Privacy Policy

Last updated: November 28, 2025

1. Introduction

Chauffs ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service, you consent to the data practices described in this policy.

2. Information We Collect

2.1 Information You Provide

We collect information you provide directly to us, including:

  • Account Information: Email address, password (hashed), and profile information
  • Trip Data: Locations, dates, times, passenger information, trip notes, and preferences
  • Driver Information: Driver email addresses, quotes, and assignment details
  • Communication Data: Messages, feedback, and support requests
  • Payment Information: Billing details processed through secure payment processors

2.2 Automatically Collected Information

We automatically collect certain information when you use the Service:

  • Usage Data: Pages visited, features used, time spent, and interaction patterns
  • Device Information: IP address, browser type, operating system, and device identifiers
  • Log Data: Access times, error logs, and system events
  • Cookies and Tracking: See our Cookie Policy section below

2.3 Third-Party Data

We may collect data from third-party services you authorize, such as:

  • Location data from Google Maps API
  • Weather data from Open-Meteo
  • Traffic and safety data from public APIs (TfL, UK Police)

3. How We Use Your Information

We use collected information for the following purposes:

  • Service Provision: To provide, maintain, and improve the Service
  • Trip Management: To create, store, and manage your trip plans and reports
  • AI Processing: To generate trip analyses, risk assessments, and driver briefings
  • Communication: To send trip updates, notifications, and respond to inquiries
  • Driver Coordination: To facilitate driver assignments, quotes, and confirmations
  • Analytics: To analyze usage patterns and improve service quality
  • Security: To detect, prevent, and address security issues
  • Legal Compliance: To comply with legal obligations and enforce our Terms
  • Marketing: To send promotional communications (with your consent, opt-out available)

4. Data Processing and AI

Your trip data is processed using artificial intelligence to generate reports and analyses. This includes:

  • Processing trip notes and requirements through AI models (OpenAI GPT-4o-mini)
  • Analyzing location data, weather, traffic, and safety information
  • Generating executive reports and driver briefings
  • Quality evaluation and improvement of AI-generated content

AI processing is performed in accordance with our data processing agreements and OpenAI's privacy policies. Your data is not used to train AI models without your explicit consent.

5. Data Sharing and Disclosure

We may share your information in the following circumstances:

5.1 Service Providers

We share data with trusted service providers who assist in operating the Service:

  • Cloud Hosting: Supabase (database and authentication)
  • AI Services: OpenAI (report generation and analysis)
  • Email Services: Resend (transactional emails)
  • Payment Processors: Secure payment processing services
  • Analytics: Service usage and performance monitoring

5.2 Driver Information

When you assign a driver to a trip, we share relevant trip information (locations, times, passenger details, trip notes) with the assigned driver via email and the Service interface.

5.3 Legal Requirements

We may disclose information if required by law or to:

  • Comply with legal processes or government requests
  • Enforce our Terms of Service
  • Protect our rights, privacy, safety, or property
  • Prevent fraud or security issues

5.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

6. Data Storage and Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption: Data in transit (TLS/SSL) and at rest
  • Access Controls: Limited access to authorized personnel only
  • Authentication: Secure password hashing and session management
  • Regular Audits: Security assessments and vulnerability testing
  • Data Backup: Regular backups with disaster recovery procedures

However, no method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

7. Data Retention

We retain your information for as long as necessary to:

  • Provide the Service to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain business records for analytics and improvement

When you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law.

8. Your Rights and Choices

Depending on your location, you may have the following rights:

8.1 Access and Portability

You can access, download, or export your data at any time through your account settings or by contacting us.

8.2 Correction

You can update or correct your account information and trip data through the Service interface.

8.3 Deletion

You can request deletion of your account and associated data by contacting us or using account deletion features.

8.4 Opt-Out

You can opt-out of marketing communications by:

  • Clicking unsubscribe links in emails
  • Updating your account preferences
  • Contacting us directly

8.5 GDPR Rights (EU Users)

If you are in the European Union, you have additional rights under GDPR:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent

8.6 CCPA Rights (California Users)

If you are a California resident, you have rights under CCPA:

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of sale of personal information (we do not sell your data)
  • Right to non-discrimination for exercising your rights

9. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Essential Cookies: Required for authentication and core functionality
  • Analytics Cookies: To understand usage patterns and improve the Service
  • Preference Cookies: To remember your settings and preferences

You can control cookies through your browser settings. However, disabling essential cookies may affect Service functionality.

10. Third-Party Services

Our Service integrates with third-party services that have their own privacy policies:

  • Supabase: Database and authentication services
  • OpenAI: AI processing and report generation
  • Resend: Email delivery services
  • Google Maps API: Location and mapping services
  • Payment Processors: Secure payment processing

We encourage you to review their privacy policies. We are not responsible for the privacy practices of third-party services.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We ensure appropriate safeguards are in place, including:

  • Standard contractual clauses
  • Adequacy decisions where applicable
  • Other appropriate safeguards as required by law

12. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete such information promptly.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on this page
  • Updating the "Last updated" date
  • Sending email notifications for significant changes
  • Displaying in-app notifications

Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

14. Data Protection Officer

For privacy-related inquiries, data protection requests, or to exercise your rights, please contact:

Email: privacy@chauffs.com

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: privacy@chauffs.com

Address: [Your Company Address]