate, trade licence, proof of address or authorised-representative details, where verification is required;
- showroom address, business contact details, dealer logo, opening hours and team-member information;
- records of verification checks, moderation decisions, complaints and suspected fraud.
Verification documents should not be displayed publicly. CheckMyRide will collect only the minimum information reasonably necessary for verification and fraud prevention.
5.3 Vehicle and listing data
- vehicle make, model, trim, year, mileage, colour, fuel, transmission, body type, engine and other specifications;
- registration number, VIN or chassis number, ownership and registration status, service history, accident status, finance or lease status and supporting records;
- vehicle photographs, videos, description, price, location and listing history;
- records showing whether a listing is pending, approved, rejected, suspended, sold, expired or removed.
5.4 Communications, enquiries and platform activity
- messages between users where in-platform messaging is available;
- customer-support requests, complaints, reports of suspicious listings and dispute information;
- records of calls, WhatsApp clicks, email interactions and other lead events, where logged;
- saved vehicles, searches, filters, page views, listing views and account preferences.
5.5 Inspection and valuation data
- customer and vehicle-owner contact details;
- vehicle location, appointment date and time, access instructions and booking notes;
- vehicle identification and condition information, inspection checklists, measurements, diagnostic information, photographs, videos, inspector notes, valuation data and generated reports;
- records of assignment to inspectors, booking status, payment status, delivery and customer communications.
5.6 Payment and transaction data
- billing name, billing contact details, invoice information, package purchased, payment status, refunds and transaction reference numbers;
- limited payment-method information received from the payment provider, such as card brand and last four digits, if supplied.
CheckMyRide should not store complete card numbers, card security codes or online-banking passwords. Payments should be processed by an appropriately contracted payment service provider.
5.7 Technical and usage data
- IP address, device identifiers, browser type, operating system, language, approximate location derived from IP and timestamps;
- authentication, security, server and audit logs;
- cookie identifiers, analytics events, referral sources and interaction data;
- information used to detect spam, account takeover, scraping, abusive behaviour and technical failures.
5.8 Data that should not be posted publicly
Users must not place the following in public listings, descriptions, images or messages unless lawfully required and specifically requested by CheckMyRide:
- full identity-document numbers or images;
- bank-account, card or authentication credentials;
- private residential addresses where not necessary;
- unmasked personal documents, signatures or QR codes;
- special-category personal data unrelated to the vehicle transaction;
- personal data of another person without authority to disclose it.
CheckMyRide will also apply moderation and technical controls intended to prevent public display of high-risk verification information. In particular, the public vehicle page should not display a full VIN or chassis number, unredacted Certificate of Registration (CR), revenue licence, NIC/passport image, signature, QR code or private residential address. A masked identifier may be shown where reasonably necessary for the marketplace purpose.
6. How we obtain personal data
We may obtain personal data:
- directly from you when you register, post an advertisement, contact another user, book an inspection, make a payment, contact support or exercise a legal right;
- from a dealer, private seller, vehicle owner, inspector, valuation provider or authorised representative;
- automatically through cookies, logs, analytics and security tools;
- from payment, identity-verification, messaging, email, hosting, map or other service providers;
- from public sources where reasonably necessary to verify a business, vehicle, fraud concern or legal claim;
- from law-enforcement, regulatory or other competent authorities where authorised by law.
Where personal data is obtained indirectly, CheckMyRide will provide the information required by law within the applicable period, unless a lawful exception applies.
7. Purposes and lawful bases
CheckMyRide will process personal data only for specified, explicit and legitimate purposes and where a lawful basis applies. The principal purposes and bases expected for the platform are set out below.
| Purpose | Data commonly used | Lawful basis |
|---|---|---|
Create and administer accounts | Account, identity, contact and authentication data | Contract / steps requested before entering a contract; legitimate interests in account security |
Publish and manage vehicle listings | Seller, vehicle, location, contact and listing data | Contract; legitimate interests in operating a reliable marketplace |
Enable buyer enquiries and communications | Buyer and seller contact data, messages and lead events | Contract / requested service; legitimate interests |
Verify sellers, dealers and listings | Identity, business, vehicle and verification data | Legitimate interests in fraud prevention and marketplace safety; legal obligation where applicable |
Moderate content and enforce platform rules | Listings, messages, complaints, reports, device and account data | Legitimate interests in safety, integrity, dispute prevention and enforcement |
Provide inspections and valuations | Booking, location, vehicle, inspection, payment and report data | Contract / pre-contract steps; legal obligation; legitimate interests in quality and claims management |
Process payments and issue invoices | Billing and transaction data | Contract; legal obligation |
Provide customer support and resolve disputes | Contact, communications, transaction, listing and complaint data | Contract; legitimate interests; legal obligation |
Secure the platform and prevent fraud | Technical, authentication, device, usage and verification data | Legitimate interests in fraud prevention and network and information security |
Analyse and improve services | Aggregated or pseudonymised usage, search and performance data | Legitimate interests, subject to appropriate safeguards; consent where required for non-essential cookies |
Send service communications | Contact and account data | Contract; legitimate interests |
Send optional marketing | Contact data and marketing preferences | Consent or another lawful basis permitted by applicable law, with an opt-out |
Comply with law and authorities | Any data reasonably required | Legal obligation; establishment, exercise or defence of legal claims |
7.1 Consent
Where processing is based on consent, the request will be presented separately and in clear language. Consent must be freely given, specific, informed and unambiguous. You may withdraw consent through the method stated at collection or by contacting us. Withdrawal does not affect processing already lawfully carried out before withdrawal.
7.2 Legitimate interests
Where CheckMyRide relies on legitimate interests, it will assess the necessity of the processing and balance those interests against the rights and reasonable expectations of affected individuals. Examples include fraud prevention, account and network security, platform moderation, service improvement, defending legal claims and maintaining an accurate marketplace.
7.3 Required information
Certain information is necessary to create an account, publish a listing, verify a seller or dealer, process a booking, receive payment or comply with law. If required information is not provided, CheckMyRide may be unable to provide the relevant service or may restrict, reject or remove an account, listing or booking.
8. Public listings and information visible to others
Vehicle advertisements and dealer profiles are intended to be public. Information included in these areas may be viewed, copied, shared or indexed by search engines and other third parties.
- A listing may show the seller or dealer name, business name, public contact method, city or district, vehicle information, photographs, price and description.
- CheckMyRide may mask a telephone number until a user selects a contact action, but cannot guarantee that public information will not be copied by others.
- A seller should use a business or dedicated contact number where possible and must not upload unredacted identity documents or financial information.
- After a listing is removed, copies may remain temporarily in browser caches, search-engine results, archives or third-party messages beyond CheckMyRide's immediate control.
- CheckMyRide may retain a non-public record of a removed listing for fraud prevention, dispute handling, legal compliance and audit purposes.
9. Vehicle inspections, valuations and related services
Where inspection or valuation services are enabled, CheckMyRide acts as controller for booking, payment, assignment, customer support and report delivery. An inspector assigned by CheckMyRide processes customer, seller, vehicle, location and report data as a contracted service provider on CheckMyRide’s documented instructions and under confidentiality and data-protection obligations, except to the limited extent applicable law independently requires that inspector to determine a separate processing purpose.
Inspection and valuation information may be disclosed to:
- the customer who booked and paid for the service;
- the vehicle owner or seller where authorised by the customer or required to arrange access;
- the assigned inspector or valuation provider;
- a bank, finance company, insurer or other recipient only where the customer requests the disclosure, gives appropriate consent, or another lawful basis applies;
- legal advisers, insurers, regulators or courts where necessary to manage claims or comply with law.
Inspection reports may contain vehicle photographs and information that indirectly identifies an owner, seller, location or user. Reports must be distributed only to authorised recipients and must not be made public without a documented lawful basis.
10. Sharing and disclosure
CheckMyRide may disclose personal data to the following categories of recipients:
| Recipient category | Reason for disclosure |
|---|---|
Other users | To display listings, dealer profiles and contact options and to facilitate enquiries or messages. |
Inspectors and valuation partners | To fulfil inspection, valuation and report-delivery services. |
Technology and hosting providers | Cloud hosting, databases, storage, backups, cybersecurity, content delivery and technical support. |
Communication providers | Email, SMS, WhatsApp integration, telephone and customer-support systems. |
Payment providers | To process payments, prevent fraud, issue refunds and reconcile transactions. |
Analytics and cookie providers | Subject to the cookie choices and lawful basis described in this Policy. |
Professional advisers and insurers | For legal, audit, accounting, insurance, claims and compliance purposes. |
Finance and insurance partners | Only where a user requests a quote or service and the disclosure is transparent and lawful. |
Authorities and courts | Where disclosure is required or permitted by written law, legal process or a lawful request. |
Business transferees | In a merger, financing, restructuring, sale or transfer, subject to confidentiality and lawful processing safeguards. |
CheckMyRide will not sell personal data as a standalone commodity. Any data-sharing arrangement must be documented, limited to an identified purpose and subject to appropriate contractual, technical and organisational safeguards.
11. Cross-border data flows
Some contracted service providers may process or store personal data outside Sri Lanka. Before a cross-border transfer is activated, CheckMyRide will identify the recipient and processing location, assess the transfer under applicable Sri Lankan data-protection law and put in place written data-processing, confidentiality, security and transfer safeguards appropriate to the transfer.
Depending on the circumstances, safeguards may include:
- binding contractual commitments, including applicable controller-processor terms and cross-border transfer clauses, together with security obligations imposed on the overseas recipient;
- instruments or directives issued or recognised by the Data Protection Authority;
- explicit informed consent where legally valid and appropriate;
- a transfer necessary to perform a contract requested by the data subject;
- a transfer necessary for legal claims, public interest or an emergency, where the statutory conditions are met.
Material hosting / processing locations: To be confirmed.
CheckMyRide will maintain a current internal vendor and sub-processor register identifying the service, processing purpose and country or region of processing. Material changes that affect this Policy will be reflected in the public notice or an accessible sub-processor register.
12. Cookies and similar technologies
CheckMyRide may use cookies, pixels, local storage and similar technologies to operate the website, remember preferences, maintain sessions, protect accounts, measure performance and, if enabled, support advertising.
| Category | Purpose | Control / basis |
|---|---|---|
Strictly necessary | Authentication, security, load balancing, fraud prevention and core site functions. | Required for the requested service; cannot normally be disabled through the consent tool. |
Preferences | Language, display, saved choices and user-interface settings. | Consent or legitimate interests, depending on the technology and applicable requirements. |
Analytics | Understanding visits, searches, listing views, errors and website performance. | Consent where required; otherwise a documented lawful basis with appropriate safeguards. |
Advertising | Measuring campaigns, limiting repetition and personalising advertising, if enabled. | Consent before activation unless another lawful basis is clearly available. |
Where CheckMyRide uses non-essential cookies based on consent, those cookies will not be activated until the user makes an affirmative choice. Users must be able to change that choice through a persistent cookie-settings link. Blocking certain cookies may affect optional functionality.
13. Marketing communications
CheckMyRide may send service communications necessary to operate an account, listing, inspection, payment or security process. These are not optional marketing messages.
Promotional email, SMS, WhatsApp or similar direct electronic marketing will be sent only where CheckMyRide has a valid lawful basis. Where consent is used, it will be obtained through a separate, unticked and unbundled choice that identifies the relevant channel or category of marketing. Marketing consent is not acceptance of the Terms of Use and is not a condition of receiving a service where the marketing is unnecessary. Every marketing message will provide a practical opt-out method.
A person who opts out may still receive essential service, safety, legal and account communications. CheckMyRide may retain a limited suppression record to ensure that the opt-out is respected.
14. Automated tools, moderation and fraud prevention
CheckMyRide may use automated rules or technical tools to detect duplicate listings, unusual logins, spam, prohibited content, suspicious contact activity, manipulated images, inconsistent vehicle information or other indicators of fraud and misuse.
Automated tools may flag content or accounts for review. Unless expressly disclosed otherwise, CheckMyRide will not make a decision based solely on automated processing that produces legal effects or similarly significant effects for an individual. Material enforcement decisions should be subject to review by an authorised person, and affected users should have access to an appeal or review process.
15. Security
CheckMyRide will use technical and organisational measures appropriate to the nature, scale, volume and sensitivity of the processing and the risks to individuals. No system can be guaranteed to be completely secure.
- encryption in transit and, where appropriate, encryption at rest;
- password hashing and secure authentication controls;
- multi-factor authentication for privileged administrator accounts;
- role-based access controls and least-privilege access;
- logging, monitoring and audit trails for sensitive administrative actions;
- secure software-development, change-management and vulnerability-management processes;
- backups, recovery testing and business-continuity measures;
- vendor due diligence, written processor contracts and confidentiality obligations;
- staff training, incident-response procedures and periodic access reviews;
- data minimisation, masking, pseudonymisation or anonymisation where appropriate.
If a personal data breach occurs, CheckMyRide will investigate, contain, assess and document the incident and will notify the Data Protection Authority and affected individuals where required by applicable law and rules. As an internal readiness target, CheckMyRide will aim to complete the regulatory-notification assessment promptly and, where notification is required, to notify the Authority within 72 hours of becoming aware of the breach unless the legally applicable rule prescribes a different period.
15.1 Data protection governance and impact assessments
CheckMyRide will maintain a documented Data Protection Management Programme appropriate to the nature and scale of its processing. The programme will include a data inventory, records of processing purposes and lawful bases, vendor and transfer registers, retention controls, rights-request procedures, security controls, incident response, staff responsibilities, training and periodic review.
CheckMyRide will conduct and document a data-protection impact or risk assessment before introducing processing that is reasonably likely to create a high risk to individuals, including identity-document verification at scale, precise inspection-location workflows, material new profiling or automated enforcement, or other processing identified by the Data Protection Authority or applicable law.
16. Retention
CheckMyRide will retain identifiable personal data only for as long as necessary for the purpose for which it was collected, or as required to comply with legal, accounting, tax, fraud-prevention, dispute-resolution or evidentiary obligations.
Retention decisions will take account of:
- the duration of the account, listing, dealer relationship, inspection booking or transaction;
- the nature and sensitivity of the data;
- the risk of harm from unauthorised use or disclosure;
- the need to prevent repeat fraud or enforce platform rules;
- applicable limitation periods and legal record-keeping duties;
- whether the data can be anonymised or aggregated instead of retained in identifiable form.
When retention is no longer justified, data will be deleted, securely destroyed or irreversibly anonymised. Temporary backup copies may remain until the relevant backup cycle expires, subject to restricted access.
Raw identity-verification documents, including NIC/passport images and vehicle-document copies collected solely to complete seller or dealer verification, should be deleted, securely destroyed or irreversibly redacted within 90 days after the verification is completed, unless a longer period is reasonably necessary for an active fraud investigation, dispute, legal claim, statutory requirement or other documented lawful purpose. A verification outcome or minimal audit record may be retained for longer where justified.
17. Your rights
Subject to applicable law, verification of identity and permitted exceptions, a data subject may have the following rights:
| Right | What it means |
|---|---|
Access | Request confirmation of whether personal data is processed and obtain access to the data and required information. |
Withdraw consent | Withdraw consent where consent is the lawful basis. This does not invalidate earlier lawful processing. |
Object / request that processing stop | Request that CheckMyRide refrain from further processing in circumstances specified by law. |
Rectification and completion | Correct inaccurate data or complete incomplete data. |
Erasure | Request deletion where the statutory grounds apply, subject to legal and evidentiary exceptions. |
Review of automated decisions | Request review of a qualifying decision based solely on automated processing. |
Appeal to the Authority | Appeal a refusal of a rights request in the form and manner prescribed by law. |
Under the amended Act, a controller must ordinarily inform the data subject in writing, without undue delay and within one month of receiving a request, whether the request is granted or refused. For reasons explained to the data subject, this period may be extended by up to two additional months, without exceeding three months from receipt. Requests are generally handled free of charge, subject to any criteria lawfully established by the Authority.
18. How to exercise your rights
Submit a written request using the following contact:
Privacy request email: [email protected]
Postal address: 115B Dugalawatta, Kumbuka North, Gonapola Junction, Horana, Sri Lanka
A request should include:
- your full name and account email or telephone number;
- the right you wish to exercise and the relevant data, account, listing or booking;
- enough information to verify identity and locate the records;
- where another person acts for you, evidence of their authority.
CheckMyRide may request proportionate identity verification to prevent unauthorised disclosure or deletion. Additional information will not be collected solely for verification unless reasonably necessary.
A request may be restricted or refused only where permitted by written law. If refused, CheckMyRide will provide reasons unless disclosure is prohibited and will explain the available appeal route.
19. Children
CheckMyRide is intended for persons aged 18 years or older. Users under 18 must not create accounts, post vehicle advertisements, enter transactions or book paid services.
Personal data relating to a child is treated as a special category of personal data under Sri Lankan law. If CheckMyRide becomes aware that it has collected a child's personal data without a valid lawful basis or required parental or guardian authority, it will restrict the data and take appropriate steps to delete it.
20. Third-party websites and services
The platform may link to or integrate with third-party services, including WhatsApp, maps, social media, payment providers, finance or insurance partners and dealer websites. CheckMyRide does not control the independent privacy practices of those third parties. Users should read the relevant third-party privacy notice before providing personal data.
21. Changes to this Policy
CheckMyRide may update this Policy when services, vendors, legal requirements or processing activities change. The current version will display the effective date. Where a change materially affects individuals, CheckMyRide will provide an appropriate notice through the website, account, email or another suitable channel before or when the change takes effect.
A change to this Policy does not create a lawful basis for materially different processing. Where required, CheckMyRide will provide additional information or obtain new consent before beginning the new processing.
22. Contact and complaints
For questions, complaints or rights requests, contact:
Privacy contact: [email protected]
Legal entity: CHECK MY RIDE.LK (PVT) LTD
Address: 115B Dugalawatta, Kumbuka North, Gonapola Junction, Horana, Sri Lanka
Telephone: +94 71 548 0412
22.1 Data Protection Authority of Sri Lanka
You may have the right to complain or appeal to the Data Protection Authority of Sri Lanka. Current official contact details are:
- Address: First Floor, Block 5, Bandaranaike Memorial International Conference Hall (BMICH), Bauddhaloka Mawatha, Colombo 07, Sri Lanka
- Email: [email protected]
- Telephone: +94 (0)11 269 7241 / +94 (0)11 269 7237
- Website: www.dpa.gov.lk
CheckMyRide encourages individuals to contact the privacy team first so that a concern can be investigated and, where possible, resolved promptly. This does not remove any right to contact the Authority.
Annex 1. Category-by-category retention criteria
The public Policy relies on retention criteria rather than fixed periods where the applicable legal period or business need may vary. The final internal retention schedule must be approved before launch and implemented through deletion, anonymisation and backup-expiry controls.
| Data category | Retention criterion |
|---|---|
Account profile and authentication | While account is active; thereafter only for a limited period necessary for reactivation, disputes, fraud prevention, security and legal obligations. |
Public listing content | While listing is live; removed from public view when sold, expired, rejected or deleted; limited non-public archive for disputes, safety, fraud and audit. |
Dealer verification | For the dealer relationship and a limited period afterward. Raw NIC/passport images and vehicle-document copies collected solely for verification should be deleted or irreversibly redacted within 90 days after verification unless a documented fraud, dispute, legal or statutory reason requires longer retention. A minimal verification outcome/audit record may be retained where justified. |
Messages and enquiries | For the time needed to provide messaging, investigate abuse, resolve disputes and protect users; shorter periods should apply where no dispute or safety need exists. |
Inspection and valuation records | For service delivery and for the period reasonably necessary to address quality complaints, contractual claims, insurance matters and legal requirements. |
Payment and invoice records | For the period required by applicable accounting, tax, anti-fraud and legal obligations. |
Security and access logs | For a limited security-monitoring period proportionate to risk; longer only where an incident, investigation or legal hold applies. |
Marketing preferences | Until consent is withdrawn or the person opts out; a minimal suppression record may be retained to honour the opt-out. |
Complaints, reports and moderation | For the time needed to investigate, enforce rules, prevent repeat abuse and defend legal claims. |
Backups | Until the next scheduled backup rotation, subject to restricted use and restoration controls. |
Annex 2. Cookie and technology register
The live cookie-settings tool or cookie register made available on checkmyride.lk will identify the cookies and similar technologies actually in use, including provider, purpose, category, duration and processing location where known. Non-essential analytics or advertising technologies that rely on consent will not be activated before the user makes the applicable choice.
| Cookie / technology | Provider | Purpose | Category | Duration | Location |
|---|---|---|---|---|---|
Live register | Shown in cookie settings | Only technologies actually deployed on the production site | Necessary / Preferences / Analytics / Advertising | Shown per technology | Shown where known |
Questions about this document? Contact us at [email protected].
