1. Who We Are
1.1This privacy policy explains how Drevo Ltd, a company registered in Scotland with company number SC887578 and registered office at Office 606 18 Young Street, Unit Lge, Edinburgh, Scotland, EH2 4JB, collects and uses personal data in connection with the Drevo platform — an online marketplace connecting UK businesses needing same-day parcel delivery with vetted self-employed couriers, currently operating in Greater London.
1.2Drevo is registered with the Information Commissioner’s Office (ICO) under registration number ZC208890.
1.3You can contact us about anything in this policy at support@drevo.co.uk.
2. Who This Policy Covers
2.1This policy is organised around the three groups of people whose personal data we handle:
- (a)Businesses — the companies that place delivery orders, and the individuals who operate their accounts (section 3);
- (b)Couriers — the self-employed individuals who collect and deliver parcels through the platform (section 4);
- (c)Recipients — the people the parcels are delivered to (section 5).
2.2For Businesses and Couriers, Drevo is the controller of the personal data described below. For Recipients, Drevo acts as a processor on behalf of the sending Business — see section 5.
2.3The policy also covers anyone who telephones us. Calls to our published number ring a person first. If nobody answers, the call is taken either by an automated voice assistant or by voicemail. An assistant call is transcribed, and the transcript, a written summary of it and the number you called from are sent to Drevo and kept with our business records; a voicemail is recorded and sent to us in the same way. If you would rather not have a call handled this way, email support@drevo.co.uk instead.
3. Information We Collect — Businesses
3.1When a business registers and uses the platform, we collect and hold:
- (a)company name and Companies House number, which we verify against the Companies House register via the Companies House API;
- (b)the account owner’s name, email address and phone number, verified by one-time passcodes sent by email (via Resend) and SMS (via Twilio);
- (c)city and postcode, and VAT status;
- (d)your password, stored only as a secure cryptographic hash — we never store passwords in plain text;
- (e)payment records processed through Stripe — Drevo never stores your card numbers; card details are handled by Stripe;
- (f)your orders, invoices and delivery records;
- (g)message threads between you and Drevo staff; and
- (h)your marketing-consent preference.
4. Information We Collect — Couriers
4.1To onboard and engage couriers as self-employed contractors, we collect and hold:
- (a)name, email address and phone number, and a password stored only as a secure hash;
- (b)date of birth, National Insurance number and home address;
- (c)right-to-work evidence: a passport or a Home Office share code;
- (d)driving licence details and a DVLA share code;
- (e)hire and reward insurance certificate, and vehicle registration;
- (f)bank account details for payouts, and optionally a Unique Taxpayer Reference (UTR) and VAT status;
- (g)a digital signature accepting the Courier Agreement;
- (h)uploaded identity, licence and insurance documents, stored in a private file store accessible only to authorised Drevo staff;
- (i)live GPS location, captured approximately every 25 seconds while the courier is online on the courier app, used for dispatch, live tracking and proof of delivery;
- (j)a reliability score derived from job history (see section 7);
- (k)a push-notification token for the courier app;
- (l)proof-of-delivery photographs the courier captures; and
- (m)DBS (Basic) check status, once DBS checking is introduced.
5. Information We Handle — Recipients
5.1Recipient data is provided by the sending Business, not by the recipient. It may include: name, phone number, optional email address, delivery address, delivery instructions (which may contain door or gate codes), a proof-of-delivery photograph taken at the doorstep (which may capture the doorstep or property), and the GPS coordinate and timestamp of the delivery.
5.2For this data, the sending Business is the controller and Drevo is a processor acting on the Business’s instructions under a data processing agreement. If you are a recipient and want to exercise your data protection rights or understand why your data was shared, please contact the business that sent you the parcel in the first instance. We will assist the sending Business in responding, and you can also contact us at support@drevo.co.uk.
5.3Proof-of-delivery photographs are stored privately, are accessible only to the sending Business and authorised Drevo staff, and are never made public.
6. How We Use Personal Data and Our Lawful Bases
6.1We use personal data on the following lawful bases under the UK GDPR:
- (a)Performance of a contract — operating accounts, computing prices, taking payment, dispatching orders to couriers, live tracking, capturing proof of delivery, paying couriers, and providing support;
- (b)Legitimate interests — verifying identity and company details, preventing fraud and abuse, securing the platform (rate limiting, audit logs), maintaining courier reliability scores, and improving the service. We balance these interests against your rights;
- (c)Consent — sending marketing communications to businesses that have opted in via the marketing-consent checkbox. You can withdraw consent at any time;
- (d)Legal obligation — keeping financial and tax records, verifying couriers’ right to work, and responding to lawful requests from authorities.
7. Reliability Scores and Automated Decision-Making
7.1Drevo maintains a reliability score for each courier, derived from their job history on the platform (for example completed, late or released jobs). The score affects which jobs are visible or offered to a courier, and certain business account tiers may restrict their orders to top-rated couriers.
7.2A courier who believes their score is wrong or unfair can contact support@drevo.co.uk and a human will review it. Genuine vehicle breakdowns handled through the platform’s recovery process do not count against a courier’s score.
7.3Other than job visibility as described above, we do not make automated decisions that produce legal or similarly significant effects about any individual.
8. Who We Share Data With
8.1We share personal data only as needed to run the platform, with the following service providers (subprocessors):
| Provider | Purpose |
|---|---|
| Vercel | Application hosting |
| Neon | Database hosting |
| Vercel Blob | Private file storage (documents, POD photos) |
| Stripe | Card payments and refunds |
| Twilio | SMS one-time passcodes and notifications, and our inbound phone line |
| ElevenLabs | The voice assistant that answers our phone line, and the transcript of the call |
| Resend | Transactional email |
| Mapbox | Maps, routing and geocoding |
| Ideal Postcodes | UK address lookup |
| postcodes.io | Checking a postcode exists and matches the address given |
| Companies House API | Company verification |
| Expo | Push notifications to the courier app |
8.2We also share data between the participants of a delivery as needed. Once a courier accepts an order, the business that placed it can see that courier’s display name, vehicle type, average star rating and the number of deliveries they have completed through Drevo, together with the courier’s live location while the job is active and the proof of delivery for each stop, including the name of the courier who captured it. Where a job is handed to a second courier mid-route, the business is also shown the name of the courier who started it. Couriers see the pickup and delivery details needed to perform a job. We do not disclose a courier’s telephone number, home address, date of birth, identity, right-to-work or licence documents, criminal-record check result, their total earnings, or their bank or payment details, to businesses or recipients — communication between a business and a courier about a live delivery goes through Drevo. A business does see the fee for its own delivery, because it sets that fee itself when it books.
8.3We may disclose data where required by law, to enforce our terms, or in connection with a sale or reorganisation of our business (with safeguards).
8.4We do not sell personal data.
9. International Transfers
9.1Some of our subprocessors process data in the United States. Where personal data is transferred outside the UK, we rely on safeguards recognised under Article 46 UK GDPR — the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum — or on UK adequacy regulations where they apply.
10. How Long We Keep Data
| Data | Retention period |
|---|---|
| Financial, order and invoice records | 6 years (HMRC requirement) |
| Courier location (live) | Not retained — each update overwrites the last; no trail is stored |
| Proof-of-delivery photographs | 12 months |
| Recipient details on an order (name, address, phone, email) | Held within the order record — 6 years, as above; anonymised sooner on request where the law allows |
| Saved recipients in a business's address book (name, address, phone, email) | While the account is active — removal hides the entry rather than erasing it; erased on request where the law allows |
| Courier onboarding documents (identity, licence, insurance) | Duration of the engagement + 6 months |
| Account data | While the account is active, then deleted or anonymised subject to the periods above |
10.1When a retention period ends, we delete or irreversibly anonymise the data.
11. How We Protect Data
11.1We apply technical and organisational security measures including: passwords stored only as secure hashes; token-based (JWT) authentication; role-based access control with two-factor authentication for staff; private (non-public) file storage for documents and POD photos; server-authoritative pricing and processing; rate limiting; a staff audit log; and single-use password-reset links that expire after 30 minutes.
12. Your Rights
12.1Under the UK GDPR you have the right to: access your personal data; have inaccurate data corrected; have data erased; restrict or object to processing; data portability; and withdraw consent at any time where processing is based on consent.
12.2You can reset your password yourself at any time via the self-service password reset. To exercise any other right, including deletion, email support@drevo.co.uk; we honour deletion requests within one month, subject to data we must keep by law (such as financial records).
12.3If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to resolve your concern first.
13. Cookies and Similar Technologies
13.1The platform uses only the minimal storage necessary to operate: authentication tokens that keep you signed in. We do not use advertising or cross-site tracking cookies.
14. Age Limits
14.1The platform is for business use and for self-employed couriers. It is not intended for, and must not be used by, anyone under 18. We do not knowingly collect data from under-18s.
15. Changes to This Policy
15.1We may update this policy from time to time. Material changes will be notified via the platform or by email, and the “Last updated” date at the top will change.
16. Contact
16.1Questions, requests and complaints: support@drevo.co.uk — Drevo Ltd, Office 606 18 Young Street, Unit Lge, Edinburgh, Scotland, EH2 4JB. Website: drevo.co.uk.