Legal
Last updated: 29 September 2026
RideSite ("RideSite", "we", "us", "our") builds websites, booking engines and business-management tools for small taxi, limousine and chauffeur operators. This policy explains what personal data we collect through:
chauffeurwebsitebuilder.lovable.app (the "app" and sign-up);name.operator.ridesite.com or the operator's own custom domain.Two different roles. For an operator's own account data, RideSite is the data controller. When passengers book a ride through an operator's published website, that operator's business is the data controller of the booking and customer data, and RideSite acts only as a data processor, handling that data on the operator's instructions. Passengers should direct questions about their booking to the operator they booked with; each operator's contact details are shown on their website.
The table below lists every category of personal data we handle, where it comes from and why.
| Category | Examples | Source | Why we need it |
|---|---|---|---|
| Account data | Name, email address, hashed password, Google account name and email if you sign in with Google | You, at sign-up or sign-in | To create and secure your account and contact you about it |
| Business profile | Business name, type, country, city, phone, WhatsApp number, logo, services offered, preferred style | You, during onboarding and in Settings | To build your website and pre-fill your site content |
| Website content | Page text, images, vehicle details, fares, fixed routes, testimonials, blog posts, theme choices | You, or AI generated from your prompts | To store, render and publish your website |
| Fleet data | Vehicle names, categories, makes, models, photos, passenger and luggage capacity, per-vehicle pricing | You, in Fleet | To display your fleet and price bookings |
| Booking and customer data | Journey addresses, date/time, flight number, passenger name, email, phone, extras, chosen vehicle, price breakdown, payment method and status, driver assigned, operator notes | Passengers booking on an operator's site | To deliver the booking service, confirmations and the operator dashboard |
| Leads and messages | Contact-form and quote-request submissions: name, email, phone, message | Visitors on an operator's site | To show the enquiry in the operator's leads inbox |
| Reviews | Reviewer name, star rating, quote, linked booking | Passengers, or added manually by the operator | To display testimonials on the operator's site |
| Payment metadata | Stripe customer and invoice IDs, credit-pack and subscription purchases, connected Stripe account status (never full card numbers) | Stripe | To grant credits, enforce plan limits and show invoices |
| Usage analytics | Page path, referring host and timestamp of views on published sites; AI action logs (action type, credits spent, token counts) | Collected automatically | To show operators their traffic and to bill and meter AI credits |
| Domain and support data | Custom domain names, DNS status, Cloudflare hostname IDs, support tickets and replies, audit-log entries | You, or recorded automatically | To connect domains, provide support and keep a security trail |
| Legal-page data | Privacy, terms and cookie text operators write for their own sites | You, in Settings → Legal | To display on the operator's website |
We do not knowingly collect special-category data (health, religion, biometrics and so on) and ask you not to submit it. Card numbers are never stored by RideSite — Stripe handles them directly.
If you are in the UK or EU, we rely on these legal bases:
Operators are independently responsible for having a lawful basis for the customer data their sites collect.
We use personal data to:
We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use customer booking data to train AI models.
AI actions (generating a site, chat edits, new pages, SEO packs, blog posts, translations) send your prompt plus the relevant parts of your website content to our AI provider, which generates the result. We log which action ran, when, and how many credits it cost. Prompts and generated content are used only to produce your result — they are not used to train models and are not shown to other customers. Please do not put passengers' personal details into AI prompts.
RideSite's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: if you sign in with Google, we receive only your Google account name and email address to identify your account; and address autocomplete and route pricing on operator sites send the addresses you type to the Google Maps Platform solely to return suggestions and distance/time estimates. Google user data is never sold, never used for advertising, and never used to train AI models.
We share personal data only with the processors needed to run the service, under contract:
| Provider | What they do for us |
|---|---|
| Lovable Cloud (Supabase) | Hosting, database, authentication and file storage |
| Stripe | Card payments, subscriptions, and operator payout accounts (Stripe Connect) |
| Google Maps Platform | Address autocomplete and route distance/time pricing |
| Resend | Transactional email delivery (confirmations, alerts, status updates) |
| Cloudflare | SSL certificates for custom domains |
| AI provider (via Lovable AI Gateway) | Generating website content, edits, SEO and blog text |
Each provider receives only the data it needs. We may also disclose data where the law requires it (for example, to respond to a court order) or to protect our rights. If a provider changes, we will update this list.
Our providers may process data in the United States and other countries outside the UK and EU. Where that happens, transfers are protected by the provider's participation in the EU–US and/or UK–US Data Privacy Framework or by the European Commission's Standard Contractual Clauses.
RideSite itself uses only strictly necessary storage: a session cookie (and equivalent local storage) to keep operators signed in, and per-site drafts saved locally in the builder. We set no advertising or third-party tracking cookies.
On operator websites: page views are recorded as anonymous counts (path, referrer host, timestamp) — no user profiles. An operator may add their own Google Analytics or Google Tag Manager ID and their own cookie banner text; those tools are set by the operator and governed by Google's privacy policy, and visitors should be told about them by the operator's cookie banner.
Data is encrypted in transit (TLS) and at rest. Access to production data is limited to authorised personnel, and database access is enforced by row-level security so each operator can read only its own data. Administrative actions on tenants and credits are written to an audit log. Payment secrets and API keys are stored as server-side secrets and never included in the app's public code. No system is perfectly secure; if a breach affects your data we will notify you and the relevant regulator as the law requires.
RideSite is a business tool and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.
| Data | Retention |
|---|---|
| Account and business profile | Until you delete your account, then removed within 30 days |
| Website content and versions | Until deleted by you or with your account |
| Bookings, customers, leads, reviews | Until deleted by the operator or with the operator's account |
| Invoices and payment records | 7 years, as tax law requires |
| AI usage logs | 24 months, for billing disputes and abuse prevention |
| Audit logs | 24 months |
| Analytics (page views) | 14 months, then aggregated or deleted |
| Support tickets | 24 months after closure |
Backups are overwritten on a rolling schedule, so complete deletion (including backups) can take up to 90 days.
Where RideSite is the controller (your operator account), you have the right to:
To exercise any right, email info@taxi-webdesign.com; we respond within 30 days and may ask you to verify your identity.
If you are a passenger who booked with one of our operators, that operator controls your booking data — contact them first, and we will help them respond. California residents have the equivalent rights to know, delete and correct, and to be free from discrimination for exercising them; we do not "sell" or "share" personal information as those terms are defined by the CCPA/CPRA.
If you run a website on RideSite, you are the controller of your customers' data. You agree to: keep your own privacy notice accurate and published on your site; only collect data you need; honour your customers' rights requests; and keep your account secure. We give you the tools (legal-page editor, cookie banner, data export) to do this.
Questions about this policy or your data? Write to us at info@taxi-webdesign.com and we will respond within 30 days. We will update this page when the service changes and change the "last updated" date above. If a change materially affects how we use your data, we will notify account holders by email before it takes effect.