Skip to content
Security and trust

Built so that nobody has to take anyone’s word for it

Last reviewed 3 September 2026. The full security and incident response policy is published in our repository as SECURITY.md; this page is the summary. Researchers: see security.txt.

Drivers

Before their first job, drivers verify their identity with a government photo ID and a live selfie. We read and review their driving licence and their insurance certificate, which must cover courier or hire-and-reward use; UK vehicle registrations are also checked against the DVLA register. Licence and insurance carry expiry dates, and a driver whose document has expired cannot go on shift until it is replaced. Ratings and on-time history follow every delivery, and tiers gate higher-value and ID-check jobs. Suspended drivers lose access immediately. The driver apps attest the device (Apple App Attest, Google Play Integrity) before going on shift, accepting a job or requesting a payout.

Deliveries

Every stop declares its proof requirements and the driver app cannot complete a stop without them. Steps are geo-fenced: a driver cannot mark a pickup or delivery from somewhere else, and impossible speeds or mock locations are blocked and flagged for review. Photos are geo-stamped and stored in a private bucket; clients receive time-limited signed URLs. Disputes freeze funds until a person reviews.

Money

Prepaid wallet with an append-only ledger. Funds are held at creation and only captured after confirmation. Card payments run through Stripe Checkout; we never see card numbers. USDC deposits settle on-chain through a facilitator. Spending caps per delivery and per day are enforced server-side.

Accounts and signup

Self-serve signup refuses disposable email domains and domains without mail servers, limits accounts per network and per company domain per day, supports a human check (Cloudflare Turnstile) and only unlocks wallet funding after the email is verified.

API and integrations

API keys are hashed at rest and shown once. TLS everywhere, HSTS, strict content-type handling. Rate limits per key and IP. Outbound webhooks are signed with HMAC-SHA256 and a timestamp. Inbound Shopify and Stripe webhooks are verified against their signing secrets and de-duplicated, so a replayed event is ignored. Driver, admin and Shopify sessions are short-lived signed tokens; Shopify store access tokens are encrypted at rest with a key that exists only on the API server. The public map shows rounded positions with no identity.

Access control and logging

Order and delivery data is readable only through the operations dashboard, which sits behind an admin login with roles (superadmin, operations, support, viewer), or through the account’s own API key or Shopify session. Drivers receive the contact details of their active job only, and only while it is active. Every authenticated API request is logged with key, route, status and time; every operator action is written to an audit log; every delivery step and every fraud signal is recorded. Admin accounts are created by operations only, passwords are hashed with argon2id, and production secrets are held in the cluster, never in source control.

Infrastructure and backups

The API, website and dashboard run on a Kubernetes cluster in Frankfurt; the database and file storage run on a dedicated server in the EU. Full database and storage backups run twice daily, are kept for 14 days and are copied to off-site object storage that is encrypted at rest. Disks are mirrored. The database host itself is not yet disk-encrypted; that is on our roadmap and is listed as a known limitation in the policy rather than hidden.

Data retention

DataKept
Proof photos and signatures90 days
Driver location history30 days
Recipient contact details on a deliveryPhone masked after 30 days; record 3 years
Shopify order recipient details (name, address, phone, note, items)Blanked 90 days after the order; the booking record stays
Processed Shopify webhook payloads30 days
Financial records7 years (legal requirement)

Shopify’s customer-redact and shop-redact requests are processed automatically: the affected order rows are blanked, and an uninstalled store’s data is deleted in full. Data requests: privacy@rentadriver.ai.

Incident response

Every report to security@rentadriver.ai is triaged within four hours. A confirmed incident is contained first (credentials rotated, accounts disabled, attack path closed, evidence preserved), then assessed from the request, audit and event logs to establish exactly which records and accounts are affected. We notify affected clients and merchants without undue delay and within 72 hours of confirmation, notify Shopify within 24 hours when Shopify merchant or customer data is involved, and notify supervisory authorities and individuals where the applicable law requires it. Each incident ends with a written root-cause review and tracked follow-ups.

Reporting a vulnerability

Email security@rentadriver.ai. We acknowledge within two business days, keep you informed, credit you if you wish, and do not pursue researchers acting in good faith who avoid privacy violations and service disruption and give us reasonable time to fix before disclosure.

Support