Privacy policy
Last updated 12 September 2026
1. Who we are
Mateen (“we”, “we”, “us”) is a UK courier and logistics company. We are the data controller for the personal data described in this notice, which means we decide why and how it is used.
Our details
- Registered company
- Mateen, company number [SET company number]
- Registered address
- [SET registered address]
- ICO registration
- [SET ICO registration]
- Privacy contact
- privacy@yourcompany.co.uk
2. Who this notice covers
Different people use us for different reasons, and we hold different data about each:
- Customers who book a delivery, whether as a one-off online booking or over the phone.
- Business account users whose company books with us on credit terms and who log in to the client portal.
- Drivers and subcontractors who carry work for us and use the driver app.
- Recipients — the people goods are collected from and delivered to, who may not be the person who booked.
- Our own staff, who have portal accounts to run the operation.
3. What we collect, and why
If you book a delivery
Booking data
- Contact details
- Your name, email address and phone number, so we can confirm the booking and reach you about it.
- Collection and delivery details
- Addresses, postcodes, contact names and phone numbers at each end, access notes and the time window you need.
- Consignment details
- What is being moved — description, weight, dimensions, vehicle needed and any special handling.
- Payment
- Card payments are taken by Stripe. We never see or store your card number. We keep the payment reference, the amount, whether it succeeded, and any refund we make.
Why we're allowed to: performance of our contract with you (UK GDPR Article 6(1)(b)), and our legitimate interests in running the delivery safely and keeping proper business records (Article 6(1)(f)). Keeping invoices and tax records is a legal obligation (Article 6(1)(c)).
If a delivery is made to you
When a driver completes a job they capture proof of delivery: the name of the person who received it, a signature, photographs of the consignment where it was left, the time, and the location coordinates at the moment of delivery. We do this because our customer needs proof their goods arrived, and because it protects you too when a delivery is disputed.
Why we're allowed to: our legitimate interests and those of the sender in proving a delivery took place (Article 6(1)(f)).
If you drive for us
Driver data
- Identity and contact
- Name, email, phone, base postcode, and whether you are employed or self-employed.
- Compliance documents
- Driving licence, basic DBS certificate, right-to-work evidence, and hire & reward, goods-in-transit and public liability insurance, each with its expiry date.
- Vehicle
- Registration, make, model, vehicle class, MOT and insurance expiry dates.
- Work records
- Jobs offered, accepted, declined and completed, availability you set, the agreed rate for each job, and messages exchanged with the office.
- Location
- GPS position, speed, direction and phone battery level while you are on duty in the driver app, and the times you went on and off duty. See section 4 — this is under your control and is switched off by default.
Why we're allowed to: performance of our contract with you (Article 6(1)(b)); a legal obligation to check right to work (Article 6(1)(c)); and our legitimate interests in allocating work only to drivers who are road-legal and insured (Article 6(1)(f)).
A basic DBS certificate is criminal offence data under Article 10 UK GDPR. We process it only to decide whether you can be engaged to carry customers' goods, under the employment condition in Schedule 1 of the Data Protection Act 2018, we record only the certificate and its date rather than any narrative detail, and access is limited to the staff who review compliance.
If you have a portal login
For any account — staff, business account user or driver — we hold your name, email address, role, and a hashed version of your password. We never store the password itself. We keep a record of sign-ins, and password reset links are stored only as a one-time hash that expires after an hour.
4. Driver location tracking
A driver goes on duty by tapping “Go on duty” in the driver app, and off duty the same way. Nothing is collected while they are off duty. Going on duty is the consent and the boundary both: while it is on, the app records the driver's position about once a minute, along with speed, direction of travel and the phone's battery level, so the office and the customer can see where a job has got to and so we know to ring a driver whose phone is about to die.
A banner sits on every screen of the driver app for as long as it is running, saying it is on, and one tap ends it.
There are two versions of the driver app and they differ in one way that matters. Used in a phone's browser, it stops sharing the moment it is closed, because a website cannot run in the background. The Android app we distribute to our own drivers keeps sharing while the driver is on duty with the phone locked and in a pocket, and shows a notification the entire time it is doing so. Both stop completely when the driver goes off duty, and neither collects anything before they go on duty.
The office can look back at where a driver went on a given day. Doing so is recorded in our audit log with the name of the person who looked, and a driver can ask us who has looked at theirs. We do not use location history to monitor individual performance or to make automated decisions about anyone. Location points are kept for 90 days and then removed.
Why we're allowed to: the driver's consent, which can be withdrawn at any time (Article 6(1)(a)), together with our legitimate interest in giving customers an accurate ETA (Article 6(1)(f)).
7. How long we keep it
Retention periods
- Job and delivery records
- Six years from the end of the tax year the job falls in, so we can answer a dispute or an HMRC enquiry.
- Invoices and payment records
- Six years, as required for tax and company records.
- Proof of delivery
- Kept with the job record it proves.
- Driver location points
- 90 days.
- On-duty and off-duty times
- Six years, alongside the job records they relate to.
- Compliance documents
- For as long as you drive for us, and 12 months after you stop. Expired documents are removed once replaced.
- Portal accounts
- While the account is in use. A deactivated account is kept for audit purposes and can be deleted on request.
- Password reset links
- One hour, then unusable.
8. Your rights
Under UK data protection law you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong or incomplete.
- Delete data we no longer have a reason to keep.
- Restrict or object to how we use it, including where we rely on legitimate interests.
- Send your data to you, or to another provider, in a portable format.
- Withdraw consent — for a driver, that means going off duty in the app, which stops collection straight away.
Email privacy@yourcompany.co.uk and we will respond within one month. There is no charge. We may ask you to confirm who you are before we release anything.
If you are not satisfied with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first so we can put it right.
9. Automated decisions
Prices are calculated automatically from distance, vehicle type and service level, and the system checks whether a driver's documents are in date before they can be given a job. Neither is a decision about you made solely by a machine with legal or similarly significant effect — a member of staff allocates work, reviews compliance documents and approves accounts. You can always ask a person to look at a decision again.
10. How we protect it
- Passwords are hashed with argon2 and are never stored or logged in readable form.
- Traffic between your device and the portal is encrypted in transit.
- Access is role-based: staff only see the screens their role needs, and refunds, pricing and account administration are restricted to administrators.
- Compliance documents and delivery photographs are never public — they are served through the app only to users allowed to see them.
- Every job carries an append-only history of who did what and when.
- Repeated failed logins on an account are temporarily locked out.
No system is perfectly secure. If a breach ever put your rights at risk, we will tell the ICO within 72 hours and tell you without undue delay.
11. Changes to this notice
We update this notice when what we do with data changes. The date at the top tells you when it last changed. If a change is significant we will tell account holders by email rather than relying on you to check.
12. Contact us
Data protection questions: privacy@yourcompany.co.uk. Anything else: hello@yourcompany.co.uk. By post: Mateen, [SET registered address].
Our terms of service cover the delivery service itself.