Privacy Policy
Last updated: 12 August 2026
This Privacy Policy explains how DeliverySigner ("we", "us", "our") collects, uses, shares and protects personal data when you use our digital proof of delivery and container operations platform (the "Service"). It applies to administrators, drivers, invited users and any individual whose personal data is processed through the Service.
1. Who we are and how to contact us
DeliverySigner is a trading name of Patience and Fortitude Ltd (registered in England and Wales, company no. 14551744), 20-22 Wenlock Road, London, N1 7GU, England. We are the data controller of personal data processed through the Service. To contact us about your personal data, email hello@deliverysigner.app.
We are established in the United Kingdom and our lead supervisory authority is the Information Commissioner's Office (ICO). Because we provide the Service to customers located in the European Economic Area, we comply with both the UK GDPR (as it forms part of UK law) and the EU GDPR. For data subjects in the EU, the protections of the EU GDPR apply, and the relevant EU supervisory authority may be contacted in addition to, or instead of, the ICO. Our EU representative for GDPR matters can be contacted at hello@deliverysigner.app.
2. Personal data we collect
- Account and profile data: your name, email address, phone number, role (admin or driver), and the company you belong to.
- Company (tenant) data: company name, logo, admin and warehouse email addresses, and the operational settings you configure.
- Delivery and operational data: delivery reference numbers, container and seal numbers, pickup and delivery addresses, customer names and contact details, booking times, driver instructions and on-site guidance, signatures, photographs, and arrival, delivery and departure timestamps.
- Communications data: the content and attachments of emails you forward to your unique DeliverySigner inbox or to our help address (for example job orders, dock or booking reports, and supplier invoices), and SMS or WhatsApp messages sent through the Service.
- Technical data: device type, browser, IP address (via our hosting provider), usage logs, and preferences stored locally on your device such as display and font settings.
- Billing data: handled by our payment provider, Stripe. We retain transaction references and a billing email address; we do not store full card numbers.
3. How and why we use your data
We process personal data under the following lawful bases (UK GDPR):
- Performance of a contract with you: to run the proof-of-delivery workflow, capture signatures, send notifications, match invoices, export documents and provide the Service you signed up for.
- Legitimate interests: to keep the Service secure, prevent fraud, analyse and improve the Service, and communicate with you about your account.
- Legal obligation: to keep records needed for transport, audit and tax compliance.
- Consent: where you opt in to something specific, for example optional cookies. You can withdraw consent at any time.
We do not sell your personal data to anyone.
4. Who we share your data with
- Within your company: tenant administrators can view deliveries belonging to their company.
- Your customers: signed POD emails you generate are sent to the recipients you choose.
- Our processors: Stripe (payments), Twilio (SMS and WhatsApp), Resend (outbound email), CloudMailin (inbound email parsing), Google Drive or OneDrive (your chosen cloud storage), our cloud hosting provider, and AI and OCR providers that extract structured data such as container numbers, addresses and driver instructions from documents you submit.
- Authorities: where we are required to by law.
5. International data transfers
Some of our processors operate outside the United Kingdom and EEA (for example in the United States). Where this happens we rely on appropriate safeguards, such as the UK International Data Transfer Agreement, standard contractual clauses, or the provider's certified framework, to protect your data.
6. How long we keep your data
We keep your personal data while your account is active. To meet UK transport, audit and tax (HMRC) record-keeping obligations, delivery notes, invoices, notification logs and inbound emails are retained for up to six years. A scheduled process runs monthly to automatically and permanently delete records older than six years. After account closure, your personal data is removed from live systems as described below, while the underlying business records (signed delivery notes, photographs and attached documents) are retained for the same six-year period as the property of your employer or customer.
Inbound email content is processed to operate the Service and the raw message is retained only as needed to do so, after which it is deleted.
7. Data Protection Impact Assessment (DPIA)
The Service processes personal data in connection with proof-of-delivery workflows, including the capture of signatures, photographs taken on site (which may incidentally show individuals), and delivery and location data. Because this processing can involve systematic monitoring, biometric-adjacent data (signatures) and images of individuals, we have carried out a Data Protection Impact Assessment in accordance with Article 35 of the UK GDPR and EU GDPR.
The DPIA identifies the risks to data subjects, the measures we apply to mitigate them (encryption, role-based access, tenant isolation, pseudonymisation on erasure, and the six-year retention schedule described below), and the residual risk, which we assess as low. A copy of the DPIA summary is available to customers and supervisory authorities on request to hello@deliverysigner.app.
8. Security
We protect data using encryption in transit (TLS), encryption at rest via our hosting provider, and role-based, least-privilege access controls. No system can be guaranteed completely secure, but we apply measures appropriate to the sensitivity of the data.
9. Your rights
Under the UK GDPR you have the right to access, rectify, erase, restrict, object to, or port your personal data, and to withdraw consent where we rely on it. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
We provide two self-service tools in My Settings to help you exercise these rights directly:
- Download My Data (right of access / portability): exports a copy of the personal data we hold about you — your profile, delivery assignments and notification history — as a downloadable JSON file.
- Request Data Erasure (right to erasure): permanently removes your name, email address, signature image and notification history from our systems and deactivates your account. Because delivery records are the business property of your employer or customer and are required by law to be retained for six years, erasure is carried out by pseudonymisation — your personal identifiers are stripped from each delivery record while the signed delivery note, photographs and attached documents are preserved as commercial evidence. This approach is supported by the Article 17(3)(b) exemption for processing necessary for legal compliance.
You can also exercise any of these rights by emailing hello@deliverysigner.app.
10. Cookies and local storage
The Service uses essential session and authentication cookies. Preferences such as dark mode and font size are stored in your browser's local storage. We do not use advertising or third-party tracking cookies.
11. Children
The Service is not offered to anyone under 18 and we do not knowingly collect personal data from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. Where a change is material we will notify you through the Service or by email. Continued use after a change takes effect means you accept the updated policy.
13. Contact
Questions about this Privacy Policy or your personal data can be sent to hello@deliverysigner.app.