Privacy Policy
Version 2026-08-21 · Last updated: 21 August 2026
Translations are for convenience only. The English version is legally binding.
1. Who is responsible for your data
BAOCAR LTD is a controller for BaoCar account administration, security, billing, support, fraud prevention, direct BaoCar communications and legal compliance.
The licensed Operator of Record identified during checkout or in your order confirmation is a separate controller for accepting and providing the journey, dispatching drivers/vehicles, statutory booking records and transport complaints. Where BaoCar hosts booking, driver or fleet information solely on an operator’s instructions, BaoCar acts as that operator’s processor. If BaoCar and an operator jointly determine a campaign or other purpose, we will identify the arrangement and responsibilities.
Contact: support@baocar.uk · Contact form
2. Data we collect
- Identity & contact: name, email, phone, address details you provide
- Booking data: pickup/drop-off, dates/times, passenger/luggage counts, notes, flight info you enter
- Account / auth: login identifiers (e.g. magic-link email verification via our auth provider)
- Support chat: messages and optional booking reference you send
- Payment: payment status and references; card details are handled by the payment processor (we do not store full card numbers)
- Technical: device/browser data, IP, cookies/local storage needed for language, tenant branding, and session
- Operator/driver accounts: company, licence, vehicle, insurance, right-to-work/check outcome, expiry, approval and audit records submitted or confirmed during enrolment
- Sources: information you provide, an inviting operator, payment/identity providers, licensing or company registers, and security/fraud signals
3. Why we use data (lawful bases)
- Contract: to provide a service you request, administer your account, process agreed payments and provide support
- Legitimate interests: platform security, fraud prevention, service administration, protecting users, B2B relationship management and routing requests to the intended operator; we balance these interests against your rights
- Legal obligation: tax/accounting, data protection, responding to lawful requests and any duties that apply to our activities
- Consent: where required (e.g. non-essential cookies or marketing — if/when enabled)
Licensed operators determine their own lawful bases for transport, statutory booking and driver/vehicle records and must provide their own privacy information where required.
4. Who we share data with
- The Operator of Record, its authorised dispatch personnel and the assigned driver to the extent needed for your journey
- Payment providers (e.g. Stripe or similar)
- Infrastructure providers (hosting, database/auth such as Supabase, email delivery, maps providers for address/route features)
- Authorities when required by law
We do not sell your personal data.
5. International transfers
Where a restricted transfer takes place outside the UK, we use an applicable adequacy regulation or contractual safeguard such as the UK International Data Transfer Agreement/Addendum and carry out any required transfer-risk assessment. Details relevant to your data are available on request.
6. Retention
We keep data only for a documented period based on purpose, legal duties, disputes, security and the Operator’s lawful instructions. Financial records are generally retained for up to six years after the relevant accounting period/relationship where required. Unsuccessful applications and expired compliance documents are reviewed for deletion or restricted retention rather than kept indefinitely. Statutory PHV booking records are retained by the responsible Operator for the period its law or licence requires.
7. Security
We use access controls, encrypted transport (HTTPS), and provider security features. No method is 100% secure. Conversation history on Contact is gated behind email magic-link verification to reduce casual access to other people’s threads.
8. Your rights
Under UK GDPR you may request: access, rectification, erasure, restriction, portability, and objection (in certain cases). You may also lodge a complaint with the ICO (ico.org.uk).
Email support@baocar.uk with enough detail for us to verify your request.
If your request concerns journey fulfilment or an operator’s statutory records, we may route it to the identified Operator of Record. Each controller remains responsible for requests relating to its own processing.
9. Cookies & local storage
We use essential storage for language preference, white-label tenant context, and login session. Details: Cookies. If we add analytics/marketing cookies later, we will update that page and seek consent where required.
10. Children
Our services are aimed at adults (18+). We do not knowingly collect data from children for accounts.
11. Automated decisions
Compliance flags and fraud/security tools may support human review or temporarily restrict access. BaoCar does not currently make solely automated decisions that produce legal or similarly significant effects without an applicable safeguard. We will update this notice before introducing such processing.
12. Changes
We may update this policy by posting a new version here with a revised “Last updated” date.