Mateen

This deployment hasn't had its company details filled in yet, so placeholders appear below. An administrator can set them under Settings → Business details before going live.

Privacy policy

Last updated 12 September 2026

1. Who we are

Mateen (“we”, “we”, “us”) is a UK courier and logistics company. We are the data controller for the personal data described in this notice, which means we decide why and how it is used.

Our details

Registered company
Mateen, company number [SET company number]
Registered address
[SET registered address]
ICO registration
[SET ICO registration]

2. Who this notice covers

Different people use us for different reasons, and we hold different data about each:

  • Customers who book a delivery, whether as a one-off online booking or over the phone.
  • Business account users whose company books with us on credit terms and who log in to the client portal.
  • Drivers and subcontractors who carry work for us and use the driver app.
  • Recipients — the people goods are collected from and delivered to, who may not be the person who booked.
  • Our own staff, who have portal accounts to run the operation.

3. What we collect, and why

If you book a delivery

Booking data

Contact details
Your name, email address and phone number, so we can confirm the booking and reach you about it.
Collection and delivery details
Addresses, postcodes, contact names and phone numbers at each end, access notes and the time window you need.
Consignment details
What is being moved — description, weight, dimensions, vehicle needed and any special handling.
Payment
Card payments are taken by Stripe. We never see or store your card number. We keep the payment reference, the amount, whether it succeeded, and any refund we make.

Why we're allowed to: performance of our contract with you (UK GDPR Article 6(1)(b)), and our legitimate interests in running the delivery safely and keeping proper business records (Article 6(1)(f)). Keeping invoices and tax records is a legal obligation (Article 6(1)(c)).

If a delivery is made to you

When a driver completes a job they capture proof of delivery: the name of the person who received it, a signature, photographs of the consignment where it was left, the time, and the location coordinates at the moment of delivery. We do this because our customer needs proof their goods arrived, and because it protects you too when a delivery is disputed.

Why we're allowed to: our legitimate interests and those of the sender in proving a delivery took place (Article 6(1)(f)).

If you drive for us

Driver data

Identity and contact
Name, email, phone, base postcode, and whether you are employed or self-employed.
Compliance documents
Driving licence, basic DBS certificate, right-to-work evidence, and hire & reward, goods-in-transit and public liability insurance, each with its expiry date.
Vehicle
Registration, make, model, vehicle class, MOT and insurance expiry dates.
Work records
Jobs offered, accepted, declined and completed, availability you set, the agreed rate for each job, and messages exchanged with the office.
Location
GPS position, speed, direction and phone battery level while you are on duty in the driver app, and the times you went on and off duty. See section 4 — this is under your control and is switched off by default.

Why we're allowed to: performance of our contract with you (Article 6(1)(b)); a legal obligation to check right to work (Article 6(1)(c)); and our legitimate interests in allocating work only to drivers who are road-legal and insured (Article 6(1)(f)).

A basic DBS certificate is criminal offence data under Article 10 UK GDPR. We process it only to decide whether you can be engaged to carry customers' goods, under the employment condition in Schedule 1 of the Data Protection Act 2018, we record only the certificate and its date rather than any narrative detail, and access is limited to the staff who review compliance.

If you have a portal login

For any account — staff, business account user or driver — we hold your name, email address, role, and a hashed version of your password. We never store the password itself. We keep a record of sign-ins, and password reset links are stored only as a one-time hash that expires after an hour.

4. Driver location tracking

A driver goes on duty by tapping “Go on duty” in the driver app, and off duty the same way. Nothing is collected while they are off duty. Going on duty is the consent and the boundary both: while it is on, the app records the driver's position about once a minute, along with speed, direction of travel and the phone's battery level, so the office and the customer can see where a job has got to and so we know to ring a driver whose phone is about to die.

A banner sits on every screen of the driver app for as long as it is running, saying it is on, and one tap ends it.

There are two versions of the driver app and they differ in one way that matters. Used in a phone's browser, it stops sharing the moment it is closed, because a website cannot run in the background. The Android app we distribute to our own drivers keeps sharing while the driver is on duty with the phone locked and in a pocket, and shows a notification the entire time it is doing so. Both stop completely when the driver goes off duty, and neither collects anything before they go on duty.

The office can look back at where a driver went on a given day. Doing so is recorded in our audit log with the name of the person who looked, and a driver can ask us who has looked at theirs. We do not use location history to monitor individual performance or to make automated decisions about anyone. Location points are kept for 90 days and then removed.

Why we're allowed to: the driver's consent, which can be withdrawn at any time (Article 6(1)(a)), together with our legitimate interest in giving customers an accurate ETA (Article 6(1)(f)).

5. Cookies and storage on your device

We do not use advertising cookies, tracking pixels or third-party analytics. The only cookies we set are the ones needed to keep you signed in and to protect the login form against cross-site request forgery. These are strictly necessary, so we don't ask for consent to set them — but the site won't work without them.

The app also stores a small amount of data in your own browser, which never reaches us:

  • Whether a driver is on duty and sharing their location.
  • Whether you have dismissed the prompt to install the app to your home screen.
  • For drivers, a queue of job updates made while offline, held until there's signal to send them.

Clearing your browser data removes all of it.

6. Who we share data with

We do not sell personal data. We share it only where it is needed to deliver the service:

Our processors and partners

Drivers
The driver carrying your job sees the collection and delivery details and the contact name and number at each end. They do not see what you paid.
Stripe
Card payments and refunds. Stripe is the controller of your card details; we are not.
Resend
Sends the transactional emails — booking confirmations, tracking links, invoices, password resets.
Twilio
Sends delivery SMS updates where a mobile number has been given.
OpenRouteService
Calculates distance and route for pricing. Receives postcodes and coordinates, not names.
OpenStreetMap
Supplies the map tiles shown behind live tracking.
Object storage
Holds compliance documents and proof-of-delivery images. Files are served only through the app, to signed-in users who are allowed to see them.
Courier exchanges
When a job is posted to a courier exchange to find a vehicle, the collection and delivery areas and the consignment details are shared. Contact details are not published.
Our hosting provider
Runs the servers and the database the system sits on.
Professional advisers and authorities
Accountants, insurers and legal advisers where needed, and the police or a regulator where we are legally required to disclose.

Each of these acts on our instructions under a written contract, except Stripe, which is a controller in its own right for payment data. Some of them process data outside the UK; where that happens we rely on UK adequacy regulations or the UK International Data Transfer Addendum. Ask us and we will tell you which applies to a particular provider.

7. How long we keep it

Retention periods

Job and delivery records
Six years from the end of the tax year the job falls in, so we can answer a dispute or an HMRC enquiry.
Invoices and payment records
Six years, as required for tax and company records.
Proof of delivery
Kept with the job record it proves.
Driver location points
90 days.
On-duty and off-duty times
Six years, alongside the job records they relate to.
Compliance documents
For as long as you drive for us, and 12 months after you stop. Expired documents are removed once replaced.
Portal accounts
While the account is in use. A deactivated account is kept for audit purposes and can be deleted on request.
Password reset links
One hour, then unusable.

8. Your rights

Under UK data protection law you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything that is wrong or incomplete.
  • Delete data we no longer have a reason to keep.
  • Restrict or object to how we use it, including where we rely on legitimate interests.
  • Send your data to you, or to another provider, in a portable format.
  • Withdraw consent — for a driver, that means going off duty in the app, which stops collection straight away.

Email privacy@yourcompany.co.uk and we will respond within one month. There is no charge. We may ask you to confirm who you are before we release anything.

If you are not satisfied with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first so we can put it right.

9. Automated decisions

Prices are calculated automatically from distance, vehicle type and service level, and the system checks whether a driver's documents are in date before they can be given a job. Neither is a decision about you made solely by a machine with legal or similarly significant effect — a member of staff allocates work, reviews compliance documents and approves accounts. You can always ask a person to look at a decision again.

10. How we protect it

  • Passwords are hashed with argon2 and are never stored or logged in readable form.
  • Traffic between your device and the portal is encrypted in transit.
  • Access is role-based: staff only see the screens their role needs, and refunds, pricing and account administration are restricted to administrators.
  • Compliance documents and delivery photographs are never public — they are served through the app only to users allowed to see them.
  • Every job carries an append-only history of who did what and when.
  • Repeated failed logins on an account are temporarily locked out.

No system is perfectly secure. If a breach ever put your rights at risk, we will tell the ICO within 72 hours and tell you without undue delay.

11. Changes to this notice

We update this notice when what we do with data changes. The date at the top tells you when it last changed. If a change is significant we will tell account holders by email rather than relying on you to check.

12. Contact us

Data protection questions: privacy@yourcompany.co.uk. Anything else: hello@yourcompany.co.uk. By post: Mateen, [SET registered address].

Our terms of service cover the delivery service itself.