Privacy Policy
Last updated:September 9, 2026
This Policy explains how AtlasSwift (Terxel Neo Vision Ltd) collects, uses, retains, and shares personal data through its website, Platform, and the AtlasSwift Ops mobile application. It complements the Terms of Service and, for end-customer data processed for Merchants, the Data Processing Agreement (DPA).
1) Who is the controller?
AtlasSwift is operated by Terxel Neo Vision Ltd, a company under UK law (No. 13441558), registered office: 483 Green Lanes, London, N13 4BS, United Kingdom. For most data relating to Merchants (accounts, billing, support), AtlasSwift acts as the controller. For end-customer data processed on behalf of a Merchant (logistics execution), AtlasSwift acts as a processor under the DPA.
2) Scope & data subjects
This Policy applies to website visitors, Merchants, logistics partners and their teams, including delivery drivers, sales staff and supervisors using AtlasSwift Ops, as well as end-customers whose data is processed through our Services.
3) Data we process
3.1 Account & professional relationship data
- Identity & contact: first/last name, email, phone, company, role.
- Credentials & security: login, hashed passwords, roles, access logs.
- Billing & B2B payments: addresses, VAT, bank details, invoice history.
- KYC/Compliance (if required): identity documents, AML/Sanctions information.
3.2 Execution data (Merchants’ end-customers)
- Contact & delivery: name, phone, address, geographic location of the delivery destination, delivery instructions.
- Order & proof: products, amounts, statuses, photos/OTP/signatures, timestamped logs.
- Cash on delivery / mobile money: amounts collected, transaction references/IDs. We do not collect full payment card numbers.
3.3 Technical & usage data
- Connection logs, IP address and country estimated from it, device and app identifiers, phone model, operating system, app version, language and time zone.
- Pages viewed, interactions with features, cookies/online identifiers and identifiers needed to deliver notifications.
- Diagnostics, performance metrics, error messages, support tickets.
3.4 Location in AtlasSwift Ops
- Data and purposes. With your permission, AtlasSwift Ops accesses your phone’s precise or approximate location, depending on your settings. This is used to show your position on the map, calculate and optimise routes, and guide you to delivery destinations.
- Driver tracking. When you are signed in with a delivery driver account and location is authorised, the app may regularly collect and send your location to AtlasSwift. For deliveries assigned to you, your latest position, linked to your name and the update time, enables authorised AtlasSwift personnel and your logistics partner to coordinate deliveries.
- Background use. Location collection and navigation may continue when the app is not visible, including while you use another app or lock your screen. Driver account tracking does not depend solely on the navigation screen being open.
- Your choices. You can refuse or withdraw location permission in your phone’s settings. Signing out of AtlasSwift Ops also stops the app from tracking your location. Without location access, navigation and live tracking may be unavailable. We do not use your location for advertising.
3.5 Photos, supporting documents & notifications
- When you attach a receipt or supporting document, the app accesses the photo you select and sends it to AtlasSwift to associate it with the relevant order.
- We use notifications to inform you about orders and account activity. You can manage the available categories in the app and allow or disable notifications in your phone’s settings.
3.6 Sensitive data
We do not intend to process special categories of data (health, biometrics, etc.). If a Merchant sends such data, the Merchant must have a lawful basis and notify us in advance (see DPA).
4) Purposes & legal bases
| Purpose | Examples | Legal basis |
|---|---|---|
| Provision of Services | Account creation, order execution, delivery, collection, payouts, supporting documents and service notifications | Contract performance |
| Navigation & delivery tracking | Position on the map, routes, navigation and driver coordination | Contract performance or legitimate interests in organising deliveries, depending on your relationship with us; consent where required |
| Support & security | Assistance, recognition of sign-in devices, incident detection, fraud prevention | Legitimate interests / legal obligations |
| Billing & compliance | Invoices, accounting, KYC/AML, authority requests | Legal obligation |
| Improvement & analytics | Usage analytics, performance, usability | Legitimate interests (with minimisation) |
| B2B marketing | Product communications, newsletters | Consent or legitimate interests (opt-out) |
Where required by law, we obtain your consent (e.g., non-essential cookies, electronic marketing).
5) Cookies & trackers
We use cookies/trackers that are (i) strictly necessary for operation, (ii) for audience measurement, (iii) for functionality and, where applicable, (iv) for advertising. You can manage your preferences via the cookie banner or at any time: Cookie settings.
Refusing certain cookies may degrade your experience.
6) Sources of data
- You (forms, account, support).
- The Merchant or logistics partner (for team accounts, assignments and end-customers).
- Service providers (payments, logistics, KYC verification).
- Automatically through the website and app (device data, logs, cookies and location according to the permissions granted).
7) Sharing with third parties
To provide our Services, we share data with service providers for hosting, payments, messaging, telephony, analytics, support and transport, bound by contractual confidentiality and security obligations.
Order information and supporting documents are accessible to people authorised to manage the delivery. Drivers’ live locations are accessible to authorised AtlasSwift personnel and the logistics partner they work with, for ongoing deliveries.
Map and navigation features use Google Maps, which receives data including location, device and usage information to provide and improve its services. Notifications use Firebase Cloud Messaging (Google), which processes app identifiers to deliver messages to your phone. See Google’s Privacy Policy and Firebase’s privacy information.
If you choose to share a receipt or contact a customer through another app, including WhatsApp, the information you choose to send is shared with that app and the intended recipient, under their own privacy rules.
We may also share data with authorities where required by law, or to enforce our rights, prevent fraud, or protect individuals.
8) International transfers
Data may be transferred outside your country (e.g., EU/EEA ↔ United Kingdom, or other countries where our providers/carriers operate). We apply appropriate safeguards (adequacy decisions, Standard Contractual Clauses / UK IDTA, technical and organisational measures) in accordance with the UK GDPR, the Data Protection Act 2018, and, where applicable, the EU GDPR.
9) Retention periods
- Merchant account & contractual documents: for the duration of the relationship, then up to 6 years (UK tax/accounting obligations).
- KYC/Compliance: generally 5 years after the end of the relationship, unless local law differs.
- Technical logs: 12 months (security/diagnostics), unless an incident requires longer retention.
- Support tickets: 24 months.
- Driver location for live tracking: the latest position replaces the previous one and is retained for up to 90 seconds after receipt for this tracking. This period does not apply to delivery addresses or locations associated with orders, or to data processed by Google under its own policy.
- Execution data (end-customers), including delivery destinations and supporting documents: for the service duration, then according to applicable evidentiary and limitation periods.
- Analytics cookies: according to the lifetime set in the consent manager.
After these periods, data is deleted or anonymised unless the law requires otherwise.
10) Security
We apply technical and organisational measures proportionate to risks: encryption in transit and at rest where relevant, role-based access control, MFA for sensitive access, logging and incident response, backups and restore tests, vendor security reviews.
No system is risk-free: best-efforts obligation and continuous improvement.
11) Automated decisions & profiling
We may use rules or scoring (e.g., fraud prevention, support prioritisation) with a limited impact. No automated decision produces legal effects concerning you or similarly significantly affects you without human involvement. You may request human review, express your point of view, and contest a decision.
12) Your rights
AtlasSwift is operated from the United Kingdom. Under the UK GDPR and the Data Protection Act 2018, you have rights including access, rectification, erasure, objection, restriction, portability, and to withdraw consent where processing is based on consent. Where the EU GDPR applies to our processing (for example if you are in the EEA), broadly equivalent rights may apply. To exercise your rights, contact: [email protected].
For data processed on a Merchant’s behalf (end-customers), also address your request to the Merchant (controller) in line with the DPA.
13) Children & vulnerable individuals
Our Services are not directed to children. When a Merchant collects minors’ data, the Merchant must have a lawful basis and the permissions required by local law. If you believe a minor has provided data to us without authorisation, contact us for deletion.
14) External links
The Platform may contain links to third-party sites/apps. We are not responsible for their privacy practices. Please consult their dedicated policies.
15) Changes to this Policy
We may update this Policy for legal, technical, or operational reasons. We will inform you by email, banner, or via the Platform, indicating the effective date. Your continued use after the update constitutes acceptance.
16) Contact & complaints
Questions, requests or complaints: [email protected]. Operational support: [email protected].
You can lodge a complaint with the competent supervisory authority. In the UK: the Information Commissioner’s Office (ICO). In the EEA: your local data protection authority.