Skip to content

Privacy & data handling

We hold as little as possible, for as short as possible.

This notice is written to be read, not to be survived. It says exactly what we collect, why we are allowed to, who else ever sees it, how long it lives and what we will never do with it — in that order, without hedging.

Version
1.0
In effect from
7 August 2026
Governing law
England and Wales
§ 01

Who we are

Blackfleet is the data controller for the personal data described in this notice. That means we decide what is collected and why, and we are the ones answerable for it. We are based in England and Wales and this notice is governed by its law.

Privacy questions, rights requests and complaints go to privacy@blackfleet.dev. Suspected vulnerabilities or exposures go to security@blackfleet.dev. Both are read by a person, not a ticketing robot.

What this notice covers

This notice covers blackfleet.dev, the Blackfleet booking platform and apps, and the corporate accounts we operate. Where a chauffeur partner processes your data on our written instructions for a journey we arranged, we remain responsible for it under § 07.

If you have only used the enquiry form on this site, the only data we hold about you is the list in § 03(a). Nothing in § 03(b) or § 03(c) applies to you until you hold an account and take a journey.

§ 02

The rules we hold ourselves to

Ten commitments. They are binding on us, they are stricter than the law requires, and they are the first thing we would have to change if we ever wanted to behave worse.

  1. 01

    We never sell personal data. There is no price at which we would.

  2. 02

    We never share it for profiling, enrichment or lead resale.

  3. 03

    We do not train, tune or evaluate machine learning models on your data.

  4. 04

    This site sets no cookie until you allow it, and refusing is one click and just as easy.

  5. 05

    We run one advertising measurement, described in full in § 10. It is the only third party that learns anything about your visit, and only if you say yes.

  6. 06

    We collect the minimum a journey needs, and refuse the rest.

  7. 07

    Nothing is recorded in the cabin — no audio, no video, ever.

  8. 08

    We do not read the contents of your calendar beyond the fields a booking needs.

  9. 09

    Every person and partner who touches your data is under a signed NDA.

  10. 10

    Deletion is real deletion, on the schedule in § 06, without you asking.

  11. 11

    If your data is ever exposed, you hear it from us within 72 hours.

If a future change to our business would break one of these, we will not make the change quietly. We will tell every account holder in writing first, under § 14.

§ 03

What we collect

Three groups, and nothing outside them. Group (a) applies to anyone who fills in a form here. Groups (b) and (c) apply only once you hold an account.

(a)

Enquiries. When you use a form on this site we receive: your name, work email address, company, phone number, your preferred time of day for a call, and — depending on the form — your role, your city, your fleet size or your approximate journeys per month, plus anything you type into the free-text box. We add the time we received it and which form it came from. That is the entire record. There is no hidden field and no enrichment lookup against a data broker. Where you have allowed advertising cookies, a one-way hash of your email address and phone number is also sent to Google to measure the advert that brought you here — § 10 sets out exactly what that is, and how to refuse it.

(b)

Accounts and journeys. To move someone, we need the passenger's name or an internal reference, a pickup and dropoff, a time, contact details for the day, and — where you give them — a flight number, a cost centre and standing preferences such as temperature or route. We hold the vehicle, the chauffeur assigned, timestamps for the journey, and the price charged.

(c)

Calendar and system connections. If you connect a calendar, we request the narrowest scope the provider offers and read only the fields a booking needs: start and end time, location, and whether the event moved. We do not store event titles, attendee lists, descriptions, attachments or any event you have not designated as travel. Tokens are held encrypted and revoked the moment you disconnect.

Our servers keep short-lived operational logs — the fact that a request happened, when, and whether it failed. Where a booking fails to reach us, the submission is written to those logs rather than lost, so that we can contact you; it is subject to the same retention limit in § 06 and the same deletion.

§ 04

What we never collect

The following are not collected, not inferred and not accepted if offered. If a field on any Blackfleet surface appears to ask for one of these, it is a bug — report it to security@blackfleet.dev.

  • Audio or video from inside a vehicle. Nothing in the cabin is recorded.
  • Special category data — health, religion, politics, sexuality, biometrics, trade union membership — unless you volunteer an access requirement, which we hold only for the journey it concerns and then delete.
  • Full payment card numbers. Card details go directly to our payment processor; we see a token, the last four digits and the expiry, never the number.
  • Background location from a phone. We hold vehicle position during a live journey, not passenger position.
  • Device fingerprints, session or screen recordings, keystroke logging, or any record of how you moved around this page. The advertising measurement in § 10 is limited to which pages were opened and whether an enquiry followed.
  • Anything bought from a data broker, list vendor or enrichment service.
§ 05

Why we are allowed to hold it

Under the UK GDPR and, where it applies, the EU GDPR, we must have a lawful basis for every use. Ours are these, and we do not quietly re-use data collected under one basis for a purpose that needs another.

Contract
Booking, running, changing and settling journeys for an account we hold. Without this data there is no journey.
Legitimate interests
Replying to an enquiry you sent us, keeping the service secure, preventing fraud and abuse, and keeping records of what we agreed. We have weighed each of these against your interests and will send you the assessment on request.
Consent
Advertising cookies and the measurement in § 10, connecting a calendar or another system, and any marketing email. Consent is asked for plainly, never bundled, and withdrawing it is one click and takes effect immediately.
Legal obligation
Tax, accounting and licensing records we are required to keep, and lawful requests we are compelled to answer.

We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. Dispatch software chooses a vehicle; it does not decide anything about you.

§ 06

How long we keep it

Deletion happens on a schedule, automatically, whether or not anyone asks. These are ceilings, not targets — if we finish with something sooner, it goes sooner.

Enquiries
12 months from your last contact with us, then deleted. If you tell us you are not interested, we delete it within 7 days and keep only your email address on a suppression list so we do not contact you again.
Journey records
24 months, then reduced to the anonymous facts we need for capacity planning — no names, no addresses, no references.
Passenger preferences
For as long as the account is open, and deleted within 30 days of it closing.
Calendar tokens
Revoked and destroyed immediately on disconnection or account closure.
Operational logs
30 days, then purged. Security logs of failed access attempts: 12 months.
Invoices and tax records
6 years, because we are required to. These are locked down to finance and are not used for anything else.
Backups
Encrypted, rolling 35 days. A deletion request is applied to live systems at once and works through backups as they expire; nothing deleted is ever restored back into service.
§ 07

Who else touches it

A short list, and we do not add to it casually. All but one are processors under a written contract binding them to our instructions, our security standards and our retention limits; none of them may use your data for their own purposes. The exception is the advertising measurement below, which is not a processor and is not bound that way — which is exactly why it is the only one on this list you are asked about before it happens.

Chauffeur partners
The operator performing your journey receives the minimum required to perform it: passenger name or reference, pickup, dropoff, time and the contact number for the day. Not your account, not your history, not your other journeys. Every chauffeur has a signed NDA on file.
Hosting
Our application and its API run on a managed cloud platform in the United Kingdom or the European Union.
Notification delivery
New enquiries are delivered to a private, unlisted channel so we can respond quickly. The message body is encrypted with AES-256-GCM before it leaves our servers; the delivery provider transports ciphertext it cannot read.
Advertising measurement
Google, and only once you have allowed advertising cookies. It receives which of our pages were opened, which advert click preceded them, and — if you send a form — a one-way SHA-256 hash of your email address and phone number, so it can match the enquiry to the click. Unlike everyone else on this list, Google is not our processor: it decides its own purposes as a controller in its own right, under its own privacy policy. That is precisely why it sits behind a consent banner instead of being assumed.
Payments
A regulated payment processor, which holds card details directly. We never receive them.
Email
A business email provider, for correspondence with you.
Authorities
Only where we are legally compelled. We require a lawful, specific request, we refuse fishing expeditions, and we will tell you unless we are prohibited by law from doing so.

We will name any current processor on request. If we ever change one in a way that affects your data, § 14 applies. If Blackfleet were ever acquired, personal data would transfer only under this notice; an acquirer wanting to use it differently would have to ask you.

§ 08

Where in the world it goes

Personal data is stored in the United Kingdom or the European Economic Area by default. We arrange journeys in cities outside the UK and EEA, and in those cases the minimum journey detail in § 07 necessarily reaches the operator performing it.

Where data leaves the UK or EEA it goes only to a country with an adequacy decision, or under the UK International Data Transfer Agreement or the relevant Standard Contractual Clauses, with a transfer risk assessment on file. We will send you a copy of the mechanism used for any specific transfer if you ask.

One transfer is worth naming outright. Where you have allowed advertising cookies, the measurement data in § 07 reaches Google in the United States, under the EU–US Data Privacy Framework and its UK extension, to which Google is certified. Declining the banner stops that transfer before it happens.

§ 09

How it is protected

Security is not a paragraph of adjectives. These are the specific measures we operate, and we expect to be held to them.

  • Everything in transit is over TLS 1.2 or better. There is no unencrypted path into our systems.
  • Enquiry payloads are encrypted with AES-256-GCM before leaving our servers, using a key held only in our own environment and never given to a third party.
  • Data at rest is encrypted, including backups.
  • Access is least-privilege and named — no shared logins, no standing production access, multi-factor authentication on every account that can reach personal data.
  • Access to personal data is logged, and the logs are reviewed.
  • Production data is never copied into development or test environments.
  • Personal data is not stored on personal devices, personal accounts or removable media.
  • Staff and chauffeur partners are under confidentiality obligations that survive the end of their engagement.
  • Access is revoked the day someone leaves, not the week after.

No system is perfect and we will not claim otherwise. What we will do is § 12.

§ 10

Cookies and tracking

This website sets no cookie until you allow it, and none at all if you say no.

There is no analytics package, no session recorder, no A/B testing tool and no social media pixel. There is exactly one thing, and we would rather describe it than bury it: a Google Ads tag, so that we can tell which adverts bring us real enquiries instead of paying to guess. If you arrived from an advert and later send us a form, it lets us join those two events together. That is its whole job.

In the UK, the EEA and Switzerland it is switched off before the page has finished loading. You are asked plainly; Accept and Decline are the same size and one click each, because a choice that is easier to accept than to refuse is not a choice. Until you answer, nothing is stored on your device.

(a)

If you decline. No cookie is set, now or later. Google is told you refused, receives no identifier for you, records no advert click and shows you nothing personalised. It is sent the bare fact that a page was opened, with nothing attached that could single you out.

(b)

If you accept. One first-party cookie, _gcl_au, remembers which advert click brought you here, for 90 days. If you then send us a form, your email address and phone number are hashed with SHA-256 inside your own browser — they never leave it in readable form — and sent alongside so that Google can match the enquiry to the click. A one-way hash is the least identifying thing that still does the job, which is why we use it rather than the address itself.

Changing your mind is one click, in the same place you gave it: the Cookies link at the foot of every page. It withdraws consent the instant you press it — before asking anything — deletes the cookie from your device rather than merely ceasing to read it, and puts the question back. Withdrawing has to be as easy as consenting, so it is.

Signed-in areas of the platform will use a strictly necessary cookie to keep you logged in. That one needs no consent, because without it you cannot stay logged in — but it is never used to watch you, and there is no advertising cookie hiding behind the word “necessary”.

§ 11

Your rights

These rights are yours under data protection law. Exercising them is free, will never count against you, and does not require a form, a portal or a reason.

Access
A copy of everything we hold about you.
Rectification
Correction of anything wrong.
Erasure
Deletion, except the narrow set of records we are legally required to keep, which we will identify to you specifically.
Portability
Your data in a machine-readable file you can take elsewhere.
Restriction
A freeze on our use of it while a dispute is resolved.
Objection
An objection to any use we base on legitimate interests. For marketing, the objection is absolute and immediate.
Withdraw consent
At any time, without affecting anything done lawfully before you withdrew it.

Write to privacy@blackfleet.dev. We answer within 14 days — the law allows a month, and we do not intend to use it. We will ask for proof of identity only where we genuinely cannot tell it is you, and we will never use that as a delaying tactic.

If you are a passenger, not the account holder

Your employer or host may have booked on your behalf. You still hold every right above directly against us, and you do not need their permission to use one. Write to us and we will deal with you, not with them.

§ 12

If something goes wrong

If personal data is exposed, we will tell you within 72 hours of establishing that it happened — not only where the law requires notification, but whenever your data was involved at all. The notice will say what was taken, when, how it happened, what we have done and what you should do. We will not wait for a complete investigation to make the first contact.

Where required, we report to the Information Commissioner's Office within 72 hours. We will not describe a breach as an incident, an issue or an anomaly.

§ 13

Children

Blackfleet is a service for businesses and is not directed at children. We do not knowingly collect data from anyone under 18 through this site. Where a minor travels as a passenger, we hold only what the journey requires and delete it on the schedule in § 06. If you believe we hold a child's data unnecessarily, tell us and it will be deleted at once.

§ 14

Changes to this notice

We may update this notice. Anything material — a new purpose, a new category of data, a new processor, a shorter list of rights or a longer retention period — is announced to account holders by email at least 30 days before it takes effect. We do not apply a new purpose retroactively to data already collected.

Every version carries a number and a date at the top of this page, and superseded versions are kept and sent on request.

§ 15

Complaints

Come to us first at privacy@blackfleet.dev — we would rather fix it than be told to. But you are entitled to go straight to the regulator, and we will never suggest that you should have come to us first.

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

0303 123 1113 — ico.org.uk/make-a-complaint

If you are in the European Economic Area, you may complain to your national supervisory authority instead.

The terms governing the service itself are at our terms and conditions.