Privacy Policy
Last updated 17 July 2026
Errandly connects neighbours in the United Kingdom so that a helper can do the grocery shopping and delivery for the people who post them — with Buyer Protection that keeps the customer's payment reserved in their own wallet until the job is confirmed done. This policy explains what personal data we collect, why, and who we share it with. It is written to align with the UK GDPR and the Data Protection Act 2018. Errandly is the data controller for the information described here.
1.Who we are
Errandly ("we", "us") operates the errandly.co.uk marketplace and the Errandly web app. For any privacy question, or to exercise the rights in section 8, contact us at privacy@errandly.co.uk.
2.The data we collect
- Account details — your name, email address, phone number and password (stored only as a hash), plus your role (customer, helper, or both).
- Profile & location — delivery addresses, pickup and drop-off points, and the approximate area you operate in, so requests can be matched to nearby helpers.
- Verification data — for helpers and higher spending tiers, a photo of a government ID and a selfie. These are used solely to confirm identity and eligibility.
- Order & wallet activity — the requests you post or accept, messages about a job, receipts and item photos, and a ledger of wallet credits, reserved amounts, earnings and withdrawals.
- Payment metadata — the amount, currency and status of a payment, and a Stripe reference. We never see or store your full card number — card details are entered directly into Stripe (see section 4).
- Support conversations — messages you send to our in-app assistant or support team.
- Technical data — basic device, log and session information needed to keep the service secure and working.
3.Why we use it, and our lawful bases
- To provide the service — matching requests, reserving the order amount in the customer's own wallet, releasing payment on confirmation, and enabling messaging (performance of a contract).
- Identity & safety checks — verifying IDs and reviewing receipts and dispute evidence, including with automated assistance (see section 5), to protect users and prevent fraud (legal obligation and our legitimate interest in a safe marketplace).
- Payments & records — processing charges, withdrawals and refunds, and keeping the financial records the law requires (contract and legal obligation).
- Communications — transactional emails such as order updates and receipts (contract). Marketing, if any, is only ever sent with your consent, which you can withdraw at any time.
- Improving and securing the service — diagnosing faults and preventing abuse (legitimate interests).
4.Who we share it with (our processors)
We do not sell your personal data. We share it only with the service providers that make Errandly work, each acting under contract on our instructions:
- Supabase — hosts our database and files and handles authentication (EU region).
- Stripe — processes card payments and payouts. Card details go directly to Stripe; they are a payment processor and, for their own compliance purposes, a controller of that payment data.
- Zoho ZeptoMail — sends transactional email (EU data centre).
- Anthropic — powers the support assistant and helps review identity and receipt documents. Data sent for these checks is processed to return a result and is not used to train their models.
We may also disclose data where the law requires it, or to establish, exercise or defend legal claims.
5.Automated checks
To keep the marketplace safe we use automated assistance to make a first assessment of identity documents, receipts and dispute evidence, and to answer support questions. These checks fail closed — if documents are missing or unclear, verification is not granted automatically. A decision that materially affects you, such as declining verification or resolving a dispute, is reviewed by a person, and you can ask us to reconsider by contacting support.
6.International transfers
We aim to keep data in the UK or the EEA. Where a provider processes data outside the UK/EEA, that transfer is covered by an adequacy decision or by Standard Contractual Clauses (with the UK Addendum) so your data keeps an equivalent level of protection.
7.How long we keep it
We keep account and profile data while your account is open. Order, wallet and payment records are kept for as long as needed to run the service and to meet legal, tax and anti-fraud obligations (generally up to six years). Verification documents are kept only as long as needed to confirm and maintain eligibility. When data is no longer needed we delete or anonymise it.
8.Your rights
Under UK data-protection law you can ask us to give you access to your data; correct it; delete it; restrict or object to how we use it; and provide a copy in a portable format. Where we rely on consent, you can withdraw it at any time. Email privacy@errandly.co.uk and we will respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk), though we hope you will contact us first.
9.Security
Access to data is restricted by row-level security so users can only reach their own records, passwords are stored only as hashes, card data never touches our servers, and money movements are recorded in an append-only ledger. No system is perfectly secure, but we work to protect your data and will tell you and the ICO about a breach where the law requires.
10.Children
Errandly is for adults aged 18 and over. We do not knowingly collect data from children.
11.Changes
We may update this policy; material changes will be notified in-app or by email. The date at the top shows the current version.