← Back to home

Privacy Policy

Last updated: May 2026 · Storm Dispatch — sole trader, United Kingdom

1. Who we are

Storm Dispatch (“we”, “us”, “our”) is a sole trader operating in the United Kingdom. We provide dispatch management software to licensed taxi and private hire operators.

Contact: [email protected]

2. Our roles under UK GDPR

We act as:

  • Data controller — for personal data we collect in connection with our own business (account registration, billing contacts, marketing enquiries).
  • Data processor — for personal data that operator customers process through our platform on behalf of their own passengers, drivers, and staff. In that capacity we act solely on the operator's documented instructions.

A Data Processing Agreement (DPA) is incorporated into our Terms of Service and applies to all operator accounts.

3. What personal data we collect

Account & billing data (controller)

Name, email address, phone number, company name and address for operators who subscribe to the platform.

Operator platform data (processor — on operator's behalf)

  • Driver data: full name, contact details, vehicle registration, licence number, DBS certificate reference, compliance document images, earnings records.
  • Passenger / customer data: name, phone number, pickup and drop-off addresses, booking history, payment method, fare records.
  • Journey data: GPS coordinates, route data, timestamps.

Usage and technical data (controller)

Browser type, IP address, pages visited, error logs. Collected via standard server logs and Supabase infrastructure. No third-party analytics trackers are used.

4. Lawful basis for processing

PurposeLawful basis
Providing the dispatch platform to operatorsContract performance (Art. 6(1)(b))
Billing and payment processingContract performance (Art. 6(1)(b))
Responding to support enquiriesLegitimate interests (Art. 6(1)(f))
Compliance and fraud preventionLegal obligation / Legitimate interests (Art. 6(1)(c)(f))
Processing operator passenger and driver dataProcessor acting on operator instructions
Marketing communications (if you opted in)Consent (Art. 6(1)(a))

5. Data retention

  • Booking and journey records are auto-anonymised after 2 years (passenger name and contact details replaced with tokens; route data retained in aggregate for reporting).
  • Driver compliance documents are retained for the duration of the driver's active relationship with the operator, plus 12 months, then deleted.
  • Account data for operators is retained for the duration of the subscription plus 6 years (UK tax record requirements) then deleted.
  • Server logs are retained for 90 days.

6. Data sharing and sub-processors

We do not sell personal data. We share data only with the following sub-processors, each bound by data processing agreements:

  • Supabase Inc. (USA) — database, authentication, and edge functions. EU/UK data stored in EU-West region. Standard Contractual Clauses apply.
  • Hetzner Online GmbH (Germany) — web hosting and VPS infrastructure. EU data residency. Standard Contractual Clauses apply.
  • Mapbox Inc. (USA) — mapping and geocoding. Geocoding queries contain address strings only, no PII identifiers.
  • Resend Inc. (USA) — transactional email (receipts, invoices). SCCs apply.
  • Twilio / Vonage / Plivo — SMS notifications (operator-configured). Operator chooses their provider; our platform transmits booking reference data only.

7. International transfers

Some of our sub-processors are based in the USA. All transfers are covered by UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs) as appropriate under UK GDPR Art. 46.

8. Your rights

As a data subject under UK GDPR you have the right to:

  • Access — obtain a copy of your personal data (subject access request).
  • Rectification — correct inaccurate data.
  • Erasure — request deletion where there is no overriding lawful basis to retain the data.
  • Restriction — pause processing pending a rectification dispute.
  • Portability — receive your data in a structured, machine-readable format.
  • Object — to processing based on legitimate interests.
  • Withdraw consent — at any time, where processing is based on consent.

Passengers of operators who use Storm Dispatch should contact that operator in the first instance, as the operator is the data controller for their journey data. Operators can also submit requests on behalf of their passengers via the GDPR tools in the dispatch console.

To exercise your rights, email [email protected]. We will respond within 30 days (or 3 months for complex requests, with notice).

9. Complaints

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk · 0303 123 1113.

10. Cookies

The dispatch console uses a single session cookie required for authentication (Supabase JWT). No advertising, analytics, or tracking cookies are set. No consent banner is required for strictly necessary cookies under PECR.

11. Changes to this policy

We will notify active operators of material changes by email at least 14 days before they take effect. The “last updated” date at the top reflects the most recent revision.

12. Contact

Data protection enquiries: [email protected]
Storm Dispatch · United Kingdom