Legal

Privacy Policy

Last updated: 1 April 2026  ·  Applies to all GoatDrive users

Plain English summary: We collect the information needed to run your account and process your bookings. We don't sell your data. We don't show you ads. We use Supabase to store data, Stripe to handle payments, and Resend to send emails — all reputable services with strong data protections.

Contents
  1. Who we are
  2. What data we collect
  3. How we use your data
  4. Legal basis for processing
  5. Who we share data with
  6. How long we keep data
  7. Your rights
  8. Cookies
  9. Security
  10. Changes to this policy
  11. Contact and complaints

1. Who we are

GoatDrive is operated as a sole trader business in the United Kingdom. For the purposes of UK GDPR, we are the data controller for the personal data we process.

We are registered with the Information Commissioner's Office (ICO). Our ICO registration number will be published here once confirmed.

Contact: hello@goatdrive.com

2. What data we collect

Data you give us directly

DataWho provides itWhy we need it
NameStudents & instructorsAccount identity, booking communications
Email addressStudents & instructorsAccount login, booking confirmations, notifications
Phone numberStudents & instructorsShared with the other party to a confirmed booking
Home postcodeStudentsPre-fill pickup field; coverage matching
Pickup postcodeStudents (at booking)Shared with instructor; travel time calculation
ADI badge numberInstructorsCredential verification
DBS check statusInstructorsCredential verification
Teaching location & operating areaInstructorsDisplayed on your public profile; search matching
Hourly rate, bio, transmission typeInstructorsDisplayed on your public profile

Data generated through using the platform

DataGenerated by
Booking recordsLesson bookings (date, time, duration, price, status)
Payment recordsStripe session ID and payment intent ID (not card details)
Reviews and ratingsPost-lesson reviews submitted by students
Login activitySupabase Auth (timestamps, session tokens)

Data we do not collect

3. How we use your data

We do not use your data for advertising. We do not sell, rent, or trade your personal data to any third party.

5. Who we share data with

We share data only with the service providers necessary to operate GoatDrive, and with the other party to a confirmed booking.

Between students and instructors

When a booking is confirmed, we share the student's name, phone number, and pickup postcode with the instructor. We share the instructor's name and phone number with the student. This is necessary to allow the lesson to take place.

Third-party service providers

ProviderPurposeData shared
Supabase (supabase.com)Database and authentication hostingAll account and booking data. Hosted on AWS in the EU.
Stripe (stripe.com)Payment processingName, email, lesson details to initiate checkout. Card details handled entirely by Stripe.
Resend (resend.com)Transactional email deliveryName and email address of email recipient, and booking details for email content.
Postcodes.io (postcodes.io)Postcode geocoding for coverage matchingPostcode strings only. No personal identifiers are sent.
Vercel (vercel.com)Frontend hostingStandard web server logs (IP address, request path). No personal data beyond what's standard for web hosting.

All third-party providers are required to process your data only for the purposes we instruct them, and have appropriate data protection measures in place.

Legal disclosure

We may disclose your data if required to do so by law, court order, or to protect the rights, safety, or property of GoatDrive, our users, or others.

6. How long we keep data

Data typeRetention period
Account data (name, email, profile)Until you close your account, then deleted within 30 days
Booking records7 years (required for UK tax and accounting records)
Payment records (Stripe session/intent IDs)7 years (required for financial records)
ReviewsUntil the instructor or student account is closed
Authentication logs90 days, managed by Supabase

When you close your account, we delete your profile data. Booking and payment records are kept for the legally required period even after account closure.

7. Your rights

Under UK GDPR, you have the following rights regarding your personal data:

Right of access
Request a copy of all personal data we hold about you.
Right to rectification
Ask us to correct inaccurate or incomplete data about you.
Right to erasure
Ask us to delete your data where we no longer have a lawful reason to keep it.
Right to restriction
Ask us to restrict how we use your data in certain circumstances.
Right to portability
Request your data in a structured, machine-readable format.
Right to object
Object to processing based on legitimate interests.

To exercise any of these rights, contact us at hello@goatdrive.com. We will respond within 30 days. We may need to verify your identity before processing the request.

8. Cookies

GoatDrive uses minimal cookies. We use only the cookies necessary to keep you signed in (session tokens managed by Supabase Auth) and to process payments securely (Stripe).

We do not use advertising cookies, third-party tracking pixels, or analytics cookies at this time. If this changes, we will update this policy and notify registered users.

You can clear cookies at any time through your browser settings. Clearing cookies will sign you out of your GoatDrive account.

9. Security

We take reasonable technical and organisational measures to protect your personal data, including:

No system is completely secure. If you suspect your account has been compromised, contact us immediately at hello@goatdrive.com.

If we become aware of a data breach that is likely to affect your rights and freedoms, we will notify you and the ICO as required by UK GDPR.

10. Changes to this policy

We may update this Privacy Policy from time to time. We'll notify registered users by email when we make significant changes. The "last updated" date at the top of this page always reflects the most recent revision.

Continued use of GoatDrive after changes take effect means you accept the updated policy.

11. Contact and complaints

For any privacy-related questions, data requests, or concerns:

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

We would appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first.