Privacy Policy

This policy explains how DriverSheet handles personal data across the DriverSheet Driver and DriverSheet Manager apps and the DriverSheet web service.

Effective date: 15 July 2026 · Last updated: 15 July 2026

1. Who we are

DriverSheet is a UK-based delivery workforce management platform. It helps delivery businesses manage drivers, operational IDs, routes and route assignments, daily delivery reports, rates, earnings and invoices. This policy covers the DriverSheet Manager app (com.driversheet.manager), the DriverSheet Driver app (com.driversheet.driver) and the DriverSheet web application.

The data controller responsible for your personal data is CHIQUESI CREATIVE STUDIO LTD, a private limited company registered in England and Wales under company number 17196117, trading as DriverSheet, with its registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

If you have any questions about this policy or your personal data, contact us at contact@driversheet.com.

2. Who this policy applies to

DriverSheet is used by two main groups of people, and this policy applies to both:

  • Managers — people who run a delivery business account, manage drivers, routes, reports, rates and invoices (typically using DriverSheet Manager or the web app).
  • Drivers — people who submit their daily delivery reports and view their own summaries and history (typically using DriverSheet Driver or the web app).

3. Information we collect

We only collect information that is needed to operate the service. The categories below reflect what the apps actually collect and store.

Account and authentication information

Authentication is provided by Supabase Auth. Depending on how your account signs in, this may include:

  • an email address and password (used mainly by managers) — passwords are stored in hashed form by Supabase and are never visible to us;
  • a driver access code (used by drivers to sign in), and, where a business has enabled it, a mobile phone number used for one-time-passcode (OTP) sign-in;
  • a Supabase user identifier and the session tokens that keep you signed in.

Company, manager and driver profile data

  • Company / manager: company name, and invoice settings such as the invoice company name, billing address, city, postcode, contact email(s) and phone number(s), invoice notes and uploaded company logos.
  • Driver: name, an internal driver ID code, mobile phone number, preferred language, working days, default van / drop / round / region, driver type, and free-text payment details (for example a sort code and account number) that the business enters so drivers can be paid.

Operational IDs, routes and route assignments

To model how work is organised, we store operational IDs, route definitions and route assignments (including cover and temporary work), together with the daily counts linked to them.

Delivery reports and report items

When a driver submits a report we store the report date, delivery and collection counts (successful deliveries, carry-forwards, cannot-deliver, successful collections, collection carry-forwards, cannot-collect), the report status, a snapshot of the applicable route/region, the pay rate applied and the resulting estimated earnings.

Uploaded screenshots and documents

Drivers upload screenshots of their delivery day summary. These images are stored securely in a private storage bucket (report-screenshots). Managers may upload company logos, which are stored in a separate private bucket (company-logos).

Data extracted through OpenAI Vision

To save drivers from typing figures manually, an uploaded day-summary screenshot is sent to OpenAI's vision model, which reads only the numeric delivery/collection figures and a confidence score. The extracted numbers are stored with the report. See section 5 for more detail on this processing.

Invoices, rates and earnings

We store the rates configured for drivers and routes, the earnings calculated from submitted reports, and the invoices, adjustments and financial records generated from that data.

Device, diagnostic and usage data

Both Android apps are secure wrappers around the DriverSheet web app. In relation to your device we only:

  • store small items in your browser/app local storage — your theme preference, language, which app you are using, and your sign-in session;
  • generate standard server logs when the app talks to our servers (for example IP address, date and time, and browser/app user-agent), which our hosting and infrastructure providers process to run and secure the service.

Both Android apps declare only the INTERNET permission; they do not declare or request access to precise location, contacts, the microphone or other device sensors. The current builds contain no third-party analytics, advertising, crash-reporting or diagnostic SDKs, and no advertising identifier is collected. Screenshots are chosen through your device's standard file/photo picker.

4. Purposes and lawful bases for processing

Under UK GDPR we rely on the following lawful bases:

  • Performance of a contract — to create and run accounts and authenticate users (whether by access code, email and password, or, where a business has enabled it, a one-time passcode sent to a mobile number), to record delivery reports, calculate earnings and produce invoices for the business using DriverSheet.
  • Legitimate interests — to operate, secure, maintain and improve the service, prevent fraud and misuse, and provide support. Where we rely on legitimate interests we have balanced them against your rights.
  • Legal obligation — to keep accounting, tax and business records that we are required by law to retain.

Controller and processor roles. The delivery business that uses DriverSheet to manage its workforce is normally the data controller for its drivers' work data (such as reports, routes, rates and payment details it enters), and DriverSheet acts as that business's processor for that data. DriverSheet is the data controller for its own account, authentication, billing, support and security operations.

5. AI processing of screenshots

Delivery day-summary screenshots are sent to the OpenAI API solely to extract the numeric figures on them. We send the image and a fixed instruction prompt; OpenAI returns only the numbers and a confidence score, which we store with the report. We do not use this feature to make automated decisions that produce legal or similarly significant effects about you — a person reviews reports, and figures can be corrected manually.

Data sent through the OpenAI API is not used by OpenAI to train its models. Under OpenAI's API data-usage terms, API inputs and outputs may be retained by OpenAI for a limited period (up to 30 days) to monitor for abuse and misuse, after which they are deleted, unless a zero-data-retention arrangement applies to our account. We do not claim zero retention.

6. Service providers and data processors

We share personal data with a small number of trusted providers who process it on our behalf, under contract and only for the purposes below:

  • Supabase — authentication, PostgreSQL database and file storage (screenshots and logos).
  • OpenAI — reading the numeric figures from uploaded day-summary screenshots (section 5).
  • Resend — delivering transactional emails such as invoices and missing-report reminders.
  • Vercel — hosting the application and serving it over its content-delivery network.

7. Whether information is shared more widely

We do not sell your personal data and we do not share it for advertising. Beyond the processors listed above, we only disclose personal data where we are required to do so by law, to establish or defend legal claims, or to protect the rights, safety and security of our users and the service. If DriverSheet is ever involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction, and we will notify affected users.

8. International data transfers

Some of our providers (for example OpenAI) are based outside the United Kingdom. Where personal data is transferred outside the UK, we rely on appropriate safeguards recognised under UK GDPR — such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or transfers to countries covered by UK adequacy regulations.

9. Data retention

We keep personal data only for as long as it is needed for the purposes described in this policy:

  • Account, profile, report, route, rate and earnings data is retained while the account is active and the business needs it to operate.
  • Uploaded screenshots and logos are retained with the related report or company record while the account is active, and are removed when that record is deleted.
  • Server and diagnostic logs generated by our hosting and infrastructure providers are retained for a limited period and then deleted or overwritten.
  • Backups are held on a short rolling cycle by our infrastructure providers. Data deleted from the active service is removed from production systems as part of the deletion process and ages out of backups within the normal backup cycle.
  • Support records (for example emails you send us) are kept for as long as needed to handle your request and for a reasonable period afterwards.
  • Invoices and related financial documents are retained for as long as required to meet UK accounting and tax obligations (generally at least six years).
  • When you close your account or request deletion, we delete or anonymise your personal data within 30 days of verifying the request, except for information we must retain for the legal, fraud-prevention, accounting or contractual reasons described on our delete-account page.

10. Security

We take appropriate technical and organisational measures to protect personal data. Data is transmitted over encrypted HTTPS connections; screenshots and logos are held in private storage buckets that are not publicly listable; database access is governed by row-level security so users can only reach data they are authorised to see; and passwords are stored only in hashed form by our authentication provider. No system can be guaranteed completely secure, but we work to protect your information and to respond quickly to any issues.

11. Your rights under UK GDPR

Subject to certain conditions, you have the right to:

  • access the personal data we hold about you;
  • ask us to correct inaccurate or incomplete data;
  • ask us to delete your data (see our delete-account page);
  • restrict or object to certain processing;
  • request a copy of certain data in a portable format.

To exercise any of these rights, contact us at contact@driversheet.com. If you are a driver managed by a business on DriverSheet, you may also need to contact that business directly. You have the right to complain to the ICO (ico.org.uk) if you are unhappy with how we handle your data, though we would appreciate the chance to help first.

12. Account and data deletion

You can ask us to delete your account and associated personal data at any time. The process, what is deleted, and what we may need to retain, are explained on our Delete Account page.

13. Children's privacy

DriverSheet is an authorised workforce and business management tool for delivery businesses and their adult workers. It is not designed, intended or marketed for children, is not a consumer product aimed at minors, and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us so that we can investigate and take appropriate action, including deletion where required.

14. Changes to this policy

We may update this policy from time to time. When we do, we will change the "last updated" date above and, where changes are significant, take reasonable steps to notify affected users. Continued use of the service after an update means you accept the revised policy.

15. Contact us

For any privacy question or request, contact us at contact@driversheet.com, or write to us at CHIQUESI CREATIVE STUDIO LTD, 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.