Privacy Policy
What personal data Cabica holds, whose it is, why we hold it, how long for, who we share it with, and how to exercise your rights under UK and EU law.
- Last Updated
- 8 August 2026
- Effective
- 8 August 2026
Who this is for: Everyone: visitors to this website, operators who subscribe, and the passengers and drivers whose data flows through the platform.
In Short
- For this website and our own sales and billing, we decide what happens to your data — we are the controller, and this policy is the whole answer.
- For everything inside an operator's system — bookings, passengers, drivers — the operator decides, and we only act on their instructions. They are the controller; we are their processor.
- That means if you are a passenger asking to see or delete your data, the firm you book with is who answers. We build the buttons; they press them.
- We do not sell personal data, we do not use it to train models, and we do not share one operator's data with another.
- You can complain to the ICO at any time, and you do not have to come to us first.
This summary is here to be read. It is not a substitute for the full text below, and where the two differ, the full text is what applies.
1. Who we are
Cabica Ltd is a company registered in England and Wales. We supply cloud software to licensed taxi and private-hire operators: a dispatch console, driver and passenger apps, a booking website, payments, and compliance tools.
Questions about this policy, or about any personal data we hold, go to privacy@cabica.co.uk. Suspected security problems go to security@cabica.co.uk — those are read faster.
2. Controller or processor — and why it matters to you
Data protection law splits responsibility in two. The controller decides why and how personal data is used and answers to the individual for it. The processor only does what the controller instructs.
Cabica is both, for different data, and confusing them would send your request to the wrong place. Here is the line:
| Data | Controller | Our role |
|---|---|---|
| This website: analytics, contact forms, demo requests, sales leads | Cabica Ltd | Controller — this policy is the full answer |
| Operator accounts, subscriptions, invoices, support tickets from operator staff | Cabica Ltd | Controller — this policy applies |
| Passengers: names, numbers, addresses, bookings, ride history, payment metadata | The operator you book with | Processor — we act only on their instructions |
| Drivers: profiles, licences, badges, DBS dates, earnings, location during shifts | The operator you drive for | Processor — we act only on their instructions |
| Call recordings and telephony records in Cabica Comms | The operator | Processor |
3. What we collect, as a controller
This section covers only the data we decide about ourselves — website visitors, sales enquiries, and operator accounts. What flows through a tenant is covered by that operator's own privacy notice.
- You tell us
- Name, firm name, email address, phone number, and whatever you write in a message when you request a demo, contact us, or open a support ticket.
- Account data
- The login details of operator staff, their role and access level, when they last signed in, and the audit trail of what they changed in the platform.
- Billing data
- Company details, VAT number, plan, invoices and payment status. Card details go straight to Stripe and we never see or store them.
- Technical data
- IP address, browser and device type, pages visited, and error diagnostics. We keep server logs to run and secure the service.
- Security data
- Failed login attempts, IP addresses associated with abuse, and records of any block we apply.
We do not knowingly collect data from children. The platform is a business tool and the passenger app is for adults booking journeys. If you believe a child has given us data, tell us and we will remove it.
We do not ask for, and do not want, special-category data (health, religion, biometrics and the like) on this website. Operators may hold some in their own systems — an accessibility requirement recorded against a passenger, for example — and where they do, they are the controller and it is their lawful basis to establish.
4. Why we use it, and our lawful basis
| What for | Lawful basis |
|---|---|
| Answering an enquiry or arranging a demo | Legitimate interests — you asked us to, and responding is what you expected |
| Providing the platform to a subscribing operator | Performance of a contract |
| Taking payment and chasing unpaid invoices | Performance of a contract, and legitimate interests in being paid |
| Keeping accounts, tax and VAT records | Legal obligation |
| Keeping the service secure: logs, rate limits, abuse blocks, audit trails | Legitimate interests in protecting the platform and everyone on it |
| Marketing email to business contacts about the product | Legitimate interests, with an unsubscribe link in every message |
| Non-essential cookies and analytics | Consent — and we do not set them until you give it |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded ours does not override yours. You can ask us to show that assessment, and you can object at any time.
We do not sell personal data. We do not use it to train machine-learning models. We do not share one operator's data with another operator, ever.
6. Sending data outside the UK
We keep data in the UK and the European Economic Area wherever we have a choice. Some suppliers — Stripe, Google, Firebase — process data in the United States and elsewhere.
Where that happens we rely on one of: an adequacy decision by the UK government or the European Commission; the UK International Data Transfer Addendum to the EU Standard Contractual Clauses; or the EU Standard Contractual Clauses themselves. Copies are available on request.
We assess each transfer for the risk that local law could compel disclosure, and we do not send more than the supplier needs to do its job.
7. How long we keep it
We keep personal data only as long as we need it, or as long as the law requires. As a controller:
| Data | Kept for | Why |
|---|---|---|
| Enquiries and demo requests that go nowhere | 24 months | Long enough to follow up, short enough not to hoard |
| Sales leads that become customers | Life of the account, then 6 years | Contract and tax records |
| Operator account and login records | Life of the account, then 12 months | Support, disputes, and reconnecting a returning customer |
| Invoices and payment records | 6 years from the end of the accounting period | HMRC requirement — not ours to shorten |
| Audit logs of administrative actions | 6 years | Accountability, licensing enquiries, and disputes about who did what |
| Server and security logs | 90 days | Long enough to investigate an incident |
| Abuse blocks and their reasons | Until the block expires, then 12 months | So a repeat is recognisable |
| Backups | Up to 35 days on a rolling cycle | Deleted data ages out of backups rather than being surgically removed |
Operator Data inside a tenant is kept for as long as the operator wants it, and deleted or anonymised 30 days after their subscription ends. Their own retention decisions are theirs to publish.
8. Your rights
Under UK GDPR and the Data Protection Act 2018 — and the EU GDPR where it applies — you have the right to:
- be told what we hold and why (this document);
- access a copy of your personal data;
- correct anything inaccurate;
- erase it, where there is no overriding reason to keep it;
- restrict what we do with it while a dispute is resolved;
- portability — receive it in a structured, machine-readable format, and have it sent elsewhere;
- object to processing based on legitimate interests, and to direct marketing at any time, with no reason needed;
- not be subject to a solely automated decision with legal or similarly significant effects.
To exercise any of these against Cabica as controller, email privacy@cabica.co.uk. We answer within one month, and we do not charge. We will ask you to confirm who you are before sending personal data anywhere — that check protects you, not us.
Automated decisions. The dispatch engine chooses which driver is offered a job, using distance, availability, queue position and vehicle capability. It affects a driver's work, so we say so plainly: it is automated, the rules are set by the operator, and a driver can ask the operator to review any decision. It does not make decisions about passengers beyond matching a car to a booking.
Complaints. You can complain to the Information Commissioner's Office at ico.org.uk, or by phone on 0303 123 1113, at any time. You do not have to raise it with us first, though we would rather you did so we can fix it.
9. How we protect it
The full technical picture is in our security documentation. In short:
- everything travels over TLS; the apps refuse plain HTTP outright;
- passwords are hashed with Argon2; one-time codes are stored hashed and are single-use;
- access tokens on phones are wrapped by hardware-backed keys in the device's secure element;
- every request is authorised server-side, against the account's role and area permissions — the interface hiding a button is not a control and we do not treat it as one;
- each operator's data is isolated by tenant, and every request re-checks that the account still belongs to the company it claims;
- administrative actions are written to an audit log the operator can read;
- uploaded documents are checked against their real file signature before they are accepted;
- rate limits and abuse controls sit in front of the parts worth attacking.
No system is perfectly secure, and we will not claim otherwise. If we suffer a breach that risks people's rights and freedoms, we notify the ICO within 72 hours of becoming aware, and we tell affected people without undue delay where the risk to them is high. Where we are a processor, we notify the operator without undue delay so they can meet their own deadline.
If you have found a security problem, please tell us at security@cabica.co.uk. We will not pursue anyone who reports a genuine issue responsibly.
11. Changes to this policy
We update this policy when what we do changes. The date at the top is the date of the current version. For material changes affecting operators we give at least 30 days' notice by email and in the platform.
We do not quietly widen what we do with data already collected. If we ever want to use it for something materially new, we will ask.
This document was last updated on 8 August 2026. See all legal documents.