Driver Transport App Driver Transport App
Features Pricing Support Privacy Terms
Download
Legal

Privacy Policy

Version 2026-05-08.2

On this page

  1. In one paragraph
  2. Who we are
  3. What is on this device
  4. On-device scanning and dictation
  5. Vehicle and address lookups (Pro)
  6. Subscriptions and Apple receipts
  7. App Cloud backup (Pro, optional)
  8. Google Drive backup (Pro, optional)
  9. Remote configuration
  10. What we do NOT collect
  11. App Store privacy summary
  12. Lawful basis (UK and EU GDPR)
  13. Where data is processed
  14. Retention
  15. Your rights
  16. Permissions on this device
  17. Children
  18. Changes to this policy
  19. Contact

In one paragraph

Driver Transport App is a private job log for UK vehicle transport drivers. Everything you record — jobs, photos, scans, addresses, notes — is stored on this device. Data only leaves the device when you trigger a feature that needs it (a vehicle or MOT check, an address suggestion, an Apple subscription check, or a backup you have switched on). There is no account, no advertising, no analytics, no cross-app tracking.

Who we are

The app is built and operated by an independent UK-based sole trader, referred to here as "we" or "the developer". We are the data controller for any personal data that leaves the device.

Contact: help@drivertransportapp.passpilot.uk

What is on this device

Stored in the app's private iOS sandbox, isolated from other apps:

  • Jobs you create: job number, customer name, coordinator name, registration, VIN, make, model, collection and delivery addresses, notes, photos and receipts.
  • Travel legs and any costs you record against them.
  • Saved authorisation-code prefixes, customer presets, leg cost presets, job templates, recent addresses, saved locations and your appearance preference.
  • The version of these documents you have accepted.
  • For Pro users with cloud backup turned on: a per-device backup ID and the SHA-256 hash of a per-device secret used to authenticate uploads.

Uninstalling the app removes everything above from this device.

On-device scanning and dictation

When you scan a job sheet, registration plate, VIN or receipt with the camera, the photograph is processed entirely on this device using Apple's on-device text recognition. Neither the image nor the recognised text is transmitted anywhere by the app.

When you tap a voice button, iOS records audio and turns it into text using Apple's speech recognition. Whether this happens on-device or via Apple's servers is controlled by your iOS settings (Settings → General → Keyboard and Siri & Search → On-Device Dictation). The app does not transmit the audio itself and does not keep it once it has been transcribed.

Vehicle and address lookups (Pro)

Two features transmit small fragments of data to our server, which forwards each request to a single named provider for the purpose of fulfilling that request only:

  • "Check Vehicle & MOT" sends the registration you typed to the DVLA Vehicle Enquiry Service to fetch make, model, MOT and tax status.
  • Address autocomplete and postcode lookup send the characters or postcode you typed to AWS Location Service (and, for postcodes, to the public Postcodes.io service) to return suggestions.

Lookup queries are not associated with any account because the app has no account system. Our server logs only the request method, path and response status — never the registration, postcode or address text — and uses those logs solely for short-term debugging and rate-limiting. Lookup results are returned to your device and not stored on our server.

Subscriptions and Apple receipts

Pro Monthly and Pro Annual are sold by Apple under the standard in-app purchase rules. Card details are handled by Apple, never by us, and never reach our server.

To check whether a Pro entitlement is active, the app sends Apple's purchase receipt to RevenueCat (revenuecat.com), our subscription processor. RevenueCat receives the receipt and an anonymous app-installation identifier; no name, email, contacts, photos or device identifiers are sent. RevenueCat is a US-based company; transfers to RevenueCat are covered by the UK and EU Standard Contractual Clauses.

App Cloud backup (Pro, optional)

If you turn on backup to "App Cloud" in Settings, the app uploads a single backup blob containing your jobs, settings and presets. The blob is stored as one object in Cloudflare R2 (S3-compatible storage, UK / EU region), keyed by your device ID. Our PostgreSQL database, hosted on Replit infrastructure in the UK / EU, holds only metadata about that backup — the device ID, the SHA-256 hash of your secret, the size in bytes, the app version that created it and the timestamps. The blob's contents stay in R2.

Photos and receipt scans you attach to jobs are uploaded to App Cloud as separate per-photo objects shortly after you add or replace them. Each image is shrunk before upload while staying clearly legible (vehicle photos are re-encoded at up to 1600 pixels long-edge, JPEG quality 70%; receipts at up to 1200 pixels, quality 60%). We keep one row per photo in PostgreSQL containing the device ID, an opaque photo ID and the size in bytes — never the photo contents themselves. Total per-device photo storage is capped at 10 GB.

The first time you back up, your device is issued a random ID and a random secret. The secret is never sent in plain text — we store only its SHA-256 hash. Together they form the Restore Code shown in Settings. Anyone with the full Restore Code can pull your backup onto another device, so treat it like a password.

Only the most recent blob per device is kept; subsequent uploads overwrite the previous one. Photos are kept until you delete the photo (or the job containing it) in the app, or tap "Delete Cloud Backup" in Settings, which removes the blob, every per-photo object and all associated metadata rows immediately.

Google Drive backup (Pro, optional)

As an alternative destination, you can sign in with your Google account and store backups in your own Google Drive. The app requests only the "drive.appdata" scope, which restricts it to a hidden "appDataFolder" dedicated to this app. The app cannot read or write any of your other Drive files, and other apps cannot read this folder.

The same backup blob (jobs, settings, presets, photos) is uploaded to your appDataFolder. Google's privacy policy applies to anything stored in your Drive. Disconnecting from Settings revokes the token on this device; you can also revoke access from your Google Account security page at any time.

Remote configuration

On launch, the app fetches a small remote configuration file from our server. The request includes your random device ID so we can target announcements, kill-switches or remote wipes. The response contains feature flags, announcement text, dynamic limits and similar settings. No personal data is sent in this request beyond the random device ID.

What we do NOT collect

  • No advertising identifier (IDFA) is requested.
  • No third-party analytics, advertising or attribution SDKs are bundled.
  • No crash-reporting SDK is bundled.
  • No device fingerprinting takes place.
  • No precise or coarse location is collected. The app does not request "Always Allow" location and does not track you in the background.
  • No contacts, calendar, health, financial, browsing or search-history data is collected.

App Store privacy summary

The data types we declare to Apple, all linked to your device and used solely for App Functionality, are:

  • Contact Info — name and physical address you enter into jobs (only if you turn on cloud backup).
  • User Content — job photos, receipts and notes (only if you turn on cloud backup).
  • Identifiers — your random device ID and the anonymous RevenueCat App User ID.
  • Purchases — your Pro subscription state via RevenueCat.

We do not use any of this data for tracking as Apple defines it. We do not share it with data brokers, do not link it with third-party data for advertising and do not use it to advertise across apps or websites.

Lawful basis (UK and EU GDPR)

  • Local storage of your job data — necessary to perform the contract for the app you bought.
  • Subscription processing (Apple, RevenueCat) — necessary to perform the Pro subscription contract while it is active.
  • Cloud backup (App Cloud or Google Drive) — your consent, given by switching the feature on. You may withdraw it at any time by setting the destination back to "Off".
  • DVLA, AWS and Postcodes.io lookups — your consent, given by tapping the lookup button. Withdraw by not using the feature.
  • Remote configuration — legitimate interest in keeping the app safe, current and operable.

Where data is processed

DVLA processes data in the United Kingdom. AWS Location Service requests are routed to AWS infrastructure in Europe. Postcodes.io operates in the UK. Our server runs on Replit infrastructure in the UK / EU and our PostgreSQL database lives on the same infrastructure. App Cloud backup blobs and per-photo objects are stored in Cloudflare R2 in the UK / EU. RevenueCat processes data in the United States under UK and EU Standard Contractual Clauses. Google Drive backups are stored in Google's own Drive infrastructure under your Google account. No other international transfers take place.

Retention

On this device: until you delete the item, clear the app's data, or uninstall.

On our server: only the most recent backup blob per device is kept, and is deleted when you tap "Delete Cloud Backup" or when the backup row is otherwise removed. Per-photo objects are deleted when you delete the photo (or the parent job) in the app, or when you wipe the cloud backup. Server access logs are retained for up to 30 days for debugging and abuse-prevention.

RevenueCat retains subscription records while your entitlement is active and for a reasonable period afterwards for accounting, fraud prevention and refund support. We do not control retention by DVLA, AWS, Postcodes.io or Google for the operations they perform; see their own policies.

Your rights

Because almost everything sits on this device, you can exercise access, portability and erasure yourself: export jobs as PDF, delete jobs individually, switch off cloud backup, tap "Delete Cloud Backup" or uninstall.

For data we hold (your cloud backup blob and the associated photo objects, plus the subscription record held by RevenueCat on our behalf), email help@drivertransportapp.passpilot.uk and we will action your request without undue delay and within one calendar month. To raise a complaint with the UK regulator, contact the Information Commissioner's Office (ico.org.uk).

Permissions on this device

  • Camera — vehicle photos, receipt photos and on-device scanning of job sheets, reg plates and VINs.
  • Photo Library — attaching existing photos to a job.
  • Microphone and Speech Recognition — voice notes and voice-to-text input.
  • Network — lookups, backups and subscription checks you initiate.

Each permission is requested only the first time you use the related feature, and any of them can be revoked from iPhone Settings.

Children

The app is intended for professional adult drivers and is not directed at children under 13.

Changes to this policy

We may update this policy from time to time. Material changes update the version date at the top of this page and you will be asked to re-accept the policy inside the app before continuing to use it.

Contact

For privacy queries, data-subject requests or anything else covered by this policy, email help@drivertransportapp.passpilot.uk.

Driver Transport App

An offline-first job log for UK vehicle transport drivers. Made in the UK by an independent developer.

Product

  • Features
  • How it works
  • Pricing
  • FAQ

Help & Legal

  • Support
  • Privacy Policy
  • Terms & Conditions
© Driver Transport App. All rights reserved. Made for trade drivers in the UK.