Driver calendar, engagement and running costs
For driver-owned availability and private vehicle, mileage, expense and price tools, UNLIMIT DIGITAL LTD determines the service purposes as controller. Processing necessary to provide the requested tools relies on performance of the driver service contract; proportionate security, abuse prevention and minimal audit records rely on documented legitimate interests, and applicable legal duties use the relevant legal-obligation basis. These purposes are separate from the business-directed delivery/workforce processing described below. The business remains controller of its own engagement declarations, required checks, schedules and delivery purposes. Actual decisions about purposes and means determine roles; calling ourselves a platform does not remove our controller or processor duties.
We record recurring weekly non-working periods and dated time off, the relevant timezone, shift offers, accept/reject/revised decisions and audit metadata. We compare commitments across the driver’s connected businesses to prevent overlapping acceptances and warn about availability or workload. A business sees generic warnings without another business’s name, exact private shift details or private time-off rules. The driver sees their own commitments. Do not enter medical or other sensitive details in shift-decline reasons; these are sent to the business and its authorised recipients.
Private vehicle settings are encrypted. Daily mileage overrides retain the settings used for estimates; automatic mileage uses completed-shift odometer records and is attributed to the shift-ending day. Expenses, fuel quantities, private notes and corrections are recorded separately from estimated consumption. Driver-entered prices keep the fuel type, amount, entered date, observation time and source. Optional price areas are rounded to approximately one kilometre and encrypted. Nearby-price searches use a single phone position in memory without storing or sending it to Fuel Finder; the server searches shared public price data. Drivers can use a manual price without supplying an area. No continuous off-shift tracking is enabled by these tools.
Driver-entered prices and private running costs are not exposed to businesses, other drivers or public price feeds. A future aggregated price service requires a separate documented purpose, lawful-basis and disclosure review; storing records now does not authorise unrestricted reuse. Public UK weekly averages and Fuel Finder station prices, including source/update dates and daily cache snapshots, are kept separately. Weekly averages carried into a daily snapshot remain weekly observations, not newly surveyed daily prices.
Drivers can remove non-working periods, erase individual entered-price records and delete their private cost records in the app. Cost erasure removes vehicle settings, mileage overrides, expenses, entered prices and their areas; minimal deletion counts and security/audit records remain without the erased content. Business-held shift, payment and compliance evidence, processor copies and backups have separate retention and request-handling rules. Private records remain while needed for the driver’s requested history, subject to purpose and inactive-account retention review; this does not authorise indefinite personal-data storage for unspecified future use. Backup expiry and any legal preservation exception must be documented in the production retention schedule.
1. Who is responsible
dropLog. is a product of UNLIMIT DIGITAL LTD, company number 16439193. Our registered office is 31–33 Worcester Street, Gloucester, England, GL1 3AJ.
For business account administration and the security of our service, the company acts as a controller. For customer, driver and delivery records entered by a takeaway, the intended arrangement is that the takeaway is the controller and dropLog. is its processor. Roles must reflect the actual contract and processing; the label alone does not determine them.
2. Information in the current application
| Information | Source and use |
|---|---|
| Business name, email, authority confirmation and policy acceptance records | Provided at registration. The email link allows password creation; only the password hash is stored. Email verification time, method and policy versions are recorded. Outlets and addresses are added after sign-in, not at registration. |
| Optional referral codes and signup attribution | When you voluntarily enter a referral code during new-account registration, we link the signup to the referring driver or business and record the time and programme version. Referrers can see counts and anonymous progress, without your name, phone number, email or account identifier. Platform administrators can review referring accounts and pause links, with an audit trail. No rewards, account access or driver enrolment are granted. Sharing is initiated by the referrer; we do not upload address books or send automated referral invitations. Referral links use no attribution cookies. Records currently remain until a reviewed account-data request is handled; automated referral retention and erasure are not implemented and a production retention schedule must be agreed. |
| Business and outlet contacts, addresses, documents and images | Business administrators and platform operators record contact person names, contact emails and telephone numbers separately from login identities. Each outlet can hold an operating address, supporting documents and images. Files are encrypted and quarantined until security scanning completes. Authorised location managers and platform administrators can access clean retained files; uploads, scans, access, changes and removal are audited. Images should show relevant premises and avoid unnecessary identifiable people or unrelated personal information. Administrator-created outlets require confirmation from the signed-in business owner through a single-use email link; the recipient, expiry, decision, method and time are recorded. |
| Business verification evidence and review decisions | Authorised applicants may upload requested business documents. Content is encrypted and quarantined pending malware scanning, then available to authenticated platform reviewers. Review decisions, reasons, requests and access actions are recorded. Provide only relevant business evidence; do not upload passports, payment-card details or unrelated sensitive information. |
| Account-service messages and verification links | Encrypted message content supports verification, password confirmation, review updates and staff invitations. In the current mock configuration no external email or SMS is sent; authorised operators can view private previews. Mock verification does not prove ownership of a live email address. |
| Business legal name, contact details, address, company number, billing email and delivery preferences | Provided during guided onboarding; used to configure the business workspace and administer its free-access period. |
| Administrator authentication and access-change records | Admin passwords and recovery codes are hashed; authenticator secrets are encrypted. Admin session/challenge hashes, verification counters, actor IDs and reasons for account locks support security and accountability. |
| Subscription and invoice records, when paid billing is enabled | Stripe customer and subscription references, invoice numbers, amounts, currency, status and document links support account billing. Card details are entered on Stripe-hosted pages and are not collected by dropLog. Live billing is not configured for this review release. |
| Driver name, phone, vehicle and agreed per-drop rate | Entered by the takeaway; used to assign deliveries and calculate recorded fees. |
| Receipt number, address, postcode, amount due and cash received | Entered by the takeaway; used to manage deliveries and reconcile payments. |
| Shift times, odometer readings, cash float, wages and notes | Entered or recorded during the shift; used for the operational ledger. |
| Latest driver position, accuracy and capture time | Accepted from an authorised device only during an active shift. Device onboarding and native apps are not yet released. |
| Driver activity, battery, incidents, compliance and messages | Authorised driver devices can report battery level, stops, incidents and renewal details. Business staff can record pickup, completion, waiting and break periods. Daily reports show observed stopped time, partial GPS distance and unusual delivery durations for human investigation; these are not proof of wasted pay or wrongdoing. Incident narratives and private image, video and audio evidence support business review. Licence, insurance and vehicle references are encrypted and displayed in masked form, alongside expiry and business review records. Business-driver chat remains available off shift; encrypted message content and explicit delivery/read acknowledgements support communications. Staff access can be limited to one outlet. Native apps and production driver identity onboarding remain unreleased. |
| Session token hash, expiry, login-attempt counters and dated activity | Business changes and API requests record the acting account, server timestamp, request identifier, connection IP and source, and relevant outlet. Approximate city/country is recorded only when a configured trusted ingress supplies it; it is not precise device location. Passwords, invitation tokens, raw request bodies and precise driver coordinates are excluded from request logs. Infrastructure logging depends on the hosting configuration. |
3. Purposes and lawful bases
For an individual who contracts with us, account processing may be necessary to perform that contract. For a business contact who is not personally the contracting party, account administration and security are intended to rely on documented legitimate interests, subject to a balancing assessment. Specific legal obligations may require processing when they apply; no particular statutory retention duty is assumed here.
For records processed on a takeaway’s instructions, that takeaway must establish and communicate its own lawful basis. Registration is not blanket consent to customer processing, employee monitoring or marketing. No advertising analytics or marketing campaigns are enabled in the current build. These proposed bases require confirmation against the final service arrangement before launch.
4. Driver location and sensitive information
The application stores the latest reported point and limited stop-window anchors, not a complete route history. GPS reports outside an active shift are rejected. The fleet map labels stale positions and shows the last capture time; it does not assume a driver is stationary when GPS is unavailable. Closing a shift clears that driver’s latest coordinate, accuracy and timestamp. Closed stop anchors are erased after fourteen days by default by the worker, while duration records remain for reporting. Last reported battery information can help diagnose loss of updates but does not establish its cause. Backup expiry and abandoned-shift cleanup remain to be implemented.
Drivers may separately choose to share a one-time availability position with their own business, including when off shift. This does not start continuous tracking or a working shift. Nearby results expose approximate distance, not the exact availability coordinate. Positions cease to appear after fifteen minutes and the worker clears the snapshot. Availability can be withdrawn immediately. Work offers require an explicit payment amount and driver acceptance; a business-authorised shift remains required before assignment.
Businesses must inform drivers about monitoring purposes, visibility, retention and review, establish the applicable lawful basis and complete any required impact assessment. Breaks, customer service, traffic and connectivity must be considered before drawing conclusions. Staff must not make automatic pay deductions or disciplinary decisions from a stop or anomaly flag. Map monitoring mode keeps a signed-in session active while the map is visible; protect the monitoring display from unauthorised viewing and use manual lock when needed.
Do not enter payment-card details, identity documents or unnecessary sensitive information into delivery notes. Allergy and accessibility notes can reveal health information; avoid recording them in this release unless the controller has established the necessary safeguards and lawful conditions. Location permission on a phone does not by itself establish a lawful basis for monitoring a worker.
5. Access, recipients and international transfers
Takeaway workspace access is restricted to the business and the signed-in staff role. Roles apply across all outlets within that business. Owners and administrators can invite colleagues and revoke access; managers and finance staff can view audit records. Invitations expire after 48 hours, but expired token hashes and audit records are not automatically deleted. Approved hosting, database and support providers may process information when production services are configured. A complete provider register and contractual safeguards have not yet been finalised. The Subprocessors & services page distinguishes verified application dependencies from unappointed providers.
When a live map is loaded, the browser requests map tiles from OpenStreetMap infrastructure. This can disclose IP address, browser information and the approximate area being viewed. Fonts are served by the Next.js application, rather than requested by visitors directly from Google Fonts.
When Firebase notifications are configured and a driver enables them, encrypted device registration tokens are associated with that signed-in phone session. Firebase and Apple notification services may process device identifiers and generic notification text. Customer addresses, payment amounts and receipt contents are excluded from push previews. Provider acceptance is not proof of device delivery or reading. In-app shift and order notices are retained for thirty days; push registration is removed on logout or expiry cleanup. Provider contracts and international-transfer arrangements must be completed before activation.
Shift attendance reports contain the driver’s explanation, schedule and business membership. Explanations and owner alert numbers are encrypted. Authorised business staff can review attendance; the owner can opt into operational SMS and WhatsApp alerts. External alerts contain a generic instruction to sign in, not the private explanation. Drivers should not submit medical details or unnecessary sensitive information. Replacement invitations record the offered shift, fixed and additional delivery pay, payment arrangements, terms and the driver’s response. These agreements and absence records need agreed retention, rights and legal-hold schedules before production; a dashboard display window is not deletion.
Production data locations and support access must be confirmed. Transfers require an applicable adequacy decision or another valid mechanism and any necessary transfer assessment. UK–EEA adequacy does not automatically authorise onward transfers to every vendor. No EU-only hosting or international-transfer compliance claim is made.
6. Retention and deletion
Retention will need to reflect each purpose and any applicable recordkeeping requirements. Operational delivery addresses should not be retained merely because a financial record is retained. There is no approved blanket “keep everything for six years” policy.
| Record | Verified behaviour / outstanding decision |
|---|---|
| Verification evidence content | The communications worker deletes retained document content 30 days after approval, rejection or termination by default; the period is configurable. Pending applications, metadata and backups require a separate retention policy. Automatic deletion requires the worker to be running. |
| Location evidence and confirmation records | Location documents and images remain available for operational evidence until removed by an authorised user. Removal and a rejected malware scan clear the retained file content; audit and file metadata remain. The last required clean document or image for an approved location must be replaced before removal. No scheduled deletion for abandoned location drafts, location confirmation records, metadata or backups is implemented yet; category-specific retention must be agreed before production. Confirmation links expire after ten minutes by default, configurable by the operator, and are invalidated by a replacement, cancellation or completed decision. |
| Message content and verification credentials | Registration verification links are single-use; resending revokes previous unused links. The link lifetime and total email allowance are configurable, defaulting to ten minutes and three emails including the initial message. Each registration keeps its policy when created; the applicable lifetime is shown in the email. Reminders are prepared after each window until the allowance is exhausted, then an incomplete application is marked inactive. An audited administrator resend opens one window using the latest lifetime without restarting automatic reminders. Delivery counters, deadlines and access decisions are recorded; inactivity does not itself delete application data. Live accepted message payloads are erased. The worker clears expired encrypted previews and unsent payloads (at most seven days by default, shorter for verification). Token hashes and message metadata do not yet have scheduled deletion. |
| Authentication cookie | Expires after seven days with the current default; sign-out removes the cookie and revokes that session. |
| Expired session rows and login-attempt counters | No scheduled deletion job exists yet. Login throttling uses a fifteen-minute counting window; that is not a retention period. |
| Latest driver coordinates | The latest report replaces the earlier point. Closing the shift clears the last stored coordinate, accuracy and timestamp. An abandoned open shift is not automatically expired; backup retention still needs a defined policy. |
| Recorded paid-subscription journeys | Each accepted GPS report during an active paid-subscription shift is archived with its time, accuracy and available battery information. Businesses can view a rolling thirty-day window; expiry of that window does not delete the archive. Authorised platform administrators can access older dates, including after a subscription ends, with a recorded purpose. There is no automatic archive deletion. Continued retention requires a documented necessary purpose and regular review; indefinite storage merely because it is possible is not justified. Following a verified privacy request and review of applicable exceptions, administrators can erase a shift or all shifts for a driver at a business and clear associated stop coordinates. A minimal case and deletion audit remains without the erased coordinates. Other records, processors and backups require separate case handling. |
| Driver stop anchors, chat content and incident media | The operational worker clears coordinates from closed stop windows after fourteen days by default. It clears chat content after its recorded expiry, default ninety days, and incident media after ninety days by default. These periods are configurable. Report durations, incident narratives, compliance records, message/receipt metadata and backups require separate agreed retention and erasure schedules; automatic removal of these records is not implemented. Stopping the worker delays content cleanup. |
| Accounts, deliveries, shifts and activity | No automatic retention or account-erasure workflow is implemented. Category-specific periods, backup deletion and any legal holds must be agreed and implemented before production onboarding. |
7. Your rights and contact route
Depending on the processing and applicable law, you may request access, correction, erasure, restriction or portability, object to processing, and withdraw consent where consent is the basis. These rights are not unconditional. The GDPR & your rights page explains how to identify the relevant controller.
You can write to UNLIMIT DIGITAL LTD, FAO Data Protection, at 31–33 Worcester Street, Gloucester, England, GL1 3AJ. Describe your request and provide a safe reply address. Do not send passwords or unnecessary identity documents. A dedicated privacy email and operational case-handling team are still to be confirmed.
You may complain to the UK Information Commissioner’s Office or the competent European supervisory authority. You do not have to waive that right or accept these policies to raise a concern.
7A. Driver evidence and arrival messages — planned processing
Driver right-to-work, licence and insurance review, expiry reminders, native tracking, route optimisation, shared-driver matching and SMS/WhatsApp arrival automation are planned modules. The present business-application document facility does not verify drivers. Do not upload driver identity or insurance evidence there or place it in delivery notes.
Before any such module is activated, the responsible parties must complete the applicable notice and processing schedule: the evidence and contact data required, purpose and lawful basis, source, authorised recipients, country of work, hosting and transfers, retention and rights route. Collect sensitive information only where necessary and with any additional legal condition required. A photograph is not automatically biometric data, but processing it for unique identification needs a separate assessment.
For the intended driver-check workflow, the engaging business determines and performs its required checks. The proposed record includes reviewer, method, decision, restrictions and expiry, with evidence access limited to authorised reviewers. Drivers must be able to correct information and challenge a decision. Records must not be shared with another business merely because it uses this platform.
UK employee right-to-work evidence generally needs to be retained throughout employment and for two years afterwards under the prescribed checks. That does not authorise keeping all GPS, customer contacts or other records for the same period. Driver evidence must have its own reviewed schedule and must not inherit the 30-day business-application-document cleanup period.
Planned arrival messages will use the customer contact and permitted channel for the specific delivery. A receipt phone number does not demonstrate WhatsApp opt-in. The business must provide required information and permissions, respect applicable preferences, and keep service messages separate from marketing. Message providers, sender identities and international transfers must be disclosed before use.
8. Children, automated decisions and changes
This service is for business delivery operations, not a service directed at children. The current release does not use automated driver scoring or solely automated decisions producing legal or similarly significant effects. Native route planning and OCR remain planned features and will need fresh privacy assessment.
Account fields are necessary to create a workspace; if they are not provided, registration cannot complete. Optional notes should be limited to the delivery purpose. This version is a review draft, not evidence that every operational safeguard has been deployed. Material changes must be communicated before new processing begins.
Official guidance & references
The sources below inform the review. They do not certify this product or replace the company’s operational responsibilities.
ICO: privacy information requirementsEU General Data Protection RegulationEDPB: controller and processor responsibilitiesICO: subject access guidanceFind your European data protection authorityGOV.UK: employer right-to-work checksWhatsApp: business messaging requirements