Skip to content

Privacy & data handling

We hold as little as possible, for as short as possible.

This notice is written to be read, not to be survived. It says exactly what we collect, why we are allowed to, who else ever sees it, how long it lives and what we will never do with it, in that order, without hedging.

Version
1.1
In effect from
8 August 2026
Governing law
England and Wales
§ 01

Who we are

Blackfleet is the data controller for the personal data described in this notice. That means we decide what is collected and why, and we are the ones answerable for it. We are based in England and Wales and this notice is governed by its law.

Privacy questions, rights requests and complaints go to privacy@blackfleet.dev. Suspected vulnerabilities or exposures go to security@blackfleet.dev. Both are read by a person, not a ticketing robot.

What this notice covers

This notice covers blackfleet.dev, the Blackfleet booking platform and apps, and the corporate accounts we operate. Where a chauffeur partner processes your data on our written instructions for a journey we arranged, we remain responsible for it under § 07.

If you have only used the enquiry form on this site, the only data we hold about you is the list in § 03(a). Nothing in § 03(b) or § 03(c) applies to you until you hold an account and take a journey.

§ 02

The rules we hold ourselves to

Eleven commitments. They are binding on us, they are stricter than the law requires, and they are the first thing we would have to change if we ever wanted to behave worse.

  1. 01

    We never sell personal data. There is no price at which we would.

  2. 02

    We never share it for profiling, enrichment or lead resale.

  3. 03

    We do not train, tune or evaluate machine learning models on your data.

  4. 04

    This site sets no cookie until you allow it, and refusing is one click and just as easy.

  5. 05

    We run two advertising measurements, Google and OpenAI, described in full in § 10. They are the only third parties that learn anything about your visit, and only if you say yes.

  6. 06

    We collect the minimum a journey needs, and refuse the rest.

  7. 07

    Nothing is recorded in the cabin: no audio, no video, ever.

  8. 08

    We do not read the contents of your calendar beyond the fields a booking needs.

  9. 09

    Every person and partner who touches your data is under a signed NDA.

  10. 10

    Deletion is real deletion, on the schedule in § 06, without you asking.

  11. 11

    If your data is ever exposed, you hear it from us within 72 hours.

If a future change to our business would break one of these, we will not make the change quietly. We will tell every account holder in writing first, under § 14.

§ 03

What we collect

Three groups, and nothing outside them. Group (a) applies to anyone who fills in a form here. Groups (b) and (c) apply only once you hold an account. Two further things are described at the end of this section, because neither is a record we keep about you: the logs our own servers write, and the advertising identifiers that live on your device rather than in our files.

(a)

Enquiries. When you use a form on this site we receive: your name, work email address, company, phone number, your preferred time of day for a call, and, depending on the form, your role, your city, your fleet size or your approximate journeys per month, plus anything you type into the free-text box. We add the time we received it and which form it came from. That is the entire record. There is no hidden field and no enrichment lookup against a data broker. Where you have allowed advertising cookies, a one-way hash of your email address is also sent to Google and to OpenAI, and a hash of your phone number to Google alone, to measure the advert that brought you here. § 10 sets out exactly what that is, and how to refuse it.

(b)

Accounts and journeys. To move someone, we need the passenger's name or an internal reference, a pickup and dropoff, a time, contact details for the day, and, where you give them, a flight number, a cost centre and standing preferences such as temperature or route. We hold the vehicle, the chauffeur assigned, timestamps for the journey, and the price charged.

(c)

Calendar and system connections. If you connect a calendar, we request the narrowest scope the provider offers and read only the fields a booking needs: start and end time, location, and whether the event moved. We do not store event titles, attendee lists, descriptions, attachments or any event you have not designated as travel. Tokens are held encrypted and revoked the moment you disconnect.

Our servers keep short-lived operational logs: the fact that a request happened, when, and whether it failed. Where a booking fails to reach us, the submission is written to those logs rather than lost, so that we can contact you; it is subject to the same retention limit in § 06 and the same deletion.

The advertising identifiers in § 10 are the one thing on this page we never hold. If you allow them, Google and OpenAI set them on your own device and read them from there; they are not sent to our servers, not attached to your enquiry, and not stored next to your name. What comes back to us is a count of conversions, not a list of people. We could not look yours up even if you asked us to.

§ 04

What we never collect

The following are not collected, not inferred and not accepted if offered. If a field on any Blackfleet surface appears to ask for one of these, it is a bug: report it to security@blackfleet.dev.

  • Audio or video from inside a vehicle. Nothing in the cabin is recorded.
  • Special category data (health, religion, politics, sexuality, biometrics, trade union membership) unless you volunteer an access requirement, which we hold only for the journey it concerns and then delete.
  • Full payment card numbers. Card details go directly to our payment processor; we see a token, the last four digits and the expiry, never the number.
  • Background location from a phone. We hold vehicle position during a live journey, not passenger position.
  • Device fingerprints, session or screen recordings, keystroke logging, or any record of how you moved around this page. The advertising measurements in § 10 are limited to which pages were opened and whether an enquiry followed.
  • Anything bought from a data broker, list vendor or enrichment service.
§ 05

Why we are allowed to hold it

Under the UK GDPR and, where it applies, the EU GDPR, we must have a lawful basis for every use. Ours are these, and we do not quietly re-use data collected under one basis for a purpose that needs another.

Contract
Booking, running, changing and settling journeys for an account we hold. Without this data there is no journey.
Legitimate interests
Replying to an enquiry you sent us, keeping the service secure, preventing fraud and abuse, and keeping records of what we agreed. We have weighed each of these against your interests and will send you the assessment on request.
Consent
Advertising cookies and the measurements in § 10, connecting a calendar or another system, and any marketing email. Consent is asked for plainly, never bundled, and withdrawing it is one click and takes effect immediately.
Legal obligation
Tax, accounting and licensing records we are required to keep, and lawful requests we are compelled to answer.

We do not carry out profiling or automated decision-making that produces legal or similarly significant effects. Dispatch software chooses a vehicle; it does not decide anything about you.

§ 06

How long we keep it

Deletion happens on a schedule, automatically, whether or not anyone asks. These are ceilings, not targets. If we finish with something sooner, it goes sooner.

Enquiries
12 months from your last contact with us, then deleted. If you tell us you are not interested, we delete it within 7 days and keep only your email address on a suppression list so we do not contact you again.
Journey records
24 months, then reduced to the anonymous facts we need for capacity planning: no names, no addresses, no references.
Passenger preferences
For as long as the account is open, and deleted within 30 days of it closing.
Calendar tokens
Revoked and destroyed immediately on disconnection or account closure.
Operational logs
30 days, then purged. Security logs of failed access attempts: 12 months.
Advertising identifiers
Not ours to delete, because they are not ours to hold. They sit on your device for the lifetimes listed in § 10 (90 days for Google's, and 30 days, 30 days and a year for OpenAI's three) and withdrawing consent deletes them from the device at once, without waiting for any of that to run out. What each platform keeps on its own side is governed by its own policy, which is precisely why § 07 names them as controllers rather than as our processors.
Invoices and tax records
6 years, because we are required to. These are locked down to finance and are not used for anything else.
Backups
Encrypted, rolling 35 days. A deletion request is applied to live systems at once and works through backups as they expire; nothing deleted is ever restored back into service.
§ 07

Who else touches it

A short list, and we do not add to it casually. All but two are processors under a written contract binding them to our instructions, our security standards and our retention limits; none of them may use your data for their own purposes. The exceptions are the two advertising measurements below, which are not processors and are not bound that way, which is exactly why they are the only ones on this list you are asked about before they happen.

Chauffeur partners
The operator performing your journey receives the minimum required to perform it: passenger name or reference, pickup, dropoff, time and the contact number for the day. Not your account, not your history, not your other journeys. Every chauffeur has a signed NDA on file.
Hosting
Our application and its API run on a managed cloud platform in the United Kingdom or the European Union.
Notification delivery
New enquiries are delivered to a private, unlisted channel so we can respond quickly. The message body is encrypted with AES-256-GCM before it leaves our servers; the delivery provider transports ciphertext it cannot read.
Advertising · Google
Google Ads, and only once you have allowed advertising cookies. It receives which of our pages were opened, which advert click preceded them, and, if you send a form, a one-way SHA-256 hash of your email address and phone number, so it can match the enquiry to the click. Unlike the processors above, Google is not our processor: it decides its own purposes as a controller in its own right, under its own privacy policy. That is precisely why it sits behind a consent banner instead of being assumed.
Advertising · OpenAI
ChatGPT Ads, on the same terms and behind the same one click. It receives less than Google does: the reference for the ChatGPT advert click that brought you here, a random identifier for the browser, the address of the page it loaded on and the page you arrived from, without any query string, and, if you send a form, a one-way SHA-256 hash of your email address. Not every page you then read, and never your phone number in any form, because OpenAI does not accept one. It too is an independent controller under its own privacy policy, not our processor. Until you have said yes, its pixel is not merely switched off. It is never fetched, so there is nothing on the page to switch off.
Payments
A regulated payment processor, which holds card details directly. We never receive them.
Email
A business email provider, for correspondence with you.
Authorities
Only where we are legally compelled. We require a lawful, specific request, we refuse fishing expeditions, and we will tell you unless we are prohibited by law from doing so.

We will name any current processor on request. If we ever change one in a way that affects your data, § 14 applies. If Blackfleet were ever acquired, personal data would transfer only under this notice; an acquirer wanting to use it differently would have to ask you.

§ 08

Where in the world it goes

Personal data is stored in the United Kingdom or the European Economic Area by default. We arrange journeys in cities outside the UK and EEA, and in those cases the minimum journey detail in § 07 necessarily reaches the operator performing it.

Where data leaves the UK or EEA it goes only to a country with an adequacy decision, or under the UK International Data Transfer Agreement or the relevant Standard Contractual Clauses, with a transfer risk assessment on file. We will send you a copy of the mechanism used for any specific transfer if you ask.

Two transfers are worth naming outright. Where you have allowed advertising cookies, the measurement data in § 07 reaches the United States: Google under the EU–US Data Privacy Framework and its UK extension, to which Google is certified, and OpenAI under the European Commission's Standard Contractual Clauses and the UK addendum to them, which is the mechanism its own advertising terms rely on. Declining the banner stops both before they happen.

§ 09

How it is protected

Security is not a paragraph of adjectives. These are the specific measures we operate, and we expect to be held to them.

  • Everything in transit is over TLS 1.2 or better. There is no unencrypted path into our systems.
  • Enquiry payloads are encrypted with AES-256-GCM before leaving our servers, using a key held only in our own environment and never given to a third party.
  • Data at rest is encrypted, including backups.
  • Access is least-privilege and named: no shared logins, no standing production access, multi-factor authentication on every account that can reach personal data.
  • Access to personal data is logged, and the logs are reviewed.
  • Production data is never copied into development or test environments.
  • Personal data is not stored on personal devices, personal accounts or removable media.
  • Staff and chauffeur partners are under confidentiality obligations that survive the end of their engagement.
  • Access is revoked the day someone leaves, not the week after.

No system is perfect and we will not claim otherwise. What we will do is § 12.

§ 10

Cookies and tracking

This website sets no cookie until you allow it, and none at all if you say no.

There is no analytics package, no session recorder, no A/B testing tool and no social media pixel. There are exactly two things, and we would rather describe them than bury them: a Google Ads tag and a ChatGPT Ads pixel, so that we can tell which adverts bring us real enquiries instead of paying to guess. If you arrived from an advert on either and later send us a form, they let us join those two events together. That is their whole job.

In the UK, the EEA and Switzerland, both are held off before the page has finished loading: the Google tag loads but is refused storage, and the ChatGPT pixel is not downloaded at all. You are asked plainly; Accept and Decline are the same size and one click each, because a choice that is easier to accept than to refuse is not a choice. Until you answer, nothing is stored on your device.

(a)

If you decline. No cookie is set, now or later. Google is told you refused, receives no identifier for you, records no advert click and shows you nothing personalised. It is sent the bare fact that a page was opened, with nothing attached that could single you out. OpenAI is sent nothing whatsoever, because its pixel is never requested: there is no file to fetch, so there is no request to make.

(b)

If you accept. First-party cookies, and this is all of them. _gcl_au remembers which Google advert click brought you here, for 90 days. For ChatGPT there are three: __oppref, the advert click, for 30 days; __obref, a random number standing in for this browser, for a year; and __oaiq_consent, which is the record of this decision, kept for 30 days and mirrored in local storage. None of the three has your name in it.

(c)

If you accept and then send a form. Your email address is hashed with SHA-256 inside your own browser, so it never leaves it in readable form, and sent to both platforms so the enquiry can be matched to the advert click. Your phone number is hashed and sent to Google alone, because OpenAI does not accept phone numbers in any form. A one-way hash is the least identifying thing that still does the job, which is why we use it rather than the address itself. We hand the hash over ourselves, at the moment your enquiry is accepted, rather than leaving OpenAI's pixel to take it from the field as you type, which, left alone, is what it would do.

Changing your mind is one click, in the same place you gave it: the Cookies link at the foot of every page. It withdraws consent the instant you press it, before asking anything, tells both platforms to stop, deletes every cookie listed above from your device rather than merely ceasing to read them, and puts the question back. Withdrawing has to be as easy as consenting, so it is.

Signed-in areas of the platform will use a strictly necessary cookie to keep you logged in. That one needs no consent, because without it you cannot stay logged in: but it is never used to watch you, and there is no advertising cookie hiding behind the word “necessary”.

§ 11

Your rights

These rights are yours under data protection law. Exercising them is free, will never count against you, and does not require a form, a portal or a reason.

Access
A copy of everything we hold about you.
Rectification
Correction of anything wrong.
Erasure
Deletion, except the narrow set of records we are legally required to keep, which we will identify to you specifically.
Portability
Your data in a machine-readable file you can take elsewhere.
Restriction
A freeze on our use of it while a dispute is resolved.
Objection
An objection to any use we base on legitimate interests. For marketing, the objection is absolute and immediate.
Withdraw consent
At any time, without affecting anything done lawfully before you withdrew it.

Write to privacy@blackfleet.dev. We answer within 14 days. The law allows a month, and we do not intend to use it. We will ask for proof of identity only where we genuinely cannot tell it is you, and we will never use that as a delaying tactic.

If you are a passenger, not the account holder

Your employer or host may have booked on your behalf. You still hold every right above directly against us, and you do not need their permission to use one. Write to us and we will deal with you, not with them.

§ 12

If something goes wrong

If personal data is exposed, we will tell you within 72 hours of establishing that it happened, not only where the law requires notification, but whenever your data was involved at all. The notice will say what was taken, when, how it happened, what we have done and what you should do. We will not wait for a complete investigation to make the first contact.

Where required, we report to the Information Commissioner's Office within 72 hours. We will not describe a breach as an incident, an issue or an anomaly.

§ 13

Children

Blackfleet is a service for businesses and is not directed at children. We do not knowingly collect data from anyone under 18 through this site. Where a minor travels as a passenger, we hold only what the journey requires and delete it on the schedule in § 06. If you believe we hold a child's data unnecessarily, tell us and it will be deleted at once.

§ 14

Changes to this notice

We may update this notice. Anything material (a new purpose, a new category of data, a new processor, a shorter list of rights or a longer retention period) is announced to account holders by email at least 30 days before it takes effect. We do not apply a new purpose retroactively to data already collected.

Every version carries a number and a date at the top of this page, and superseded versions are kept and sent on request.

§ 15

Complaints

Come to us first at privacy@blackfleet.dev. We would rather fix it than be told to. But you are entitled to go straight to the regulator, and we will never suggest that you should have come to us first.

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

0303 123 1113 · ico.org.uk/make-a-complaint

If you are in the European Economic Area, you may complain to your national supervisory authority instead.

The terms governing the service itself are at our terms and conditions.