Last Updated: 25 August 2026
Business Name: Anytime Taxi
Trading As: Collection of licensed sole trader taxi operators
Registered Address: [TO BE ADDED - Your registered business address]
ICO Registration Number: ZC229168
Contact Email: hello@anytimetaxi.co.uk
Contact Phone: 01453 393457
Data Protection Contact: hello@anytimetaxi.co.uk (mark for the attention of the Data Protection Officer)
We collect the following personal data when you book a taxi:
If a booking is for an unaccompanied passenger aged 14 or over, we collect the following additional consent data at the point of booking:
This data is stored against the booking record and shared with the assigned driver for the duration of the journey. It is retained as part of the booking record (see section 6).
If you use our customer app at app.anytimetaxi.co.uk (also accessible at anytimetaxi.co.uk/portal_beta), we additionally collect:
portal_session cookie) to keep you logged in for up to 90 days. This is strictly necessary for the service and is not used for tracking or advertising.If you use our customer app (PWA), the app may automatically send crash reports when it encounters an error. These reports include:
Crash reports do not include your name, phone number, booking details, or any other personal data. They are retained for 90 days for debugging purposes and then automatically purged. You can view the full technical details in our Cookie Policy.
We use your personal data for the following purposes:
Under UK GDPR, we process your data based on:
Your name, phone number, pickup location, destination, and any booking notes (including unaccompanied-minor consent details) are shared with the driver assigned to your job. All drivers are licensed sole traders who are required to protect your data. See our Driver Privacy Notice for how drivers handle your data.
We use two SMS gateways depending on the type of message:
Addresses you type are autocompleted and geocoded using the Google Maps Platform API. Your typed address query is sent to Google. Google's privacy policy applies: policies.google.com/privacy. We also use Google Distance Matrix for fare estimates and live traffic routing.
Card payments are processed by Stripe (stripe.com/en-gb/privacy), a PCI DSS Level 1 certified payment processor. When you save a card or pay by card:
If you opt in to push notifications via the customer app, your browser generates a push subscription endpoint. This endpoint is held by your browser vendor (e.g. Google for Chrome via Firebase Cloud Messaging, Apple for Safari) and shared with us so we can send you notifications. We do not sell or share this endpoint with any other third party. A delivery log (the FCM response status) is retained for 12 months so we can confirm whether a notification was delivered when you ask.
Our booking forms use Cloudflare Turnstile for bot-detection. Turnstile processes a cryptographic token and your IP address to verify you are a human, not a bot. Cloudflare does not receive your booking details. Cloudflare privacy policy.
If you call our booking line and our AI voice assistant handles your call, Twilio processes the audio stream and the phone number you called from. The AI assistant (powered by Google Gemini) transcribes your booking request and may record the call for service quality and training. Call recordings are retained for 6 months unless needed for an ongoing dispute (see section 9).
If you provide a flight number for an airport pickup, we query the AeroDataBox API to track the flight's arrival status. AeroDataBox receives the flight number and the airline code — it does not receive any personal data (no name, phone, or booking details are sent to AeroDataBox).
Our retention periods are aligned to the UK GDPR storage limitation principle (Article 5(1)(e)) and HMRC requirements. A daily automated purge job (taxi-cleanup cron at 03:30 UTC) enforces these periods:
| Data Type | Retention Period | Reason |
|---|---|---|
| Booking Records | 72 months (6 years) | HMRC tax requirements + transport licensing record-keeping |
| Payment Records (Stripe) | 72 months (6 years) | Tax / accounting compliance |
| Driver Payout Ledger | 72 months (6 years) | Financial record keeping (driver earnings reconciliation) |
| Audit Logs (system events) | 36 months (3 years) | Security incident investigation + regulatory enquiry window |
| Job Status Audit Trail | 36 months (3 years) | Dispute resolution + "who assigned this job" traceability |
| Unaccompanied Minor Consent Records | 72 months (6 years) — retained with the booking record | Proof of parental authorisation; safeguarding record-keeping |
| Push Notification Delivery Logs | 12 months | To confirm delivery when a customer asks; FCM response retention |
| SMS Delivery Logs | 12 months | To confirm delivery when a customer asks; ClickSend/Traccar response retention |
| Push Notification Subscriptions | 12 months of inactivity, then anonymised | Necessary for the service; stale subscriptions purged |
| PWA Crash Reports | 90 days | Debugging; no personal data in the reports |
| Driver Onboarding Applications | 24 months, then anonymised | Hiring record-keeping; non-hired applicants' data anonymised after 24 months |
| Driver Leave Records | 36 months (3 years) | Annual leave allowance tracking + employment dispute window |
| Banned Customers (fraud / abuse) | 60 months (5 years) | Repeat-offender detection; name + phone retained, all other data anonymised |
| Inactive Customer Profiles | 24 months of inactivity, then anonymised | Storage limitation; active customers retained indefinitely |
| Inactive Driver Profiles | 24 months of inactivity, then anonymised (except where licensing retention applies) | Storage limitation; licensing records may require longer retention (see Driver Privacy Notice) |
| Password Reset Tokens | 30 minutes (single-use, consumed on use) | Security; expired tokens purged automatically |
| Magic Link Login Tokens | 30 minutes (single-use, consumed on use) | Security; expired tokens purged automatically |
| Marketing Consent | Until withdrawn | Ongoing consent; you can withdraw at any time |
| Call Recordings (inbound) | 6 months, then deleted (unless retained for an ongoing dispute) | Service quality + training; dispute evidence |
| Saved Card References (Stripe token) | Until you remove the card in the app or request deletion | Card-on-file payment service |
| App Session Cookies | 90 days (or until you log out) | Authentication |
After the retention period, personal data is either permanently deleted or anonymised (irreversibly stripped of identifiers) depending on whether the underlying record has a legal hold or ongoing business need.
Under UK GDPR, you have the following rights:
You can request a copy of all personal data we hold about you, including booking history, payment records, SMS logs, push delivery logs, and audit trail entries. We maintain an internal audit log of every significant system event (booking created, status changed, SMS sent, push delivered) specifically so we can answer subject access requests comprehensively. We will provide this free of charge within 30 days (within 1 month as per ICO guidance).
If your data is inaccurate or incomplete, you can ask us to correct it. This includes correcting a misspelled name, an outdated phone number, or an incorrect address.
You can ask us to delete your data, except where we have a legal obligation to retain it (e.g., tax records for 6 years, safeguarding records for unaccompanied minors). When you request erasure, we will:
You can ask us to temporarily stop processing your data in certain circumstances (e.g., while a dispute is resolved).
You can request your booking history and loyalty points data in a machine-readable format (JSON) to transfer to another service.
You can object to direct marketing at any time. We will immediately stop sending you marketing messages. You can also object to processing based on legitimate interests — we will assess each objection on its merits.
Where we rely on consent (marketing, push notifications, unaccompanied-minor authorisation), you can withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing that took place before the withdrawal.
We do not use automated decision-making that produces legal or similarly significant effects. Our dispatch system uses a fairness-based algorithm to assign jobs to drivers (based on each driver's recent job count, fare, and mileage), but this does not produce decisions about you (the customer) — it only determines which driver is offered your booking. You have the right not to be subject to decisions based solely on automated processing that produce legal effects.
To make a data subject request, contact us at:
We will respond within 30 days. We may need to verify your identity before processing your request (e.g., by sending a verification code to the phone number we hold for you). We do not charge for subject access requests unless they are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse to act).
We protect your data using:
If we experience a data breach that poses a risk to your rights and freedoms, we will:
A journal-watcher systemd service monitors our application logs for unhandled exceptions (Tracebacks) and alerts the operator via SMS in real time, so we become aware of potential breaches promptly.
Our website uses minimal first-party cookies. See our Cookie Policy for a full inventory of cookies and third-party services. In summary:
portal_session) — strictly necessary for the customer app login; HttpOnly; 90-day max-ageWe do not use advertising cookies, tracking pixels, or third-party analytics. The only first-party cookie we set (portal_session) is strictly necessary and does not require consent under PECR.
Our website may contain links to external sites (e.g., Google Maps, Stripe, Cloudflare). We are not responsible for the privacy practices of these third parties. Please review their privacy policies before sharing any personal data with them.
Our service is not intended for children under 14. We can carry unaccompanied passengers aged 14 and over, but only with explicit parental/guardian consent, which is captured at the point of booking (see section 2 — Unaccompanied Minor Consent). For passengers under 14, a parent or guardian must accompany them in the vehicle.
We do not knowingly collect data from children under 14. If you believe we have collected data from a child under 14 without parental consent, please contact us and we will delete it promptly.
Our customer app is a Progressive Web App (PWA) accessible at app.anytimetaxi.co.uk (also at anytimetaxi.co.uk/portal_beta). It can be installed to your home screen and runs like a native app — without going through an app store.
We authenticate you via a one-time magic link sent by SMS to the phone number you registered with us. No password is required. We do not use social login. The session is maintained via a secure, HTTP-only cookie that expires after 90 days or on logout.
You may opt in to push notifications within the app. Opting in instructs your browser to generate a push subscription endpoint, which we store against your account. We use this endpoint exclusively to send you ride status notifications (driver assigned, en route, arrived, completed). You can revoke this at any time via your browser or device settings, or by turning off notifications within the app profile menu. Revoking permission does not affect your ability to use the service — we will fall back to SMS updates.
A delivery log (the FCM response status + timestamp) is retained for 12 months so we can confirm whether a notification was delivered when you ask (e.g., in a subject access request).
Your loyalty points balance and transaction history are visible in the app. Points are earned automatically on completed journeys and may be redeemed against future bookings. The loyalty programme is operated by Anytime Taxi. Points have no cash value and are non-transferable. Loyalty ledger entries are retained indefinitely (part of the financial record).
The app remembers your recent and frequent routes to enable the quick-rebook feature. This data is held on our servers (not just locally), associated with your customer profile, so it persists across devices.
Card payments via the app are processed by Stripe. Card details, when added, are collected directly by Stripe's secure card elements and never pass through our servers in raw form — only a Stripe token is stored by us. See section 5 (Payment Processors) for Stripe's data handling. A pre-authorisation hold may be placed on your card at booking time and captured at journey completion. A no-show fee may be charged if you cancel within 2 hours of pickup without a valid reason.
When you book a job, it may be offered to our drivers via a bidding portal where drivers can opt in to available jobs. The bidding portal uses a fairness algorithm (based on each driver's recent job count, fare, and mileage) to assign the job to the most suitable driver. Your personal data (name, phone, pickup, destination) is shared only with the winning driver — other bidding drivers see only the route (pickup town and dropoff town) and the estimated price, not your personal details.
When your driver is en route, the app shows a live map with the driver's GPS position updating in real time. The driver's GPS position is polled at a dynamic interval (5–60 seconds depending on distance from your pickup) to balance real-time accuracy with battery usage. The driver's GPS is only tracked while they have an active job assigned to you — it is not tracked outside of active jobs.
The app uses browser localStorage to cache your session state (e.g. active job ID, booking preferences, notification preferences). This data is stored only on your device and is cleared when you log out. It is separate from the data held on our servers. A cookie-consent dismissal flag (cookie_consent_dismissed) is also stored in localStorage so the cookie banner doesn't reappear after you dismiss it.
The app automatically sends crash reports when it encounters an error. These reports include the error message, stack trace, app version, device type, and a randomly-generated device ID (stored in localStorage to deduplicate reports). Crash reports do not include your name, phone number, booking details, or any other personal data. They are retained for 90 days and then automatically purged. See section 2 (Crash Reports) for the full list of what's collected.
App type: Standalone, offline Android application. The Nameboard app is separate from and unrelated to the Anytime Taxi dispatch system, website, and customer portal.
Data collection: The Nameboard app does NOT collect, store, transmit, or share any personal data or device data. Specifically, it does not collect:
Third-party SDKs: The Nameboard app does not include any third-party SDKs that collect data.
Permissions: The Nameboard app requests no sensitive permissions. Any permissions requested are strictly for core offline functionality.
Children's privacy: The Nameboard app is suitable for all ages and does not collect any data from anyone, including children.
Data Safety declaration: In accordance with Google Play's Data Safety requirements, the Nameboard app is declared as collecting no user data.
Google Play Store URL: [TO BE ADDED — Play Store listing URL]
Your personal data is processed in the United Kingdom and the European Union. Some of our sub-processors may transfer data outside the UK/EU (e.g., Google, Cloudflare, Stripe — all of which have offices in the US). Where this is the case, the transfer is made under appropriate safeguards (either an adequacy decision by the UK Government, Standard Contractual Clauses, or binding corporate rules). A full list of our sub-processors and their processing locations is available in our Cookie Policy and on request.
We may update this privacy policy from time to time. Significant changes will be notified via:
The current version of this policy was last updated on 25 August 2026 to reflect our GDPR compliance programme (audit trails, push delivery logs, unaccompanied-minor consent capture, file integrity monitoring, and retention schedule alignment).
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if you believe we have not handled your data correctly. We would welcome the opportunity to resolve any concerns directly first, but you are always entitled to contact the ICO without first contacting us.
ICO Contact:
For any privacy questions, data requests, or to exercise your rights, contact:
Email: hello@anytimetaxi.co.uk
Phone: 01453 393457
Post: [TO BE ADDED — registered business address]
Data Protection Officer: hello@anytimetaxi.co.uk (mark for the attention of the DPO)
We use the following sub-processors to deliver our service. Each has a Data Processing Agreement (DPA) in place where required by GDPR:
AeroDataBox does not receive any personal data (no name, phone, or booking details) — only the flight number and airline code for flight status lookups. No DPA is required for AeroDataBox under Article 28 because no personal data is processed by them.