Who we are
MyLyft Technologies Ltd provides MyLyft ride booking, driver, payment, support, and account services for users in the United Kingdom.
For general business enquiries, contact contact@mylyft.co.uk or +44 7453 262944. For privacy questions, data rights requests, or account deletion questions, contact privacy@mylyft.co.uk.
For UK data protection purposes, MyLyft acts as controller for account, trip, support, safety, driver approval, and platform records unless a separate notice says otherwise.
Personal data we collect
We collect the information needed to create accounts, verify users, request rides, match drivers, process payments, provide support, keep records, and keep the platform secure.
- Account data: name, username, email address, phone number, password credentials, profile image, user type, verification status, and login method.
- Trip data: pickup and drop-off addresses, coordinates, route, ride type, fare estimate, schedule time, assigned driver, vehicle, plate, status history, cancellation reason, ratings, and support notes.
- Location data: rider pickup/drop-off location and driver location while drivers are online or assigned to a trip, including live tracking updates.
- Live ride data: rider live location during an active trip where enabled, driver live location, ETA, route changes, stops, call status, unread message/call indicators, and notification delivery events.
- Payment data: payment method type, protected Stripe customer and payment-method references, card brand/last four digits/expiry for saved-card display, payment status, refund records, receipts, and billing metadata. Full card numbers and CVC are handled by Stripe and are not stored by MyLyft.
- Communications: rider-driver chat messages, push notification tokens, SMS/email verification logs, complaints, and support messages.
- Device and technical data: IP address, device identifiers, push tokens, app version, browser, operating system, security logs, cookies, local storage, crash diagnostics, and delivery logs.
- Driver onboarding data: driver photo, driving licence, taxi/private-hire paperwork, vehicle licence details, insurance, MOT, medical certificate, optional DBS certificate, vehicle documents, review notes, approval status, and safety/compliance records.
How we use personal data
We use personal data to provide the service users ask for, operate the platform safely, meet legal obligations, prevent fraud, and improve reliability.
- Create and secure accounts, including login, social login, phone verification, password reset, and account recovery.
- Find pickup and drop-off addresses, calculate route previews, estimate fares, dispatch ride offers to drivers, and show live trip status.
- Process cash, Stripe card, Apple Pay, and Google Pay records, issue receipts, handle refunds, and investigate payment disputes.
- Send service messages such as OTP codes, booking confirmations, driver arrival updates, ride chat notifications, and safety notices.
- Review complaints, safety reports, fraud signals, chargebacks, driver conduct, rider conduct, and support history.
- Meet private-hire, tax, accounting, insurance, safety, law-enforcement, and regulatory record requirements where applicable.
Lawful bases
Where UK data protection law applies, we rely on different lawful bases depending on the processing activity.
- Contract: to create accounts, provide ride booking, process payment, send service updates, and deliver support.
- Legal obligation: to keep records required for accounting, tax, licensing, safety, fraud, or lawful requests.
- Legitimate interests: to prevent fraud, protect users, improve reliability, investigate disputes, and secure the service.
- Consent: for optional marketing, non-essential cookies, certain device permissions, and push notifications where required.
Location data
Location data is central to a ride-booking service. Riders provide pickup and destination information. Drivers provide live location while they are online, receiving ride offers, or completing a trip.
Rider live location may be used during an active ride to help the assigned driver find the pickup point and improve trip safety. Driver live location is used for nearby driver discovery, ride matching, ETA, trip tracking, safety review, and support.
The rider app and driver app should request device permissions only when needed and should show clear in-app disclosures before collecting sensitive location data. If background location is used, it must be limited to core ride functionality such as driver availability, dispatch, or active trip tracking, and not used for advertising.
App permissions
The mobile apps may request permissions only when needed for the service. Users can manage permissions in device settings, although disabling some permissions can limit ride, driver, notification, or call features.
- Location: pickup selection, route display, live trip tracking, driver dispatch, ETA, and safety review.
- Notifications: ride offers, trip updates, chat messages, incoming ride calls, payment updates, safety notices, and account messages.
- Microphone: optional rider-driver in-app voice calls during active assigned rides. MyLyft does not record ride calls unless a future feature clearly asks for consent and explains retention.
- Camera/photos/files: profile images and driver document uploads where the user chooses to provide them.
Who we share data with
We share data only where needed to run the service, complete a trip, process a payment, comply with law, or protect users.
- Riders and drivers receive limited trip information needed to complete a ride, such as name, pickup/drop-off, vehicle, plate, ETA, and chat messages.
- Stripe processes card, Apple Pay, and Google Pay credentials needed for payments, saved cards, authentication, and refunds.
- Google Maps and related mapping services process address search, maps, geocoding, and routing information.
- Firebase, SMS, email, hosting, analytics, crash reporting, and support providers may process operational data on our behalf.
- Apple App Store, Google Play, Firebase Cloud Messaging, and device platform services may process app identifiers, device tokens, crash, notification, and review-related information according to their own developer and platform terms.
- Licensing authorities, insurers, auditors, courts, regulators, law enforcement, or professional advisers may receive data when legally required or reasonably necessary.
International transfers
Some suppliers and platform services may process data outside the United Kingdom. Where required, MyLyft relies on appropriate safeguards such as adequacy regulations, standard contractual clauses, supplier security terms, or other lawful transfer mechanisms.
Retention
We keep personal data only for as long as needed for the purposes in this policy, including service delivery, safety, complaint handling, fraud prevention, accounting, tax, regulatory, and legal reasons.
- Account records are kept while the account is active and for a limited period after closure where needed for safety, disputes, tax, fraud prevention, or legal compliance.
- Trip, payment, complaint, and safety records may be kept longer where required by private-hire licensing conditions, accounting rules, insurance, dispute resolution, or law.
- Push tokens, session tokens, and diagnostic records are deleted or rotated when no longer needed.
Your rights and choices
Depending on the lawful basis and circumstances, UK users may have rights to access, correct, delete, restrict, object to, or receive a copy of their personal data. Users can also withdraw consent where processing is based on consent.
To exercise rights, email privacy@mylyft.co.uk. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk.
Account deletion
Users can request account deletion inside the app/account area or through the public account deletion page. Deleting an account removes or anonymises account data where possible.
Some records may be retained where necessary for safety, fraud prevention, chargebacks, tax, accounting, licensing, insurance, dispute resolution, or legal obligations. We will explain retained categories when responding to a deletion request.
Children
MyLyft is not intended for children. Users must be old enough to enter into a ride-booking agreement in their country and must not create an account using false identity information.
Security
We use technical and organisational measures designed to protect personal data, including HTTPS, access controls, encrypted secrets, payment provider tokenisation, logging, and restricted admin access.
No online service can guarantee absolute security. Users should use strong passwords, protect their devices, and contact support immediately if they believe their account has been compromised.
