Dashboard Profile Chats

WightRides — Privacy Policy

Last updated: 30 September 2025

This Privacy Policy explains how WightRides collects, uses, shares, and protects your personal data when you use our platform to coordinate cost-sharing rides and ferry travel.

1. Who we are

WightRides ("we", "us", "our") operates an online community platform for genuine cost sharing. We are the data controller for processing described in this policy. Contact details are in Section 13.

2. Scope & summary

  • We collect account data, profile info, listings, messages, ratings, reports, and limited payment metadata for optional VIP/subscriptions.
  • We use this data to run the platform, keep users safe, and improve services, relying on Contract, Legitimate Interests, Consent (where used), and Legal Obligation.
  • We don't act as an escrow and do not process ride cost-sharing between users.

3. Data we collect

3.1 You provide

  • Account: name, email, password hash, phone (optional), address (optional), verification choices, preferences, avatar.
  • Profile & listings: routes, dates, seats, notes/tags, ride requests; ratings/reviews you write.
  • Messages: direct messages you send via the platform.
  • Reports: content of abuse/scam reports you submit.
  • Payments (VIP/subscriptions): plan choice, amount, currency, and payment provider identifiers (e.g., PayPal order/subscription IDs). We do not collect or store full card numbers.

3.2 Automatically collected

  • Technical: IP address, device/browser info, pages viewed, timestamps, error logs.
  • Cookies/Local storage: used for authentication/session, preferences, and basic analytics (see Section 6).

3.3 From others

  • Other users: ratings, messages, and reports about interactions with you.
  • Payment providers: status updates for VIP/subscriptions (e.g., active/cancelled).

4. How we use data (lawful bases)

PurposeExamplesLawful basis
Provide the platform Account creation, login, profile, listings, messaging Contract
Safety and moderation Handle reports, detect spam/abuse, enforce rules Legitimate Interests; Legal Obligation where applicable
VIP/subscriptions Boost visibility, manage subscription status Contract
Service communications Account/security notices, policy updates Legitimate Interests; Legal Obligation
Improvement & troubleshooting Analytics, performance, bug fixing Legitimate Interests
Marketing (if used) Opt-in emails about new features Consent (you can withdraw anytime)
We do not operate as a taxi/PHV or escrow. Any money exchanged for ride costs is strictly between users; we do not process, guarantee, or mediate those payments.

5. Sharing & recipients

  • Other users: profile name, avatar, ratings, and info you include on listings/messages.
  • Service providers: hosting, email, analytics, content moderation, payment processing for VIP/subscriptions. They act under contract and only process data on our instructions.
  • Compliance & safety: we may disclose information to law enforcement or regulators where required by law or to protect users and the platform.
  • Business changes: in a merger, acquisition, or asset sale, data may transfer subject to this Policy.

6. Cookies & similar tech

  • Strictly necessary: session/authentication, security, load balancing.
  • Preferences: UI choices (e.g., filters, theme).
  • Analytics (basic, privacy-minded): aggregate usage to improve reliability. We do not build individual advertising profiles.

You can control cookies via your browser. If we introduce non-essential cookies, we will present a consent banner where required.

7. Security

  • We use safeguards such as TLS, hashed passwords, access controls, and Content-Security-Policy.
  • No method is 100% secure; report suspected issues to [email protected].

8. Retention

We keep data only as long as necessary for the purposes in this Policy, then delete or anonymise it.

CategoryTypical retention
Account dataActive use + up to 24 months after last activity or account closure (longer if required by law/disputes)
Listings (rides/requests)History retained for community integrity (e.g., ratings context); may be anonymised over time
MessagesWhile your account is active; may be retained longer where required for safety, moderation, or legal reasons
Ratings & reportsAs needed for trust/safety and audit; may be anonymised when possible
Payments (VIP metadata)Provider records per legal/tax requirements (typically 6–7 years in the UK)
Logs/analytics90–365 days, unless needed longer for security/investigation

9. International transfers

Your data may be processed outside the UK/EEA by our service providers. Where we transfer data internationally, we rely on appropriate safeguards such as adequacy regulations or Standard Contractual Clauses.

10. Your rights

Under UK GDPR, you have rights to:

  • Access your personal data;
  • Rectify inaccurate data;
  • Erase data where applicable;
  • Restrict or object to processing in certain cases;
  • Portability of data you provided to us;
  • Withdraw consent where processing relies on consent (e.g., marketing).

To exercise rights, contact us (see Section 13). We may need to verify your identity. You also have the right to complain to the ICO.

11. Children

WightRides is for users aged 18+. We do not knowingly collect data from children. If you believe a child has provided data, contact us to remove it.

12. Changes

We may update this Policy from time to time. Material changes will be notified via the platform. Continued use after changes take effect signifies acceptance.

13. Contact & complaints

Email: [email protected]

Security reports: [email protected]

Supervisory authority (UK): Information Commissioner's Office (ICO).

Payments: VIP/subscription payments are handled by third-party providers (e.g., PayPal). Their privacy notices apply to their processing. We store only limited identifiers (order/subscription IDs) and status for account features.