Courier247
UK GDPR · Data Protection Act 2018

Privacy notice

How Courier247 uses personal data for invited drivers and fleet operators. This is the notice we give to Apple, Google and anyone using the service.

Effective 20 August 2026 Last updated 20 August 2026 Service: courier247.com

1. Who we are

Courier247 is a transport operations service for courier fleets. Drivers use the Courier247 Driver app. Fleet owners use the dispatch workspace at courier247.com.

Until a Companies House entity is published here, the data controller for the Courier247 platform (accounts, hosting, security, support) is the operator of this service. Contact: amy132932@gmail.com.

The fleet that invited you is the controller for day-to-day job, evidence and invoicing data about work you do for them. We process that data on their instructions.

2. Who this notice covers

  • Drivers using iOS, Android or the web driver workspace
  • Fleet owners, dispatchers and admin users
  • People named on jobs or invoices (customers, sites, payees) where a fleet stores that information

The app is not for children. You must be 18 or over. Companies and drivers can register from the app. Trading documents are collected later and are only required before invoicing.

3. Personal data we process

CategoryExamplesSource
AccountName, email, phone, login identifiers, role (owner / driver)You or your fleet when inviting you
ComplianceOnboarding documents and licence / vehicle details the fleet requiresYou, in the app
JobsAddresses, time windows, notes, status, quotesYour fleet
LocationGPS stamps at job events while the app is in use — not background trackingDevice, with permission
EvidencePOD photos, signatures, related timestampsYou, in the app
DevicePush token, app version, approximate device typeApp, after you enable notifications
FinanceInvoice snapshots, VAT figures, bank details you enter for self-bill payee lines, recorded payments (in-app record only — we do not debit your bank)You and your fleet
Support / securityEmails you send us, deletion requests, audit events, screenshot-event metadata (not the screenshot image)You / the app
DiagnosticsCrash and error reportsDevice via Sentry, if enabled

We do not sell personal data. We do not use it for advertising profiles. We do not ask for special-category data (health, ethnicity, biometrics for identification) as part of the core product.

4. Why we use it and lawful bases (UK GDPR Art. 6)

  • Contract — creating your invited account, showing jobs, completing deliveries, producing invoices the fleet asked for.
  • Legitimate interests — keeping the service secure, preventing abuse, diagnosing crashes, showing the fleet operational evidence. You can object; we will stop unless we have a compelling ground or a legal hold.
  • Legal obligation — UK tax and VAT records (including self-billing rules), accounting retention, responding to lawful requests.
  • Consent — optional notifications, optional camera/photos, optional precise location. You can refuse or withdraw in device settings. Some job steps cannot complete without evidence the fleet requires.

5. Location

Phase 1 uses when-in-use location only. We record event stamps tied to job actions (for example arriving or completing a stop). We do not request background / always-on tracking and we do not live-broadcast a continuous GPS trail.

If you deny location permission, some arrival checks cannot run. The fleet may still require a manual confirmation.

6. Photos, camera, signatures and screenshot protection

Proof of delivery photos and signatures are stored as operational evidence for the fleet. They are encrypted in transit and at rest with our hosting providers.

On Android, FLAG_SECURE blocks ordinary screenshots and recents previews of sensitive screens. On iOS, sensitive screens are excluded from screenshots and recording; the app may record a screenshot event (time, user, job — not the image itself) for the fleet’s audit log.

This does not stop someone photographing the screen with another camera.

7. Invoices, bank details and self-billing

Fleets can issue customer invoices and HMRC-style self-billed invoices. Issued documents are snapshots and are not silently rewritten; corrections use credit or debit notes.

If you submit payee bank details, they are used to print on self-bill paperwork and to record that a fleet marked a claim paid or partly paid in the app. Courier247 does not operate a bank, wallet or card acquiring. We do not take money from your account.

Financial records are kept for the statutory UK period (typically up to 6 years after the end of the relevant accounting period, longer if HMRC or a dispute requires it).

8. Optional owner AI

Chat and briefing for owners are off unless the fleet owner turns them on. If enabled, prompts and limited operational context may be sent to our AI provider (currently NVIDIA NIM, with a configured fallback only if the owner selected it) to generate a short answer. Do not paste secrets into chat. AI output can be wrong; it does not replace dispatch decisions.

9. Who we share data with

Your fleet’s authorised users see job and driver data for that fleet only (row-level access control).

We use processors under contract. Current categories:

  • Supabase — database, auth and file storage (EU region for production)
  • Vercel — website and admin/driver web hosting
  • Railway — API and background workers
  • Google Firebase — push notifications (FCM / APNs)
  • Resend — transactional email (invites, password reset) when configured
  • Sentry — crash diagnostics (EU)
  • Map and address providers — OpenFreeMap tiles; Google Places only when an API key is configured for address lookup
  • NVIDIA — only if the owner enables AI features

We disclose data if required by UK law, a court or regulator, or to protect the service from abuse.

10. International transfers

We aim to keep primary databases in the UK/EU. Some processors (for example Google push, Vercel edge, optional AI) may process data in other countries. Where UK GDPR requires a transfer tool, we rely on the supplier’s UK addendum / Standard Contractual Clauses and their published transfer documentation.

11. How long we keep it

  • Account after deletion — identifiers and device tokens are removed; see delete account.
  • Job evidence — normally 12 months after completion, unless a dispute or legal hold applies.
  • Audit / security logs — limited operational window, longer if investigating an incident.
  • Tax and invoice records — as required by UK law (see section 7).

12. Security

Access is authenticated. Production data is separated by fleet. Transport uses HTTPS. Uploaded evidence is stored with provider encryption. No method is perfect; you must keep your login private and use a unique password.

13. Your rights

Under UK GDPR you can request access, correction, erasure, restriction, objection, and portability where applicable. You can withdraw consent for optional permissions in the OS settings.

Some rights are limited where we (or your fleet) must keep records for tax, disputes or security. We will explain if we cannot fully erase a record and what we anonymise instead.

To exercise rights: use the app where possible, or email amy132932@gmail.com from the address on the account. We may need to verify it is you.

14. Deleting your account

Drivers: Me → Request account deletion. The fleet owner confirms erasure. Direct identifiers are removed. Lawful transport and financial records may remain in anonymous form.

If you cannot open the app, follow courier247.com/delete-account.

15. Cookies and similar tech

The web workspace uses cookies or local storage that are necessary to keep you signed in, remember theme, and protect the session. We do not run advertising cookies. Browser diagnostics may set a first-party error-reporting cookie if Sentry is enabled.

16. Automated decisions

Job matching uses rules the fleet configured (for example vehicle size). That is not solely automated legal-effect profiling under Art. 22. Optional AI suggestions are assistive only.

17. Changes

We will update this page when the product or processors change. The “Last updated” date at the top is the version in force. Material changes may also be notified in the app or by email where we have a working address.

18. Complaints

Please contact us first so we can try to fix it. You can also complain to the UK Information Commissioner’s Office: ico.org.uk/make-a-complaint.

Contact
Courier247 privacy
amy132932@gmail.com
Web: courier247.com