Privacy Policy

Effective August 13, 2026 · Version 2026-08-13

LiveryOS is dispatch software sold to transportation companies. Most of the personal information we hold belongs to those companies, not to us: we store and process it on their instructions, and they decide what happens to it. This policy explains what we collect in each role, who we share it with, how long we keep it, and how to exercise your rights. We do not sell personal information, and we do not use it to train machine-learning models.

1. Who this policy covers

This policy applies to LiveryOS and to everything we operate: the LiveryOS website, the dispatch dashboard, the driver applications for iOS and Android, and the APIs behind them.

It describes our handling of information about four groups: people at companies that subscribe to us or enquire about subscribing; drivers, dispatchers and administrators who use the applications; passengers whose ride details are entered by a subscribing company; and visitors to our website.

2. Our two roles: controller and processor

The distinction determines who you ask for what, so it comes first.

As a controller

We decide how information about our own customers is handled: the companies that subscribe, the administrators who sign up, billing records, support conversations, and enquiries through our website. This policy governs that information in full.

As a processor

We store and process the operational data a subscribing company puts into the platform — its passengers, rides, addresses, accounts, pricing, drivers, dispatchers, messages, documents and payment records. That company is the controller of that data. We process it only to provide the service, on that company's instructions and under our agreement with it.

If you are a driver or a passenger of a company that uses LiveryOS and you want your data accessed, corrected, exported or deleted, ask that company — they control it. We will support their handling of your request, and if you cannot reach them, write to us and we will pass it on and act on it for them.

Each subscribing company's operational data is held in its own dedicated database, separate from every other company on the platform.

3. What we collect as a controller

Account and company information

When someone signs up we collect the company name and code, business address, phone and website, the administrator's name, email and phone, a hashed password, the time zone, fleet size, how they heard about us, and the version of the terms they accepted together with the time, IP address and browser user agent of that acceptance.

Billing information

Subscription plan, seats, invoices, payment status and the identifiers our payment processor gives us. Card numbers are collected and stored by Stripe, not by us; we see only the last four digits, card brand and expiry.

Support and enquiries

Messages you send us by email, through the website contact and support forms, or as in-product tickets, together with what you tell us in them.

Technical information

Server logs, IP addresses, device and browser characteristics, pages and features used, and diagnostic data from crashes and errors. We use this to run, secure and improve the service. We do not use advertising trackers and we do not run third-party advertising on our site or in our apps.

4. What we process on behalf of subscribing companies

A subscribing company decides what it puts into the platform. In ordinary use that includes:

  • passenger names, phone numbers, email addresses, pickup and drop-off addresses, ride times, notes and special requirements the company records;
  • driver and dispatcher records: name, contact details, login credentials, vehicle assignments, licence and insurance documents the company uploads, duty status, and location history from completed rides;
  • ride, fare, tip, wait-time, invoice, receipt and payment records, including house account balances;
  • messages between dispatchers and drivers sent through the platform; and
  • whatever else the company chooses to type into a free-text field.

A company should not put protected health information into the platform without a business associate agreement with us, and should not collect information about its passengers or drivers that it has no lawful basis to collect. What goes in is its decision and its responsibility.

5. The driver app: location, notifications and permissions

Location

The driver application collects precise device location, including while the app is in the background, when a driver is signed in and on duty. The company that the driver works for uses it to see where its drivers are during a ride, to route the nearest available car to a call, to give passengers accurate arrival times, and to keep a record of completed trips.

Collection stops when the driver goes off duty or signs out. A driver can refuse or later withdraw the permission in the device settings; the app will still open, but features that depend on location will not work, and the company may have its own rules about that. Location data is not sold, is not used for advertising, and is not shared with anyone outside the driver's own company and the infrastructure providers listed below.

Notifications

With permission, we send push notifications about new calls, reassignments and messages from dispatch. Delivery uses Apple's and Google's notification services, which receive a device token. Notifications can be turned off in device settings.

Other device access

The app requests camera or photo access only when a driver chooses to upload a document or photograph, and requests nothing else it does not need. It collects device model, operating system version and app version for diagnostics.

6. How we use information

  • to provide, operate, secure and support the platform;
  • to create and administer accounts, and to authenticate users;
  • to bill subscriptions, collect payment, and keep financial and tax records;
  • to send service communications — confirmations, receipts, security alerts, billing notices and material changes to terms;
  • to answer support requests and investigate incidents;
  • to detect, prevent and investigate fraud, abuse and security threats;
  • to diagnose faults and improve reliability and features, including through aggregated, de-identified statistics that identify nobody; and
  • to comply with law and to establish, exercise or defend legal claims.

We do not sell personal information, share it for cross-context behavioural advertising, or use it to train machine-learning models. We send marketing email only to business contacts about our own product, and every such message has an unsubscribe link.

Where European or United Kingdom law applies, our legal bases are: performance of a contract, for providing and billing the service; legitimate interests, for security, fraud prevention, product improvement and business communications; consent, for device permissions such as location and notifications, which can be withdrawn at any time; and legal obligation, for tax, accounting and lawful requests.

7. Who we share information with

We share personal information only as described here. Every provider below is bound to protect it and to use it only to perform services for us.

  • Microsoft Azure — hosting, databases, backups and application monitoring (United States).
  • Google Maps Platform — mapping, address autocomplete, geocoding, routing and distance calculation. Addresses and coordinates are sent to Google to answer these requests.
  • Stripe — subscription billing for us, and card payments for companies that connect their own Stripe account.
  • Square — card payments for companies that connect their own Square account.
  • Resend — delivery of transactional email such as confirmations, receipts and password notices.
  • EmailJS — delivery of messages submitted through the website contact and support forms.
  • Apple Push Notification service and Firebase Cloud Messaging, via Expo — delivery of push notifications to devices.
  • Sentry — crash and error reporting from the applications.

We also disclose information: to a subscribing company, about its own users and operations; to professional advisers such as lawyers and accountants under confidentiality; to authorities where required by law or valid legal process, or to protect rights, safety or property; and to an acquirer in a merger, financing or sale of assets, subject to this policy.

8. Cookies and local storage

We use browser local storage to keep you signed in and to remember interface preferences, and cookies strictly necessary to operate the site. We do not use advertising or cross-site tracking cookies. Clearing site data signs you out.

9. How long we keep information

Account and operational data is kept while the account is active. After a subscription ends, a company's data remains available for export for 30 days and may then be permanently deleted, including from backups on our ordinary backup cycle.

Some records are kept longer where we must: invoices and payment records for tax and accounting periods, security and audit logs for a limited period, records of terms acceptance for as long as they may be needed to establish or defend a claim, and anything subject to a legal hold. Support correspondence is kept while it remains useful for servicing the account.

A subscribing company may delete individual records itself at any time, which is the ordinary route for a driver or passenger deletion request.

10. How we protect information

  • encryption in transit over HTTPS/TLS, and encryption at rest for hosted databases and backups;
  • passwords stored only as salted hashes, never in readable form;
  • a separate database per subscribing company, so one company's data is not mixed with another's;
  • role-based access control inside the product, and optional two-factor authentication for administrators;
  • no storage of full card numbers anywhere in our systems; and
  • access to production systems limited to the people who need it, with logging and regular patching.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects personal information we hold, we will notify affected companies and, where the law requires, individuals and regulators, without undue delay.

11. Your privacy rights

Depending on where you live, you may have the right to know what personal information we hold about you, to obtain a copy or a portable export, to correct it, to delete it, to limit certain uses, to withdraw consent, and not to be discriminated against for exercising these rights.

For residents of California and other US states with comprehensive privacy laws: we do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We do not use or disclose sensitive personal information — which for us means precise geolocation and account credentials — for any purpose other than providing the service, securing it and complying with law. You may designate an authorised agent to make a request on your behalf.

For individuals in the European Economic Area and the United Kingdom: you additionally have the right to object to processing based on legitimate interests and to lodge a complaint with your supervisory authority.

To exercise a right, write to admin@liveryos.com. We will verify your identity before acting, and respond within the period the applicable law allows. If your request concerns data a subscribing company controls — most driver and passenger data — we will route it to that company and assist them in fulfilling it, because the decision is theirs to make.

12. Where information is held

Our systems and our providers are located in the United States, and information you give us is processed there. If you access the platform from outside the United States, you are transferring information to a country whose data protection laws may differ from your own. Where required, we rely on standard contractual clauses or another lawful transfer mechanism with our providers.

13. Children's privacy

The platform is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 18 as a controller. A subscribing company may record a minor passenger's details in the course of arranging a ride, which is that company's responsibility as controller. If you believe we hold a child's information in error, contact us and we will delete it or route the request to the company that controls it.

14. Changes to this policy

We may update this policy. The effective date and version above always reflect the current text. For material changes we will give notice by email to account administrators or in the product before the change takes effect.

15. Contact us

  • Privacy requests: admin@liveryos.com
  • Support: support@liveryos.com
  • Legal notices: admin@liveryos.com
  • Website: https://liveryos.com