Version 2026-05-08.2
Driver Transport App is a private job log for UK vehicle transport drivers. Everything you record — jobs, photos, scans, addresses, notes — is stored on this device. Data only leaves the device when you trigger a feature that needs it (a vehicle or MOT check, an address suggestion, an Apple subscription check, or a backup you have switched on). There is no account, no advertising, no analytics, no cross-app tracking.
The app is built and operated by an independent UK-based sole trader, referred to here as "we" or "the developer". We are the data controller for any personal data that leaves the device.
Contact: help@drivertransportapp.passpilot.uk
Stored in the app's private iOS sandbox, isolated from other apps:
Uninstalling the app removes everything above from this device.
When you scan a job sheet, registration plate, VIN or receipt with the camera, the photograph is processed entirely on this device using Apple's on-device text recognition. Neither the image nor the recognised text is transmitted anywhere by the app.
When you tap a voice button, iOS records audio and turns it into text using Apple's speech recognition. Whether this happens on-device or via Apple's servers is controlled by your iOS settings (Settings → General → Keyboard and Siri & Search → On-Device Dictation). The app does not transmit the audio itself and does not keep it once it has been transcribed.
Two features transmit small fragments of data to our server, which forwards each request to a single named provider for the purpose of fulfilling that request only:
Lookup queries are not associated with any account because the app has no account system. Our server logs only the request method, path and response status — never the registration, postcode or address text — and uses those logs solely for short-term debugging and rate-limiting. Lookup results are returned to your device and not stored on our server.
Pro Monthly and Pro Annual are sold by Apple under the standard in-app purchase rules. Card details are handled by Apple, never by us, and never reach our server.
To check whether a Pro entitlement is active, the app sends Apple's purchase receipt to RevenueCat (revenuecat.com), our subscription processor. RevenueCat receives the receipt and an anonymous app-installation identifier; no name, email, contacts, photos or device identifiers are sent. RevenueCat is a US-based company; transfers to RevenueCat are covered by the UK and EU Standard Contractual Clauses.
If you turn on backup to "App Cloud" in Settings, the app uploads a single backup blob containing your jobs, settings and presets. The blob is stored as one object in Cloudflare R2 (S3-compatible storage, UK / EU region), keyed by your device ID. Our PostgreSQL database, hosted on Replit infrastructure in the UK / EU, holds only metadata about that backup — the device ID, the SHA-256 hash of your secret, the size in bytes, the app version that created it and the timestamps. The blob's contents stay in R2.
Photos and receipt scans you attach to jobs are uploaded to App Cloud as separate per-photo objects shortly after you add or replace them. Each image is shrunk before upload while staying clearly legible (vehicle photos are re-encoded at up to 1600 pixels long-edge, JPEG quality 70%; receipts at up to 1200 pixels, quality 60%). We keep one row per photo in PostgreSQL containing the device ID, an opaque photo ID and the size in bytes — never the photo contents themselves. Total per-device photo storage is capped at 10 GB.
The first time you back up, your device is issued a random ID and a random secret. The secret is never sent in plain text — we store only its SHA-256 hash. Together they form the Restore Code shown in Settings. Anyone with the full Restore Code can pull your backup onto another device, so treat it like a password.
Only the most recent blob per device is kept; subsequent uploads overwrite the previous one. Photos are kept until you delete the photo (or the job containing it) in the app, or tap "Delete Cloud Backup" in Settings, which removes the blob, every per-photo object and all associated metadata rows immediately.
As an alternative destination, you can sign in with your Google account and store backups in your own Google Drive. The app requests only the "drive.appdata" scope, which restricts it to a hidden "appDataFolder" dedicated to this app. The app cannot read or write any of your other Drive files, and other apps cannot read this folder.
The same backup blob (jobs, settings, presets, photos) is uploaded to your appDataFolder. Google's privacy policy applies to anything stored in your Drive. Disconnecting from Settings revokes the token on this device; you can also revoke access from your Google Account security page at any time.
On launch, the app fetches a small remote configuration file from our server. The request includes your random device ID so we can target announcements, kill-switches or remote wipes. The response contains feature flags, announcement text, dynamic limits and similar settings. No personal data is sent in this request beyond the random device ID.
The data types we declare to Apple, all linked to your device and used solely for App Functionality, are:
We do not use any of this data for tracking as Apple defines it. We do not share it with data brokers, do not link it with third-party data for advertising and do not use it to advertise across apps or websites.
DVLA processes data in the United Kingdom. AWS Location Service requests are routed to AWS infrastructure in Europe. Postcodes.io operates in the UK. Our server runs on Replit infrastructure in the UK / EU and our PostgreSQL database lives on the same infrastructure. App Cloud backup blobs and per-photo objects are stored in Cloudflare R2 in the UK / EU. RevenueCat processes data in the United States under UK and EU Standard Contractual Clauses. Google Drive backups are stored in Google's own Drive infrastructure under your Google account. No other international transfers take place.
On this device: until you delete the item, clear the app's data, or uninstall.
On our server: only the most recent backup blob per device is kept, and is deleted when you tap "Delete Cloud Backup" or when the backup row is otherwise removed. Per-photo objects are deleted when you delete the photo (or the parent job) in the app, or when you wipe the cloud backup. Server access logs are retained for up to 30 days for debugging and abuse-prevention.
RevenueCat retains subscription records while your entitlement is active and for a reasonable period afterwards for accounting, fraud prevention and refund support. We do not control retention by DVLA, AWS, Postcodes.io or Google for the operations they perform; see their own policies.
Because almost everything sits on this device, you can exercise access, portability and erasure yourself: export jobs as PDF, delete jobs individually, switch off cloud backup, tap "Delete Cloud Backup" or uninstall.
For data we hold (your cloud backup blob and the associated photo objects, plus the subscription record held by RevenueCat on our behalf), email help@drivertransportapp.passpilot.uk and we will action your request without undue delay and within one calendar month. To raise a complaint with the UK regulator, contact the Information Commissioner's Office (ico.org.uk).
Each permission is requested only the first time you use the related feature, and any of them can be revoked from iPhone Settings.
The app is intended for professional adult drivers and is not directed at children under 13.
We may update this policy from time to time. Material changes update the version date at the top of this page and you will be asked to re-accept the policy inside the app before continuing to use it.
For privacy queries, data-subject requests or anything else covered by this policy, email help@drivertransportapp.passpilot.uk.