Privacy policy
Last updated: 18 May 2026 · Effective for all customers of Driveino.
This policy explains what personal data Driveino collects, why we collect it, how we use it, and your rights over it. It is written in plain English. Where we use a defined term in bold, that meaning applies wherever it appears in this document.
1. Who we are
Driveino is operated by Driveino Ltd ("Driveino", "we", "us") — a dispatch software platform for chauffeur, executive and small-fleet taxi operators. We are the data controller for personal data processed about the people who sign up to and use our platform directly.
When your dispatch company uses Driveino to process data about their drivers and customers, we act as a data processor — your company is the data controller, and Driveino is bound by a Data Processing Agreement with them.
Contact: hello@driveino.com · 020 3332 2424 · Data requests: legal@driveino.com
2. What data we collect
From accounts you create
- Identity: name, email, phone number, password hash.
- Company details (operators only): trading name, business address, fleet size, plan, currency.
- Driver details (drivers only): name, mobile, photo (if uploaded), vehicle and document details you choose to upload.
- Two-factor data: if you enable 2FA, we store a TOTP secret (encrypted at rest) or your mobile number for SMS / WhatsApp delivery.
From your use of the platform
- Bookings & jobs you create, including customer name and contact for trip recipients.
- Live GPS while a driver is on a job (en route, arrived, on board). Capture stops when the job completes.
- Messages we send on your behalf (WhatsApp, SMS, email) and delivery receipts from providers.
- Device tokens for mobile push notifications.
- Audit trail: who did what, and when — used for security and dispute resolution.
Automatically when you visit the site or app
- IP address and the device / browser making each request.
- Session cookies required to keep you signed in (see "Cookies" below).
- Error logs when something goes wrong — these may contain partial request data.
Payment data
We do not handle card details. Direct Debit mandates and payment instructions are managed by GoCardless, who hold the bank-account information directly. We store only the GoCardless customer ID and mandate ID to reference your subscription.
3. Why we use your data (legal basis)
- To provide the service — performance of contract. Without this data the platform cannot function.
- To take payment — performance of contract. Direct Debit instructions are processed via GoCardless.
- To send service notices (login codes, billing reminders, security alerts) — legitimate interests and contractual necessity.
- To improve the platform — legitimate interests. Aggregated, never sold.
- To meet legal obligations — accounting records, tax reporting, fraud prevention.
We do not use your data for advertising, profiling or training third-party AI models.
4. Who we share data with
| Provider | What we share | Why |
|---|---|---|
| GoCardless | Company name, email, bank-mandate references | Direct Debit collections |
| WaSenderAPI | Recipient phone numbers + message body | WhatsApp delivery |
| SMS / email providers | Recipient details + content | Fallback notifications |
| Firebase Cloud Messaging | Device tokens, notification payload | Mobile push notifications |
| AviationStack (or equivalent) | Flight numbers from your jobs | Flight status tracking |
| Hosting (StackCP, UK) | All platform data | Running the application |
We do not sell your data. We do not share with marketing networks. Sub-processors are bound by appropriate contracts.
5. International transfers
Platform data is hosted in the UK. Some of our sub-processors (FCM, certain email providers) operate globally; where data leaves the UK we rely on Standard Contractual Clauses or adequacy decisions to protect it.
6. How long we keep data
- Account data: while your account is active, plus 30 days after closure (recoverable on request) and then deleted, except where law requires longer retention.
- Billing / accounting records: 6 years after the relevant tax year, as required by UK accounting law.
- Audit logs: 2 years from creation, then anonymised.
- Messages we send on your behalf: 12 months for deliverability investigation, then deleted.
- Live GPS pings: deleted within 30 days of the job ending unless required for an active dispute.
7. Your rights (UK GDPR)
You have the right to:
- Access — a copy of your personal data.
- Rectify — correct anything wrong.
- Erase — ask us to delete your data (subject to legal retention obligations).
- Restrict / object to processing.
- Data portability — receive your data in a machine-readable format.
- Withdraw consent where we relied on it (and to know consent was given).
- Complain to the UK Information Commissioner's Office (ico.org.uk).
Email legal@driveino.com — we'll reply within 30 days, usually faster.
8. Cookies
We use only essential cookies:
- Session cookie (
PHPSESSID) — keeps you signed in. Cleared when you log out. - CSRF token — protects against cross-site form submissions.
We do not use advertising, analytics or third-party tracking cookies on the marketing site or the platform.
9. Security
We hash passwords with bcrypt, enforce HTTPS site-wide, support two-factor authentication, and apply role-based access controls. We run a written incident-response process; if your data is ever affected by a security incident, we will notify you and the ICO within the 72-hour statutory window where required.
10. Children
The platform is not intended for users under 16. Driver accounts require proof of age and licence on the company side. If you believe a minor has signed up, email us and we'll close the account.
11. Changes to this policy
If we make material changes, we'll email account holders at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.
12. Contact
Driveino Ltd · 020 3332 2424 · Email: legal@driveino.com · For general enquiries: hello@driveino.com
This policy is provided in good faith and based on UK GDPR / Data Protection Act 2018 requirements at time of writing. We recommend treating this version as a working baseline and reviewing periodically.