Privacy · version 1.0

Ask4Drivers privacy notice — platform draft

The platform processes account information needed to operate the service, including contact details, driver work preferences, business locations, shift history, reviews, reports, security events and verification records.

Profile photographs and private documents

Driver profile photographs and verification documents are stored outside normal public asset folders. Profile photographs are made available only to the driver, administrators and businesses with a relevant booked shift. Verification documents are restricted to authorised administrative access.

Location matching

Driver matching uses coordinates for the driver's chosen base/search postcode and business branch postcode. Businesses are not shown the driver's private home coordinates. Drivers can change their search postcode and work radius.

Email, cookies and security data

The platform records email delivery events for operational monitoring, including verification emails, password resets, one-time 2FA codes, job alerts and other service messages. Reset and one-time-code secrets are stored as hashes and expire automatically. If a user selects Remember Me, the browser receives a secure random authentication token rather than a password. Active device/session records may include IP address, browser/device information and last-active time so the user can review or revoke sessions.

Policy acceptance

When users accept Terms, Privacy or role-specific responsibility declarations, the platform records the policy version, acceptance time, IP address and browser information as an audit record.

Reviews and reports

Reviews may contribute to public driver or location reputation. Conduct reports are private and available to authorised administrators for investigation. Evidence uploaded with a report is stored privately.

Retention and security

Passwords are hashed. Forms use CSRF protection and prepared database statements. Before public launch, define formal retention periods for identity documents, expired records, report evidence, messages, email logs and closed accounts.

Replace or legally review this draft with your final controller details, lawful bases, data-rights procedure, retention schedule and business contact information before public launch.