Privacy Policy
Last updated: 16 September 2026
This policy explains how RideLoop collects and uses personal data, in line with UK GDPR and the Data Protection Act 2018. It covers our own role as a business (your account data as an Operator, and technical processing of Guest data) — for what a Guest’s own booking terms cover, see the terms shown on that Operator’s own storefront, not this page.
1. Who we are
RideLoop is the data controller for account and platform-usage data belonging to Operators. For bookings made through an Operator’s storefront, RideLoop processes Guest data as a data processor on the Operator’s behalf — the Operator is the data controller for their own customers’ booking details.
2. What we collect
- Account details: name, email, phone, and organisation details for Operators.
- Booking details: name, email, phone, and message content submitted by Guests when making an enquiry or booking.
- Payment data: handled directly by Stripe — RideLoop does not store card numbers or bank details.
- Usage data: pages visited and actions taken across our marketing site, operator portal, and platform admin, collected via PostHog (including an anonymised session replay) — see our Cookie Policy for detail.
- AI assistant conversations: if you use an AI assistant we provide (operator-facing, or a guest-facing one an Operator has enabled), the underlying AI model is called with zero data retention at the model-provider level, and we don’t store the conversation content ourselves unless it’s handed off to a person — in which case it’s kept like any other support conversation (see retention below).
3. How we use it
To operate accounts and subscriptions, process bookings and payments, send transactional emails (booking confirmations, status updates), provide customer support, and meet legal obligations. We do not sell personal data.
4. Who we share it with
Stripe (payments), Resend (transactional email), Clerk (authentication), PostHog (analytics and session replay), and our hosting and database providers — each acting under their own data processing agreements. Guest booking details are shared with the relevant Operator so they can fulfil the booking.
5. Data retention
Booking and financial records are retained indefinitely, to meet UK tax and accounting record-keeping obligations — we do not auto-delete these.
- Guest support chat conversations are automatically deleted (including their message content) after 24 months with no new message.
- Internal account-activity logs are automatically deleted after 24 months.
- Guest personal details (name and phone number) on a booking, quote, or chat thread with no new activity for 12 months are automatically anonymised — the underlying booking record itself is kept (see above), only the identifying display fields are removed.
This is enforced automatically by a scheduled process, not left to a manual review — see our contact page if you have questions about how this applies to your data.
6. Your rights
Under UK GDPR you have the right to access, correct, delete, or export your personal data, and to object to certain processing. Contact us via our contact page to exercise these rights.
7. Cookies
See our Cookie Policy for details on the cookies we use.
8. Changes to this policy
We may change this policy at any time, without prior notice, by publishing the updated version at this address.
This page is a template and has not yet been reviewed by a solicitor — treat it as a starting point, not final legal advice.