Privacy Policy
Last updated: January 2025
1. Information We Collect
1.1 Personal Information
We collect information you provide directly to us, including:
- Full name, email address, and phone number
- Delivery and collection addresses
- Account registration details and preferences
- Payment information and billing addresses
- Communication preferences and marketing consent
1.2 Delivery Information
- Package descriptions, dimensions, and weight
- Special handling instructions
- Delivery time preferences and urgency levels
- Recipient contact details for deliveries
1.3 Technical Information
- IP address, browser type, and device information
- Website usage patterns and click-through data
- Session recordings for customer support purposes
- Cookies and similar tracking technologies
2. How We Use Your Information
2.1 Service Delivery
- Process and fulfill delivery requests
- Calculate accurate quotes and pricing
- Coordinate with delivery partners and drivers
- Provide real-time tracking and updates
- Handle customer service inquiries and support
2.2 Business Operations
- Process payments and manage billing
- Detect and prevent fraudulent activities
- Maintain accurate financial records
- Comply with legal and regulatory requirements
- Improve our services through data analysis
2.3 Communication
- Send delivery confirmations and status updates
- Provide customer support and assistance
- Send promotional offers (with your consent)
- Notify you of service changes or updates
3. Legal Basis for Processing
We process your personal information based on the following legal grounds:
Contract Performance
Processing necessary to fulfill our delivery services and contractual obligations
Legitimate Interests
Improving services, preventing fraud, and ensuring platform security
Legal Compliance
Meeting regulatory requirements and legal obligations
Consent
Marketing communications and optional features (withdrawable anytime)
4. Information Sharing and Disclosure
4.1 Service Partners
- Authorized delivery drivers and courier services
- Payment processors (Stripe, PayPal) for transaction handling
- Address validation services for accurate routing
- Customer support platforms for service assistance
4.2 Legal Requirements
- Law enforcement agencies when legally required
- Regulatory bodies for compliance purposes
- Courts and legal proceedings when necessary
- Tax authorities for financial reporting
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity, with appropriate notice and protection measures.
5. Location and Tracking Data
Our delivery services require location information for optimal functionality:
- Address Information: Collection and delivery locations for route planning
- GPS Tracking: Real-time location during active deliveries
- Route Optimization: Historical data to improve delivery efficiency
- Distance Calculation: Accurate pricing based on travel distance
- Delivery Confirmation: Verification of successful package delivery
Note: Location tracking is only active during delivery periods and can be disabled for completed orders.
6. Payment and Financial Data
6.1 Payment Processing
- Credit and debit card information processed through secure payment gateways
- PayPal account integration for alternative payment methods
- Billing addresses and invoicing information
- Transaction history and payment confirmations
6.2 Financial Security
- PCI DSS compliance for credit card data protection
- Tokenization of sensitive payment information
- Regular security audits and vulnerability assessments
- Fraud detection and prevention mechanisms
6.3 Refunds and Disputes
Financial records are maintained to handle refunds, chargebacks, and payment disputes in accordance with our terms of service and applicable regulations.
7. Data Security Measures
7.1 Technical Safeguards
- End-to-end encryption for data transmission
- Secure database storage with access controls
- Regular security updates and patch management
- Multi-factor authentication for admin access
- Automated backup systems and disaster recovery
7.2 Operational Security
- Employee training on data protection best practices
- Strict access controls based on job responsibilities
- Regular security audits and penetration testing
- Incident response procedures for security breaches
7.3 Data Breach Response
In the unlikely event of a data breach, we will notify affected users within 72 hours and provide detailed information about the incident and our response measures.
8. Data Retention Policies
Account Information
Retained until account deletion
Delivery Records
7 years for legal compliance
Payment Data
6 years for financial regulations
Support Communications
3 years for service improvement
Marketing Preferences
Until consent withdrawal
Anonymous Analytics
2 years for trend analysis
9. Your Privacy Rights
9.1 Access and Portability
- Request a copy of all personal data we hold about you
- Download your data in a commonly used, machine-readable format
- Transfer your data to another service provider
9.2 Correction and Deletion
- Update or correct inaccurate personal information
- Request deletion of your personal data (right to be forgotten)
- Restrict processing of your information in certain circumstances
9.3 Marketing and Communications
- Opt out of marketing emails and promotional communications
- Customize notification preferences for delivery updates
- Object to automated decision-making and profiling
10. Third-Party Services and Integrations
Address Validation
GetAddress API for UK postcode lookup
Privacy Policy: getaddress.io/privacy
Payment Processing
Stripe and PayPal for secure transactions
Privacy Policies: stripe.com/privacy, paypal.com/privacy
Mapping Services
Google Maps for route calculation
Privacy Policy: policies.google.com/privacy
Analytics
Usage analytics for service improvement
Anonymized data collection only
11. International Data Transfers
Your personal information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards through:
- European Commission adequacy decisions for approved countries
- Standard Contractual Clauses (SCCs) approved by data protection authorities
- Binding Corporate Rules for intra-group data transfers
- Certification schemes and codes of conduct
Note: We maintain the same level of protection regardless of where your data is processed.
12. Children's Privacy Protection
Our services are not intended for children under 16 years of age. We do not knowingly collect, use, or disclose personal information from children under 16.
If We Learn We Have Collected Children's Information:
- We will delete the information as quickly as possible
- We will notify the child's parent or guardian
- We will review our collection practices to prevent recurrence
If you believe we have collected information from a child under 16, please contact us immediately at privacy@velocishift.com.
13. Automated Decision Making and Profiling
13.1 Automated Systems
We use automated systems for:
- Route optimization and delivery time estimation
- Dynamic pricing based on distance and demand
- Fraud detection and risk assessment
- Customer service chatbot responses
13.2 Your Rights
You have the right to:
- Request human review of automated decisions
- Express your point of view regarding automated processing
- Contest decisions that significantly affect you
14. Marketing and Communications
14.1 Types of Communications
- Transactional: Order confirmations, delivery updates (cannot opt out)
- Service: Account updates, policy changes, security notices
- Marketing: Promotional offers, new features, company news (opt-in required)
14.2 Preference Management
You can manage your communication preferences through your account settings or by contacting us directly. Marketing unsubscription links are included in all promotional emails.
15. Business Continuity and Data Protection
15.1 Data Backup and Recovery
- Regular automated backups to secure, geographically distributed locations
- Disaster recovery procedures tested quarterly
- Business continuity plans for service disruptions
15.2 Service Availability
We maintain 99.9% uptime commitment with redundant systems and failover mechanisms to ensure your data remains accessible and secure.
16. Regulatory Compliance
VelociShift complies with applicable data protection regulations including:
GDPR (EU)
General Data Protection Regulation
UK GDPR
UK Data Protection Act 2018
PECR
Privacy and Electronic Communications Regulations
PCI DSS
Payment Card Industry Data Security Standard
17. Updates to This Privacy Policy
17.1 Notification Process
When we update this Privacy Policy, we will:
- Update the "Last updated" date at the top of this page
- Send email notifications for material changes
- Display prominent website notices for 30 days
- Obtain explicit consent where required by law
17.2 Review Schedule
We review and update this policy annually or when significant changes occur to our data processing activities.
18. Contact Information and Data Protection Officer
For all privacy-related inquiries, exercising your rights, or reporting concerns:
Data Protection Officer
dpo@velocishift.com
+44 20 1234 5678 (Ext. 101)
General Privacy Inquiries
privacy@velocishift.com
Response within 48 hours
Postal Address
VelociShift Limited
Data Protection Team
Business Address
City, Postal Code, Country
Supervisory Authority
Information Commissioner's Office (ICO)
ico.org.uk
Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority if you believe we have not handled your personal information appropriately.