RidenRank Ltd
Privacy policy
Last updated: 2 August 2026
This policy explains how RidenRank Ltd collects and uses personal data in connection with RideDesk (https://ridedesk.app), our software for transport and vehicle-rental operators.
1. Who we are
RidenRank Ltd
A private limited company registered in England & Wales, company number 17315160
33 Meadow Way, Bristol BS32 8BN, United Kingdom
Email: hello@ridenrank.com · Privacy: privacy@ridenrank.com
Phone: +44 7576 995765
RideDesk is a product operated by RidenRank Ltd. It is a brand, not a separate legal entity — RidenRank Ltd is the contracting and responsible party for everything described here.
2. Two different roles — please read this first
RideDesk is business-to-business software. That gives us two distinct roles, and which one applies decides whose privacy policy governs your data.
- We are the controller for the data of the operators who sign up for RideDesk — the transport company, its staff accounts, billing details and how they use the product. That is what this policy covers.
- We are a processor for the data an operator puts into RideDesk about their own customers — passengers, bookings, invoices, messages. The operator is the controller of that data, decides what happens to it, and publishes their own privacy notice. We process it only on their documented instructions under a written data processing agreement.
If you booked a ride or hired a vehicle from a company that uses RideDesk, the company you booked with is the controller — please read their privacy notice, not this one.
3. What we collect about operators
- Account data: name, work email address, password hash, organisation name, role and membership.
- Business and billing data: company legal name, address, VAT ID, registration details, subscription and invoice records.
- Support and correspondence: messages you send us and our replies.
- Technical data: IP address, browser and device type, pages requested, and timestamps, generated automatically when the panel is used and kept in server and security logs.
- Integration credentials: access tokens and account identifiers for the third-party services you choose to connect — see sections 4 and 5.
4. Meta Platform Data (Facebook, Instagram and WhatsApp)
RideDesk is a Meta Tech Provider. An operator may connect their own Facebook Page, Instagram Business account and WhatsApp Business Account to RideDesk so they can publish posts and message their customers from inside the panel. Connecting is entirely optional, is started by the operator, and can be undone at any time.
We access Meta Platform Data only to provide those features to the operator who granted access. We do not sell it, we do not use it for advertising, we do not use it to build profiles, and we do not use it to train machine-learning models. One operator's Meta data is never visible to another operator.
4.1 Permissions we request, and why
| Permission | Product | What we use it for |
|---|---|---|
public_profile | Facebook Login | Identifies the person who connected the account, so the connection can be shown in the panel and removed later. We store their app-scoped ID and name only. |
pages_show_list | Lists the Facebook Pages the person manages so the operator can pick which Page RideDesk should post to. | |
pages_manage_posts | Publishes the operator’s own scheduled posts and photos to the Page they selected. | |
pages_read_engagement | Reads engagement and metadata on the operator’s own Page so it can be shown in the panel. | |
pages_read_user_content | Reads the comments customers leave on the operator’s own Page posts, so those comments can be shown in RideDesk and answered there. Only content on Pages the operator connected is read. | |
pages_manage_metadata | Subscribes the operator’s own Page to comment notifications, so a new comment reaches RideDesk in real time instead of being found by chance later. Used only to register that subscription. | |
pages_manage_engagement | Posts the operator’s replies to comments on their own Page. | |
business_management | Meta Business | Reads which Pages, Instagram accounts and WhatsApp Business Accounts the operator has granted RideDesk, so the correct asset is used. Also required to publish Facebook Page Stories. |
instagram_basic | Reads the Instagram Business account linked to the selected Page (ID and username) so posts can be addressed to it. | |
instagram_content_publish | Publishes the operator’s own feed posts and stories to their Instagram Business account. | |
instagram_manage_comments | Reads comments on the operator’s Instagram posts and posts their replies. | |
whatsapp_business_messaging | WhatsApp Business Platform | Sends and receives messages on the operator’s own WhatsApp Business number — booking confirmations, driver details, invoices and two-way conversations with their customers. |
whatsapp_business_management | WhatsApp Business Platform | Registers the operator’s phone number, subscribes it to message webhooks, and creates and manages the message templates their notifications use. |
4.2 What we store
- Access tokens for the connected Page, Instagram account and WhatsApp Business Account, plus the app-scoped ID of the person who granted them. Tokens are encrypted at rest (AES-256-GCM) and are never sent to a browser.
- Account identifiers and labels: Page ID and name, Instagram Business account ID and username, WhatsApp Business Account ID, phone number ID and verified display name.
- Content the operator publishes: the posts, captions, images and scheduling they create in RideDesk, and the ID of the resulting post.
- Comments and replies on the operator’s own Facebook and Instagram posts, so they can be read and answered in the panel.
- WhatsApp messages sent to and from the operator’s business number: message text, attachments, the Meta message ID, timestamps, delivery status, and the customer’s phone number. These are shown to the operator’s staff as a conversation thread and linked to the relevant booking.
Message content and phone numbers in WhatsApp threads are the operator’s customer data — for that data the operator is the controller and we are their processor, exactly as described in section 2.
4.3 How long we keep it
- Access tokens are held until the operator disconnects the account, the person who granted them removes our app, or the operator’s RideDesk account is closed — whichever happens first. They are then deleted.
- Published-post records and message threads are kept for as long as the operator’s account is open, because they are that operator’s business record of what was sent to their customers. They are deleted when the account is closed, or earlier on the operator’s instruction.
- A customer who replies STOP to a WhatsApp message is recorded as opted out and receives no further messages from that operator through RideDesk.
4.4 How to remove it
- In RideDesk: Settings → Social or Settings → WhatsApp → Disconnect. This deletes the stored tokens and revokes the grant with Meta.
- In Facebook: Settings & Privacy → Settings → Business Integrations → remove RideDesk. Meta notifies us and we delete the connection automatically.
- By request: email privacy@ridenrank.com and we will delete the data and confirm in writing.
Removing the app in Facebook triggers our deauthorization and data-deletion callbacks, which delete the stored tokens and connection records for that person across every organisation they connected. You can check the status of a deletion request at https://ridedesk.app/api/social/meta/data-deletion.
5. Other services an operator can connect
Operators may also connect their own Google Business Profile, payment providers (Stripe, PayPal, SumUp), email mailboxes (IMAP/SMTP) and other messaging providers. In each case we store only the credentials and identifiers needed to operate the connection, encrypted at rest, and use them solely to provide the feature the operator switched on. Payment credentials belong to the operator's own merchant account — we never hold card details, which are handled by the payment provider directly.
6. Why we process it, and our legal bases
- To provide, operate and support the RideDesk service under our contract with the operator — Art. 6(1)(b) UK GDPR / GDPR (performance of a contract).
- To keep the service secure, prevent abuse and fraud, and maintain proper business records — Art. 6(1)(f) (legitimate interests). You may object at any time.
- To meet our legal, tax and accounting obligations — Art. 6(1)(c) (legal obligation).
- To send service-related messages about your account. Marketing about similar services is sent under legitimate interests within the direct-marketing rules and can be stopped at any time; where consent is required we ask for it — Art. 6(1)(a).
- Data an operator loads into RideDesk about their own customers is processed on that operator’s documented instructions — Art. 28.
7. Who we share it with
We share personal data only with providers who help us run the service, and only as far as they need it. Each acts under a written contract. The current list is published at https://ridedesk.app/legal/subprocessors.
We may also disclose data where the law requires it, or to establish or defend legal claims. We do not sell personal data and we do not share it for anyone else’s marketing.
8. International transfers
Our database, file storage and email sending are pinned to EU regions. Some providers nevertheless process data outside the UK/EEA. Where they do, we rely on UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, the EU-US Data Privacy Framework, or the EU Standard Contractual Clauses, with any additional safeguards needed. You may request a copy of these safeguards from us.
9. How long we keep it
- Operator account and organisation records: for the life of the account, then deleted or anonymised.
- Invoices and tax records: six years after the end of the relationship, as UK accounting and limitation rules require.
- Security, access and platform event logs: a short rolling period for diagnostics and abuse prevention.
- Integration tokens and connection records: as set out in section 4.3.
- Data processed on an operator’s behalf: as set out in that operator’s data processing agreement.
10. Security
- All traffic is served over HTTPS with HSTS and a restrictive content security policy.
- Third-party credentials and access tokens are encrypted at rest with AES-256-GCM and are never exposed to the browser.
- Every organisation’s data is isolated by tenant, enforced in both the database and the application layer.
- Access to production data is limited to the people who need it, and access to customer identity documents is recorded in an audit trail.
- No transmission over the internet is ever completely secure, so please do not send us passwords or payment card details by email.
11. Your rights
You have the right to be informed about our processing, and to access, rectify, erase, restrict or object to it, to receive your data in a portable form, and to withdraw any consent you have given. Exercising these rights is free.
To exercise any right, email privacy@ridenrank.com. We may ask you to confirm your identity first, and we aim to respond within one month. If you are a passenger or customer of an operator that uses RideDesk, please contact that operator — they are the controller of your data and we will refer your request to them.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office (ICO), the UK supervisory authority, at ico.org.uk. If you are in the EU you may instead complain to your national data protection authority.
12. Automated decisions and children
We carry out no automated decision-making or profiling that produces legal or similarly significant effects. AI-assisted features may draft text for a member of staff to review and send; a human always decides whether to send it. RideDesk is sold to businesses, not to children, and we do not knowingly collect data about anyone under 18.
13. Changes to this policy
We update this policy as the product changes; the date at the top shows the current version. Material changes are notified to operators in the panel or by email.