Privacy & data handling
We hold as little as possible, for as short as possible.
This notice is written to be read, not to be survived. It says exactly what we collect, why we are allowed to, who else ever sees it, how long it lives and what we will never do with it, in that order, without hedging.
- Version
- 1.1
- In effect from
- 8 August 2026
- Governing law
- England and Wales
Contents
- 01Who we are
- 02The rules we hold ourselves to
- 03What we collect
- 04What we never collect
- 05Why we are allowed to hold it
- 06How long we keep it
- 07Who else touches it
- 08Where in the world it goes
- 09How it is protected
- 10Cookies and tracking
- 11Your rights
- 12If something goes wrong
- 13Children
- 14Changes to this notice
- 15Complaints
Who we are
Blackfleet is the data controller for the personal data described in this notice. That means we decide what is collected and why, and we are the ones answerable for it. We are based in England and Wales and this notice is governed by its law.
Privacy questions, rights requests and complaints go to privacy@blackfleet.dev. Suspected vulnerabilities or exposures go to security@blackfleet.dev. Both are read by a person, not a ticketing robot.
What this notice covers
This notice covers blackfleet.dev, the Blackfleet booking platform and apps, and the corporate accounts we operate. Where a chauffeur partner processes your data on our written instructions for a journey we arranged, we remain responsible for it under § 07.
If you have only used the enquiry form on this site, the only data we hold about you is the list in § 03(a). Nothing in § 03(b) or § 03(c) applies to you until you hold an account and take a journey.
The rules we hold ourselves to
Eleven commitments. They are binding on us, they are stricter than the law requires, and they are the first thing we would have to change if we ever wanted to behave worse.
- 01
We never sell personal data. There is no price at which we would.
- 02
We never share it for profiling, enrichment or lead resale.
- 03
We do not train, tune or evaluate machine learning models on your data.
- 04
This site sets no cookie until you allow it, and refusing is one click and just as easy.
- 05
We run two advertising measurements, Google and OpenAI, described in full in § 10. They are the only third parties that learn anything about your visit, and only if you say yes.
- 06
We collect the minimum a journey needs, and refuse the rest.
- 07
Nothing is recorded in the cabin: no audio, no video, ever.
- 08
We do not read the contents of your calendar beyond the fields a booking needs.
- 09
Every person and partner who touches your data is under a signed NDA.
- 10
Deletion is real deletion, on the schedule in § 06, without you asking.
- 11
If your data is ever exposed, you hear it from us within 72 hours.
If a future change to our business would break one of these, we will not make the change quietly. We will tell every account holder in writing first, under § 14.
What we collect
Three groups, and nothing outside them. Group (a) applies to anyone who fills in a form here. Groups (b) and (c) apply only once you hold an account. Two further things are described at the end of this section, because neither is a record we keep about you: the logs our own servers write, and the advertising identifiers that live on your device rather than in our files.
Enquiries. When you use a form on this site we receive: your name, work email address, company, phone number, your preferred time of day for a call, and, depending on the form, your role, your city, your fleet size or your approximate journeys per month, plus anything you type into the free-text box. We add the time we received it and which form it came from. That is the entire record. There is no hidden field and no enrichment lookup against a data broker. Where you have allowed advertising cookies, a one-way hash of your email address is also sent to Google and to OpenAI, and a hash of your phone number to Google alone, to measure the advert that brought you here. § 10 sets out exactly what that is, and how to refuse it.
Accounts and journeys. To move someone, we need the passenger's name or an internal reference, a pickup and dropoff, a time, contact details for the day, and, where you give them, a flight number, a cost centre and standing preferences such as temperature or route. We hold the vehicle, the chauffeur assigned, timestamps for the journey, and the price charged.
Calendar and system connections. If you connect a calendar, we request the narrowest scope the provider offers and read only the fields a booking needs: start and end time, location, and whether the event moved. We do not store event titles, attendee lists, descriptions, attachments or any event you have not designated as travel. Tokens are held encrypted and revoked the moment you disconnect.
Our servers keep short-lived operational logs: the fact that a request happened, when, and whether it failed. Where a booking fails to reach us, the submission is written to those logs rather than lost, so that we can contact you; it is subject to the same retention limit in § 06 and the same deletion.
The advertising identifiers in § 10 are the one thing on this page we never hold. If you allow them, Google and OpenAI set them on your own device and read them from there; they are not sent to our servers, not attached to your enquiry, and not stored next to your name. What comes back to us is a count of conversions, not a list of people. We could not look yours up even if you asked us to.
What we never collect
The following are not collected, not inferred and not accepted if offered. If a field on any Blackfleet surface appears to ask for one of these, it is a bug: report it to security@blackfleet.dev.
- Audio or video from inside a vehicle. Nothing in the cabin is recorded.
- Special category data (health, religion, politics, sexuality, biometrics, trade union membership) unless you volunteer an access requirement, which we hold only for the journey it concerns and then delete.
- Full payment card numbers. Card details go directly to our payment processor; we see a token, the last four digits and the expiry, never the number.
- Background location from a phone. We hold vehicle position during a live journey, not passenger position.
- Device fingerprints, session or screen recordings, keystroke logging, or any record of how you moved around this page. The advertising measurements in § 10 are limited to which pages were opened and whether an enquiry followed.
- Anything bought from a data broker, list vendor or enrichment service.
Why we are allowed to hold it
Under the UK GDPR and, where it applies, the EU GDPR, we must have a lawful basis for every use. Ours are these, and we do not quietly re-use data collected under one basis for a purpose that needs another.
- Contract
- Booking, running, changing and settling journeys for an account we hold. Without this data there is no journey.
- Legitimate interests
- Replying to an enquiry you sent us, keeping the service secure, preventing fraud and abuse, and keeping records of what we agreed. We have weighed each of these against your interests and will send you the assessment on request.
- Consent
- Advertising cookies and the measurements in § 10, connecting a calendar or another system, and any marketing email. Consent is asked for plainly, never bundled, and withdrawing it is one click and takes effect immediately.
- Legal obligation
- Tax, accounting and licensing records we are required to keep, and lawful requests we are compelled to answer.
We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. Dispatch software chooses a vehicle; it does not decide anything about you.
How long we keep it
Deletion happens on a schedule, automatically, whether or not anyone asks. These are ceilings, not targets. If we finish with something sooner, it goes sooner.
- Enquiries
- 12 months from your last contact with us, then deleted. If you tell us you are not interested, we delete it within 7 days and keep only your email address on a suppression list so we do not contact you again.
- Journey records
- 24 months, then reduced to the anonymous facts we need for capacity planning: no names, no addresses, no references.
- Passenger preferences
- For as long as the account is open, and deleted within 30 days of it closing.
- Calendar tokens
- Revoked and destroyed immediately on disconnection or account closure.
- Operational logs
- 30 days, then purged. Security logs of failed access attempts: 12 months.
- Advertising identifiers
- Not ours to delete, because they are not ours to hold. They sit on your device for the lifetimes listed in § 10 (90 days for Google's, and 30 days, 30 days and a year for OpenAI's three) and withdrawing consent deletes them from the device at once, without waiting for any of that to run out. What each platform keeps on its own side is governed by its own policy, which is precisely why § 07 names them as controllers rather than as our processors.
- Invoices and tax records
- 6 years, because we are required to. These are locked down to finance and are not used for anything else.
- Backups
- Encrypted, rolling 35 days. A deletion request is applied to live systems at once and works through backups as they expire; nothing deleted is ever restored back into service.
Who else touches it
A short list, and we do not add to it casually. All but two are processors under a written contract binding them to our instructions, our security standards and our retention limits; none of them may use your data for their own purposes. The exceptions are the two advertising measurements below, which are not processors and are not bound that way, which is exactly why they are the only ones on this list you are asked about before they happen.
- Chauffeur partners
- The operator performing your journey receives the minimum required to perform it: passenger name or reference, pickup, dropoff, time and the contact number for the day. Not your account, not your history, not your other journeys. Every chauffeur has a signed NDA on file.
- Hosting
- Our application and its API run on a managed cloud platform in the United Kingdom or the European Union.
- Notification delivery
- New enquiries are delivered to a private, unlisted channel so we can respond quickly. The message body is encrypted with AES-256-GCM before it leaves our servers; the delivery provider transports ciphertext it cannot read.
- Advertising · Google
- Google Ads, and only once you have allowed advertising cookies. It receives which of our pages were opened, which advert click preceded them, and, if you send a form, a one-way SHA-256 hash of your email address and phone number, so it can match the enquiry to the click. Unlike the processors above, Google is not our processor: it decides its own purposes as a controller in its own right, under its own privacy policy. That is precisely why it sits behind a consent banner instead of being assumed.
- Advertising · OpenAI
- ChatGPT Ads, on the same terms and behind the same one click. It receives less than Google does: the reference for the ChatGPT advert click that brought you here, a random identifier for the browser, the address of the page it loaded on and the page you arrived from, without any query string, and, if you send a form, a one-way SHA-256 hash of your email address. Not every page you then read, and never your phone number in any form, because OpenAI does not accept one. It too is an independent controller under its own privacy policy, not our processor. Until you have said yes, its pixel is not merely switched off. It is never fetched, so there is nothing on the page to switch off.
- Payments
- A regulated payment processor, which holds card details directly. We never receive them.
- A business email provider, for correspondence with you.
- Authorities
- Only where we are legally compelled. We require a lawful, specific request, we refuse fishing expeditions, and we will tell you unless we are prohibited by law from doing so.
We will name any current processor on request. If we ever change one in a way that affects your data, § 14 applies. If Blackfleet were ever acquired, personal data would transfer only under this notice; an acquirer wanting to use it differently would have to ask you.
Where in the world it goes
Personal data is stored in the United Kingdom or the European Economic Area by default. We arrange journeys in cities outside the UK and EEA, and in those cases the minimum journey detail in § 07 necessarily reaches the operator performing it.
Where data leaves the UK or EEA it goes only to a country with an adequacy decision, or under the UK International Data Transfer Agreement or the relevant Standard Contractual Clauses, with a transfer risk assessment on file. We will send you a copy of the mechanism used for any specific transfer if you ask.
Two transfers are worth naming outright. Where you have allowed advertising cookies, the measurement data in § 07 reaches the United States: Google under the EU–US Data Privacy Framework and its UK extension, to which Google is certified, and OpenAI under the European Commission's Standard Contractual Clauses and the UK addendum to them, which is the mechanism its own advertising terms rely on. Declining the banner stops both before they happen.
How it is protected
Security is not a paragraph of adjectives. These are the specific measures we operate, and we expect to be held to them.
- Everything in transit is over TLS 1.2 or better. There is no unencrypted path into our systems.
- Enquiry payloads are encrypted with AES-256-GCM before leaving our servers, using a key held only in our own environment and never given to a third party.
- Data at rest is encrypted, including backups.
- Access is least-privilege and named: no shared logins, no standing production access, multi-factor authentication on every account that can reach personal data.
- Access to personal data is logged, and the logs are reviewed.
- Production data is never copied into development or test environments.
- Personal data is not stored on personal devices, personal accounts or removable media.
- Staff and chauffeur partners are under confidentiality obligations that survive the end of their engagement.
- Access is revoked the day someone leaves, not the week after.
No system is perfect and we will not claim otherwise. What we will do is § 12.
Your rights
These rights are yours under data protection law. Exercising them is free, will never count against you, and does not require a form, a portal or a reason.
- Access
- A copy of everything we hold about you.
- Rectification
- Correction of anything wrong.
- Erasure
- Deletion, except the narrow set of records we are legally required to keep, which we will identify to you specifically.
- Portability
- Your data in a machine-readable file you can take elsewhere.
- Restriction
- A freeze on our use of it while a dispute is resolved.
- Objection
- An objection to any use we base on legitimate interests. For marketing, the objection is absolute and immediate.
- Withdraw consent
- At any time, without affecting anything done lawfully before you withdrew it.
Write to privacy@blackfleet.dev. We answer within 14 days. The law allows a month, and we do not intend to use it. We will ask for proof of identity only where we genuinely cannot tell it is you, and we will never use that as a delaying tactic.
If you are a passenger, not the account holder
Your employer or host may have booked on your behalf. You still hold every right above directly against us, and you do not need their permission to use one. Write to us and we will deal with you, not with them.
If something goes wrong
If personal data is exposed, we will tell you within 72 hours of establishing that it happened, not only where the law requires notification, but whenever your data was involved at all. The notice will say what was taken, when, how it happened, what we have done and what you should do. We will not wait for a complete investigation to make the first contact.
Where required, we report to the Information Commissioner's Office within 72 hours. We will not describe a breach as an incident, an issue or an anomaly.
Children
Blackfleet is a service for businesses and is not directed at children. We do not knowingly collect data from anyone under 18 through this site. Where a minor travels as a passenger, we hold only what the journey requires and delete it on the schedule in § 06. If you believe we hold a child's data unnecessarily, tell us and it will be deleted at once.
Changes to this notice
We may update this notice. Anything material (a new purpose, a new category of data, a new processor, a shorter list of rights or a longer retention period) is announced to account holders by email at least 30 days before it takes effect. We do not apply a new purpose retroactively to data already collected.
Every version carries a number and a date at the top of this page, and superseded versions are kept and sent on request.
Complaints
Come to us first at privacy@blackfleet.dev. We would rather fix it than be told to. But you are entitled to go straight to the regulator, and we will never suggest that you should have come to us first.
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
0303 123 1113 · ico.org.uk/make-a-complaint
If you are in the European Economic Area, you may complain to your national supervisory authority instead.
The terms governing the service itself are at our terms and conditions.