Legal

Privacy policy

Last updated: 29 September 2026

1. Who we are and what this policy covers

RideSite ("RideSite", "we", "us", "our") builds websites, booking engines and business-management tools for small taxi, limousine and chauffeur operators. This policy explains what personal data we collect through:

  • our marketing website at chauffeurwebsitebuilder.lovable.app (the "app" and sign-up);
  • the operator dashboard operators use to run their business; and
  • the websites we host for operators, such as name.operator.ridesite.com or the operator's own custom domain.

Two different roles. For an operator's own account data, RideSite is the data controller. When passengers book a ride through an operator's published website, that operator's business is the data controller of the booking and customer data, and RideSite acts only as a data processor, handling that data on the operator's instructions. Passengers should direct questions about their booking to the operator they booked with; each operator's contact details are shown on their website.

2. The data we collect

The table below lists every category of personal data we handle, where it comes from and why.

CategoryExamplesSourceWhy we need it
Account dataName, email address, hashed password, Google account name and email if you sign in with GoogleYou, at sign-up or sign-inTo create and secure your account and contact you about it
Business profileBusiness name, type, country, city, phone, WhatsApp number, logo, services offered, preferred styleYou, during onboarding and in SettingsTo build your website and pre-fill your site content
Website contentPage text, images, vehicle details, fares, fixed routes, testimonials, blog posts, theme choicesYou, or AI generated from your promptsTo store, render and publish your website
Fleet dataVehicle names, categories, makes, models, photos, passenger and luggage capacity, per-vehicle pricingYou, in FleetTo display your fleet and price bookings
Booking and customer dataJourney addresses, date/time, flight number, passenger name, email, phone, extras, chosen vehicle, price breakdown, payment method and status, driver assigned, operator notesPassengers booking on an operator's siteTo deliver the booking service, confirmations and the operator dashboard
Leads and messagesContact-form and quote-request submissions: name, email, phone, messageVisitors on an operator's siteTo show the enquiry in the operator's leads inbox
ReviewsReviewer name, star rating, quote, linked bookingPassengers, or added manually by the operatorTo display testimonials on the operator's site
Payment metadataStripe customer and invoice IDs, credit-pack and subscription purchases, connected Stripe account status (never full card numbers)StripeTo grant credits, enforce plan limits and show invoices
Usage analyticsPage path, referring host and timestamp of views on published sites; AI action logs (action type, credits spent, token counts)Collected automaticallyTo show operators their traffic and to bill and meter AI credits
Domain and support dataCustom domain names, DNS status, Cloudflare hostname IDs, support tickets and replies, audit-log entriesYou, or recorded automaticallyTo connect domains, provide support and keep a security trail
Legal-page dataPrivacy, terms and cookie text operators write for their own sitesYou, in Settings → LegalTo display on the operator's website

We do not knowingly collect special-category data (health, religion, biometrics and so on) and ask you not to submit it. Card numbers are never stored by RideSite — Stripe handles them directly.

3. Legal bases for processing (UK/EU GDPR)

If you are in the UK or EU, we rely on these legal bases:

  • Contract — to provide the website builder, booking engine, credits and subscription you signed up for;
  • Legitimate interests — to secure the service (audit logs, fraud and abuse prevention), meter usage, and improve the product;
  • Consent — for optional cookies/analytics an operator enables on their own site, and for marketing emails where we send them;
  • Legal obligation — keeping invoices and payment records as tax and accounting law requires.

Operators are independently responsible for having a lawful basis for the customer data their sites collect.

4. How we use data — and what we never do

We use personal data to:

  • create and run your account, website, booking engine and dashboard;
  • send service emails: booking confirmations, operator new-booking alerts, status updates, password resets and account notices;
  • process credit purchases and subscriptions and enforce plan limits;
  • show traffic, booking and revenue statistics on dashboards;
  • connect custom domains and provision SSL certificates;
  • provide support and investigate problems;
  • detect abuse and keep the service secure.

We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use customer booking data to train AI models.

5. AI features

AI actions (generating a site, chat edits, new pages, SEO packs, blog posts, translations) send your prompt plus the relevant parts of your website content to our AI provider, which generates the result. We log which action ran, when, and how many credits it cost. Prompts and generated content are used only to produce your result — they are not used to train models and are not shown to other customers. Please do not put passengers' personal details into AI prompts.

6. Google user data — Limited Use disclosure

RideSite's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: if you sign in with Google, we receive only your Google account name and email address to identify your account; and address autocomplete and route pricing on operator sites send the addresses you type to the Google Maps Platform solely to return suggestions and distance/time estimates. Google user data is never sold, never used for advertising, and never used to train AI models.

7. Third parties we share data with

We share personal data only with the processors needed to run the service, under contract:

ProviderWhat they do for us
Lovable Cloud (Supabase)Hosting, database, authentication and file storage
StripeCard payments, subscriptions, and operator payout accounts (Stripe Connect)
Google Maps PlatformAddress autocomplete and route distance/time pricing
ResendTransactional email delivery (confirmations, alerts, status updates)
CloudflareSSL certificates for custom domains
AI provider (via Lovable AI Gateway)Generating website content, edits, SEO and blog text

Each provider receives only the data it needs. We may also disclose data where the law requires it (for example, to respond to a court order) or to protect our rights. If a provider changes, we will update this list.

8. International data transfers

Our providers may process data in the United States and other countries outside the UK and EU. Where that happens, transfers are protected by the provider's participation in the EU–US and/or UK–US Data Privacy Framework or by the European Commission's Standard Contractual Clauses.

9. Cookies and similar technologies

RideSite itself uses only strictly necessary storage: a session cookie (and equivalent local storage) to keep operators signed in, and per-site drafts saved locally in the builder. We set no advertising or third-party tracking cookies.

On operator websites: page views are recorded as anonymous counts (path, referrer host, timestamp) — no user profiles. An operator may add their own Google Analytics or Google Tag Manager ID and their own cookie banner text; those tools are set by the operator and governed by Google's privacy policy, and visitors should be told about them by the operator's cookie banner.

10. How we protect data

Data is encrypted in transit (TLS) and at rest. Access to production data is limited to authorised personnel, and database access is enforced by row-level security so each operator can read only its own data. Administrative actions on tenants and credits are written to an audit log. Payment secrets and API keys are stored as server-side secrets and never included in the app's public code. No system is perfectly secure; if a breach affects your data we will notify you and the relevant regulator as the law requires.

11. Children's privacy

RideSite is a business tool and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.

12. How long we keep data

DataRetention
Account and business profileUntil you delete your account, then removed within 30 days
Website content and versionsUntil deleted by you or with your account
Bookings, customers, leads, reviewsUntil deleted by the operator or with the operator's account
Invoices and payment records7 years, as tax law requires
AI usage logs24 months, for billing disputes and abuse prevention
Audit logs24 months
Analytics (page views)14 months, then aggregated or deleted
Support tickets24 months after closure

Backups are overwritten on a rolling schedule, so complete deletion (including backups) can take up to 90 days.

13. Your rights

Where RideSite is the controller (your operator account), you have the right to:

  • Access — get a copy of your data (most of it is visible and exportable in the app, e.g. CSV of bookings);
  • Correct — fix inaccurate data in Settings;
  • Delete — delete your account in Settings → Account, which removes your sites, bookings and customer data;
  • Object or restrict — ask us to stop a particular use;
  • Portability — receive your data in a machine-readable format;
  • Complain — to your local data-protection authority (in the UK, the ICO).

To exercise any right, email info@taxi-webdesign.com; we respond within 30 days and may ask you to verify your identity.

If you are a passenger who booked with one of our operators, that operator controls your booking data — contact them first, and we will help them respond. California residents have the equivalent rights to know, delete and correct, and to be free from discrimination for exercising them; we do not "sell" or "share" personal information as those terms are defined by the CCPA/CPRA.

14. Operator responsibilities

If you run a website on RideSite, you are the controller of your customers' data. You agree to: keep your own privacy notice accurate and published on your site; only collect data you need; honour your customers' rights requests; and keep your account secure. We give you the tools (legal-page editor, cookie banner, data export) to do this.

How to contact us

Questions about this policy or your data? Write to us at info@taxi-webdesign.com and we will respond within 30 days. We will update this page when the service changes and change the "last updated" date above. If a change materially affects how we use your data, we will notify account holders by email before it takes effect.