Skip to content
Legal

Data processing addendum

This addendum forms part of the Terms of Service for business clients (the controller) whose deliveries RentADriver (the processor) fulfils. It applies where the UK GDPR, the EU GDPR or the Australian Privacy Act applies to the personal data in a delivery. Last updated 6 September 2026.

1. What we process and why

To perform a delivery we process the personal data you submit in a booking: recipient and sender names, phone numbers, addresses, delivery instructions and, where you request it, proof of delivery (photo, signature, recipient name). We process it only to quote, dispatch, perform, prove and invoice the delivery, to notify the recipient, and to resolve disputes. We never sell it or use it for advertising.

2. Instructions

We act only on your documented instructions, which are the API calls, console actions and MCP tool calls you make, plus these terms. If we believe an instruction breaks the law we will tell you before acting.

3. Confidentiality and security

Drivers see only what a delivery needs (names, addresses, phone numbers via the app, instructions) and only while the job is active. Staff access is role-based and logged. Data is encrypted in transit; backups are encrypted at rest and stored in the EU; every database table has row-level security enabled; secrets live in an encrypted store, never in code. See Security for the current controls.

4. Subprocessors

We use the following subprocessors. We will update this page at least 14 days before adding one that processes your data; you may object in writing within that period, in which case you may terminate the affected service.

SubprocessorPurposeRegionData
DigitalOcean, LLCKubernetes cluster (API, website, console, MCP server), DNS, encrypted backup storage, uptime checksFrankfurt, Germany (EU)All platform data in transit through our services
OVHcloudDedicated server hosting our own PostgreSQL / Supabase stack (database, file storage, realtime) and the self-hosted notification serviceEuropean UnionAccounts, deliveries, driver profiles, proof-of-delivery files, notification history
Stripe, Inc.Card payments for wallet deposits, driver payouts (Stripe Connect Express)United States / EU entitiesPayment details, payout identity (handled by Stripe directly)
Mailgun Technologies, Inc.Transactional and account email, inbound support mailEU regionEmail addresses, message content
Twilio Inc.SMS notifications to recipients and drivers, one-time codesUnited StatesPhone numbers, message content
Functional Software, Inc. (Sentry)Error monitoring for the APIUnited StatesRequest metadata in error reports (no message bodies)
Google LLCFirebase Cloud Messaging (Android push), Google Analytics (website, only with consent), Play IntegrityUnited States / globalPush tokens, device integrity tokens, pseudonymous analytics
Apple Inc.Apple Push Notification service, App AttestUnited States / globalPush tokens, device attestation
Cloudflare, Inc.Turnstile bot check on browser sign-upGlobalIP address, browser signals during sign-up only
Open-data mapping, geocoding and routing servicesMap tiles, address geocoding, road routingEuropean UnionAddresses and coordinates of pickups and drop-offs
Shopify Inc.Only for merchants who install the Shopify app: order and fulfilment syncCanada / globalOrder and recipient details of merchant deliveries

5. Individuals' rights

We help you answer access, correction and deletion requests within 10 business days. Recipients can also reach us directly; we will confirm with you before acting on a request that concerns your booking.

6. Breach notification

We notify you without undue delay, and in any case within 48 hours of confirming a personal data breach that affects your data, with what we know, what we are doing and a contact.

7. Retention and deletion

Delivery records are kept for 7 years for tax and dispute purposes; proof-of-delivery files for 90 days after delivery unless a dispute is open; driver location history for 30 days; API request logs for 30 days. On termination we delete or return your data within 30 days unless the law requires retention. See Delete your account and data.

8. International transfers

Core data stays in the EU. Where a subprocessor above is outside the UK/EU we rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, and on the EU-US Data Privacy Framework where the provider is certified.

9. Audit

On written request, no more than once a year, we provide our latest security summary and answers to a reasonable questionnaire. On-site audits are available for enterprise plans under a separate agreement.

10. Contact

Data protection questions: privacy@rentadriver.ai. RentADriver is the contracting entity.

Support