Privacy Policy
Effective June 14, 2026 · Applies to batching.missourimvr.com
MissouriMVR Batching is a service of Insurance Information Services, Inc., the operator of Missouri Motor Vehicle Records (MissouriMVR) ("we," "us," the "Service"). The Service provides a platform for authorized businesses to request bulk Missouri driver records (MVRs). Access to driver records is regulated under the federal Driver's Privacy Protection Act (DPPA, 18 U.S.C. §2721 et seq.) and the Gramm-Leach-Bliley Act (GLBA). This policy explains what information we collect, how we use and protect it, how long we keep it, and the choices available to you.
1. Who this policy covers
- Customers — the businesses and their users who register for and use the Service.
- Drivers / data subjects — individuals whose Missouri driver records are requested by a Customer. We process driver-record data on behalf of vetted Customers for their certified permissible purpose; we are not the source of the underlying records.
- Visitors — anyone who browses our public pages.
2. Information we collect
- Account & company information — name, work email, phone, company legal name and address, and your certified permissible purpose, collected at registration.
- Authentication data — password (stored only as a salted hash) and two-factor authentication settings/secrets.
- Search input & results (regulated driver data) — the identifiers a Customer submits to run a lookup (driver-license number, or name plus date of birth, and optional reference numbers) and the resulting Missouri driver records returned as PDF reports.
- Payment information — processed by our payment provider, Stripe. We do not receive or store full card numbers; we retain only non-sensitive records of charges, prepaid balance ledger entries, and receipts.
- Usage & technical data — log records of sign-ins, batch and report activity, API calls (method, path, status, timing, and a correlation ID — never request/response bodies), and the IP address and timestamp associated with regulated-data access, for security and DPPA/GLBA audit purposes.
3. How we use information
- To provide the Service — process batches, match records, and deliver reports.
- To authenticate users, secure accounts, and prevent fraud and misuse.
- To process payments and maintain prepaid balances and receipts.
- To maintain the permissible-purpose, access, and tamper-evident audit records required for DPPA/GLBA compliance.
- To send transactional email (verification, password reset, sign-in codes, batch and payment notifications). We do not send marketing email and do not sell personal information.
- To meet legal, regulatory, and contractual obligations.
4. Regulated driver-record data (DPPA & GLBA)
Customers must certify a permissible purpose under the DPPA and, where applicable, the GLBA before requesting any record, and that certification is recorded with each access. We process driver-record data solely to fulfill Customer requests for their certified purpose and apply the safeguards described in Section 7. We retain a per-access audit trail (who accessed what, when, from where, and for which purpose).
If you are a driver and have a question about a record that was obtained about you, the request was made by one of our Customers under a permissible purpose; please contact the business that requested it. Questions about the underlying official record should be directed to the Missouri Department of Revenue.
5. How we share information
We do not sell personal information. We share information only with service providers that help us operate the Service, under contract and only as needed:
- Stripe — payment processing.
- Email (SMTP) and SMS providers — delivery of transactional messages.
- Hosting / infrastructure — where the application and databases run.
We may also disclose information if required by law, to enforce our agreements, or to protect the rights, safety, and security of our users and the Service.
6. Cookies
We use only essential, first-party cookies required to keep you signed in and to protect forms against cross-site request forgery. We do not use advertising or third-party analytics trackers, so no cookie-consent banner is required for our current use.
7. Security
We apply industry-standard safeguards, including: encryption in transit (HTTPS/HSTS); encryption at rest of sensitive identifiers (driver-license numbers and dates of birth) and of stored secrets; hashed passwords with a breached-password check; two-factor authentication; least-privilege access controls and rate limiting; and an append-only, tamper-evident audit log. No method of transmission or storage is perfectly secure, but we work to protect your information commensurate with its sensitivity.
8. Data retention
- Report files are retained online for a limited period (currently 90 days by default) and then purged; metadata and the access audit trail are retained for compliance.
- Audit records are retained for a configurable minimum period (currently at least 730 days) to meet compliance and tamper-evidence requirements.
- Account and billing records are retained for the life of the account and as required for legal, tax, and accounting purposes.
9. Your choices and rights
Customers can review and update their account and company information, manage two-factor authentication and API credentials, and view their batch and API activity from within the application. Depending on your jurisdiction, you may have rights to access, correct, or delete certain personal information. To make a privacy request, or if you are a driver seeking information about a record, contact us at the address below; note that records processed for a Customer's permissible purpose may be subject to legal retention and exemptions.
10. California privacy rights (CCPA/CPRA)
We comply with the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). We do not sell personal information and do not share it for cross-context behavioral advertising, and we use only essential, first-party cookies — no advertising or marketing cookies (see Section 6). California residents have the right to know what personal information we hold, to access or delete it, to correct inaccuracies, and not to be discriminated against for exercising these rights. To exercise a right, contact us using Section 13; we will verify your request and respond as required by law.
11. Children's privacy
The Service is intended for business use and is not directed to children under 13, and we do not knowingly collect personal information from them.
12. Changes to this policy
We may update this policy from time to time. We will revise the effective date above and, for material changes, provide notice through the Service.
13. Contact us
For privacy questions or requests, contact us:
Insurance Information Services, Inc. (Missouri Motor Vehicle Records)PO Box 17088, Tucson, AZ 85731
Email: accounts@missourimvr.com
Phone: (816) 866-1656