Privacy Policy
Last updated: 1 October 2026
1. Who we are
Vanround is a multi-drop courier app for courier businesses. It is operated by Glebefish Limited, a company registered in England and Wales (company number 14038854), whose registered office is at 1 Johns Road, Woolston, Southampton, SO19 9BW ("we", "us").
For privacy questions, or to exercise any of the rights in section 8, contact us at hello@vanround.com.
2. Two different kinds of people, and who is responsible for their data
This distinction matters, because Vanround holds personal data about people who never use the app.
Vanround users โ the courier firm owners, admins and drivers who sign in and use the app. For their account data, we are the data controller.
Customers of those courier firms โ the people receiving a delivery, whose name, address, phone number, email and signature a courier firm records against a drop. These people do not have Vanround accounts and typically never interact with us. For their data, the courier firm using Vanround is the data controller and we act as a data processor on that firm's instructions.
In practice: if you are a customer of a courier firm that uses Vanround and you want your data corrected or deleted, please contact that firm directly โ they control it. We will assist them, but we cannot act on their data without their instruction.
3. What we collect
From people who use the app
| Data | Why |
|---|---|
| Email address | Sign-in credential and account identifier |
| Password | Authentication. Handled entirely by Google Firebase Authentication; we never see or store it |
| Name | Shown to colleagues so drops and messages are attributable |
| Phone number (optional) | So colleagues can reach you about a drop |
| Your role, and which company you belong to | Controls what you are allowed to see and do |
| Notification token | To deliver push notifications about your round. Tied to your device |
| Which of the company's vehicles you are assigned to, and any odometer reading you enter, only where your employer keeps its vehicles in the app | So the office knows who drives which vehicle and when it is due its MOT, tax, insurance or service. A reading is only ever one you type in yourself |
| Where your phone was at the moment you tapped a stage — only where your employer has turned this on | So the office can see that a drop stage was recorded at the drop address. One reading, taken at the instant you press the button, and nothing in between. The app tells you before this is ever switched on for you. See section 4 for exactly what it does not do |
About the courier firm's customers, entered by its staff
| Data | Why |
|---|---|
| Customer name, phone, email | Identifying and contacting the customer about the drop |
| Drop address, and its map coordinates | Locating the drop and sequencing the round |
| Signature, and the name of the person signing | Proof of delivery โ evidence the drop was completed |
| Drop details, notes and photographs | The record of the delivery itself |
| A record of each drop email sent to them, and what became of it | Only where the courier firm has turned drop emails on. We keep the address it went to, when, and whether it arrived, bounced or was reported as spam — bounces and spam reports are what get a sending address blocked, and they arrive silently |
| The fact that they asked us to stop emailing them | Kept so that we do not email them again. It is the record that makes an unsubscribe stick |
| What they were quoted and charged, and the billing name and address on the invoice | Quoting the work and invoicing for it. An issued invoice also records the VAT position — whether VAT was charged, at what rate, and where the domestic reverse charge applies, the amount the customer must account for to HMRC themselves. See section 7: an issued invoice is a VAT record and is kept for six years, including where a deletion is requested |
Photographs are taken by drivers to document a delivery. They may incidentally show the outside of a customer's property.
Collected automatically
| Data | Why |
|---|---|
| Crash reports โ error details, device model, operating system version | Diagnosing crashes. Provided by Google Firebase Crashlytics |
| Usage data โ which screens are opened, and actions such as creating a drop or completing a proof of delivery | Understanding which parts of the app are used, and where people get stuck. Provided by Google Analytics for Firebase |
| An app instance identifier | Used by the above to group events from the same installation. Reset if you reinstall the app |
| Your user ID, attached to the above | So we can diagnose a fault affecting a specific user who reports one |
Crash and usage reporting is on by default.
4. What we deliberately do not collect
- We do not track your location, and the difference from what we do collect matters. Where your employer has turned it on, the app records where your phone was at the single moment you tap a stage or take the delivery photo — and that is all. It does not follow you. It reads nothing while the app is closed or in your pocket, nothing between one tap and the next, nothing on your way to or from work, and nothing at all on a day you tap nothing. There is no trail, because there is nothing to join up: a drop with four stages has at most four readings on it, each one taken at a moment you chose by pressing a button. The reading at the delivery photo is used to remember where the door is, so the next driver to that address is taken to the door rather than the road. It is saved against the customer's address without your name or the time. The app has no background location permission and no always-on location service — not as a setting we have switched off, but because it does not ask the operating system for either. If your employer has not turned this on, or you have not granted location permission, the app records no position of yours at any time. The other use of the permission is unchanged: to place a drop on a map, the drop address is sent to Google to be converted into coordinates and to draw the map, or to Apple on an iPhone. Both do this as independent controllers under their own terms; see section 6. That is the address someone typed, not anyone's location. And when a worker taps “Open in Maps”, the drop address is handed to whichever navigation app they pick — Google Maps, Waze or Apple Maps. That app is then working for them, not for us, and what it does with the address is covered by its own terms rather than by this policy. Nothing else about the drop goes with it.
- We do not use your data for advertising, and we do not sell it.
- Apart from the map, address and card payment services named in section 6, we do not share your data with third parties for their own purposes. Google Analytics offers a setting that would let Google use the data we collect to improve its own products; we have turned it off, so Google handles that data only on our instructions. See section 6.
5. Legal basis for using this data (UK GDPR)
- Performance of a contract โ providing the app to courier firms that have signed up for it, and to their staff.
- Legitimate interests โ keeping the app secure, diagnosing crashes, and understanding usage to improve it. We have considered the impact on you and believe these uses are ones you would reasonably expect. Analytics data is not used to make decisions about individuals.
Where we act as a processor (see section 2), the courier firm is responsible for establishing its own legal basis for holding its customers' data.
6. Who your data is shared with
Vanround is built on Google Firebase, and Google acts as our sub-processor for authentication, database storage, file storage, push notifications, crash reporting and analytics. Google's handling of that data is governed by its own terms.
Data is stored in Google's London (europe-west2) region. Some Google services โ including crash reporting and analytics โ may process data outside the UK. Where that happens, it is covered by Google's data transfer safeguards.
Google Analytics data sharing is turned off. Analytics offers a setting that lets Google use the data to improve its own products; enabling it would make Google an independent user of that data rather than a service acting on our instructions. We have disabled it, along with the options that contribute to industry benchmarks and that give Google's sales staff access. The one option we have left on lets Google's technical support staff look at the data when diagnosing a fault.
We also use Resend as a sub-processor to send email on our behalf. It is used only to send email and for no other purpose. Messages are sent from Ireland; Resend's own infrastructure is in the United States, covered by standard contractual clauses and the UK Addendum. There are two kinds of message:
- Invitations. When a courier firm invites someone to join it on Vanround, we pass that person's email address and the name of the person inviting them, so the invitation can be delivered.
- Drop updates to a courier firm's own customers — only if that courier firm turns them on. This is off unless a courier firm chooses to switch it on, and it can be sent either from our own address on their behalf or, if they have connected their Microsoft or Google account to us, from their own mailbox. Where it is on, we pass that customer's name and email address, and what the message says about their drop — its title, its reference, the address and, when it is complete, who signed for it. Every one of those emails carries a link the customer can use to stop them.
This changed on 6 September 2026. Until then this section said no drop or customer data was sent to Resend, which was true of the service as it stood. It is written this way before the feature can be used rather than after, so this page is never describing something narrower than what the software can do.
Our map server — added 17 September 2026, before the feature reaches anyone. Working out the real driving distance of a drop runs on a machine we rent from Hetzner Online GmbH and run ourselves. It is sent map coordinates and nothing else: the stops on a drop or a round, and, for a firm that keeps its vans in the app, the firm's own address as the start and end of each van's day. No name, no address in words, no phone number, no email address. The map it reads is open data held on that same machine. It is in Germany, so the data stays in the EU and no transfer safeguards are needed.
Drive times in traffic, added 28 September 2026. When a drop is raised on the office dashboard, how long it will take to drive in the usual traffic for the day and time it leaves is worked out by HERE Europe B.V., in the Netherlands. It is sent map coordinates and the day and time the drop leaves, nothing else: no name, no address in words, no phone number, no email address. The drive time that comes back is deleted from the drop after 30 days. HERE's terms let it use anonymised, aggregated learnings from these requests to improve its own products; we have asked HERE to switch that off for our account. Its terms do not say which country a request is processed in, and we have asked.
Maps and addresses, corrected 30 September 2026. Turning a typed drop address into coordinates, and drawing a map, is done by Google's Maps service on the office dashboard and on Android phones, and by Apple's on an iPhone. Each is sent the address typed and nothing else about the drop; drawing a map also shows them the device's IP address and the area on screen. Google and Apple do this as independent controllers, under their own terms, rather than on our instructions. The maps on the office dashboard are drawn from the OpenStreetMap Foundation's tile servers, which see the office computer's IP address and the area on screen, under the Foundation's own privacy policy. Until 30 September this section did not name Apple or OpenStreetMap, or say that Google does this as a controller.
Address lookup. When a postcode is typed and an address picked from the list that comes back, that postcode is sent to Ideal Postcodes, in the United Kingdom, which returns every address at it. The postcode on its own is all they get — nothing about the customer, the drop or who was asking.
Card payments, added 29 September 2026, before they are switched on. When a customer pays an invoice by card, the payment is taken by Stripe Payments UK Limited into the courier firm's own Stripe account. Stripe is sent the invoice amount and reference, the courier firm's name and the customer's email address. The customer types their card details into Stripe's own page, so they never pass through us. Stripe takes the payment under the courier firm's own agreement with Stripe, which it accepts when it connects its account. Stripe is also an independent controller for its own purposes: fraud checks, identity and money-laundering checks, choosing the banks and card networks a payment goes through, and improving its own products. Corrected 30 September 2026: this said Stripe was an independent controller for the card details, which is only true for those purposes. It processes in the UK, the EU and the United States, under the EU Standard Contractual Clauses and the UK Addendum. Nobody can pay by card yet.
Load exchanges, added 30 September 2026. A courier firm can connect its own Courier Exchange or SDCN membership. The exchange then works for the courier firm, under the membership and terms it already has, not for us. We hold the login it gives us, encrypted, and use it only when one of its admins asks to see its own loads and the quotes on them. What comes back is shown to that admin and not kept. Nothing is sent to an exchange except that login and the dates asked for. Disconnecting it deletes the login at our end.
Two further services support the app. Neither is sent a customer's name or contact details:
- Expo builds the app and delivers updates to it. When your phone checks whether a newer version exists, Expo sees its IP address and the app version. Expo's terms let it use aggregated, anonymised data to improve its own products.
- Cloudflare hosts our website and the dashboard, and forwards email sent to our contact address, so anything you email us passes through it. It also carries the requests to our map server described above, which hold map coordinates and nothing else.
Mistral AI, in use from 1 October 2026. Mistral AI, in Paris, is on our sub-processor list for two features. The first is importing an existing customer list from a spreadsheet, where the column headings and a sample of up to twenty rows are sent so the layout can be worked out. The second is reading a PDF booking confirmation you upload, where the whole document is sent so the customer and addresses can be picked out for you to check; it is off for your firm until one of your admins turns it on in Settings, and nothing is created from it until you have checked what was found. What we send is not kept. Mistral has agreed with us that it is not stored or logged for any longer than it takes to produce the answer. It is processed in the EU, and Mistral’s terms with us say it may not train its models on it. It was listed here, and you were told by email, before it was switched on. Nothing else in Vanround sends data to an AI or machine learning service.
Anthropic, until 1 October 2026. These two features were set up to use Anthropic Ireland, Limited from 3 September 2026. No customer data was ever sent to it, and it is no longer on our list.
A complete and current list, including what each service handles and where, is published at vanround.com/subprocessors.
We do not share your data with anyone else, except where we are legally required to.
7. How long we keep it
- Drop records are kept for as long as the courier firm's account is active, because they are that firm's working records. The firm decides when to delete them.
- Photographs and the signature image from a proof of delivery are deleted automatically 12 months after the drop they belong to is finished (delivered or cancelled). This runs on a schedule, whether or not the firm asks. The rest of a sign-off record โ who signed, when, and whether a photo was taken โ is kept with the job, because that is the audit trail a firm needs to answer a dispute, and none of it is an image.
- Account details are kept while the account is active.
- Invitations expire automatically after 7 days.
- A record that somebody asked us to stop emailing them is kept indefinitely, on purpose. Deleting it is how an unsubscribe gets undone by accident. It is the address and the date, and nothing else.
- An issued invoice is kept for six years from the date it was issued, and a deletion request does not reach it. That is not our choice: HMRC requires VAT records to be kept for six years, and the UK GDPR right to erasure does not apply where the law requires the information to be held (Article 17(3)(b)). It is the invoice as it was sent — the billing name and address, the lines, the figures and the VAT. Added 7 September 2026, when invoicing was built. Everything else about the money goes: an unissued draft invoice is deleted, the link a customer was sent to view an invoice is deleted — which also stops that link working — and what a job was priced or quoted at is deleted with the job. Where a business closes its account entirely, all of it goes including the issued invoices, and it is that business's own responsibility to export its records first.
- The log of drop emails sent — address, time and delivery outcome — is deleted automatically after 90 days, and sooner if that customer or the whole company is deleted. Ninety days is what the log is for: catching bounces and spam complaints, which is a question about now rather than a history worth keeping. Added 6 September 2026 — it had no expiry at all until then, which was said here before it was fixed rather than after.
- The position recorded when you tap a stage is kept with the drop it belongs to, and is deleted when that drop is. It is not held anywhere else and there is no separate log of it. We keep it with the drop rather than expiring it sooner because it only means anything next to the stage it corroborates — a question about when a vehicle arrived somewhere is usually asked weeks later, and a stage time whose corroboration has been deleted underneath it is worse than one that never had any. The trade business decides when to delete its drop records, and deleting the drop deletes this with it.
- A door position saved from a delivery photo is kept with the customer's address, without anyone's name or the time, until the customer is deleted or the office clears it.
- Crash and usage data is retained according to Google Firebase's own retention settings.
- Data waiting to be sent, held on the driver's phone. The app is built to work without a signal, so a photograph or a customer's signature captured on the round is stored on that device until it can be uploaded. It is deleted from the device as soon as it reaches our servers. If it repeatedly cannot be sent, it is deliberately kept on the device rather than discarded โ a customer's signature is the record that a drop was delivered, and losing it would be worse than holding it โ and the app shows the driver that it is still waiting. It is removed if the app is uninstalled.
8. Your rights
Under UK data protection law you have the right to: access a copy of your data; have inaccurate data corrected; have your data deleted; restrict or object to how we use it; and receive your data in a portable format.
One thing the right to deletion does not reach, and we would rather say so here than when you ask. An invoice that has been issued to you is a VAT record and the law requires it to be kept for six years — see section 7 for what that covers and what is deleted alongside it. Nothing else about the money survives a deletion request.
To exercise any of these, contact hello@vanround.com. We will respond within one month.
If you are a customer of a courier firm that uses Vanround, please contact that firm โ see section 2.
You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk.
9. Security
Access is controlled by server-enforced security rules, so a courier firm's data can only be read by members of that firm. Passwords are handled by Google Firebase Authentication and are never visible to us. Data is encrypted in transit and at rest by Google. Changes to user roles and permissions are recorded in an audit log.
No system is completely secure, and we cannot guarantee absolute security.
10. Children
Vanround is a tool for businesses and is not intended for anyone under 18. We do not knowingly collect data from children.
11. Changes to this policy
If we make significant changes we will update the date at the top and, where the change materially affects you, notify you in the app.