Effective date: [Insert Date]
1. Who we are
We are [Company Name] (registered in England & Wales, company number [XXX]), trading as [TaxiBookingSite]. Our registered address is [Address]. We are the data controller for your personal information.
2. What data we collect
- Account data: name, email address, phone number, home/postcode address (if you create an account).
- Booking data: pickup/drop-off locations, journey date/time, passenger notes (e.g., accessibility needs), fare amount.
- Payment data: card details (processed by our PCI‑DSS compliant payment partner – we do not store full card numbers).
- Device & usage data: IP address, browser type, location (if you allow), cookies.
- Communications: messages to drivers or customer support via our platform.
3. How we use your data
We use your data to:
- Process and confirm taxi bookings.
- Dispatch a driver to your pickup location.
- Calculate fares and process payments.
- Send booking confirmations, reminders, and receipts.
- Improve our service (e.g., journey times, app performance).
- Comply with legal obligations (e.g., VAT, driver license checks).
- Prevent fraud and ensure safety.
4. Legal basis for processing (UK GDPR)
- Contract: to provide the booking service you request.
- Legal obligation: for record‑keeping, tax, or regulatory compliance (e.g., taxi licensing).
- Legitimate interests: to improve our platform, prevent fraud, and communicate service updates.
- Consent: for marketing emails (you can opt out at any time) or precise location data.
5. Who we share your data with
- Taxi drivers / operators: name, pickup location, and journey details (drivers need this to collect you).
- Payment processors: for secure card transactions.
- IT service providers: hosting, analytics, SMS notifications.
- Law enforcement / regulators: if required by law (e.g., for an accident investigation or safeguarding).
We never sell your personal data.
6. How long we keep your data
- Booking records: 7 years (for tax and insurance purposes).
- Account data: until you close your account, plus 2 years.
- Marketing data: until you unsubscribe.
- Call/chat logs: 12 months.
7. Your rights
Under UK GDPR you have the right to:
- Access your data (subject access request).
- Rectify inaccurate data.
- Erasure (in certain circumstances).
- Restrict processing.
- Data portability.
- Object to processing based on legitimate interests or direct marketing.
To exercise a right, contact us at [privacy@example.com]. We will respond within one month.
8. Security
We use encryption (TLS) for data in transit, restrict access to staff/drivers, and regularly review our systems.
9. Cookies
Our site uses essential cookies for booking functionality and analytics cookies (Google Analytics). You can manage preferences via our cookie banner.
10. Children
We do not knowingly collect data from anyone under 13. If you are under 18, you must have parental/guardian permission to book a taxi.
11. Changes to this policy
We will post any changes on this page with an updated effective date. Significant changes will be notified by email or website notice.
12. Contact us
For privacy queries or to complain to the ICO (www.ico.org.uk), please contact:
Data Protection Officer
[Company Name]
[Address]
[Email]
[Phone]