Privacy Policy
How we handle your personal data.
This policy explains what information National Taxi collects, how we use it, and the rights you have under UK GDPR. Last updated 2026-04-24.
At a glance
The short version of this policy:
- We collect the information we need to arrange your journey and keep you informed — name, phone, email, pickup / destination, payment status.
- We do not sell your personal data.
- We use Stripe for card payments — we never see or store your card details.
- We share only the minimum data the Driver needs to complete your journey.
- You can ask for a copy of your data, correct it, or have it deleted at any time.
- You can opt out of marketing SMS by replying STOP, or marketing email via the unsubscribe link.
- Questions or requests: email privacy@nationaltaxi.co.uk.
The rest of this page is the full notice required by UK GDPR Articles 13–14.
1. Who we are
National Taxi Ltd (trading as National Taxi) ("we", "us", "our") is the data controller for the personal information described in this policy.
Registered office: 7 Maldon Road, Brighton, England, BN1 5BD.
Registered in England & Wales, company number 14491447.
Private Hire Vehicle operator licence: 872, issued by Brighton & Hove City Council.
For privacy questions, subject-access requests, or to exercise your rights, email privacy@nationaltaxi.co.uk. You can also call us on 01273 757474.
2. What information we collect
We collect the following categories of personal data, mostly directly from you:
- Identification and contact: name, phone number, email address, booking account password (stored as a one-way hash).
- Journey details: pickup and destination addresses and postcodes, date and time, passenger count, luggage, flight number, special requirements, any notes you provide.
- Payment information: processed by Stripe. We receive and store only the payment-intent identifier, the receipt URL, the amount, and the outcome status — we never see, hold, or log your card number, expiry, or CVV.
- Communications: the content of SMS and email messages we send you about your Bookings; your replies; notes on phone calls to our office.
- Marketing preferences: whether you have opted in to marketing SMS or email, and the record of that consent (timestamp, source).
- Technical data: IP address, device type, browser, referrer, timestamps, and cookie identifiers — used for security, fraud prevention, and (with your consent) analytics.
- Feedback: reviews, complaints, and correspondence about your Bookings.
We also receive information from other sources, including:
- Our Drivers — pickup confirmation, journey completion, notes about the trip, reports of damage or soiling.
- Stripe — payment outcomes, fraud / risk signals associated with a transaction.
- Flight-tracking providers — live status for the flight number you provide (arrival time, gate, delays).
- Mapbox — geocoded coordinates when we resolve an address you type into a map point.
3. How and why we use your information
We process personal data on the following legal bases under UK GDPR Article 6:
- Contract — Article 6(1)(b): to arrange, confirm, dispatch, and complete your Booking; to process payment; to issue receipts; to monitor your flight and adjust timings; to respond to customer-service queries.
- Legitimate interests — Article 6(1)(f): to prevent fraud and misuse; to enforce rate limits and protect our systems; to investigate soiling / damage claims; to keep a record of communications for quality and training; to analyse aggregate usage of our website. We balance our interest against your rights — you can object at any time.
- Legal obligation — Article 6(1)(c): to retain financial and tax records; to respond to lawful requests from police or licensing authorities; to comply with our PHV operator-licence conditions; to fulfil consumer-protection obligations.
- Consent — Article 6(1)(a): for marketing SMS, marketing email, and non-essential cookies. You can withdraw consent at any time without affecting processing that happened before.
4. Who we share your information with
We share the minimum data necessary with the following processors and partners. Every processor listed here operates under a written data-processing agreement with us.
- Our Drivers: your name, pickup and destination, phone number (during the trip only), flight number, passenger count, and special requirements. Drivers are licensed professionals bound by confidentiality.
- Stripe Payments UK Ltd — card payment processing. Stripe is the data controller for the card data you enter into their checkout; we receive only the outcome.
- Supabase Inc. (hosted on AWS, eu-west-1 / eu-west-2) — application backend, database, authentication.
- ClickSend Ltd — transactional and operational SMS delivery.
- Our email provider (Resend / equivalent) — booking confirmations, receipts, and any marketing email you've consented to.
- Vercel Inc. — Website and application hosting.
- Mapbox — address autocomplete, geocoding, routing, and maps.
- Flight-data provider — flight-number status lookups where you provide a flight number.
- Google Analytics / Google Ads — usage analytics and campaign measurement, only after you accept the relevant cookie category.
- Regulators and authorities — where we are legally required to disclose (e.g. Brighton & Hove City Council, HMRC, police, courts).
- Professional advisors and successors — lawyers, accountants, insurers, and any buyer of our business (under confidentiality).
We do not sell your personal data.
5. International transfers
Most processing happens in the UK and EEA. Where a processor (e.g. Stripe, Mapbox, our email provider, Google) transfers personal data outside the UK or EEA, we rely on one of the following safeguards under UK GDPR Chapter V:
- An adequacy decision made by the UK Government (e.g. for transfers to the EEA).
- The UK's International Data Transfer Agreement (IDTA).
- The UK Addendum to the EU Standard Contractual Clauses.
We add supplementary measures where the destination country's laws do not provide equivalent protection. You can request the safeguards in place for a specific transfer by contacting us.
6. How long we keep your information
We retain personal data only as long as we need it for the purposes set out above. Our default periods are:
- Booking records (jobs, receipts, invoices): 7 years from the date of travel (HMRC / Companies Act). Personal identifiers are redacted earlier on request (see §7).
- SMS message log: 13 months from send date, then automatically pruned.
- Contact-form submissions: 12 months, unless escalated into a complaint file.
- Complaint files: 6 years from resolution (limitation periods under UK law).
- Login and rate-limit logs: 24 hours.
- Marketing consent records: for the life of your account plus 2 years.
- Stripe webhook events: 30 days for fraud forensics.
- Website analytics (with consent): 14 months.
If you delete your account, we redact the personal identifiers on your past jobs (name, phone, email, home address become "REDACTED") while keeping the anonymised journey record for accounting, complaint, and insurance-defence purposes.
7. Your rights under UK GDPR
You have the following rights, free of charge:
- Right of access — a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete information.
- Right to erasure ("right to be forgotten") — delete your account and have your identifiers redacted, subject to our legal retention obligations.
- Right to restriction — ask us to pause processing while a dispute is resolved.
- Right to data portability — receive your data in a structured, machine-readable format (CSV / JSON) where we rely on consent or contract.
- Right to object — to processing based on legitimate interests or for direct marketing (absolute right for marketing).
- Right to withdraw consent — at any time, for any processing based on consent.
- Right not to be subject to solely-automated decisions — we do not make decisions with legal or similarly significant effects about you using only automated processing.
- Right to complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint. We would appreciate the chance to address the issue first.
To exercise any of these rights, email privacy@nationaltaxi.co.uk. We respond within one calendar month of receiving a valid request — we may ask for proof of identity before releasing personal data. In complex or repeat cases we may extend the response time by up to two further months and will tell you why.
8. Marketing and your preferences
We send transactional communications (booking confirmations, driver updates, receipts, cancellation notices) under contract — these are not marketing and cannot be unsubscribed from while you have a live Booking, because they are essential to the service.
We only send marketing SMS or email if you have actively opted in. You can withdraw consent at any time:
- SMS: reply STOP (also UNSUB, END, or QUIT) to any message. We process the opt-out within minutes and send a final confirmation. Your number is added to a suppression list so a new signup with the same number stays opted out until re-confirmed.
- Email: click the "unsubscribe" link at the foot of any marketing email.
- Account preferences: manage your marketing settings in your account or email privacy@nationaltaxi.co.uk.
9. CCTV and in-vehicle recording
Some of the Vehicles dispatched under our operator licence are fitted with in-vehicle cameras (dashcams) by the Driver, operated independently under the Driver's own data-controller responsibilities — not by us. Where a camera is in use, a notice must be displayed inside the Vehicle.
Footage is typically recorded only for safety and insurance purposes and is held briefly before overwrite. If you need to request footage of a specific journey (e.g. to support an insurance claim or complaint), contact us and we will facilitate the request with the Driver as far as we are able — the Driver will be the data controller for any CCTV footage.
10. Cookies and analytics
We use the following cookie categories on our Website:
- Strictly necessary — your Supabase auth session, booking-wizard progress, form tokens, cookie-consent preferences. These cannot be disabled as they are required for the Website to function.
- Analytics (Google Analytics 4) — only loaded after you accept analytics cookies. Helps us understand site usage.
- Advertising — only loaded after you accept advertising cookies, to measure campaign effectiveness and show relevant ads.
You can change your choices at any time via the Cookie settings link in the footer. We implement Google Consent Mode v2, so tags only fire once you consent.
11. Security
We protect personal data with a layered set of controls:
- TLS 1.2+ encryption for all data in transit.
- Encryption at rest for our database (Supabase, managed via AWS RDS).
- Row-Level Security policies so users and staff only see the records they are authorised to see.
- Role-based access for admins and Drivers, with individual authenticated sessions.
- Rate limits, input validation, and automated abuse detection on every public endpoint.
- Payment details handled by Stripe's PCI-DSS Level 1 infrastructure — card data never reaches our servers.
- Regular security reviews and dependency-vulnerability scanning.
12. Breach notification
If a personal-data breach occurs that is likely to pose a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware (Article 33 UK GDPR). Where the breach is likely to pose a high risk, we will contact affected users directly without undue delay (Article 34).
13. Children
Our services are intended for people aged 16 and over (the minimum age to travel unaccompanied under §4 of our Terms). If you believe we hold data about a child under 13 collected without a parent's consent, please email privacy@nationaltaxi.co.uk and we will delete it promptly.
14. Third-party links
Our Website and emails may contain links to third-party sites (e.g. Stripe receipts, the licensing authority's check page, review platforms). We are not responsible for the privacy practices of those sites — please read their own privacy notices.
15. Changes to this policy
We review this policy regularly and will post material changes on this page with an updated "last updated" date. Significant changes — particularly any that require new consent — will be notified by email to account holders.
16. How to contact us
For any privacy-related matter, including subject-access requests, rectification, erasure, or to complain:
- Email: privacy@nationaltaxi.co.uk
- Phone: 01273 757474
- Post: Data Protection, National Taxi Ltd, 7 Maldon Road, Brighton, England, BN1 5BD
You also have the right to complain to the Information Commissioner's Office at any time: ico.org.uk/make-a-complaint or 0303 123 1113.
Questions or requests? Email privacy@nationaltaxi.co.uk or call 01273 757474 — we aim to respond within one calendar month.