Privacy & data handling
We hold as little as possible, for as short as possible.
This notice is written to be read, not to be survived. It says exactly what we collect, why we are allowed to, who else ever sees it, how long it lives and what we will never do with it — in that order, without hedging.
- Version
- 1.0
- In effect from
- 7 August 2026
- Governing law
- England and Wales
Contents
- 01Who we are
- 02The rules we hold ourselves to
- 03What we collect
- 04What we never collect
- 05Why we are allowed to hold it
- 06How long we keep it
- 07Who else touches it
- 08Where in the world it goes
- 09How it is protected
- 10Cookies and tracking
- 11Your rights
- 12If something goes wrong
- 13Children
- 14Changes to this notice
- 15Complaints
Who we are
Blackfleet is the data controller for the personal data described in this notice. That means we decide what is collected and why, and we are the ones answerable for it. We are based in England and Wales and this notice is governed by its law.
Privacy questions, rights requests and complaints go to privacy@blackfleet.dev. Suspected vulnerabilities or exposures go to security@blackfleet.dev. Both are read by a person, not a ticketing robot.
What this notice covers
This notice covers blackfleet.dev, the Blackfleet booking platform and apps, and the corporate accounts we operate. Where a chauffeur partner processes your data on our written instructions for a journey we arranged, we remain responsible for it under § 07.
If you have only used the enquiry form on this site, the only data we hold about you is the list in § 03(a). Nothing in § 03(b) or § 03(c) applies to you until you hold an account and take a journey.
The rules we hold ourselves to
Ten commitments. They are binding on us, they are stricter than the law requires, and they are the first thing we would have to change if we ever wanted to behave worse.
- 01
We never sell personal data. There is no price at which we would.
- 02
We never share it for profiling, enrichment or lead resale.
- 03
We do not train, tune or evaluate machine learning models on your data.
- 04
This site sets no cookie until you allow it, and refusing is one click and just as easy.
- 05
We run one advertising measurement, described in full in § 10. It is the only third party that learns anything about your visit, and only if you say yes.
- 06
We collect the minimum a journey needs, and refuse the rest.
- 07
Nothing is recorded in the cabin — no audio, no video, ever.
- 08
We do not read the contents of your calendar beyond the fields a booking needs.
- 09
Every person and partner who touches your data is under a signed NDA.
- 10
Deletion is real deletion, on the schedule in § 06, without you asking.
- 11
If your data is ever exposed, you hear it from us within 72 hours.
If a future change to our business would break one of these, we will not make the change quietly. We will tell every account holder in writing first, under § 14.
What we collect
Three groups, and nothing outside them. Group (a) applies to anyone who fills in a form here. Groups (b) and (c) apply only once you hold an account.
Enquiries. When you use a form on this site we receive: your name, work email address, company, phone number, your preferred time of day for a call, and — depending on the form — your role, your city, your fleet size or your approximate journeys per month, plus anything you type into the free-text box. We add the time we received it and which form it came from. That is the entire record. There is no hidden field and no enrichment lookup against a data broker. Where you have allowed advertising cookies, a one-way hash of your email address and phone number is also sent to Google to measure the advert that brought you here — § 10 sets out exactly what that is, and how to refuse it.
Accounts and journeys. To move someone, we need the passenger's name or an internal reference, a pickup and dropoff, a time, contact details for the day, and — where you give them — a flight number, a cost centre and standing preferences such as temperature or route. We hold the vehicle, the chauffeur assigned, timestamps for the journey, and the price charged.
Calendar and system connections. If you connect a calendar, we request the narrowest scope the provider offers and read only the fields a booking needs: start and end time, location, and whether the event moved. We do not store event titles, attendee lists, descriptions, attachments or any event you have not designated as travel. Tokens are held encrypted and revoked the moment you disconnect.
Our servers keep short-lived operational logs — the fact that a request happened, when, and whether it failed. Where a booking fails to reach us, the submission is written to those logs rather than lost, so that we can contact you; it is subject to the same retention limit in § 06 and the same deletion.
What we never collect
The following are not collected, not inferred and not accepted if offered. If a field on any Blackfleet surface appears to ask for one of these, it is a bug — report it to security@blackfleet.dev.
- Audio or video from inside a vehicle. Nothing in the cabin is recorded.
- Special category data — health, religion, politics, sexuality, biometrics, trade union membership — unless you volunteer an access requirement, which we hold only for the journey it concerns and then delete.
- Full payment card numbers. Card details go directly to our payment processor; we see a token, the last four digits and the expiry, never the number.
- Background location from a phone. We hold vehicle position during a live journey, not passenger position.
- Device fingerprints, session or screen recordings, keystroke logging, or any record of how you moved around this page. The advertising measurement in § 10 is limited to which pages were opened and whether an enquiry followed.
- Anything bought from a data broker, list vendor or enrichment service.
Why we are allowed to hold it
Under the UK GDPR and, where it applies, the EU GDPR, we must have a lawful basis for every use. Ours are these, and we do not quietly re-use data collected under one basis for a purpose that needs another.
- Contract
- Booking, running, changing and settling journeys for an account we hold. Without this data there is no journey.
- Legitimate interests
- Replying to an enquiry you sent us, keeping the service secure, preventing fraud and abuse, and keeping records of what we agreed. We have weighed each of these against your interests and will send you the assessment on request.
- Consent
- Advertising cookies and the measurement in § 10, connecting a calendar or another system, and any marketing email. Consent is asked for plainly, never bundled, and withdrawing it is one click and takes effect immediately.
- Legal obligation
- Tax, accounting and licensing records we are required to keep, and lawful requests we are compelled to answer.
We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. Dispatch software chooses a vehicle; it does not decide anything about you.
How long we keep it
Deletion happens on a schedule, automatically, whether or not anyone asks. These are ceilings, not targets — if we finish with something sooner, it goes sooner.
- Enquiries
- 12 months from your last contact with us, then deleted. If you tell us you are not interested, we delete it within 7 days and keep only your email address on a suppression list so we do not contact you again.
- Journey records
- 24 months, then reduced to the anonymous facts we need for capacity planning — no names, no addresses, no references.
- Passenger preferences
- For as long as the account is open, and deleted within 30 days of it closing.
- Calendar tokens
- Revoked and destroyed immediately on disconnection or account closure.
- Operational logs
- 30 days, then purged. Security logs of failed access attempts: 12 months.
- Invoices and tax records
- 6 years, because we are required to. These are locked down to finance and are not used for anything else.
- Backups
- Encrypted, rolling 35 days. A deletion request is applied to live systems at once and works through backups as they expire; nothing deleted is ever restored back into service.
Who else touches it
A short list, and we do not add to it casually. All but one are processors under a written contract binding them to our instructions, our security standards and our retention limits; none of them may use your data for their own purposes. The exception is the advertising measurement below, which is not a processor and is not bound that way — which is exactly why it is the only one on this list you are asked about before it happens.
- Chauffeur partners
- The operator performing your journey receives the minimum required to perform it: passenger name or reference, pickup, dropoff, time and the contact number for the day. Not your account, not your history, not your other journeys. Every chauffeur has a signed NDA on file.
- Hosting
- Our application and its API run on a managed cloud platform in the United Kingdom or the European Union.
- Notification delivery
- New enquiries are delivered to a private, unlisted channel so we can respond quickly. The message body is encrypted with AES-256-GCM before it leaves our servers; the delivery provider transports ciphertext it cannot read.
- Advertising measurement
- Google, and only once you have allowed advertising cookies. It receives which of our pages were opened, which advert click preceded them, and — if you send a form — a one-way SHA-256 hash of your email address and phone number, so it can match the enquiry to the click. Unlike everyone else on this list, Google is not our processor: it decides its own purposes as a controller in its own right, under its own privacy policy. That is precisely why it sits behind a consent banner instead of being assumed.
- Payments
- A regulated payment processor, which holds card details directly. We never receive them.
- A business email provider, for correspondence with you.
- Authorities
- Only where we are legally compelled. We require a lawful, specific request, we refuse fishing expeditions, and we will tell you unless we are prohibited by law from doing so.
We will name any current processor on request. If we ever change one in a way that affects your data, § 14 applies. If Blackfleet were ever acquired, personal data would transfer only under this notice; an acquirer wanting to use it differently would have to ask you.
Where in the world it goes
Personal data is stored in the United Kingdom or the European Economic Area by default. We arrange journeys in cities outside the UK and EEA, and in those cases the minimum journey detail in § 07 necessarily reaches the operator performing it.
Where data leaves the UK or EEA it goes only to a country with an adequacy decision, or under the UK International Data Transfer Agreement or the relevant Standard Contractual Clauses, with a transfer risk assessment on file. We will send you a copy of the mechanism used for any specific transfer if you ask.
One transfer is worth naming outright. Where you have allowed advertising cookies, the measurement data in § 07 reaches Google in the United States, under the EU–US Data Privacy Framework and its UK extension, to which Google is certified. Declining the banner stops that transfer before it happens.
How it is protected
Security is not a paragraph of adjectives. These are the specific measures we operate, and we expect to be held to them.
- Everything in transit is over TLS 1.2 or better. There is no unencrypted path into our systems.
- Enquiry payloads are encrypted with AES-256-GCM before leaving our servers, using a key held only in our own environment and never given to a third party.
- Data at rest is encrypted, including backups.
- Access is least-privilege and named — no shared logins, no standing production access, multi-factor authentication on every account that can reach personal data.
- Access to personal data is logged, and the logs are reviewed.
- Production data is never copied into development or test environments.
- Personal data is not stored on personal devices, personal accounts or removable media.
- Staff and chauffeur partners are under confidentiality obligations that survive the end of their engagement.
- Access is revoked the day someone leaves, not the week after.
No system is perfect and we will not claim otherwise. What we will do is § 12.
Your rights
These rights are yours under data protection law. Exercising them is free, will never count against you, and does not require a form, a portal or a reason.
- Access
- A copy of everything we hold about you.
- Rectification
- Correction of anything wrong.
- Erasure
- Deletion, except the narrow set of records we are legally required to keep, which we will identify to you specifically.
- Portability
- Your data in a machine-readable file you can take elsewhere.
- Restriction
- A freeze on our use of it while a dispute is resolved.
- Objection
- An objection to any use we base on legitimate interests. For marketing, the objection is absolute and immediate.
- Withdraw consent
- At any time, without affecting anything done lawfully before you withdrew it.
Write to privacy@blackfleet.dev. We answer within 14 days — the law allows a month, and we do not intend to use it. We will ask for proof of identity only where we genuinely cannot tell it is you, and we will never use that as a delaying tactic.
If you are a passenger, not the account holder
Your employer or host may have booked on your behalf. You still hold every right above directly against us, and you do not need their permission to use one. Write to us and we will deal with you, not with them.
If something goes wrong
If personal data is exposed, we will tell you within 72 hours of establishing that it happened — not only where the law requires notification, but whenever your data was involved at all. The notice will say what was taken, when, how it happened, what we have done and what you should do. We will not wait for a complete investigation to make the first contact.
Where required, we report to the Information Commissioner's Office within 72 hours. We will not describe a breach as an incident, an issue or an anomaly.
Children
Blackfleet is a service for businesses and is not directed at children. We do not knowingly collect data from anyone under 18 through this site. Where a minor travels as a passenger, we hold only what the journey requires and delete it on the schedule in § 06. If you believe we hold a child's data unnecessarily, tell us and it will be deleted at once.
Changes to this notice
We may update this notice. Anything material — a new purpose, a new category of data, a new processor, a shorter list of rights or a longer retention period — is announced to account holders by email at least 30 days before it takes effect. We do not apply a new purpose retroactively to data already collected.
Every version carries a number and a date at the top of this page, and superseded versions are kept and sent on request.
Complaints
Come to us first at privacy@blackfleet.dev — we would rather fix it than be told to. But you are entitled to go straight to the regulator, and we will never suggest that you should have come to us first.
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
0303 123 1113 — ico.org.uk/make-a-complaint
If you are in the European Economic Area, you may complain to your national supervisory authority instead.
The terms governing the service itself are at our terms and conditions.