Who we are
This policy explains how Wheelerate (“we”, “us”) handles personal data when you use the Wheelerate application and this website.
For anything about your personal data, email hello@wheelerate.com.
What this policy covers
This policy covers the personal data we handle for our own purposes: the accounts people use to sign in to Wheelerate, the way we run and secure the service, and this website.
Operators, the safari and tour companies that use Wheelerate, also keep their own information in it: their customers, drivers, bookings and quotes. The operator decides what that information is and why it is kept; we process it only on the operator’s behalf and on its instructions, under our data processing agreement. If you are an operator’s customer or driver, contact the operator first; we will help it answer you.
What we collect and why
- Your account
-
Your name, your email address and the identifier your organization’s identity provider gives you. We receive them when you sign in; we never see or store your password. We use them to give you access and to show your team who did what.
Why: to provide the service you or your organization asked for.
- Your team and roles
-
The organizations you belong to, your role in each (owner, administrator, operations, finance or viewer), and invitations, including the email address an invitation was sent to. We use them to decide what you can see and do.
Why: to provide the service.
- What changed, and who changed it
-
A record of the changes made in your organization: who made each one and when. Contact details, notes and itineraries appear in it only as “changed”, never with their values; the names of customers and drivers appear when they are renamed.
Why: your organization’s and our legitimate interest in security and accountability.
- Paying for Wheelerate
-
When an organization subscribes: the billing email address and name its owner gives, its plan, its invoices, and each payment’s result. Payments are made on Paystack’s own pages: we never see or store a card number, security code or PIN, or an M-Pesa PIN. From a card payment we keep only the card’s brand, its last four digits and its expiry date, to show which card renews the subscription.
Why: to provide the subscription the organization chose, and to keep the records of what was billed and paid.
- How the service is used
-
Technical records: the network address a request came from when it reaches our network’s edge, the time, the page asked for (without search terms), user and organization identifiers, and a reference number for each request. They never contain names, email addresses, phone numbers or anything you typed.
Why: our legitimate interest in keeping Wheelerate secure and working, and in investigating problems you report to us.
- When you contact us
-
Your email address and what you write, so that we can answer you.
Why: to answer you, including before you use Wheelerate.
- This website
-
No forms, no analytics and no cookies. The provider that delivers it sees your network address, as every website’s host does, to send you the pages and to protect the site.
Why: our legitimate interest in delivering the site and keeping it secure.
Information operators keep in Wheelerate
Operators use Wheelerate to record their customers (names, email addresses and phone numbers), their drivers (names, phone numbers, licence numbers and expiry dates), vehicles, quotes, bookings (including pickup and drop-off places and itineraries) and costs.
Each operator is responsible for this information as its data controller, and we process it as the operator’s data processor, only to provide Wheelerate to that operator. The data processing agreement sets out what we do with it. Wheelerate keeps each organization’s information separate: the members of one organization cannot see another’s.
Where it is stored
Wheelerate’s data is hosted on Google Cloud. If it is stored outside the country you are in, your personal data is transferred there; we transfer it only as data protection law allows, with the safeguards it requires.
How long we keep it
- Your account: while it exists. You can delete it yourself at any time, from Your account in Wheelerate: it is deleted at once. We then forget your name, your email and how you sign in, and keep only an anonymous number, so that what you did in an organization still has an author there. Your sign-in itself (your password and second factor) is held by your identity provider.
- Information operators keep in Wheelerate: for as long as the operator keeps it. An operator can download all of it, or erase what identifies one of its customers or drivers, at any time; and it can delete its organization, which is then deleted with all its information 14 days later, unless it cancels. See the data processing agreement.
- The record of changes: for as long as the organization exists, because it is the organization’s record of who changed what. When a person’s details are erased, they are erased from the record of changes too.
- Billing records: invoices and payments for as long as the organization exists, as the record of what was billed and paid; they are deleted with it. Paystack keeps its own records of payments as the law that applies to it requires.
- Technical records: only as long as we need them to support you and to investigate security incidents; then they are deleted.
- Backups: 14 days, so that Wheelerate can be recovered after a failure; then they expire. Information deleted from Wheelerate leaves the backups when they expire.
How we protect it
- Each organization’s information is kept apart by the database itself: every request carries a signed statement of the organization it acts for, and the database refuses anything that belongs to another.
- Connections are encrypted. Backups are encrypted before they are stored and can be read only with a recovery key kept offline.
- You sign in at your organization’s identity provider, so Wheelerate never holds passwords. Sessions end after at most 12 hours.
- Within an organization, roles decide what each person can see and do, and every change is recorded.
- Our logs are designed to hold no names, contact details or anything you typed.
No system is perfectly secure. If a breach affects your personal data, we will tell you, or the operator responsible for it, as data protection law requires.
Your rights
Subject to the law that applies to you, you can ask us to:
- tell you what personal data we hold about you, and give you a copy of it;
- correct it if it is inaccurate or misleading;
- delete it;
- restrict its use, or object to it;
- give it to you in a format you can take elsewhere.
You can do two of these yourself in Wheelerate, from Your account: download a copy of everything Wheelerate holds about you, in formats you can take elsewhere (JSON and CSV), and delete your account. For the rest, email hello@wheelerate.com. We may need to confirm who you are before we act, and we will answer within the time the law allows. For information an operator keeps about you in Wheelerate, as its customer or driver, ask that operator; we will help it answer you.
If you are unhappy with how your personal data has been handled, you can complain to the data protection authority where you live; in Kenya, that is the Office of the Data Protection Commissioner.
Children
Wheelerate is a service for businesses. It is not meant for children, and we do not knowingly collect personal data from anyone under 18.
Changes to this policy
If we change this policy, we will publish the new version here with the date it takes effect. If a change is significant, we will also tell the owners of the organizations that use Wheelerate before it takes effect.
Contact us
Email hello@wheelerate.com.