Privacy Policy

Last updated: 1 July 2026

1. Who we are

LogisticsFlow is a software-as-a-service platform for delivery slot management, operated by VBU4 Limited (trading as LogisticsFlow), a company registered in England and Wales.

Company name: VBU4 Limited (trading as LogisticsFlow)
Registered in: England and Wales
Contact email: privacy@logisticsflow.co.uk
Website: www.logisticsflow.co.uk

VBU4 Limited is the data controller for personal data collected from visitors to our website and users of the LogisticsFlow platform. Where we process personal data on behalf of our business customers (e.g. their employees, suppliers, or drivers), we act as a data processor.

2. What personal data we collect

We collect the following categories of personal data:

  • Account data: Name, email address, job title, and company name when you register an account or contact us.
  • Authentication data: Hashed password, email verification status, and session tokens.
  • Business operations data: Booking records, delivery slots, supplier details, warehouse sites, driver names, vehicle registrations, and collection records entered through the platform.
  • Document data: Files uploaded against bookings (e.g. proof of delivery, compliance documents). Stored securely in Cloudflare R2.
  • Usage data: Pages visited, features used, timestamps, IP addresses, and browser/device information collected via server logs.
  • Communications: Messages sent through the platform's booking messaging feature, or emails sent to our support team.
  • Payment data: Processed securely by our payment provider. We do not store card numbers or full payment details.

3. How we use your data

We use your personal data to:

  • Create and manage your account and company profile
  • Provide, operate, and improve the LogisticsFlow platform
  • Process delivery bookings, send approval notifications, and coordinate supplier and driver communications
  • Send transactional emails (booking confirmations, slot approvals, password resets, weekly digest reports)
  • Respond to support requests and enquiries
  • Enforce platform security and prevent fraud or unauthorised access
  • Comply with our legal obligations under UK law
  • Analyse platform usage to improve performance and user experience

We do not sell your data to third parties. We do not use your data for advertising or marketing profiling.

4. Legal basis for processing

We rely on the following lawful bases under UK GDPR:

  • Contract performance (Article 6(1)(b)): Processing necessary to provide the platform you have signed up for.
  • Legitimate interests (Article 6(1)(f)): Platform security, fraud prevention, abuse detection, and product improvement, where our interests do not override your rights.
  • Legal obligation (Article 6(1)(c)): Where processing is required to comply with UK law.
  • Consent (Article 6(1)(a)): For optional communications (e.g. marketing emails), where we will always ask for your permission first.

5. Data retention

We retain your personal data according to the following policy:

  • Active accounts: Data is retained for the duration of your subscription.
  • Closed accounts: Data is retained for 30 days after account closure to allow for data export requests, then permanently deleted.
  • Booking records: Retained for 7 years after the booking date to comply with potential legal and contractual obligations.
  • Uploaded documents: Retained for 12 months from upload date (configurable by the account administrator), then permanently deleted from our storage.
  • Server logs: Retained for 90 days for security and debugging purposes.
  • Anonymised/aggregated data: May be retained indefinitely for analytics purposes, this cannot be used to identify any individual.

6. Your rights under UK GDPR

You have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Ask us to correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): Request deletion of your personal data, subject to our legal retention obligations.
  • Right to restriction: Ask us to pause processing of your data in certain circumstances.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at privacy@logisticsflow.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

7. Cookies

We use essential cookies to maintain your login session and protect against fraud. These are strictly necessary and cannot be disabled. We may also use analytics cookies to understand how the platform is used, these are anonymous and aggregated. You can manage your cookie preferences at any time on our Cookie Preferences page.

8. Third-party data processors

We use the following trusted third-party service providers who act as data processors under our instructions. Each has been selected for their security standards and GDPR compliance, and we have Data Processing Agreements (DPAs) in place with each:

  • Neon Inc. · Managed PostgreSQL database hosting. Your platform data is stored in their EU (London) region. Neon Privacy Policy
  • Vercel Inc. · Platform hosting and deployment (serverless infrastructure). Vercel Privacy Policy
  • Cloudflare Inc. (R2 Storage) · Secure file and document storage. Files stored in Cloudflare's infrastructure with encryption at rest. Cloudflare Privacy Policy
  • Resend Inc. · Transactional email delivery (booking notifications, account emails, password resets). Resend Privacy Policy

We do not share your data with any other third parties except where required by law.

9. International transfers

Some of our third-party processors (including Vercel and Resend) are based in the United States. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR, including Standard Contractual Clauses (SCCs) or reliance on adequacy decisions where applicable.

10. Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • TLS encryption for all data in transit
  • AES-256 encryption for data at rest
  • Bcrypt password hashing (minimum 12 rounds)
  • Role-based access control, each user sees only the data they are authorised to access
  • Company data isolation, client companies cannot access each other's data
  • HttpOnly, Secure, SameSite session cookies
  • Email verification required before account activation
  • Manual account approval gate for new registrations
  • Security headers (HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy)

11. Data breach notification

In the event of a personal data breach, VBU4 Limited will notify the Information Commissioner's Office (ICO) within 72 hoursof becoming aware of the breach, where it is likely to result in a risk to individuals' rights and freedoms, in accordance with Article 33 of UK GDPR. Where a breach is likely to result in a high risk to individuals, we will also notify affected users without undue delay.

12. Children's data

LogisticsFlow is a business-to-business platform and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email to registered account holders with at least 14 days' notice. The current version will always be available at this URL.

14. Contact us

For any questions about this Privacy Policy or how we handle your data, please contact:

VBU4 Limited (trading as LogisticsFlow)
Email: privacy@logisticsflow.co.uk