Fair Transfer Ltd t/a Timeless Chauffeurs
1.1. This Privacy Policy sets out how Fair Transfer Ltd t/a Timeless Chauffeurs (the "Operator") collects, uses, stores, transfers and protects personal data in the course of providing private hire / chauffeur services.
1.2. This Policy applies to:
1.3. This Policy forms an integral part of the Terms and Conditions of Service, and the version published on the Operator's website and in force from time to time shall apply.
2.1. The data controller is:
2.2. The Operator acts as the data controller in respect of the processing of personal data and is required to comply with the provisions of the UK GDPR and the Data Protection Act 2018. In accordance with ICO expectations, the data controller must clearly state who processes the data, for what purpose, for how long, and with whom the data is shared.
2.3. ICO registration number: ZC101757
3.1. The Operator processes personal data in accordance with the following legislation and regulatory requirements:
3.2. In accordance with TfL requirements, London private hire operators must retain booking records and certain related records.
4.1. Personal Data: any information relating to an identified or identifiable natural person, whether directly or indirectly.
4.2. Processing: any operation performed on personal data, including in particular collection, recording, organisation, storage, use, retrieval, disclosure, restriction, erasure or destruction.
4.3. Data Subject: the natural person whose personal data is processed by the Operator, including in particular Clients, passengers, drivers, staff and contact persons.
5.1. The Operator shall process personal data only for specified, explicit and lawful purposes. Under the UK GDPR, each processing activity must have an appropriate legal basis; the ICO emphasises that the legal basis must be matched to the purpose of the processing, and that consent should not automatically be used for all processing activities.
5.2. The Operator processes personal data for the following principal purposes:
a) Performance of a contract / booking management
Recording, confirming and fulfilling travel bookings, assigning vehicles and drivers, maintaining client communications, and processing route and pick-up details.
b) Compliance with legal obligations
Meeting record-keeping, invoicing, taxation, TfL compliance, complaint handling and other statutory obligations. TfL's separate guidance for private hire operators also sets out data protection and record-keeping requirements.
c) Legitimate interests
Fraud prevention, service security, the establishment, exercise or defence of legal claims, investigation of complaints, protection of systems, and incident management.
d) Consent
Only where the relevant processing may lawfully and appropriately be based on consent.
5.3. Where the Operator processes special category data or criminal offence data, this shall only take place where additional applicable conditions are satisfied. The ICO emphasises that, in the case of special category data and criminal offence data, an additional condition is required beyond the general legal basis.
6.1. The Operator may request and process the following data from Clients and passengers, in particular:
6.2. The Operator does not store bank card details. Payments may be processed through secure third-party payment service providers.
6.3. The Client is required to provide accurate and complete information necessary for the fulfilment of the booking.
7.1. The Operator may process the following data relating to drivers, staff and other persons involved in the provision of the Service, in particular:
7.2. The purposes of such processing include in particular:
8.1. Personal data is obtained directly from the data subject, during the booking process, through the use of the website, during client communications, and, where necessary, from lawful third-party sources.
8.2. Data required for the performance of booking and dispatch functions may be made accessible, to the extent necessary, to drivers and operational staff involved in the provision of the Service.
9.1. The Operator shall share personal data only to the extent necessary.
9.2. Client data may be disclosed, for the purpose of fulfilling the booking, to the appropriately licensed driver or service partner who actually performs the journey.
9.3. Driver or staff data may be shared with the Client to the extent necessary for the performance of the journey, for example name, telephone number, vehicle type, registration number or arrival information.
9.4. The Operator may share personal data with regulatory authorities, TfL, the police, courts, tax authorities or other competent authorities where this is necessary for compliance with a legal obligation, an investigation, safeguarding purposes, or the establishment, exercise or defence of legal claims. TfL's data protection guidance expressly states that regulatory obligations must be taken into account in the processing of data by private hire operators.
9.5. The Operator does not sell personal data and does not use such data for its own marketing purposes.
10.1. The Operator shall not retain personal data for longer than is necessary. According to the ICO, the UK GDPR does not prescribe a single retention period for all cases; the controller must be able to demonstrate that the retention period is purpose-based and justifiable.
10.2. Data relating to bookings shall be retained for the period required by applicable legislation and licensing conditions. Under TfL requirements applicable to private hire operators, certain operator records — in particular booking records — are subject to a minimum retention period of 12 months.
10.3. Different retention periods may apply to different categories of data, in particular booking records, invoicing documents, complaint handling records, and compliance documentation relating to drivers and vehicles.
10.4. Where the purpose of processing has ceased and no further legal retention obligation applies, the Operator shall securely delete or destroy the data.
11.1. The Operator applies appropriate technical and organisational measures to protect personal data.
11.2. Personal data may be stored both in paper form and in electronic systems.
11.3. The storage location of records is:
11.4. Electronically stored data is processed in the following system(s):
Location of data storage:
The infrastructure provided by the service provider complies with the applicable data protection and information security requirements.
The following technologies are used in the operation of the website and related systems:
These technologies ensure the stable operation of the Service and an appropriate level of data protection.
11.5. Access to data shall be restricted to those persons who require such access for operational, compliance or service-related reasons.
11.6. The Operator documents its data processing activities and records in accordance with the ICO's accountability requirements.
12.1. The Operator's vehicles, or the vehicles of drivers involved in the provision of the Service, may be equipped with camera systems for security purposes.
12.2. Where a camera is in operation in a particular vehicle, its purpose shall be limited to:
12.3. Under this Policy, the camera is, as a general rule, intended to record the external environment of the vehicle. Interior recording may only be used where this is based on a separate lawful basis, accompanied by appropriate notice, and carried out in compliance with applicable data protection requirements.
12.4. Where a camera used in the vehicle is operated by a self-employed driver acting as an independent data controller, that driver shall be separately responsible for compliance with the data protection obligations applicable to them.
13.1. Use of Cookies
Our website uses so-called cookies in order to ensure proper operation, improve user experience, and support statistical and marketing purposes.
13.2. What are cookies?
Cookies are small data files stored by the browser on the user's device (computer, mobile phone or tablet) when the website is visited.
13.3. What types of cookies do we use?
13.3.1. Necessary cookies
These are essential for the proper functioning of the website. They help us ensure, for example, the basic functions and security of the website. These cookies cannot be switched off.
13.3.2. Statistical (analytical) cookies
These allow us to collect information about how visitors use the website (for example, which pages they visit and how long they spend on them). Such data is processed anonymously.
13.3.3. Marketing cookies
These cookies are used to display relevant advertisements to users and to measure the effectiveness of campaigns.
13.4. Legal basis for cookies
The use of necessary cookies is based on our legitimate interest in the operation of the Service.
All other cookies (statistical and marketing) are used only on the basis of the user's prior consent.
13.5. Managing and deleting cookies
Users may accept or reject the use of cookies at any time through the cookie management interface displayed on the website.
In addition, cookies may also be deleted or disabled in the browser settings.
13.6. Third-party cookies
Third-party service providers (for example analytics or marketing providers) may also place cookies on the user's device. Such providers are subject to their own privacy policies.
14.1. As a general rule, the Operator's services are not intended for children.
14.2. Where the processing of personal data relating to a child nevertheless becomes necessary in the course of providing the Service, the Operator shall act only to the extent lawful, necessary and proportionate, with appropriate safeguards and in compliance with the UK GDPR and the Data Protection Act 2018.
15.1. The Operator shall keep a record of all security incidents affecting personal data.
15.2. Where a personal data breach occurs, the Operator shall assess the associated risk in accordance with applicable law and, where necessary, notify the affected individuals, the ICO, and, where applicable, the competent regulatory authority.
15.3. The Operator shall maintain appropriate internal procedures for the investigation, documentation and remediation of incidents.
In relation to the processing of personal data, data subjects may be entitled to the following rights under applicable data protection legislation:
16.1. Right of access
The data subject has the right to request confirmation as to whether the Operator processes personal data relating to them and to request a copy of such data.
16.2. Right to rectification
The data subject has the right to request the correction of inaccurate or incomplete personal data.
16.3. Right to erasure
The data subject has the right to request the deletion of their personal data where processing is no longer necessary or where the processing is unlawful.
16.4. Right to restriction of processing
The data subject may request the restriction of processing, for example where they contest the accuracy of the data or the lawfulness of the processing.
16.5. Right to object
The data subject has the right to object to processing carried out on the basis of legitimate interests.
16.6. Right to data portability
Where processing is carried out by automated means and is based on a contract or consent, the data subject has the right to request that their personal data be provided in a structured, commonly used format.
16.7. Right to lodge a complaint
The data subject has the right to lodge a complaint with the United Kingdom's supervisory authority for data protection, the Information Commissioner's Office (ICO).
Data subjects may exercise their rights using the Operator's contact details.
17.1. For data protection questions, requests or complaints, data subjects may contact the Operator at:
17.2. Where a data subject believes that the Operator's data processing does not comply with applicable law, they are entitled to lodge a complaint with the Information Commissioner's Office (ICO).
18.1. This Privacy Policy sets out the data processing principles and practices applied by Fair Transfer Ltd t/a Timeless Chauffeurs.
18.2. The Operator reserves the right to amend this Policy from time to time in accordance with applicable law.
18.3. The version of the Policy in force at any given time shall be available on the Operator's website.
Policy Effective Date: 15 May 2026
Last Reviewed: 15 May 2026
Version: 1.0