Courier Passport

Legal

Privacy notice

Last updated 15 September 2026. This page is a template for solicitor review and is not legal advice.

Controller: Courier Drivers (operating the Courier Passport service at courierpassport.com). Contact: [email protected].

This notice is for people in the United Kingdom and, where we offer the service to them, the European Economic Area. We apply UK GDPR. Where EU GDPR applies, you have the rights described below and may complain to your local supervisory authority.

What we collect

  • Account data: name, email, phone, password hash.
  • Application data: identity verification status, driving-licence status, right-to-work evidence dates, insurance policy dates, DBS result band (not the certificate file for partners), fit-for-work status.
  • Sharing data: which businesses you authorised, lookup audit (who looked up your passport, when).
  • Partner data: company name, company number, API key hashes, webhook URLs.
  • Insurer interest: company name, company number, contact details, optional FCA firm reference, and whether they want to list from-prices or quote for cover (used only to review a listing request).
  • Courier goods-in-transit quote details from the driver app: van registration, postcode, goods type, sum insured, and overnight parking (used to ask an insurer for a quote; not a purchase).
  • Service messages: expiry reminders (30 / 7 / 1 days and after a passport is no longer valid).
  • Wallet pass metadata: a device registration and authentication token if you add the passport to Apple Wallet (Google Wallet uses Google’s save flow under Google’s terms).
  • Cookie and similar-technology data as described in our cookie policy.

We do not give partners Veriff images, DVLA enquiry payloads, or DBS certificate files.

Lawful bases (UK GDPR / EU GDPR)

  • Contract — creating your account, issuing and revalidating a passport, sending service email needed to keep that passport in date, and sending a password-reset link you asked for.
  • Consent — sharing passport status with a named business; processing special-category data (health / criminal-record related DBS status); optional analytics cookies if you switch them on; asking an insurer to quote from goods-in-transit details you submitted.
  • Legitimate interests — security, fraud prevention, audit logs, and reviewing insurer listing requests (balanced against your rights).

You can withdraw sharing consent at any time. That does not erase a passport that has already been issued, but partners immediately lose access. You can withdraw optional cookie consent from Cookie settings.

Special-category data

Fit-for-work and DBS-related status are special category. We process them only with explicit consent, store the minimum (status, dates, result band), and restrict staff access.

Sharing

We share passport status with businesses you approve. We use processors (identity provider, DVLA commercial enquiry, DBS umbrella, hosting, email delivery, Apple/Google if you add a Wallet pass) under written contracts or their terms you accept.

Hiring businesses and apps are independent controllers when they look up a passport. They must have their own lawful basis for using the result.

Cookies and similar technologies

We do not use advertising cookies. Session sign-in uses sessionStorage, not a third-party cookie. Details, legal bases, and your PECR / ePrivacy choices are in the cookie policy.

Retention

  • Application and passport records: while the account is open, then up to 6 years for dispute/audit unless a shorter period is required.
  • Lookup audit: 2 years.
  • Expiry-notice records: keyed to the current valid-until date so a revalidation starts a new cycle.
  • Identity images held by the identity provider per their retention schedule — we store session IDs and status, not the images.
  • Cookie consent record: in your browser until you clear it or we publish a new consent version.
  • Password-reset tokens: one hour, then deleted. Refresh tokens: until you sign out, reset your password, or 30 days.

Your rights

Access, rectification, erasure, restriction, portability, objection, and the right not to be subject to a solely automated decision with legal or similarly significant effect. We do not make hiring decisions; businesses do.

  • United Kingdom: complain to the ICO (ico.org.uk).
  • EEA: complain to your local supervisory authority (see edpb.europa.eu).

Contact: [email protected].

International transfers

If a processor stores data outside the UK, we use the UK addendum to the EU SCCs, the UK IDTA, or UK adequacy regulations. Transfers from the EEA to the UK rely on the European Commission’s adequacy decision for the UK where it remains in force, otherwise EU SCCs.

We are established in the United Kingdom. If we offer this service to people in the EEA, we will appoint an EU representative under Article 27 GDPR and publish their contact details on this page.

Children

The service is for professional courier drivers and businesses, not for children.