Legal
Privacy Policy
How Drevo collects, uses and protects personal data — businesses, couriers and parcel recipients.
Version 1.0 · Last updated: [date to be confirmed]
1. Who we are
1.1This privacy policy explains how Drevo Ltd (trading as Drevo), a company registered in Scotland with company number SC887578 and registered office at [registered address — to be confirmed], collects and uses personal data in connection with the Drevo platform — an online marketplace connecting UK businesses needing delivery, same-day or scheduled, with vetted self-employed couriers, currently operating in Greater London.
1.2Drevo is not yet registered with the Information Commissioner’s Office (ICO). Registration is being completed before the platform opens to customers, and our registration number will be published here as soon as it is issued. Our obligations under UK GDPR — and your rights under it — apply in full regardless, from the moment we handle your data.
1.3You can contact us about anything in this policy at hello@drevo.co.uk.
2. Who this policy covers
2.1This policy is organised around the three groups of people whose personal data we handle:
- (a) Businesses — the companies that place delivery orders, and the individuals who operate their accounts (section 3);
- (b) Couriers — the self-employed couriers who deliver parcels through the platform (section 4);
- (c) Recipients — the people the parcels are delivered to (section 5).
2.2For Businesses and Couriers, Drevo is the controller of the personal data described below. For Recipients, Drevo acts as a processor on behalf of the sending Business — see section 5.
3. Information we collect — Businesses
3.1When a business registers and uses the platform, we collect and hold:
- (a) company name and Companies House number, which we verify against the Companies House register via the Companies House API;
- (b) the account owner’s name, email address and phone number, verified by one-time passcodes sent by email (via Resend) and SMS (via Twilio);
- (c) city and postcode, and VAT status;
- (d) your password, stored only as a secure cryptographic hash — we never store passwords in plain text;
- (e) payment records processed through Stripe — Drevo never stores your card numbers; card details are handled by Stripe;
- (f) your orders, invoices and delivery records;
- (g) message threads between you and Drevo staff; and
- (h) your marketing-consent preference.
4. Information we collect — Couriers
4.1To onboard and engage couriers as self-employed couriers, we collect and hold:
- (a) name, email address and phone number, and a password stored only as a secure hash;
- (b) date of birth, National Insurance number and home address;
- (c) right-to-work evidence: a passport or a Home Office share code;
- (d) driving licence details and a DVLA share code;
- (e) hire and reward insurance certificate, and vehicle registration;
- (f) bank account details for payouts, and optionally a Unique Taxpayer Reference (UTR) and VAT status;
- (g) a digital signature accepting the Courier Agreement;
- (h) uploaded identity, licence and insurance documents, stored in a private file store accessible only to authorised Drevo staff;
- (i) live GPS location, captured approximately every 25 seconds while the courier is online on the courier app, used for dispatch, live tracking and proof of delivery;
- (j) a reliability score derived from job history (see section 7);
- (k) a push-notification token for the courier app;
- (l) proof-of-delivery photographs the courier captures; and
- (m) DBS (Basic) check status, once DBS checking is introduced.
5. Information we handle — Recipients
5.1Recipient data is provided by the sending Business, not by the recipient. It may include: name, phone number, optional email address, delivery address, delivery instructions (which may contain door or gate codes), a proof-of-delivery photograph taken at the doorstep (which may capture the doorstep or property), and the GPS coordinate and timestamp of the delivery.
5.2For this data, the sending Business is the controller and Drevo is a processor acting on the Business’s instructions under a data processing agreement. If you are a recipient and want to exercise your data protection rights or understand why your data was shared, please contact the business that sent you the parcel in the first instance. We will assist the sending Business in responding, and you can also contact us at hello@drevo.co.uk.
5.3Proof-of-delivery photographs are stored privately, are accessible only to the sending Business and authorised Drevo staff, and are never made public.
6. How we use personal data and our lawful bases
6.1We use personal data on the following lawful bases under the UK GDPR:
- (a) Performance of a contract — operating accounts, computing prices, taking payment, dispatching orders to couriers, live tracking, capturing proof of delivery, paying couriers, and providing support;
- (b) Legitimate interests — verifying identity and company details, preventing fraud and abuse, securing the platform (rate limiting, audit logs), maintaining courier reliability scores, and improving the service. We balance these interests against your rights;
- (c) Consent — sending marketing communications to businesses that have opted in via the marketing-consent checkbox. You can withdraw consent at any time;
- (d) Legal obligation — keeping financial and tax records, verifying couriers’ right to work, and responding to lawful requests from authorities.
7. Reliability scores and automated decision-making
7.1Drevo maintains a reliability score for each courier, derived from their job history on the platform (for example completed, late or released jobs). The score affects which jobs are visible or offered to a courier, and certain business account tiers may restrict their orders to top-rated couriers.
7.2A courier who believes their score is wrong or unfair can contact hello@drevo.co.uk and a human will review it. Genuine vehicle breakdowns handled through the platform’s recovery process do not count against a courier’s score.
7.3Other than job visibility as described above, we do not make automated decisions that produce legal or similarly significant effects about any individual.
8. Who we share data with
8.1We share personal data only as needed to run the platform, with the following service providers (subprocessors):
| Provider | Purpose |
|---|---|
| Vercel | Application hosting |
| Neon | Database hosting |
| Vercel Blob | Private file storage (documents, POD photos) |
| Stripe | Card payments and refunds |
| Twilio | SMS one-time passcodes and notifications |
| Resend | Transactional email |
| Mapbox | Maps, routing and geocoding |
| Ideal Postcodes | UK address lookup |
| Companies House API | Company verification |
| Expo | Push notifications to the courier app |
8.2We also share data between the participants of a delivery as needed: businesses see courier first name, live location and POD for their orders; couriers see the pickup and delivery details needed to perform a job.
8.3We may disclose data where required by law, to enforce our terms, or in connection with a sale or reorganisation of our business (with safeguards).
8.4We do not sell personal data.
9. International transfers
9.1Some of our subprocessors process data in the United States. Where personal data is transferred outside the UK, we rely on safeguards recognised under Article 46 UK GDPR — the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum — or on UK adequacy regulations where they apply.
10. How long we keep data
| Data | Retention period |
|---|---|
| Financial, order and invoice records | 6 years (HMRC requirement) |
| Courier GPS traces | 12 months |
| Proof-of-delivery photographs | 12 months |
| Courier onboarding documents (identity, licence, insurance) | Duration of the engagement + 6 months |
| Account data | While the account is active, then deleted or anonymised subject to the periods above |
10.1When a retention period ends, we delete or irreversibly anonymise the data.
11. How we protect data
11.1We apply technical and organisational security measures including: passwords stored only as secure hashes; token-based (JWT) authentication; role-based access control with two-factor authentication for staff; private (non-public) file storage for documents and POD photos; server-authoritative pricing and processing; rate limiting; a staff audit log; and single-use password-reset links that expire after 30 minutes.
12. Your rights
12.1Under the UK GDPR you have the right to: access your personal data; have inaccurate data corrected; have data erased; restrict or object to processing; data portability; and withdraw consent at any time where processing is based on consent.
12.2You can reset your password yourself at any time via the self-service password reset. To exercise any other right, including deletion, email hello@drevo.co.uk; we honour deletion requests within one month, subject to data we must keep by law (such as financial records).
12.3If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to resolve your concern first.
13. Cookies and similar technologies
13.1The platform uses only the minimal storage necessary to operate: authentication tokens that keep you signed in. We do not use advertising or cross-site tracking cookies.
14. Age limits
14.1The platform is for business use and for self-employed couriers. It is not intended for, and must not be used by, anyone under 18. We do not knowingly collect data from under-18s.
15. Changes to this policy
15.1We may update this policy from time to time. Material changes will be notified via the platform or by email, and the “Last updated” date at the top will change.
16. Contact
16.1Questions, requests and complaints: hello@drevo.co.uk — Drevo, [registered address — to be confirmed]. Website: drevo.co.uk.
Version 1.0 · These terms are being finalised — questions: hello@drevo.co.uk

